<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=prisma+with+astro%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Wed, 29 Jul 2026 19:59:26 +0200</lastBuildDate>
<pubDate>Wed, 29 Jul 2026 19:59:26 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=prisma+with+astro%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=prisma+with+astro%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[The agent security gap: 54% of enterprises have already had an AI agent incident, and most still let agents share credentials]]></title>
<description><![CDATA[Across 107 enterprises, AI agents are being given real access to systems and data while the controls meant to contain them lag behind. More than half have already had a confirmed agent security incident or a near-miss; only about a third give every agent its own scoped identity, and most agents s...]]></description>
<link>https://tsecurity.de/de/3689827/it-nachrichten/the-agent-security-gap-54-of-enterprises-have-already-had-an-ai-agent-incident-and-most-still-let-agents-share-credentials/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689827/it-nachrichten/the-agent-security-gap-54-of-enterprises-have-already-had-an-ai-agent-incident-and-most-still-let-agents-share-credentials/</guid>
<pubDate>Thu, 23 Jul 2026 19:19:41 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Across 107 enterprises, AI agents are being given real access to systems and data while the controls meant to contain them lag behind. More than half have already had a confirmed agent security incident or a near-miss; only about a third give every agent its own scoped identity, and most agents still share credentials; and only three in ten isolate their highest-risk agents. The security stack is overwhelmingly borrowed from the model providers and hyperscalers rather than purpose-built for agents, spending remains a thin slice of the security budget, and enterprises are evenly split on whether their defenses are keeping pace with AI-enabled attackers. The result is an agent security gap — autonomous agents proliferating faster than the identity, isolation, and enforcement controls needed to hold them.</p><p>This wave of VentureBeat Pulse Research examines how enterprises secure their AI agents: what tooling they run, how they manage agent identity and isolation, what has already gone wrong, how much they spend, and whether they believe their defenses are keeping pace with AI-enabled attackers.</p><p>The central finding is an agent security gap — the distance between the autonomy enterprises are granting their agents and the controls in place to contain them. More than half of organizations (54%) have already experienced a confirmed agent security incident (18%) or a near-miss caught before harm (36%). The structural weakness beneath those numbers is identity: only about a third (32%) give every agent its own scoped, managed identity, while the rest report that some agents share credentials or that agents mostly run on shared API keys and human or service-account credentials. When agents share credentials, a single compromised or over-permissioned agent carries a wide blast radius — and only three in ten enterprises (30%) isolate their highest-risk agents in sandboxes to bound that radius.</p><p>What makes the gap notable is how comfortable enterprises are inside it. The security stack is overwhelmingly provider-native — OpenAI’s guardrails (51%), Google’s and Microsoft’s cloud controls, and Anthropic’s managed-agent controls dominate, while the dedicated agent-security specialists barely register — and satisfaction with that borrowed stack is high, averaging 4.2 out of 5. Yet spending remains a thin slice of the security budget, only a third of enterprises believe their AI defenses are ahead of AI-enabled attackers, and a clear majority plan to change tooling within the year. Enterprises are satisfied with controls they are simultaneously preparing to replace.</p><h2>Methodology</h2><p>VentureBeat fielded this survey as part of its ongoing Pulse Research series, this instrument focused on enterprise agent security — the tooling, identity, isolation, and enforcement controls organizations use to secure autonomous AI agents. Responses are filtered to organizations with more than 100 employees (n=107; the survey’s smallest size band, 1–100 employees, is excluded), drawn from a single June 2026 wave. Because this is one wave rather than a pooled multi-month sample, the report reads cross-sectionally and does not infer month-over-month trends. Several questions were multiple-select, so those shares can sum to more than 100%.</p><p>By role the sample is senior and buyer-credible: 45% are final decision-makers for AI purchases and another 30% recommenders or influencers. Managers (43%), individual contributors (24%), VPs and directors (15%), and the C-suite (11%) make up the seniority mix. By organization size the sample is mid-market-weighted: 251–1,000 (42%) and 101–250 (25%) employees lead, with 1,001–5,000 (19%), 5,001–10,000 (8%), and 10,001+ (7%) above them. Technology/Software is the largest industry at 23%, followed by Manufacturing (15%), Retail/E-commerce (14%), and Healthcare/Life Sciences (13%).</p><p>At 107 respondents the sample is large enough to read directionally but should be treated as a directional signal rather than a precise measurement; it is self-selected and is not a probability sample. It skews toward the mid-market, so it is best read as the view from organizations actively standing up agent security rather than from the largest operators.</p><p>Satisfaction ratings are computed on the respondents who answered each rating question; the overall satisfaction score reflects 82 of the 107 qualified respondents.</p><h2>Finding 1: The incidents are already here</h2><p><b>More than half have had an agent security incident or near-miss</b></p><p>We asked whether organizations had experienced an agent security incident — a confirmed breach, or a near-miss caught before harm. Most that run agents in production had.</p><div></div><p>This is the report’s defining number. More than half of organizations (54%) have already had an agent security event — 18% a confirmed incident and 36% a near-miss caught before it caused harm. Only 42% report nothing, and a small remainder either run no agents in production or don’t track such events. That so many report near-misses rather than only confirmed incidents is telling: enterprises are catching problems, but they are catching them close to the edge. The controls examined in the rest of this report — identity, isolation, enforcement — are what determine whether the next near-miss stays a near-miss.</p><p>Exposure scales with company size, but containment does not. The incident-or-near-miss rate rises from 49% in the mid-market (companies with 101-1,000 employees) to 63% at larger enterprises (above 1,000 employees), while sandbox isolation of high-risk agents falls from 35% to 20%, and satisfaction with security tooling drops from 4.36 to 3.97. The organizations running the most agents across the most systems carry the most incidents and the least of the one control that bounds an incident's blast radius.</p><h2>Finding 2: The identity gap</h2><p><b>Only a third give every agent its own scoped identity</b></p><p>We asked how enterprises manage the identity of their AI agents — whether each agent has its own credentials, or agents share them. Full per-agent identity is the exception.</p><div></div><p>Rolled together, the overlapping answers show 69% of enterprises (74 of 107) with credential sharing somewhere in the agent fleet. Identity is the structural weakness beneath the incidents. Only about a third of enterprises (32%) give every agent its own scoped, managed identity — the precondition for least-privilege access and clean attribution. Nearly half (48%) say some agents have scoped identities but many still share credentials, and another 32% say agents mostly run on shared API keys or borrowed human and service-account credentials. (Respondents could describe more than one pattern across their agent fleet, so these overlap.) </p><p>The consequence is direct: when agents share credentials, an over-permissioned or compromised agent can act with far more reach than intended, and forensics after an incident cannot cleanly tell which agent did what. The non-human identity problem — giving every agent its own governed identity — is the single largest unfinished piece of enterprise agent security.</p><p>Moreover, a company’s agent credential posture is correlated with incidents. Organizations with credential sharing anywhere in the fleet were hit — with an incident or a near-miss in the past twelve months — at 63.5% (47 of 74). Organizations where every agent carries its own scoped identity were hit at 40.9% (9 of 22). The fully-scoped group is small, so for now the relationship is an association rather than proven causation, and the gap is concentrated in the mid-market — but within a single survey, a twenty-three point difference in incident rate suggests significance.</p><h2>Finding 3: Observe and enforce, but rarely isolate</h2><p><b>Only three in 10 sandbox their highest-risk agents</b></p><p>We asked what an organization’s agent security posture looks like in practice — whether they observe, enforce, isolate, or some combination. The control that bounds damage is the least common.</p><div></div><p>Monitoring and enforcement are reasonably common; containment is not. Roughly half of enterprises observe agent activity (47%) or enforce scoped permissions at runtime (49%), but only 30% isolate their highest-risk agents in sandboxes that bound the blast radius when the other controls fail. That ordering is backwards from a defense-in-depth standpoint: observation tells you what happened, enforcement tries to prevent it, but isolation is what limits the damage when prevention fails — and it is the control enterprises have adopted least. Combined with the identity gap in Finding 2, the picture is of agents that are watched and permissioned but rarely boxed in, which is precisely the configuration in which a single failure propagates.</p><h2>Finding 4: Security runs on borrowed, provider-native controls</h2><p><b>Guardrails from OpenAI, Google and Microsoft dominate; specialists barely register</b></p><p>We asked which agent security tooling enterprises use, and which is their primary layer. The answer favors the model providers and hyperscalers over the dedicated security vendors.</p><div></div><p>Enterprises are securing agents with tools that came bundled with their models and clouds. OpenAI’s guardrails lead at 51%, followed by Google’s and Microsoft’s cloud-native controls and Anthropic’s managed-agent controls — and when asked to name their single primary security layer, 82% name one of these provider-native offerings. The purpose-built agent-security category — Palo Alto’s Prisma AIRS, CrowdStrike, Cisco AI Defense, Zenity, HiddenLayer, Check Point’s Lakera, Okta for AI Agents, non-human identity platforms — barely registers, each in the low single digits, and only 5% run no dedicated tooling at all. As with retrieval and evaluation elsewhere in this series, the provider bundle is winning the default: enterprises reach first for the guardrails their platform ships, and the independent security layer that would address the identity and isolation gaps has not yet been adopted at scale.</p><p>The provider-default pattern is consistent across both Q2 survey waves. In April–May (n=110), usage was led by the same names — OpenAI's controls at 26%, Azure at 15%, AWS at 14%, Google at 12% — with every dedicated agent-security specialist at 3% or below and one in ten using no dedicated tooling at all. The common finding from the two surveys: Enterprises are defaulting to the solutions provided by the platform they’re using, and the specialist category vendors have yet to become big players here.</p><p>(<i>A note on reading these shares. As described in the methodology section, the respondent sample is self-selected and skews mid-market, and the usage question counted every vendor or approach a respondent has in place — so the figures measure presence in the security stack rather than spending or exclusivity. Individual vendor percentages therefore carry all the usual sample caveats. The structural pattern, however, held across both Q2 waves on two differently worded questions: provider-native and hyperscaler controls lead, and dedicated agent-security specialists remain in low single digits. Read the individual shares loosely and the pattern with confidence.)</i></p><h2>Finding 5: And enterprises are comfortable with it</h2><p><b>Satisfaction is high, even as incidents mount and identity lags</b></p><p>We asked how satisfied enterprises are with their current agent security tooling. The comfort is notably out of step with the exposure documented above.</p><div></div><p>Satisfaction with agent security tooling is high — 4.2 out of 5 overall, and 4.1 for value for money — among the most positive readings in this series. That is the striking part: enterprises are highly satisfied with a stack that is mostly borrowed provider guardrails, even though more than half have already had an incident or near-miss and only a third give their agents scoped identities. The comfort appears to rest on the convenience and low friction of provider-native controls rather than on demonstrated containment. It is a false comfort in the making — the same enterprises expressing satisfaction are, as Finding 8 shows, a clear majority planning to change tooling within the year, which suggests the confidence is thinner than the score implies.</p><h2>Finding 6: Budgets haven’t caught up</h2><p><b>Most spend under a tenth of the security budget on agents</b></p><p>We asked what share of the security budget enterprises allocate to securing AI agents. For a fast-emerging risk, the allocation is modest.</p><div></div><p>Spending on agent security is still a thin slice. The most common allocation is 6–10% of the security budget (46%), and a third of enterprises (34%) spend 5% or less; only a quarter (24%) devote more than a tenth. Given the incident rate in Finding 1 and the identity and isolation gaps in Findings 2 and 3, the budget looks like a lagging indicator — the risk has arrived faster than the funding to address it. The enterprises spending more than a tenth of their security budget on agents are a distinct minority, and they are likely the ones building the scoped-identity and isolation controls the rest have not.</p><h1>Finding 7: The arms race is even, at best</h1><p><b>Only a third think their AI defenses are ahead of AI-enabled attackers</b></p><p>We asked how enterprises assess the balance between their AI-enabled defenses and AI-enabled attackers. Confidence is far from settled.</p><div></div><p>Enterprises are split on whether they are winning. Only about a third (35%) believe their AI-enabled defenses are ahead of AI-enabled attackers; the rest are less sure — 32% call it roughly even, 21% think attackers are ahead, and another 21% say it is too early to tell. Taken together, a clear majority (53%) rate the balance as even or tilted toward the attacker. That uncertainty sits uneasily beside the high satisfaction of Finding 5: enterprises are content with their tooling yet unconvinced it is winning the contest it exists to win. In a domain where the offense is also compounding with AI, an even race is not a comfortable place to be.</p><h2>Finding 8: A security reshuffle is coming</h2><p><b>Nearly six in 10 plan to adopt or switch tooling within a year</b></p><p>We asked whether enterprises plan to adopt a new, additional, or replacement agent security solution, and which they are considering. Few intend to stand pat.</p><div></div><p>The security stack is not settled. While 41% have no plans to change, a clear majority (59%) intend to adopt a new, additional, or replacement agent security solution within twelve months, and 29% within the next quarter — a strong signal that, high satisfaction notwithstanding, enterprises know the current stack is provisional. Incidents are what start the buying cycle. </p><p>Among organizations that have been hit, 42.1% plan to adopt, add, or replace agent security tooling within the next ninety days, against 14.0% of organizations with no incident — and after a confirmed incident it becomes majority behavior, at 52.6%. Getting hit also changes the threat assessment: 33.3% of hit organizations say AI-armed attackers are ahead of their defenses, against 8.0% of the unhit. Experience, in this data, is the strongest predictor of both urgency and pessimism.</p><p>The consideration set still leans provider-native (OpenAI 34%, Google 30%, Anthropic 29%, Azure 25%), but the dedicated security vendors — Cloudflare, Cisco, Palo Alto, Okta, Check Point’s Lakera — draw early interest in the mid-to-high single digits, more than their current footprint. </p><p>What the shopping does not yet include is the identity layer specifically. Twelve percent of the respondents include an agent-identity product — Okta for AI Agents, Microsoft Entra Agent ID, or a non-human identity platform — anywhere in their consideration set, and among the credential-sharing organizations that have already had an incident, identity consideration is essentially unchanged, at roughly one in ten. The control most directly implicated by the incident data is the one largely missing from the purchase plans. Whether this wave hardens the provider-native default or finally opens the door to purpose-built agent security — the identity and isolation controls the incidents call for — is the question this series will keep tracking.</p><h2>The bottom line: A security gap that autonomy will test first</h2><p>Organizations with more than 100 employees are giving AI agents real reach into systems and data while securing them with controls built for something else. More than half have already had an incident or near-miss; only a third give every agent its own scoped identity, and most still share credentials; only three in ten isolate their highest-risk agents; and the stack doing this work is overwhelmingly borrowed from the model providers and hyperscalers rather than purpose-built for agents.</p><p>The uncomfortable pairing is confidence with exposure: satisfaction with the current tooling is among the highest in this series, yet spending is a thin slice of the security budget, only a third believe their defenses are ahead of AI-enabled attackers, and a clear majority are already planning to replace what they have. At 107 respondents in a single wave this is a directional read, skewed toward the mid-market — but the direction is clear: agent adoption is running ahead of agent security, and the controls that matter most when something fails — scoped identity and isolation — are the ones enterprises have built least. The agent security gap is not a coverage problem that a provider guardrail will close on its own; it is a problem of identity, isolation, and enforcement built for autonomous software. The open question for later waves is whether enterprises close it deliberately — or whether a confirmed incident closes it for them.</p><hr><p><i>Based on survey responses from 107 qualified enterprise respondents (100+ employees), drawn from a single June 2026 wave. This is a directional read, not a precise measurement — the sample is self-selected and skews mid-market, so it's best read as the view from organizations actively standing up agent security rather than from the largest operators. Respondents are senior and buyer-credible (45% final decision-makers, 30% recommenders/influencers), spanning managers through the C-suite, and drawn primarily from Technology/Software, Manufacturing, Retail/E-commerce, and Healthcare/Life Sciences.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Agentic coding is everywhere]]></title>
<description><![CDATA[I use a very cool and relatively new web framework called Astro. The keen insight that the Astro team had was that most websites are made up of static content, so they made it really easy to add content to a website. To add a blog post to my personal website, all I have to do is create a Markdown...]]></description>
<link>https://tsecurity.de/de/3685748/ai-nachrichten/agentic-coding-is-everywhere/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685748/ai-nachrichten/agentic-coding-is-everywhere/</guid>
<pubDate>Wed, 22 Jul 2026 11:04:58 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">I use a very cool and relatively new web framework called <a href="https://www.infoworld.com/article/3842325/designing-a-dynamic-web-application-with-astro-js.html" data-type="link" data-id="https://www.infoworld.com/article/3842325/designing-a-dynamic-web-application-with-astro-js.html">Astro</a>. The keen insight that the Astro team had was that most websites are made up of static content, so they made it really easy to add content to a website. To add a blog post to <a href="https://nickhodges.com/">my personal website</a>, all I have to do is create a Markdown file with some front matter, deploy it, and the blog post automatically appears. If I need to reach deeper for more dynamic functionality, I can easily do that with <a href="https://www.infoworld.com/article/2257305/what-is-typescript-strongly-typed-javascript.html" data-type="link" data-id="https://www.infoworld.com/article/2257305/what-is-typescript-strongly-typed-javascript.html">TypeScript</a>, <a href="https://www.infoworld.com/article/2253289/react-tutorial-get-started-with-the-reactjs-javascript-library.html" data-type="link" data-id="https://www.infoworld.com/article/2253289/react-tutorial-get-started-with-the-reactjs-javascript-library.html">React</a>, or almost any other framework. It’s really cool.</p>



<p class="wp-block-paragraph">And these days, I really don’t write any code. <a href="https://www.infoworld.com/article/4136718/claude-code-is-blowing-me-away.html" data-type="link" data-id="https://www.infoworld.com/article/4136718/claude-code-is-blowing-me-away.html">Claude Code</a> does most (all?) of the work. Since Astro is <a href="https://github.com/withastro/astro">an open-source project</a> and has <a href="https://docs.astro.build/">excellent documentation</a>, Claude knows all about how Astro works. It has no trouble at all managing my site and making the improvements I ask for.  </p>



<p class="wp-block-paragraph">And that got me thinking, how does Astro get built? Is the Astro team building with agentic coding? Astro itself has many dependencies, including big projects like Vite and Node. And of course, Vite and Node have dependencies, too. Are those dependencies being developed by hand, or are those development teams also using AI agents to code?</p>



<p class="wp-block-paragraph">My curiosity got the best of me, and I asked Claude to dig deeper. It turns out that the Astro repository has <a href="https://github.com/withastro/astro/blob/main/AGENTS.md">an AGENTS.md</a> file, and some of the commits even have commit message trailers indicating that they were at least co-authored by Claude and <a href="https://www.infoworld.com/article/3609013/github-copilot-everything-you-need-to-know.html" data-type="link" data-id="https://www.infoworld.com/article/3609013/github-copilot-everything-you-need-to-know.html">GitHub Copilot</a>. Further down, there is a <code>.agents/skills</code> directory with skills covering development, merging, triage, and more. I poked around for a look, and someone has done a great job building agentic support.</p>



<p class="wp-block-paragraph">Now my interest is really piqued, and further investigation reveals quite a bit of interesting stuff. About a year ago, documentation started appearing about how to build Astro sites with coding agents.  Around that same time, the docs team released an <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html" data-type="link" data-id="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">MCP server</a> that gives developers coding agents deeper, easier access to the Astro documentation.  </p>



<p class="wp-block-paragraph">And there are small steps in the Astro codebase that indicate it is “agentic ready.” For instance, the command-line development server can tell when it is being started by an agent, and the application itself can tell if it is being driven by an agent. Small things, but steps in the direction of embracing Astro developers who use coding agents. </p>



<p class="wp-block-paragraph">Okay, that was a fun spelunking trip. But so what?</p>



<p class="wp-block-paragraph">The “so what” is that code is going to be commoditized. As an Astro developer I am using AI agents pretty much all of the time. The Astro development team is starting to use AI agents more and more. The folks building the Astro dependencies are using AI agents. Shoot, the people building Claude Code and the agents themselves are “eating their own dogfood” and <a href="https://www.anthropic.com/institute/recursive-self-improvement">using their own tools to build the next frontier model</a>. Before we know it, it will be <a href="https://en.wikipedia.org/wiki/Turtles_all_the_way_down">turtles all the way down</a>. </p>



<p class="wp-block-paragraph">No one says “who generated that electricity?” or “who wove the fabric in that shirt?” any more. And it won’t be long before no one says “Who wrote the code for that app?” because it won’t matter. Just as we don’t look at the assembly code written by our compilers, we’ll stop looking at the “regular” code written by our agents. I’m not even sure anyone is <a href="https://news.ycombinator.com/item?id=39587051" data-type="link" data-id="https://news.ycombinator.com/item?id=39587051">writing assembly code anymore</a>. Soon we’ll be saying that about TypeScript, Python, and C++.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tools, um MCP-Server abzusichern]]></title>
<description><![CDATA[width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px">Unabhängig davon, welche MCP-Server Unternehmen wofür einsetzen – “Unsicherheiten” sollten dabei außenvorbleiben.Gorodenkoff | shutterstock.com



Model Context Protocol (MCP) verbindet KI-Agenten mit Datenquellen und erfre...]]></description>
<link>https://tsecurity.de/de/3685216/it-security-nachrichten/tools-um-mcp-server-abzusichern/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685216/it-security-nachrichten/tools-um-mcp-server-abzusichern/</guid>
<pubDate>Wed, 22 Jul 2026 06:10:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption">Unabhängig davon, welche MCP-Server Unternehmen wofür einsetzen – “Unsicherheiten” sollten dabei außenvorbleiben.</figcaption></figure><p class="imageCredit">Gorodenkoff | shutterstock.com</p></div>



<p class="wp-block-paragraph">Model Context Protocol (<a href="https://www.computerwoche.de/article/4031227/was-ist-model-context-protocol.html" target="_blank">MCP</a>) verbindet KI-Agenten mit Datenquellen und erfreut sich im Unternehmensumfeld wachsender Beliebtheit. Allerdings ist auch MCP nicht frei von Sicherheitslücken, wie entsprechende Entdeckungen, etwa beim SaaS-Anbieter <a href="https://www.upguard.com/blog/asana-discloses-data-exposure-bug-in-mcp-server" target="_blank" rel="noreferrer noopener">Asana</a> oder dem IT-Riesen <a href="https://www.catonetworks.com/blog/cato-ctrl-poc-attack-targeting-atlassians-mcp/" target="_blank" rel="noreferrer noopener">Atlassian</a> gezeigt haben. Inzwischen hat sich jedoch einiges in Sachen MCP-Sicherheit getan. Einerseits wurden mit Blick auf das Kernprotokoll etliche Fortschritte erzielt. Beispielsweise in Form von Support für OAuth sowie für Authentifizierungs-Server von Drittanbietern und Identity-Management-Systeme. Darüber hinaus wurde inzwischen auch eine <a href="https://modelcontextprotocol.info/tools/registry/" target="_blank" rel="noreferrer noopener">offizielle MCP Registry</a> geschaffen, die einen Überblick über sichere, öffentlich verfügbare MCP-Server bietet.</p>



<p class="wp-block-paragraph">Dennoch bestehen weiterhin Sicherheitslücken, die sich für diverse Cyberschandtaten ausnutzen lassen – <a href="https://www.computerwoche.de/article/4044551/wenn-der-ki-agent-im-fakeshop-kauft.html" target="_blank">Prompt Injection</a>, Tool Poisoning, Token-Diebstahl, Server-übergreifende Attacken oder manipulierte Messages sind nur einige von vielen Beispielen. Mit anderen Worten: Unternehmen, die sich beim <a href="https://www.computerwoche.de/article/4049237/3-tipps-um-agentic-ai-systeme-in-der-cloud-zu-entwickeln.html" target="_blank">Aufbau von Agentic-AI-Systemen</a> einen Wettbewerbsvorteil verschaffen wollen, müssen erhebliche Anstrengungen unternehmen, um zu gewährleisten, dass sensible Daten nicht nach außen dringen. Glücklicherweise gibt es diverse Tools, die dabei Unterstützung versprechen.</p>



<p class="wp-block-paragraph">In diesem Artikel lesen Sie:</p>



<ul class="wp-block-list">
<li>was Security-Tools für MCP leisten sollten, und</li>



<li>welche Angebote in diesem Bereich interessant sind.</li>
</ul>



<h2 class="wp-block-heading">Das sollten MCP-Sicherheitslösungen können</h2>



<p class="wp-block-paragraph">Die Gefahr von Datenlecks, Prompt Injections und weiteren Sicherheitsbedrohungen besteht unabhängig davon, ob Unternehmen:</p>



<ul class="wp-block-list">
<li>ihre eigenen KI-Agenten mit MCP-Servern von Drittanbietern,</li>



<li>ihre eigenen MCP-Server mit Drittanbieter-Agenten, oder</li>



<li>ihre eigenen Server mit den eigenen Agenten verbinden.</li>
</ul>



<p class="wp-block-paragraph">Soll heißen: Unternehmen müssen in jedem Fall Autorisierungen und Berechtigungen überprüfen, detaillierte Zugriffskontrollen implementieren und alles protokollieren. Daraus ergeben sich auch die Anforderungen für MCP-Sicherheitslösungen. Diese sollten bieten:</p>



<ul class="wp-block-list">
<li><strong>MCP-Servererkennung.</strong> Für Mitarbeiter eines Unternehmens ist es einfach, MCP-Server herunterzuladen und zu nutzen. Mit Scan-Services für MCP-Server können Unternehmen sämtliche Instanzen von Schatten-MCP-Servern in ihrer Umgebung finden.</li>



<li><strong>Laufzeitschutz.</strong> KI-Agenten kommunizieren mit MCP-Servern in natürlicher Sprache. MCP-Sicherheits-Tools sollten deshalb in der Lage sein, diese Kommunikation auf Sicherheitsprobleme wie Prompt Injections hin zu überwachen.</li>



<li><strong>Authentifizierungs- und Zugriffskontrollen.</strong> Das MCP-Protokoll unterstützt inzwischen OAuth, aber das ist nur ein erster Schritt. Für zusätzliche Sicherheit empfehlen sich Tools mit integrierten Kontroll-Frameworks für Zero Trust und Least Privilege.</li>



<li><strong>Logging und Observability.</strong> Tools und Plattformen sollten zudem die Möglichkeit bieten, MCP-Protokolle zu sammeln, Sicherheitsteams über Richtlinienverstöße zu informieren, Compliance-Daten zu erfassen oder Protokolle in die bestehende Sicherheitsinfrastruktur einzuspeisen.</li>
</ul>



<h2 class="wp-block-heading">MCP-Security-Angebote</h2>



<p class="wp-block-paragraph">Im Folgenden haben wir die Anbieter von MCP-Security-Tools in drei Kategorien aufgeteilt. Diese Aufstellung erhebt keinen Anspruch auf Vollständigkeit.</p>



<p class="wp-block-paragraph"><strong>Hyperscaler</strong></p>



<p class="wp-block-paragraph">Für Unternehmen, die sich vollständig auf eine bestimmte Cloud-Plattform verlassen, bieten die MCP-Tools des jeweiligen Hyperscalers einen einfachen Einstieg.</p>



<ul class="wp-block-list">
<li><strong>Amazon Web Services (AWS)</strong> hat Mitte 2025 seine eigene agentenbasierte KI-Plattform eingeführt. <a href="https://aws.amazon.com/de/bedrock/agentcore/" target="_blank" rel="noreferrer noopener">Amazon Bedrock AgentCore</a> umfasst ein Gateway, das mehrere Protokolle unterstützt (darunter auch MCP), ein Identity-Management-System sowie Observability.</li>



<li><strong>Microsoft</strong> bietet einen grundlegenden <a href="https://learn.microsoft.com/de-de/azure/developer/azure-mcp-server/overview" target="_blank" rel="noreferrer noopener">Azure-MCP-Server</a> an, inklusive Support für Azure Key Vault. Darüber hinaus unterstützen auch Azure AI Foundry Agent Service und Azure API Management das Model Context Protocol. Zudem bietet Microsoft mit dem <a href="https://learn.microsoft.com/de-de/agent-framework/overview/agent-framework-overview" target="_blank" rel="noreferrer noopener">Agent Framework</a> auch ein Open-Source-Entwicklungskit, das sowohl MCP als auch Agent2Agent unterstützt und beispielsweise Schutz vor Prompt Injections verspricht.</li>



<li><strong>Google Cloud</strong> kündigte Anfang 2025 seine <a href="https://cloud.google.com/blog/products/ai-machine-learning/mcp-toolbox-for-databases-now-supports-model-context-protocol?hl=en" target="_blank" rel="noreferrer noopener">MCP Toolbox für Datenbanken</a> an – inklusive integrierter Authentifizierung und Observability. Außerdem hat der Hyperscaler auch <a href="https://cloud.google.com/blog/products/identity-security/how-to-secure-your-remote-mcp-server-on-google-cloud?hl=en" target="_blank" rel="noreferrer noopener">eine Referenzarchitektur</a> veröffentlicht, um MCP-Server auf seiner Cloud-Plattform abzusichern.</li>
</ul>



<p class="wp-block-paragraph"><strong>Große Plattformanbieter</strong></p>



<ul class="wp-block-list">
<li>Der IT-Dienstleister <strong>Cloudflare</strong> hat mit <a href="https://blog.cloudflare.com/zero-trust-mcp-server-portals/" target="_blank" rel="noreferrer noopener">MCP Server Portals</a> ein Tool veröffentlicht, mit dem Unternehmen MCP-Verbindungen zentralisiert absichern und überwachen können. Die Funktion ist Bestandteil der Cloudflare-One-Plattform.</li>



<li><strong>Palo Alto Networks</strong> hat mit Blick auf MCP-Sicherheit mehrere Eisen im Feuer. Mit <a href="https://www.paloaltonetworks.com/blog/2025/06/securing-ai-agent-innovation-prisma-airs-mcp-server/" target="_blank" rel="noreferrer noopener">Prisma AIRS</a> hat das Unternehmen einen eigenen, intermediären MCP-Server veröffentlicht. Dieser sitzt zwischen den KI-Agenten und dem eigentlichen MCP-Server und erkennt schadhafte Inhalte und Daten. Das Tool <a href="https://www.paloaltonetworks.com/blog/2025/06/cloud-security-model-context-protocol-mcp-security/" target="_blank" rel="noreferrer noopener">MCP Security</a> ist hingegen Bestandteil von Cortex Cloud WAAS und überprüft die MCP-Kommunikation an der Netzwerkgrenze auf bösartige Aktivitäten.</li>



<li><strong>SentinelOne</strong> gewährt mit seiner <a href="https://www.sentinelone.com/blog/avoiding-mcp-mania-how-to-secure-the-next-frontier-of-ai/" target="_blank" rel="noreferrer noopener">Singularity Platform</a> ebenfalls Einblick in die MCP-Interaktionskette und bietet zum Beispiel Warnmeldungen und automatisierte Incident Response für MCP-Server auf lokaler oder Remote-Ebene.</li>



<li>Die <a href="https://acuvity.ai/" target="_blank" rel="noreferrer noopener">Plattform</a> von <strong>Acuvity</strong> (seit Februar 2026 Teil von <strong>Proofpoint</strong>) verspricht, MCP-Server umfassend abzusichern. Dafür sorgt laut dem Anbieter eine Kombination aus Least-Privilege-Execution, unveränderlichen Laufzeiten, kontinuierlichen Schwachstellenscans, Authentifizierung und Bedrohungserkennung.</li>



<li>Daneben hat auch <strong>Broadcom</strong> MCP-Sicherheitsfunktionen für VMware Cloud Foundation <a href="https://www.broadcom.com/company/news/product-releases/63401" target="_blank" rel="noreferrer noopener">angekündigt</a>, die künftig mehr Sicherheit für agentenbasierte Workflows gewährleisten sollen.</li>
</ul>



<p class="wp-block-paragraph"><strong>Startups</strong></p>



<ul class="wp-block-list">
<li>Das API-Security-Startup <strong>Akto</strong> hat eine <a href="https://www.akto.io/mcp-security" target="_blank" rel="noreferrer noopener">MCP-Security-Plattform</a> im Angebot. Sie umfasst ein Discovery Tool, um MCP-Server in Unternehmensumgebungen zu identifizieren, Security-Testing-Werkzeuge sowie Monitoring- und Threat-Detection-Funktionen.</li>



<li><strong>Invariant Labs</strong> bietet mit <a href="https://github.com/invariantlabs-ai/mcp-scan" target="_blank" rel="noreferrer noopener">MCP-Scan</a> ein quelloffenes Tool, das die statische Analyse und Echtzeitüberwachung von MCP-Servern ermöglicht. Mit <a href="https://invariantlabs.ai/blog/guardrails" target="_blank" rel="noreferrer noopener">Guardrails</a> hat das Startup auch ein kommerzielles Produkt im Angebot. Dabei handelt es sich um einen Proxy. Der zwischen KI-Agenten und MCP-Servern sitzt und vor Security-Risiken schützen soll. Das Tool befähigt Anwender außerdem dazu, Richtlinien aufzusetzen.</li>



<li><strong>Highflame </strong>(vormals Javelin) <a href="https://www.highflame.com/" target="_blank" rel="noreferrer noopener">addressiert</a> ebenfalls das Thema MCP-Sicherheit. Etwa mit Funktionen wie MCP-Server auf Risiken zu scannen oder Datenanfragen zu überprüfen.  </li>



<li><strong>Lasso Security</strong> stellt ein Open-Source-<a href="https://github.com/lasso-security/mcp-gateway" target="_blank" rel="noreferrer noopener">MCP-Gateway</a> zur Verfügung, das die Konfiguration und das Lebenszyklusmanagement von MCP-Servern ermöglicht und Messages um sensible Informationen bereinigt.</li>
</ul>



<p class="wp-block-paragraph">(fm)</p>



<p class="wp-block-paragraph"><strong>Dieser Artikel ist <a href="https://www.csoonline.com/article/4087656/what-cisos-need-to-know-about-new-tools-for-securing-mcp-servers.html" target="_blank">im Original</a> bei unser Schwesterpublikation CSOonline.com erschienen.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW]]></title>
<description><![CDATA[View CSAF
Summary
Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Customers are advised to consult and implement the workarounds provided in Palo Alto Networks' upstream s...]]></description>
<link>https://tsecurity.de/de/3684508/it-security-nachrichten/siemens-ruggedcom-ape1808-with-palo-alto-networks-virtual-ngfw/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684508/it-security-nachrichten/siemens-ruggedcom-ape1808-with-palo-alto-networks-virtual-ngfw/</guid>
<pubDate>Tue, 21 Jul 2026 19:45:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-02.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Customers are advised to consult and implement the workarounds provided in Palo Alto Networks' upstream security notifications. [1] https://security.paloaltonetworks.com/</strong></p>
<p>The following versions of Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW are affected:</p>
<ul>
<li>RUGGEDCOM APE1808 vers:all/* </li>
</ul>
<div class="csaf-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS</th>
<th role="columnheader">Vendor</th>
<th role="columnheader">Equipment</th>
<th role="columnheader">Vulnerabilities</th>
</tr>
</thead>
<tbody>
<tr>
<td>v3 7.2</td>
<td>Siemens</td>
<td>Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW</td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Missing Authorization, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</td>
</tr>
</tbody>
</table>
</div>
<h3>Background</h3>
<ul>
<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>
<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>
<li><strong>Company Headquarters Location: </strong>Germany</li>
</ul>
<hr>
<h2>Vulnerabilities</h2>
<div class="csaf-accordion">
<p><a class="csaf-accordion-toggle-all" href="https://www.cisa.gov/#">Expand All +</a></p>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-0266</a></h3>
<div class="csaf-accordion-content">
<p>A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma® Access are not affected by this vulnerability.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-0266">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Contact customer support to receive patch and update information</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/79.html">CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>2.4</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N">CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-0272</a></h3>
<div class="csaf-accordion-content">
<p>A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with access to the Command Line Interface (CLI) to perform actions on the device with root privileges. The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators and by restricting access to the management interface to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-0272">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Contact customer support to receive patch and update information</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/862.html">CWE-862 Missing Authorization</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N">CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-0273</a></h3>
<div class="csaf-accordion-content">
<p>A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI or Web UI. The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators and by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma® Access are not affected by this vulnerability.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-0273">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Contact customer support to receive patch and update information</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/78.html">CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.2</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<hr>
<h2>Acknowledgments</h2>
<ul>
<li>Siemens ProductCERT reported these vulnerabilities to CISA.</li>
</ul>
<hr>
<h2>General Recommendations</h2>
<p>As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity</p>
<hr>
<h2>Additional Resources</h2>
<p>For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories</p>
<hr>
<h2>Terms of Use</h2>
<p>The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.</p>
<hr>
<h2>Legal Notice and Terms of Use</h2>
<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>
<hr>
<h2>Recommended Practices</h2>
<p>CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.</p>
<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>
<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>
<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>
<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<hr>
<h2>Advisory Conversion Disclaimer</h2>
<p>This ICSA is a verbatim republication of Siemens ProductCERT SSA-104023 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.</p>
<h2>Revision History</h2>
<ul>
<li><strong>Initial Release Date: </strong>2026-07-14</li>
</ul>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Date</th>
<th role="columnheader">Revision</th>
<th role="columnheader">Summary</th>
</tr>
</thead>
<tbody>
<tr>
<td>2026-07-14</td>
<td>1</td>
<td>Publication Date</td>
</tr>
<tr>
<td>2026-07-21</td>
<td>2</td>
<td>Initial CISA Republication of Siemens ProductCERT SSA-104023 advisory</td>
</tr>
</tbody>
</table>
<hr>
<h2>Legal Notice and Terms of Use</h2>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-0277 | Palo Alto Prisma Access Agent Certificate Validation channel accessible]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in Palo Alto Prisma Access Agent. This affects an unknown part of the component Certificate Validation. Executing a manipulation can lead to channel accessible by non-endpoint.

This vulnerability is tracked as CVE-2026-0277. The attack...]]></description>
<link>https://tsecurity.de/de/3677491/sicherheitsluecken/cve-2026-0277-palo-alto-prisma-access-agent-certificate-validation-channel-accessible/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677491/sicherheitsluecken/cve-2026-0277-palo-alto-prisma-access-agent-certificate-validation-channel-accessible/</guid>
<pubDate>Sat, 18 Jul 2026 07:35:56 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/palo_alto:prisma_access_agent">Palo Alto Prisma Access Agent</a>. This affects an unknown part of the component <em>Certificate Validation</em>. Executing a manipulation can lead to channel accessible by non-endpoint.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2026-0277">CVE-2026-0277</a>. The attack can be launched remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-0243 | Palo Alto Prisma SD-WAN ION up to 25.3.2 unchecked input for loop condition]]></title>
<description><![CDATA[A vulnerability identified as critical has been detected in Palo Alto Prisma SD-WAN ION up to 5.5.x/6.0.x/24.3.5/25.1.7/25.3.2. Affected by this vulnerability is an unknown functionality. This manipulation causes unchecked input for loop condition.

This vulnerability is registered as CVE-2026-02...]]></description>
<link>https://tsecurity.de/de/3676098/sicherheitsluecken/cve-2026-0243-palo-alto-prisma-sd-wan-ion-up-to-2532-unchecked-input-for-loop-condition/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676098/sicherheitsluecken/cve-2026-0243-palo-alto-prisma-sd-wan-ion-up-to-2532-unchecked-input-for-loop-condition/</guid>
<pubDate>Fri, 17 Jul 2026 14:53:50 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">critical</a> has been detected in <a href="https://vuldb.com/product/palo_alto:prisma_sd-wan_ion">Palo Alto Prisma SD-WAN ION up to 5.5.x/6.0.x/24.3.5/25.1.7/25.3.2</a>. Affected by this vulnerability is an unknown functionality. This manipulation causes unchecked input for loop condition.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2026-0243">CVE-2026-0243</a>. The attack requires access to the local network. No exploit is available.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-0248 | Palo Alto Prisma Access Agent up to 26.2.0 on Android/Chrome certificate validation]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in Palo Alto Prisma Access Agent up to 26.2.0 on Android/Chrome. This issue affects some unknown processing. The manipulation results in improper certificate validation.

This vulnerability was named CVE-2026-0248. The attack may be ...]]></description>
<link>https://tsecurity.de/de/3675942/sicherheitsluecken/cve-2026-0248-palo-alto-prisma-access-agent-up-to-2620-on-androidchrome-certificate-validation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675942/sicherheitsluecken/cve-2026-0248-palo-alto-prisma-access-agent-up-to-2620-on-androidchrome-certificate-validation/</guid>
<pubDate>Fri, 17 Jul 2026 13:55:22 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, was found in <a href="https://vuldb.com/product/palo_alto:prisma_access_agent">Palo Alto Prisma Access Agent up to 26.2.0</a> on Android/Chrome. This issue affects some unknown processing. The manipulation results in improper certificate validation.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-0248">CVE-2026-0248</a>. The attack may be performed from remote. There is no available exploit.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-0247 | Palo Alto Prisma Access Agent up to 26.2.0 DLP Endpoint missing authentication]]></title>
<description><![CDATA[A vulnerability was found in Palo Alto Prisma Access Agent up to 26.2.0. It has been declared as critical. This affects an unknown function of the component DLP Endpoint. Executing a manipulation can lead to missing authentication.

This vulnerability is tracked as CVE-2026-0247. The attack is re...]]></description>
<link>https://tsecurity.de/de/3675726/sicherheitsluecken/cve-2026-0247-palo-alto-prisma-access-agent-up-to-2620-dlp-endpoint-missing-authentication/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675726/sicherheitsluecken/cve-2026-0247-palo-alto-prisma-access-agent-up-to-2620-dlp-endpoint-missing-authentication/</guid>
<pubDate>Fri, 17 Jul 2026 12:21:41 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/palo_alto:prisma_access_agent">Palo Alto Prisma Access Agent up to 26.2.0</a>. It has been declared as <a href="https://vuldb.com/kb/risk">critical</a>. This affects an unknown function of the component <em>DLP Endpoint</em>. Executing a manipulation can lead to missing authentication.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2026-0247">CVE-2026-0247</a>. The attack is restricted to local execution. No exploit exists.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-0244 | Palo Alto Prisma SD-WAN ION up to 5.5.x/6.0.x/6.4.3-b7/6.5.3-b14 certificate validation]]></title>
<description><![CDATA[A vulnerability was found in Palo Alto Prisma SD-WAN ION up to 5.5.x/6.0.x/6.4.3-b7/6.5.3-b14. It has been rated as problematic. This impacts an unknown function. The manipulation leads to improper certificate validation.

This vulnerability is listed as CVE-2026-0244. The attack may be initiated...]]></description>
<link>https://tsecurity.de/de/3675725/sicherheitsluecken/cve-2026-0244-palo-alto-prisma-sd-wan-ion-up-to-55x60x643-b7653-b14-certificate-validation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675725/sicherheitsluecken/cve-2026-0244-palo-alto-prisma-sd-wan-ion-up-to-55x60x643-b7653-b14-certificate-validation/</guid>
<pubDate>Fri, 17 Jul 2026 12:21:40 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/palo_alto:prisma_sd-wan_ion">Palo Alto Prisma SD-WAN ION up to 5.5.x/6.0.x/6.4.3-b7/6.5.3-b14</a>. It has been rated as <a href="https://vuldb.com/kb/risk">problematic</a>. This impacts an unknown function. The manipulation leads to improper certificate validation.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2026-0244">CVE-2026-0244</a>. The attack may be initiated remotely. There is no available exploit.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-0245 | Palo Alto Prisma Access Agent up to 26.2.0 Configuration Data information disclosure]]></title>
<description><![CDATA[A vulnerability was found in Palo Alto Prisma Access Agent up to 26.2.0 and classified as problematic. The affected element is an unknown function of the component Configuration Data Handler. Such manipulation leads to information disclosure.

This vulnerability is referenced as CVE-2026-0245. Th...]]></description>
<link>https://tsecurity.de/de/3675724/sicherheitsluecken/cve-2026-0245-palo-alto-prisma-access-agent-up-to-2620-configuration-data-information-disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675724/sicherheitsluecken/cve-2026-0245-palo-alto-prisma-access-agent-up-to-2620-configuration-data-information-disclosure/</guid>
<pubDate>Fri, 17 Jul 2026 12:21:39 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/palo_alto:prisma_access_agent">Palo Alto Prisma Access Agent up to 26.2.0</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. The affected element is an unknown function of the component <em>Configuration Data Handler</em>. Such manipulation leads to information disclosure.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2026-0245">CVE-2026-0245</a>. The attack can only be performed from a local environment. No exploit is available.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-0246 | Palo Alto Prisma Access Agent up to 26.2.0 on Windows authorization]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in Palo Alto Prisma Access Agent up to 26.2.0 on Windows. This vulnerability affects unknown code. The manipulation leads to missing authorization.

This vulnerability is uniquely identified as CVE-2026-0246. Local access is requir...]]></description>
<link>https://tsecurity.de/de/3675723/sicherheitsluecken/cve-2026-0246-palo-alto-prisma-access-agent-up-to-2620-on-windows-authorization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675723/sicherheitsluecken/cve-2026-0246-palo-alto-prisma-access-agent-up-to-2620-on-windows-authorization/</guid>
<pubDate>Fri, 17 Jul 2026 12:21:37 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, has been found in <a href="https://vuldb.com/product/palo_alto:prisma_access_agent">Palo Alto Prisma Access Agent up to 26.2.0</a> on Windows. This vulnerability affects unknown code. The manipulation leads to missing authorization.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2026-0246">CVE-2026-0246</a>. Local access is required to approach this attack. No exploit exists.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[The agent security gap: 54% of enterprises have already had an AI agent incident, and most still let agents share credentials]]></title>
<description><![CDATA[Across 107 enterprises, AI agents are being given real access to systems and data while the controls meant to contain them lag behind. More than half have already had a confirmed agent security incident or a near-miss; only about a third give every agent its own scoped identity, and most agents s...]]></description>
<link>https://tsecurity.de/de/3674536/it-nachrichten/the-agent-security-gap-54-of-enterprises-have-already-had-an-ai-agent-incident-and-most-still-let-agents-share-credentials/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674536/it-nachrichten/the-agent-security-gap-54-of-enterprises-have-already-had-an-ai-agent-incident-and-most-still-let-agents-share-credentials/</guid>
<pubDate>Thu, 16 Jul 2026 21:47:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Across 107 enterprises, AI agents are being given real access to systems and data while the controls meant to contain them lag behind. More than half have already had a confirmed agent security incident or a near-miss; only about a third give every agent its own scoped identity, and most agents still share credentials; and only three in ten isolate their highest-risk agents. The security stack is overwhelmingly borrowed from the model providers and hyperscalers rather than purpose-built for agents, spending remains a thin slice of the security budget, and enterprises are evenly split on whether their defenses are keeping pace with AI-enabled attackers. The result is an agent security gap — autonomous agents proliferating faster than the identity, isolation, and enforcement controls needed to hold them.</p><p>This wave of VentureBeat Pulse Research examines how enterprises secure their AI agents: what tooling they run, how they manage agent identity and isolation, what has already gone wrong, how much they spend, and whether they believe their defenses are keeping pace with AI-enabled attackers.</p><p>The central finding is an agent security gap — the distance between the autonomy enterprises are granting their agents and the controls in place to contain them. More than half of organizations (54%) have already experienced a confirmed agent security incident (18%) or a near-miss caught before harm (36%). The structural weakness beneath those numbers is identity: only about a third (32%) give every agent its own scoped, managed identity, while the rest report that some agents share credentials or that agents mostly run on shared API keys and human or service-account credentials. When agents share credentials, a single compromised or over-permissioned agent carries a wide blast radius — and only three in ten enterprises (30%) isolate their highest-risk agents in sandboxes to bound that radius.</p><p>What makes the gap notable is how comfortable enterprises are inside it. The security stack is overwhelmingly provider-native — OpenAI’s guardrails (51%), Google’s and Microsoft’s cloud controls, and Anthropic’s managed-agent controls dominate, while the dedicated agent-security specialists barely register — and satisfaction with that borrowed stack is high, averaging 4.2 out of 5. Yet spending remains a thin slice of the security budget, only a third of enterprises believe their AI defenses are ahead of AI-enabled attackers, and a clear majority plan to change tooling within the year. Enterprises are satisfied with controls they are simultaneously preparing to replace.</p><h2>Methodology</h2><p>VentureBeat fielded this survey as part of its ongoing Pulse Research series, this instrument focused on enterprise agent security — the tooling, identity, isolation, and enforcement controls organizations use to secure autonomous AI agents. Responses are filtered to organizations with more than 100 employees (n=107; the survey’s smallest size band, 1–100 employees, is excluded), drawn from a single June 2026 wave. Because this is one wave rather than a pooled multi-month sample, the report reads cross-sectionally and does not infer month-over-month trends. Several questions were multiple-select, so those shares can sum to more than 100%.</p><p>By role the sample is senior and buyer-credible: 45% are final decision-makers for AI purchases and another 30% recommenders or influencers. Managers (43%), individual contributors (24%), VPs and directors (15%), and the C-suite (11%) make up the seniority mix. By organization size the sample is mid-market-weighted: 251–1,000 (42%) and 101–250 (25%) employees lead, with 1,001–5,000 (19%), 5,001–10,000 (8%), and 10,001+ (7%) above them. Technology/Software is the largest industry at 23%, followed by Manufacturing (15%), Retail/E-commerce (14%), and Healthcare/Life Sciences (13%).</p><p>At 107 respondents the sample is large enough to read directionally but should be treated as a directional signal rather than a precise measurement; it is self-selected and is not a probability sample. It skews toward the mid-market, so it is best read as the view from organizations actively standing up agent security rather than from the largest operators.</p><p>Satisfaction ratings are computed on the respondents who answered each rating question; the overall satisfaction score reflects 82 of the 107 qualified respondents.</p><h2>Finding 1: The incidents are already here</h2><p><b>More than half have had an agent security incident or near-miss</b></p><p>We asked whether organizations had experienced an agent security incident — a confirmed breach, or a near-miss caught before harm. Most that run agents in production had.</p><div></div><p>This is the report’s defining number. More than half of organizations (54%) have already had an agent security event — 18% a confirmed incident and 36% a near-miss caught before it caused harm. Only 42% report nothing, and a small remainder either run no agents in production or don’t track such events. That so many report near-misses rather than only confirmed incidents is telling: enterprises are catching problems, but they are catching them close to the edge. The controls examined in the rest of this report — identity, isolation, enforcement — are what determine whether the next near-miss stays a near-miss.</p><p>Exposure scales with company size, but containment does not. The incident-or-near-miss rate rises from 49% in the mid-market (companies with 101-1,000 employees) to 63% at larger enterprises (above 1,000 employees), while sandbox isolation of high-risk agents falls from 35% to 20%, and satisfaction with security tooling drops from 4.36 to 3.97. The organizations running the most agents across the most systems carry the most incidents and the least of the one control that bounds an incident's blast radius.</p><h2>Finding 2: The identity gap</h2><p><b>Only a third give every agent its own scoped identity</b></p><p>We asked how enterprises manage the identity of their AI agents — whether each agent has its own credentials, or agents share them. Full per-agent identity is the exception.</p><div></div><p>Rolled together, the overlapping answers show 69% of enterprises (74 of 107) with credential sharing somewhere in the agent fleet. Identity is the structural weakness beneath the incidents. Only about a third of enterprises (32%) give every agent its own scoped, managed identity — the precondition for least-privilege access and clean attribution. Nearly half (48%) say some agents have scoped identities but many still share credentials, and another 32% say agents mostly run on shared API keys or borrowed human and service-account credentials. (Respondents could describe more than one pattern across their agent fleet, so these overlap.) </p><p>The consequence is direct: when agents share credentials, an over-permissioned or compromised agent can act with far more reach than intended, and forensics after an incident cannot cleanly tell which agent did what. The non-human identity problem — giving every agent its own governed identity — is the single largest unfinished piece of enterprise agent security.</p><p>Moreover, a company’s agent credential posture is correlated with incidents. Organizations with credential sharing anywhere in the fleet were hit — with an incident or a near-miss in the past twelve months — at 63.5% (47 of 74). Organizations where every agent carries its own scoped identity were hit at 40.9% (9 of 22). The fully-scoped group is small, so for now the relationship is an association rather than proven causation, and the gap is concentrated in the mid-market — but within a single survey, a twenty-three point difference in incident rate suggests significance.</p><h2>Finding 3: Observe and enforce, but rarely isolate</h2><p><b>Only three in 10 sandbox their highest-risk agents</b></p><p>We asked what an organization’s agent security posture looks like in practice — whether they observe, enforce, isolate, or some combination. The control that bounds damage is the least common.</p><div></div><p>Monitoring and enforcement are reasonably common; containment is not. Roughly half of enterprises observe agent activity (47%) or enforce scoped permissions at runtime (49%), but only 30% isolate their highest-risk agents in sandboxes that bound the blast radius when the other controls fail. That ordering is backwards from a defense-in-depth standpoint: observation tells you what happened, enforcement tries to prevent it, but isolation is what limits the damage when prevention fails — and it is the control enterprises have adopted least. Combined with the identity gap in Finding 2, the picture is of agents that are watched and permissioned but rarely boxed in, which is precisely the configuration in which a single failure propagates.</p><h2>Finding 4: Security runs on borrowed, provider-native controls</h2><p><b>Guardrails from OpenAI, Google and Microsoft dominate; specialists barely register</b></p><p>We asked which agent security tooling enterprises use, and which is their primary layer. The answer favors the model providers and hyperscalers over the dedicated security vendors.</p><div></div><p>Enterprises are securing agents with tools that came bundled with their models and clouds. OpenAI’s guardrails lead at 51%, followed by Google’s and Microsoft’s cloud-native controls and Anthropic’s managed-agent controls — and when asked to name their single primary security layer, 82% name one of these provider-native offerings. The purpose-built agent-security category — Palo Alto’s Prisma AIRS, CrowdStrike, Cisco AI Defense, Zenity, HiddenLayer, Check Point’s Lakera, Okta for AI Agents, non-human identity platforms — barely registers, each in the low single digits, and only 5% run no dedicated tooling at all. As with retrieval and evaluation elsewhere in this series, the provider bundle is winning the default: enterprises reach first for the guardrails their platform ships, and the independent security layer that would address the identity and isolation gaps has not yet been adopted at scale.</p><p>The provider-default pattern is consistent across both Q2 survey waves. In April–May (n=110), usage was led by the same names — OpenAI's controls at 26%, Azure at 15%, AWS at 14%, Google at 12% — with every dedicated agent-security specialist at 3% or below and one in ten using no dedicated tooling at all. The common finding from the two surveys: Enterprises are defaulting to the solutions provided by the platform they’re using, and the specialist category vendors have yet to become big players here.</p><p>(<i>A note on reading these shares. As described in the methodology section, the respondent sample is self-selected and skews mid-market, and the usage question counted every vendor or approach a respondent has in place — so the figures measure presence in the security stack rather than spending or exclusivity. Individual vendor percentages therefore carry all the usual sample caveats. The structural pattern, however, held across both Q2 waves on two differently worded questions: provider-native and hyperscaler controls lead, and dedicated agent-security specialists remain in low single digits. Read the individual shares loosely and the pattern with confidence.)</i></p><h2>Finding 5: And enterprises are comfortable with it</h2><p><b>Satisfaction is high, even as incidents mount and identity lags</b></p><p>We asked how satisfied enterprises are with their current agent security tooling. The comfort is notably out of step with the exposure documented above.</p><div></div><p>Satisfaction with agent security tooling is high — 4.2 out of 5 overall, and 4.1 for value for money — among the most positive readings in this series. That is the striking part: enterprises are highly satisfied with a stack that is mostly borrowed provider guardrails, even though more than half have already had an incident or near-miss and only a third give their agents scoped identities. The comfort appears to rest on the convenience and low friction of provider-native controls rather than on demonstrated containment. It is a false comfort in the making — the same enterprises expressing satisfaction are, as Finding 8 shows, a clear majority planning to change tooling within the year, which suggests the confidence is thinner than the score implies.</p><h2>Finding 6: Budgets haven’t caught up</h2><p><b>Most spend under a tenth of the security budget on agents</b></p><p>We asked what share of the security budget enterprises allocate to securing AI agents. For a fast-emerging risk, the allocation is modest.</p><div></div><p>Spending on agent security is still a thin slice. The most common allocation is 6–10% of the security budget (46%), and a third of enterprises (34%) spend 5% or less; only a quarter (24%) devote more than a tenth. Given the incident rate in Finding 1 and the identity and isolation gaps in Findings 2 and 3, the budget looks like a lagging indicator — the risk has arrived faster than the funding to address it. The enterprises spending more than a tenth of their security budget on agents are a distinct minority, and they are likely the ones building the scoped-identity and isolation controls the rest have not.</p><h1>Finding 7: The arms race is even, at best</h1><p><b>Only a third think their AI defenses are ahead of AI-enabled attackers</b></p><p>We asked how enterprises assess the balance between their AI-enabled defenses and AI-enabled attackers. Confidence is far from settled.</p><div></div><p>Enterprises are split on whether they are winning. Only about a third (35%) believe their AI-enabled defenses are ahead of AI-enabled attackers; the rest are less sure — 32% call it roughly even, 21% think attackers are ahead, and another 21% say it is too early to tell. Taken together, a clear majority (53%) rate the balance as even or tilted toward the attacker. That uncertainty sits uneasily beside the high satisfaction of Finding 5: enterprises are content with their tooling yet unconvinced it is winning the contest it exists to win. In a domain where the offense is also compounding with AI, an even race is not a comfortable place to be.</p><h2>Finding 8: A security reshuffle is coming</h2><p><b>Nearly six in 10 plan to adopt or switch tooling within a year</b></p><p>We asked whether enterprises plan to adopt a new, additional, or replacement agent security solution, and which they are considering. Few intend to stand pat.</p><div></div><p>The security stack is not settled. While 41% have no plans to change, a clear majority (59%) intend to adopt a new, additional, or replacement agent security solution within twelve months, and 29% within the next quarter — a strong signal that, high satisfaction notwithstanding, enterprises know the current stack is provisional. Incidents are what start the buying cycle. </p><p>Among organizations that have been hit, 42.1% plan to adopt, add, or replace agent security tooling within the next ninety days, against 14.0% of organizations with no incident — and after a confirmed incident it becomes majority behavior, at 52.6%. Getting hit also changes the threat assessment: 33.3% of hit organizations say AI-armed attackers are ahead of their defenses, against 8.0% of the unhit. Experience, in this data, is the strongest predictor of both urgency and pessimism.</p><p>The consideration set still leans provider-native (OpenAI 34%, Google 30%, Anthropic 29%, Azure 25%), but the dedicated security vendors — Cloudflare, Cisco, Palo Alto, Okta, Check Point’s Lakera — draw early interest in the mid-to-high single digits, more than their current footprint. </p><p>What the shopping does not yet include is the identity layer specifically. Twelve percent of the respondents include an agent-identity product — Okta for AI Agents, Microsoft Entra Agent ID, or a non-human identity platform — anywhere in their consideration set, and among the credential-sharing organizations that have already had an incident, identity consideration is essentially unchanged, at roughly one in ten. The control most directly implicated by the incident data is the one largely missing from the purchase plans. Whether this wave hardens the provider-native default or finally opens the door to purpose-built agent security — the identity and isolation controls the incidents call for — is the question this series will keep tracking.</p><h2>The bottom line: A security gap that autonomy will test first</h2><p>Organizations with more than 100 employees are giving AI agents real reach into systems and data while securing them with controls built for something else. More than half have already had an incident or near-miss; only a third give every agent its own scoped identity, and most still share credentials; only three in ten isolate their highest-risk agents; and the stack doing this work is overwhelmingly borrowed from the model providers and hyperscalers rather than purpose-built for agents.</p><p>The uncomfortable pairing is confidence with exposure: satisfaction with the current tooling is among the highest in this series, yet spending is a thin slice of the security budget, only a third believe their defenses are ahead of AI-enabled attackers, and a clear majority are already planning to replace what they have. At 107 respondents in a single wave this is a directional read, skewed toward the mid-market — but the direction is clear: agent adoption is running ahead of agent security, and the controls that matter most when something fails — scoped identity and isolation — are the ones enterprises have built least. The agent security gap is not a coverage problem that a provider guardrail will close on its own; it is a problem of identity, isolation, and enforcement built for autonomous software. The open question for later waves is whether enterprises close it deliberately — or whether a confirmed incident closes it for them.</p><hr><p><i>Based on survey responses from 107 qualified enterprise respondents (100+ employees), drawn from a single June 2026 wave. This is a directional read, not a precise measurement — the sample is self-selected and skews mid-market, so it's best read as the view from organizations actively standing up agent security rather than from the largest operators. Respondents are senior and buyer-credible (45% final decision-makers, 30% recommenders/influencers), spanning managers through the C-suite, and drawn primarily from Technology/Software, Manufacturing, Retail/E-commerce, and Healthcare/Life Sciences.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Announcing the General Availability of Prisma AIRS AI Gateway]]></title>
<description><![CDATA[Every modern enterprise is moving from an organization run by software to one orchestrated by AI, creating a tension between velocity and control. To resolve this tension, organizations require a unified architecture. … The post Announcing the General Availability of…
Read more →
The post Announc...]]></description>
<link>https://tsecurity.de/de/3673950/it-security-nachrichten/announcing-the-general-availability-of-prisma-airs-ai-gateway/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673950/it-security-nachrichten/announcing-the-general-availability-of-prisma-airs-ai-gateway/</guid>
<pubDate>Thu, 16 Jul 2026 17:23:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Every modern enterprise is moving from an organization run by software to one orchestrated by AI, creating a tension between velocity and control. To resolve this tension, organizations require a unified architecture. … The post Announcing the General Availability of…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/announcing-the-general-availability-of-prisma-airs-ai-gateway/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/announcing-the-general-availability-of-prisma-airs-ai-gateway/">Announcing the General Availability of Prisma AIRS AI Gateway</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Top 10 Best Firewall as a Service (FWaaS) Providers – 2026 ]]></title>
<description><![CDATA[The firewall is leaving the rack: firewall-as-a-service delivers inspection, intrusion prevention, and policy from the cloud, so every user, branch, and cloud workload gets identical protection without appliances to size, patch, or refresh. Zscaler is our top FWaaS pick for 2026 on the strength o...]]></description>
<link>https://tsecurity.de/de/3673901/it-security-nachrichten/top-10-best-firewall-as-a-service-fwaas-providers-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673901/it-security-nachrichten/top-10-best-firewall-as-a-service-fwaas-providers-2026/</guid>
<pubDate>Thu, 16 Jul 2026 17:08:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The firewall is leaving the rack: firewall-as-a-service delivers inspection, intrusion prevention, and policy from the cloud, so every user, branch, and cloud workload gets identical protection without appliances to size, patch, or refresh. Zscaler is our top FWaaS pick for 2026 on the strength of the industry’s largest dedicated security cloud, with Palo Alto Networks Prisma Access delivering the […]</p>
<p>The post <a href="https://cybersecuritynews.com/firewall-as-a-service/">Top 10 Best Firewall as a Service (FWaaS) Providers – 2026 </a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meet Blume: An Open-Source, Zero-Config Documentation Framework That Ships AI-Ready Docs From a Markdown Folder]]></title>
<description><![CDATA[Developer Hayden Bleasel has released Blume, an open-source, MIT-licensed documentation framework. It reads a folder of Markdown or MDX and generates a hidden Astro project, shipping static, AI-ready docs with local search, 30+ MDX components, llms.txt, and a built-in MCP server.
The post Meet Bl...]]></description>
<link>https://tsecurity.de/de/3667266/ai-nachrichten/meet-blume-an-open-source-zero-config-documentation-framework-that-ships-ai-ready-docs-from-a-markdown-folder/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667266/ai-nachrichten/meet-blume-an-open-source-zero-config-documentation-framework-that-ships-ai-ready-docs-from-a-markdown-folder/</guid>
<pubDate>Tue, 14 Jul 2026 10:19:26 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Developer Hayden Bleasel has released Blume, an open-source, MIT-licensed documentation framework. It reads a folder of Markdown or MDX and generates a hidden Astro project, shipping static, AI-ready docs with local search, 30+ MDX components, llms.txt, and a built-in MCP server.</p>
<p>The post <a href="https://www.marktechpost.com/2026/07/14/meet-blume-an-open-source-zero-config-documentation-framework-that-ships-ai-ready-docs-from-a-markdown-folder/">Meet Blume: An Open-Source, Zero-Config Documentation Framework That Ships AI-Ready Docs From a Markdown Folder</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Get started with Angular: Introducing the modern reactive workflow]]></title>
<description><![CDATA[Angular is a cohesive, all-in-one reactive framework for web development. It is one of the larger reactive frameworks, focused on being a single architectural system that handles all your web development needs under one idiom. While Angular was long criticized for being heavyweight as compared to...]]></description>
<link>https://tsecurity.de/de/3665664/ai-nachrichten/get-started-with-angular-introducing-the-modern-reactive-workflow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665664/ai-nachrichten/get-started-with-angular-introducing-the-modern-reactive-workflow/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:25 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Angular is a cohesive, all-in-one <a href="https://www.infoworld.com/article/3962039/what-you-need-to-know-about-angular-react-vue-and-svelte-popular-javascript-frameworks-compared.html">reactive framework</a> for web development. It is one of the larger reactive frameworks, focused on being a single architectural system that handles all your web development needs under one idiom. While Angular was long criticized for being heavyweight as compared to <a href="https://www.infoworld.com/article/2253289/react-tutorial-get-started-with-the-reactjs-javascript-library.html">React</a>, many of those issues <a href="https://www.infoworld.com/article/3964105/catching-up-with-angular-19.html">were addressed in Angular 19</a>. Modern Angular is built around the <a href="https://blog.angular-university.io/angular-signals">Signals API</a> and minimal formality, while still delivering a one-stop-shop that includes dependency injection and integrated routing.</p>



<p class="wp-block-paragraph">Angular is popular with the enterprise because of its stable, curated nature, but it is becoming more attractive to the wider developer community thanks to its more <a href="https://www.infoworld.com/article/3802707/angular-team-unveils-strategy-for-2025.html">community engaged development philosophy</a>. That, along with its recent technical evolution, make Angular one of the most interesting projects to watch right now.</p>



<h2 class="wp-block-heading">Why choose Angular?</h2>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/2336227/whats-the-best-javascript-framework.html">Choosing a JavaScript development framework</a> sometimes feels like a philosophical debate, but it should be a practical decision. Angular is unique because it is strongly opinionated. It doesn’t just give you a view layer; it provides a complete toolkit for building web applications.</p>



<p class="wp-block-paragraph">Like other reactive frameworks, Angular is built around its reactive engine, which lets you bind state (variables) to the view. But if that’s all you needed, one of the smaller, more focused frameworks would be more than enough. What Angular has that some of these other frameworks don’t is its ability to use data binding to automatically synchronize data from your user interface (UI) with your JavaScript objects. Angular also leverages dependency injection and inversion of control to help structure your application and make it easier to test. And it contains more advanced features like server-side rendering (SSR) and static-site generation (SSG) within itself, rather than requiring you to engage a <a href="https://www.infoworld.com/article/3831686/plug-and-play-web-development-with-astro-js.html">meta-framework</a> for either style of development.</p>



<p class="wp-block-paragraph">While Angular might not be your top choice for every occasion, it’s an excellent option for larger projects that require features you won’t get with a more lightweight framework.</p>



<p class="wp-block-paragraph"><strong>Also see: <a href="https://www.infoworld.com/article/3964105/catching-up-with-angular-19.html" data-type="link" data-id="https://www.infoworld.com/article/3964105/catching-up-with-angular-19.html">Catching up with Angular 19</a>.</strong></p>



<h2 class="wp-block-heading">Getting started with Angular</h2>



<p class="wp-block-paragraph">With those concepts in mind, let’s set up Angular in your development environment. After that, we can run through developing a web application with Angular. To start, make sure you have Node and NPM installed. From the command line, enter:</p>



<pre class="wp-block-code"><code>$ node -v
$ npm -v</code></pre>



<p class="wp-block-paragraph">Next, you can use the Angular CLI to launch a new app:</p>



<pre class="wp-block-code"><code>$ ng new iw-ng</code></pre>



<p class="wp-block-paragraph">You can use the defaults in your responses to the interactive prompts shown here:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/01/angular1.png?w=1024" alt="A screenshot of a new project setup in the Angular command-line interface." class="wp-image-4123771" width="1024" height="413" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Matthew Tyson</p></div>



<p class="wp-block-paragraph">We now have a basic project layout in the new directory, which you can import into an IDE (such as <a href="https://www.infoworld.com/article/2254808/get-started-with-visual-studio-code.html" data-type="link" data-id="https://www.infoworld.com/article/2254808/get-started-with-visual-studio-code.html">VS Code</a>) or edit directly.</p>



<p class="wp-block-paragraph">Looking at the project layout, you might notice it is fairly lean, a break from Angular projects of the past. The most important parts are:</p>



<ul class="wp-block-list">
<li><code>src/main.ts</code>: This is the main entry point. In older versions of Angular, this file had to bootstrap a module, which then bootstrapped a component. Now, it avoids any verbose syntax, calling bootstrapApplication with your root component directly.</li>



<li><code>src/index.html</code>: The main HTML page that hosts your application. This is the standard index.html that serves all root requests in a web page and contains the  tag where your Angular component will render. It is the “body” that the “spirit” of your code animates.</li>



<li><code>src/app/app.ts</code>: The root component of your application. This single file defines the view logic and the component metadata. In the new “standalone” world, it manages its own imports, meaning you can see exactly what dependencies it uses right at the top of the file. (This is the <code></code> root element that appears in <code>src/index.html</code>.)</li>



<li><code>src/app/app.config.ts</code>: This file is new in modern Angular and replaces the old A<code>ppModule providers</code> array. It is where you configure global services, like the router or HTTP client.</li>



<li><code>angular.json</code>: The configuration file for the CLI itself. It tells the build tools how to process your code, though you will rarely need to touch this file manually anymore.</li>
</ul>



<p class="wp-block-paragraph">Here is the basic flow of how the engine renders these components:</p>



<ol start="1" class="wp-block-list">
<li><strong>The arrival (HTML)</strong>: The browser receives <code>index.html</code>. The <code></code> tag is there, but it’s empty.</li>



<li><strong>The unpacking (JavaScript)</strong>: The browser sees the <code></code> tags at the bottom of the HTML and downloads the JavaScript bundles (your compiled code) from <code>src/app/app.ts</code>.</li>



<li><strong>The assembly (Bootstrap)</strong>: The browser runs that JavaScript. The code “wakes up,” finds the <code></code> tag in the DOM, and dynamically inserts your title, buttons, and lists.</li>
</ol>



<p class="wp-block-paragraph">This flow will be different if you are using server-side rendering (SSR), but we’ll leave that option aside for now. Now that you’ve seen the basic architecture, let’s get into the code.</p>



<h2 class="wp-block-heading">Developing your first web app in Angular</h2>



<p class="wp-block-paragraph">If you open <code>src/app/app.ts</code> (more info <a href="http://app.ts/">here</a>) the component definition looks like this:</p>



<pre class="wp-block-code"><code>import { Component, signal } from '@angular/core';
import { RouterOutlet } from '@angular/router';

@Component({
  selector: 'app-root',
  imports: [RouterOutlet],
  templateUrl: './app.html',
  styleUrl: './app.css'
})
export class App {
  protected readonly title = signal('iw-ng');
}</code></pre>



<p class="wp-block-paragraph">Before we dissect the code, let’s run the app and see what it produces:</p>



<pre class="wp-block-code"><code>$ ng serve</code></pre>



<p class="wp-block-paragraph">You should see a page like this one at <code>localhost:4200</code>:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/01/angular2.png?w=1024" alt="A screenshot of a Hello, World! app built with Angular." class="wp-image-4123772" width="1024" height="585" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Matthew Tyson</p></div>



<p class="wp-block-paragraph">Returning to the <code>src/app.ts</code> component, notice that there are three main parts of the definition: the class, the metadata, and the view. Let’s unpack these separately.</p>



<h3 class="wp-block-heading">The class (export class App)</h3>



<p class="wp-block-paragraph">Export class <code>App</code> is vanilla TypeScript that holds your component’s data and logic. In our example, <code>title = signal(‘iw-ng’)</code> defines a piece of reactive state. Unlike older versions of Angular where data was just a plain property, here we use a <a href="https://www.solidjs.com/tutorial/introduction_signals">signal</a>. Signals are wrappers around values that notify the template precisely when they change, enabling fine-grained performance.</p>



<h3 class="wp-block-heading">The metadata (@Component)</h3>



<p class="wp-block-paragraph">The <code>@Component</code> decorator tells Angular it is dealing with a component, not just a generic class. There are several elements involved in the decorator’s communication with the engine:</p>



<ul class="wp-block-list">
<li><code>selector: 'app-root'</code>: Defines the custom HTML tag associated with any given component. Angular finds <code></code> in your <code>index.html</code> and renders the component there.</li>



<li><code>imports</code>: In the new Angular era, dependencies are explicit. You list exactly what a component needs (like <code>RouterOutlet</code> or other components) here, rather than hiding them in a separate module file.</li>



<li><code>templateUrl</code>: Points to the external HTML file that defines the view.</li>
</ul>



<h3 class="wp-block-heading">The view (the template)</h3>



<p class="wp-block-paragraph">This is the visual part of the component, defined in <code>app.html</code>. It combines standard HTML with Angular’s template syntax. (JSX handles this part for React-based apps.)</p>



<p class="wp-block-paragraph">We can modify <code>src/app/app.html</code> to see how these three elements work together. To start, delete the default content and add the following:</p>



<pre class="wp-block-code"><code><h1>Hello, {{ title() }}</h1>
</code></pre>



<p class="wp-block-paragraph">The double curly braces <code>{{ }}</code> are called <a href="https://angular.dev/guide/templates/binding">interpolation</a>. Notice the parentheses in <code>title()</code>. We are reading the “title” signal value by calling its function. If you were to update that signal programmatically (e.g., <code>this.title.set('New Value')</code>), the text on the screen would update instantly.</p>



<h2 class="wp-block-heading">Angular’s built-in control flow</h2>



<p class="wp-block-paragraph">Old-school Angular required “structural directives” like <code>*ngIf</code> and <code>*ngFor</code> logic control. These were powerful but required importing <code>CommonModule</code> and learning a specific micro-syntax. Modern Angular uses a built-in control flow that looks like standard JavaScript (similar to other Reactive platforms).</p>



<p class="wp-block-paragraph">To see the new control flow in action, let’s add a list to our component. Update <code>src/app/app.ts</code> as follows, leaving the rest of the file the same:</p>



<pre class="wp-block-code"><code>export class App {
  protected readonly title = signal('iw-ng');
  protected readonly frameworks = signal(['Angular', 'React', 'Vue', 'Svelte']);
  protected showList = signal(true);

  toggleList() {
    this.showList.update(v =&gt; !v);
  }
}</code></pre>



<p class="wp-block-paragraph">While we’re at it, let’s also update <code>src/app/app.html</code> to render this new list (don’t worry about <code></code> for now; it just tells Angular where to render the framing template):</p>



<pre class="wp-block-code"><code><button>Toggle List</button>

@if (showList()) {
  <ul>
    @for (tech of frameworks(); track tech) {
      <li>{{ tech }}</li>
    }
  </ul>
} @else {
  <p>List is hidden</p>
}

</code></pre>



<p class="wp-block-paragraph">The app will now display a list that can be toggled for visibility:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/01/angular3.png?w=1024" alt="Screenshot of a list that can be toggled on and off for visibility." class="wp-image-4123773" width="1024" height="585" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Matthew Tyson</p></div>



<p class="wp-block-paragraph">This syntax is cleaner and easier to read than the old <code>*ngFor</code> loops:</p>



<ul class="wp-block-list">
<li><code>@if</code> conditionally renders the block if the signal’s value is true.</li>



<li><code>@for</code> iterates over the array. The track keyword is required for performance (it tells Angular how to identify unique items in the list).</li>



<li><code>(click)</code> is an <a href="https://angular.dev/guide/templates/event-listeners">event binding</a>. It lets us run code (the <code>toggleList</code> method) when the user interacts with the button.</li>
</ul>



<h2 class="wp-block-heading">Services: Managing business logic in Angular</h2>



<p class="wp-block-paragraph">Components focus on the view (i.e., what you see). For the business logic that backs the application functionality, we use services.</p>



<p class="wp-block-paragraph">A service is just a class that can be “injected” into a component that needs it. This is Angular’s famous dependency injection system. It allows you to write logic once and reuse it anywhere. It’s a slightly different way of thinking about how an application is wired together, but it gives you real organizational benefits over time.</p>



<p class="wp-block-paragraph">To generate a service, you can use the CLI:</p>



<pre class="wp-block-code"><code>$ ng generate service frameworks</code></pre>



<p class="wp-block-paragraph">This command creates a <code>src/app/hero.ts</code> file. In modern Angular, we define services using the <code>@Injectable</code> decorator. Currently, the <code>src/app/hero.ts</code> file just has this:</p>



<pre class="wp-block-code"><code>import { Injectable } from '@angular/core';

@Injectable({
  providedIn: 'root',
})
export class Frameworks {
  
}</code></pre>



<p class="wp-block-paragraph">Open the file and add a simple method to return our data:</p>



<pre class="wp-block-code"><code>import { Injectable } from '@angular/core';

@Injectable({
  providedIn: 'root', // Available everywhere in the app
})
export class Frameworks {
  getList() {
    return ['Angular', 'React', 'Vue', 'Svelte'];
  }
}</code></pre>



<p class="wp-block-paragraph">The providedIn: <code>'root'</code> metadata is important, it tells Angular to create a single, shared instance of this service for the entire application (you might recognize this as an instance of the <a href="https://en.wikipedia.org/wiki/Singleton_pattern">singleton pattern</a>).</p>



<h3 class="wp-block-heading">Using the service</h3>



<p class="wp-block-paragraph">In the past, we had to list dependencies in the constructor. Modern Angular offers a cleaner way: the <code>inject()</code> function. Subsequently, we can refactor our <code>src/app/app.ts</code> to get its data from the service instead of hardcoding it:</p>



<pre class="wp-block-code"><code>import { Component, inject, signal } from '@angular/core';
import { RouterOutlet } from '@angular/router';
import { Frameworks } from './frameworks'; // Import the service

@Component({
  selector: 'app-root',
  imports: [RouterOutlet],
  templateUrl: './app.html',
  styleUrl: './app.css'
})
export class App {
  private frameworksService = inject(Frameworks); // Dependency Injection
  
  protected readonly title = signal('iw-ng');
  
  // Initialize signal with data directly from the service
  protected readonly frameworks = signal(this.frameworksService.getList());
  protected showList = signal(true);

  toggleList() {
    this.showList.update(v =&gt; !v);
  }
}</code></pre>



<p class="wp-block-paragraph">Dependency injection is a powerful pattern. The component doesn’t need to know where the list came from (it could be coming from an API, a database, or a hard-coded array); it just asks the service for what it needs. This pattern adds a bit of extra work up front, but it delivers a more flexible, organized codebase as the app grows in size and complexity.</p>



<h2 class="wp-block-heading">Routers and routes</h2>



<p class="wp-block-paragraph">Once your application grows beyond a single view, you need a way to navigate between different screens. In Angular, we use the built-in router for this purpose. In our example project, <code>src/app/app.routes.ts </code>is the dedicated home for the router config. Let’s follow the steps for creating a new route.</p>



<p class="wp-block-paragraph">First, we define the route. When you open <code>src/app/app.routes.ts</code>, you will see an exported routes array. This array contains the available routes for your app. Each string name resolves to a component that handles rendering that route. In effect, this is the map of your application’s landscape.</p>



<p class="wp-block-paragraph">In a real application, you’d often have “framing template” material in the root of the app (like the navbar) and then the routes fill in the body content. (Remember that by default, Angular is designed for single-page apps, where navigation does reload the screen, but swaps content.)</p>



<p class="wp-block-paragraph">For now, let’s just get a sense of how the router works. First, create a new component so we have a destination to travel to. In your terminal, run:</p>



<pre class="wp-block-code"><code>$ ng generate component details</code></pre>



<p class="wp-block-paragraph">This will generate a simple <code>details</code> component in the <code>src/app/details</code> directory.</p>



<p class="wp-block-paragraph">Now we can update <code>src/app/app.routes.ts</code> to include this new path. We will also add a “default” path that redirects empty requests to the home view, ensuring the user always lands somewhere:</p>



<pre class="wp-block-code"><code>import { Routes } from '@angular/router';
import { App } from './app'; // Matches src/app/app.ts
import { Details } from './details/details'; // Matches src/app/details/details.ts

export const routes: Routes = [
  { path: '', redirectTo: '/home', pathMatch: 'full' },
  { path: 'home', component: App },
  { path: 'details', component: Details },
];</code></pre>



<p class="wp-block-paragraph">Now if you visit <code>localhost:4200/home</code>, you’ll get the message from the <code>details</code> component: “Details works!”</p>



<p class="wp-block-paragraph">Next, we’ll use the <code>routerLink</code> directive to move between views without refreshing the page. In <code>src/app/app.html</code>,  we create a navigation bar that sits permanently at the top of the page (the “stationary” element), while the router swaps the content below it (the “impermanent” element):</p>



<pre class="wp-block-code"><code><nav>
  <a>Home</a> | 
  <a>Details</a>
</nav>

<hr>

</code></pre>



<p class="wp-block-paragraph">And with that, the application has a navigation flow. The user clicks, the URL updates, and the content transforms, all without the jarring flicker of a browser reload.</p>



<h2 class="wp-block-heading">Parametrized routes</h2>



<p class="wp-block-paragraph">The last thing we’ll look at is handling route parameters, where the route accepts variables in the path. To manage this kind of dynamic data, you define a route with a variable, marked by a colon. Open <code>src/app/app.routes.ts</code> and add a dynamic path:</p>



<pre class="wp-block-code"><code>export const routes: Routes = [
  // ... existing routes
  { path: 'details/:id', component: Details }, 
];</code></pre>



<p class="wp-block-paragraph">The <code>:id</code> is a placeholder. Whether the URL is <code>/details/42</code> or <code>/details/108</code>, this router will receive it because it matches the path. Inside the details component, we have access to this parameter (using the <a href="https://angular.dev/api/router/ActivatedRoute">ActivatedRoute</a> service or the new <a href="https://angular.dev/api/router/withComponentInputBinding">withComponentInputBinding</a>). We can use that value to retrieve the data we need (like using it to recover a detail item from a database).</p>



<h2 class="wp-block-heading">Conclusion</h2>



<p class="wp-block-paragraph">We have seen the core elements of modern Angular: Setting up the environment, building reactive components with signals, organizing logic with services, and tying it all together with interactive routing.</p>



<p class="wp-block-paragraph">Deploying these pieces together is the basic work in Angular. Once you get comfortable with it, you have an extremely powerful platform at your fingertips. And, when you are ready to go deeper, there is a whole lot more to explore in Angular, including:</p>



<ul class="wp-block-list">
<li>State management: Beyond signals, Angular has support for managing complex, application-wide state.</li>



<li>Forms: Angular has a robust system for handling user input.</li>



<li>Signals: We only scratched the surface of signals here. Signals offer a powerful, fine-grained way to manage state changes.</li>



<li>Build: You can learn more about producing production builds.</li>



<li><a href="https://www.infoworld.com/article/3964105/catching-up-with-angular-19.html" data-type="link" data-id="https://www.infoworld.com/article/3964105/catching-up-with-angular-19.html">RxJS</a>: Takes reactive programming to the next level.</li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-0278 | Palo Alto Prisma Access Agent Data Loss Prevention protection mechanism]]></title>
<description><![CDATA[A vulnerability was found in Palo Alto Prisma Access Agent and classified as problematic. This issue affects some unknown processing of the component Data Loss Prevention. The manipulation results in protection mechanism failure.

This vulnerability is cataloged as CVE-2026-0278. The attack must ...]]></description>
<link>https://tsecurity.de/de/3664220/sicherheitsluecken/cve-2026-0278-palo-alto-prisma-access-agent-data-loss-prevention-protection-mechanism/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664220/sicherheitsluecken/cve-2026-0278-palo-alto-prisma-access-agent-data-loss-prevention-protection-mechanism/</guid>
<pubDate>Mon, 13 Jul 2026 06:38:51 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/palo_alto:prisma_access_agent">Palo Alto Prisma Access Agent</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This issue affects some unknown processing of the component <em>Data Loss Prevention</em>. The manipulation results in protection mechanism failure.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2026-0278">CVE-2026-0278</a>. The attack must be initiated from a local position. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Shared API keys expose AI agents at 69% of enterprises, new VentureBeat research finds]]></title>
<description><![CDATA[Share one API key across five AI agents, and a single compromised agent inherits the reach of all five. The attacker immediately benefits from the accumulated permissions of every workflow that the key touches. The forensic trail goes cold at the credential level because five agents on one accoun...]]></description>
<link>https://tsecurity.de/de/3658311/it-nachrichten/shared-api-keys-expose-ai-agents-at-69-of-enterprises-new-venturebeat-research-finds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658311/it-nachrichten/shared-api-keys-expose-ai-agents-at-69-of-enterprises-new-venturebeat-research-finds/</guid>
<pubDate>Thu, 09 Jul 2026 23:32:38 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Share one API key across five AI agents, and a single compromised agent inherits the reach of all five. The attacker immediately benefits from the accumulated permissions of every workflow that the key touches. The forensic trail goes cold at the credential level because five agents on one account leave no record of which agent did what.</p><p>Sixty-nine percent of enterprises run agents with credential sharing somewhere in their deployments, according to VentureBeat’s June 2026 <a href="https://venturebeat.com/category/resources">Pulse Research</a> wave of 107 enterprises. </p><p>That one number explains the buying spree reshaping enterprise security this year. Palo Alto Networks, CrowdStrike, and Cisco have collectively bet more than $22 billion on it in the past year, targeting exactly the layer most enterprises in this survey haven't finished building. </p><p>Palo Alto Networks completed its acquisition of CyberArk on February 11 for <a href="https://venturebeat.com/security/link">$21.1 billion in total consideration</a> at close — a deal it <a href="https://venturebeat.com/security/link">announced last July at roughly $25 billion</a> and the largest in the company's history.</p><p>CrowdStrike <a href="https://venturebeat.com/security/link">closed its $740 million acquisition</a> of runtime authorization platform SGNL and, by June 15, <a href="https://venturebeat.com/security/link">shipped the first product from the deal, Continuous Identity for AI Agents</a>. CrowdStrike integrated SGNL in less than a year, delivering a product that validates every agent action in real time based on who owns it, who is calling it, and the device's risk posture.</p><p>Cisco <a href="https://venturebeat.com/security/link">announced its intent to acquire</a> non-human identity specialist Astrix Security on May 4 for a reported <a href="https://venturebeat.com/security/link">$400 million</a>.</p><p>For a security director, this survey reads as a board-level question, not a trend line. It also surfaces a finding no competitor’s data shows, one that exposes which companies are the most at risk.</p><p>The data below is the first look at VentureBeat’s Q2 Agentic Security report, drawn from 107 qualified respondents at organizations with more than 100 employees. The full report will be released to attendees at <a href="https://venturebeat.com/vbtransform2026?gad_source=1&amp;gad_campaignid=23980639323&amp;gbraid=0AAAAADnGhh6a1PPkuB60-_ayDUaXOZo3h&amp;gclid=Cj0KCQjwjb3SBhDgARIsAMKiWziNibd4i5buzaXuw91BVLngDsyqVdgLZBQxUTUBkbuWlmUGubj-fMYaAowKEALw_wcB">VB Transform</a>, the event in Menlo Park next week (July 14-15) focusing on enterprise autonomous agents. </p><p>Forty-five percent are final decision-makers for AI purchases. The sample skews mid-market, so read the numbers as the view from organizations adopting agent security right now rather than from the largest enterprises. </p><p>More than half of respondents, 54%, have already had an agent security incident or near-incident. Eighteen percent confirmed an incident, and thirty-six percent caught a near-miss before a breach. Security teams are stopping most of these events at the last control point in the chain, but the rest of the data shows how thin that margin is.</p><h2>Your agents are sharing credentials</h2><p>Only 32% of enterprises give every AI agent its own scoped, managed identity. Nearly half (48%) report that some agents have scoped identities, while many still share credentials. Another 32% say agents mostly run on shared API keys or borrowed human and service-account credentials. The survey question allowed more than one selection, and 24 of the 107 respondents chose multiple options — which is why the three categories sum to 112%. Deduplicated by respondent, 74 organizations, or 69%, flagged credential sharing in at least one answer.</p><p>One number explains why the acquisitions target this layer. A shared credential converts a single compromised agent into many, and <a href="https://www.cyberark.com/press/machine-identities-outnumber-humans-by-more-than-80-to-1-new-report-exposes-the-exponential-threats-of-fragmented-identity-security/">CyberArk's research</a> puts machine identities at 82 for every human in organizations worldwide, with agents as the fastest-growing category of the ratio. Cisco made the same diagnosis when it bought Astrix, whose founders built the company around API keys, service accounts, and OAuth tokens. Cisco’s announcement calls those the credentials AI agents are now “using (and abusing)” to execute work at scale.</p><p>Adam Meyers, senior vice president of counter adversary operations at CrowdStrike, described the mechanism directly in an interview with VentureBeat. Some AI systems have their own identities, he said, and in other cases “people give their identity to the AI to take action on their behalf, and that also further kind of murkies the water and makes it very complex.” The murk is the point, because when the identity is shared, attribution dies with it.</p><h2>Exposure scales with size, and containment does not</h2><p>Forty-nine percent of enterprises enforce scoped permissions at runtime, and 47% monitor and log agent activity, which can help reduce security incidents. Only 30% sandbox their highest-risk agents, the one control that limits blast radius when the first two fail. Isolation is what keeps a single compromised agent from becoming a deployment-wide event. Enterprises have funded detection and resistance, but the containment layer barely exists.</p><p>The sharpest finding in the survey, and the one no vendor report captures, shows up when you split results by company size. The incident rate is 49% for companies with 101 to 1,000 employees, but it shoots up to 63% for companies with more than 1,000. Sandbox isolation moves the other way, falling from 35% to 20% at the larger companies.</p><p>The chart above shows the same finding at finer granularity: the 49%/63% split above is a binary cut at 1,000 employees, while the bars here break incident rate and isolation rate into four size bands. The red line measures incidents and near-misses, and the navy tracks the one control that contains damage after everything else fails. At organizations with 101 to 250 employees, the two sit 7 points apart, but above 5,000, the gap blows out to 60 points. That top band pools the survey's two largest size groups and holds only 15 respondents, so treat the number as directional. Larger enterprises run more agents across more systems, which drives incidents up while sandboxing, the engineering project that would contain them, goes unfunded. The enterprises with the most agents have the least isolation around them.</p><p>The deals target exactly those accounts. Palo Alto Networks, Cisco, and CrowdStrike sell to large enterprises first, where incident rates are highest and containment is the thinnest.</p><h2>Guarded by whoever shipped the model</h2><p>The model providers are the security layer. OpenAI's built-in guardrails lead at 51%. Google Cloud reaches 36%, Microsoft Azure's Purview and Copilot Studio DLP 35%, and Anthropic's managed-agent controls 29%. Eighty-two percent of respondents name a provider-native or hyperscaler control as their single primary agent security layer.</p><p>The purpose-built specialists are in single digits, with Palo Alto Networks' Prisma AIRS at 7%, CrowdStrike at 6%, and Okta for AI Agents at 4%. Zenity and the dedicated non-human identity platforms are at 3% each. Microsoft Entra Agent ID is the highest-penetration identity-specific control in the dataset at 13%, the only one from a hyperscaler, and it still falls outside the top four. Only 5% of enterprises run no dedicated agent tooling at all, and the rest have tooling that came pre-installed.</p><p>Bundled controls lead because they ship free and are enabled by default. Most filter prompts and outputs, but they do not give an agent its own identity or sandbox it. Hyperscalers sell identity-layer products, and Entra Agent ID is in the dataset at 13%, but adoption stays low. The two controls that reward incident data the most, scoped identity and isolation, are the two that the default stack does not include.</p><p>Prompt-and-output filters evaluate whether a call looks malicious. That is an intent problem, and intent cannot be solved at the language layer. CrowdStrike CTO Elia Zaitsev drew the line in an <a href="https://venturebeat.com/security/rsac-2026-agent-identity-frameworks-three-gaps">interview at RSAC 2026</a>. "Observing actual kinetic actions is a structured, solvable problem," Zaitsev said. "Intent is not." CrowdStrike's Falcon sensor walks the process tree on an endpoint and tracks what agents did, not what agents appeared to intend. A scoped identity and an isolation boundary give that sensor something to track, while a shared credential on a bundled guardrail does not.</p><p>Cloud security went through the same cycle a decade ago, and Palo Alto Networks, CrowdStrike, and Wiz built multi-billion-dollar businesses on the gaps native cloud controls left open. Agent security is tracking the same path faster. A misconfigured storage bucket sat open until a human noticed. A misconfigured agent exploits its own over-permissioning on every run, and no human is watching when it does. Merritt Baer, chief security officer at <a href="https://www.enkryptai.com/">Enkrypt AI</a> and a former deputy CISO at AWS, <a href="https://venturebeat.com/security/most-enterprises-cant-stop-stage-three-ai-agent-threats-venturebeat-survey-finds">told VentureBeat</a> that the default layer is thinner than enterprises assume. "Enterprises believe they've 'approved' AI vendors, but what they've actually approved is an interface, not the underlying system," Baer said. "The real dependencies are one or two layers deeper, and those are the ones that fail under stress."</p><h2>Comfortable, unconvinced, and already shopping</h2><p>Here is the contradiction worth a keynote slide. Enterprises rate their agent security tooling 4.2 out of 5, with value for money at 4.1 and ease of implementation at 3.9. Those scores would make most SaaS vendors envious.</p><p>Only 35% believe their AI-enabled defenses are ahead of AI-enabled attackers, while thirty-two percent call it roughly even. Twenty-one percent say attackers lead, and another 21% say it is too early to tell, showing how enterprises trust their tooling more than they trust its outcomes.</p><p>Budgets confirm it. Forty-six percent allocate 6 to 10% of the security budget to agent security, and a full third spend 5% or less. Half the sample has already had an incident or near-miss, but the funding does not match the exposure.</p><p>Fifty-nine percent plan to adopt, add, or replace agent security tooling within 12 months, and twenty-nine percent plan to move this quarter. OpenAI leads forward interest at 34%, followed by Google at 30%, Anthropic at 29%, and Azure at 25%. The dedicated vendors draw more interest looking forward than their current single-digit footprint suggests. Satisfied customers do not reshuffle this fast unless they know the stack they're currently using is provisional.</p><h2><b>Three moves for security directors </b></h2><p><b>1. Inventory every agent’s credentials this quarter.</b> Map which agents share credentials with other agents and which run on borrowed human or service-account identities. The goal is not one credential per agent. Agents that touch multiple systems need multiple scoped identities. The goal is zero shared credentials between agents and zero borrowed human identities. Thirteen percent of surveyed enterprises already run Microsoft Entra Agent ID. Okta for AI Agents and the non-human identity specialists sell equivalents. Shared and borrowed credentials are the first thing to eliminate.</p><p><b>2. Sandbox the riskiest agents first.</b> Isolation is the least-adopted control at 30% and the only one that contains blast radius after prevention fails. Rank agents by the sensitivity of what they touch and isolate the top of the list. Above 1,000 employees, where isolation falls to 20%, this is the single highest-return move in the dataset. Sandboxing does not require replacing the agent or the platform. It requires a policy decision and an isolation layer.</p><p><b>3. Match the budget to the incident rate. </b>A third of enterprises fund agent security at 5% or less of the security budget, even though more than half have already had an incident or near-miss. Nine percent allocate more than 25% today. The full report breaks out exposure and containment by company size, showing which bands carry the most risk and the least protection.</p><p>The board's question is simpler. If one of our AI agents was compromised this afternoon, which systems did it touch, and whose credentials was it holding? For the 69% of enterprises running agents on shared credentials, the answer is a shrug. The trail goes cold at the key.</p><p>The full Q2 Agentic Security report, with the complete vendor matrix, industry cuts, and the full dataset behind these charts, debuts July 14 and 15 at <a href="https://venturebeat.com/vbtransform2026">VB Transform</a>, held at Hotel Nia in Menlo Park. The open question it leaves is whether enterprises close the agent security gap on their own terms, or whether a confirmed breach closes it for them.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-0280 | Palo Alto Cloud NGFW/PAN-OS/Prisma Access Dataplane improper authentication (EUVD-2026-42681)]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in Palo Alto Cloud NGFW, PAN-OS and Prisma Access. Impacted is an unknown function of the component Dataplane. Performing a manipulation results in improper authentication.

This vulnerability was named CVE-2026-0280. The attack may be initi...]]></description>
<link>https://tsecurity.de/de/3658235/sicherheitsluecken/cve-2026-0280-palo-alto-cloud-ngfwpan-osprisma-access-dataplane-improper-authentication-euvd-2026-42681/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658235/sicherheitsluecken/cve-2026-0280-palo-alto-cloud-ngfwpan-osprisma-access-dataplane-improper-authentication-euvd-2026-42681/</guid>
<pubDate>Thu, 09 Jul 2026 22:54:22 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">problematic</a> has been reported in <a href="https://vuldb.com/product/palo_alto:cloud_ngfw">Palo Alto Cloud NGFW, PAN-OS and Prisma Access</a>. Impacted is an unknown function of the component <em>Dataplane</em>. Performing a manipulation results in improper authentication.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-0280">CVE-2026-0280</a>. The attack may be initiated remotely. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-0284 | Palo Alto Cloud NGFW/PAN-OS/Prisma Access LSVPN xml injection (EUVD-2026-42677)]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in Palo Alto Cloud NGFW, PAN-OS and Prisma Access. The impacted element is an unknown function of the component LSVPN. The manipulation leads to xml injection.

This vulnerability is referenced as CVE-2026-0284. Remote exploitation of the atta...]]></description>
<link>https://tsecurity.de/de/3658233/sicherheitsluecken/cve-2026-0284-palo-alto-cloud-ngfwpan-osprisma-access-lsvpn-xml-injection-euvd-2026-42677/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658233/sicherheitsluecken/cve-2026-0284-palo-alto-cloud-ngfwpan-osprisma-access-lsvpn-xml-injection-euvd-2026-42677/</guid>
<pubDate>Thu, 09 Jul 2026 22:54:20 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/palo_alto:cloud_ngfw">Palo Alto Cloud NGFW, PAN-OS and Prisma Access</a>. The impacted element is an unknown function of the component <em>LSVPN</em>. The manipulation leads to xml injection.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2026-0284">CVE-2026-0284</a>. Remote exploitation of the attack is possible. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[LlamaIndex ‘legal-kb’: Agentic Retrieval over Index v2 with retrieve, find, read, and grep Tools]]></title>
<description><![CDATA[LlamaIndex’s legal-kb is a public reference app that gives agents filesystem-style access to a document knowledge base on Index v2. It exposes retrieve (hybrid semantic search), find, read, and grep as tools, with automatic per-file versioning and visual citations. The stack is TanStack Start, AI...]]></description>
<link>https://tsecurity.de/de/3646422/ai-nachrichten/llamaindex-legal-kb-agentic-retrieval-over-index-v2-with-retrieve-find-read-and-grep-tools/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646422/ai-nachrichten/llamaindex-legal-kb-agentic-retrieval-over-index-v2-with-retrieve-find-read-and-grep-tools/</guid>
<pubDate>Sun, 05 Jul 2026 10:03:49 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>LlamaIndex’s legal-kb is a public reference app that gives agents filesystem-style access to a document knowledge base on Index v2. It exposes retrieve (hybrid semantic search), find, read, and grep as tools, with automatic per-file versioning and visual citations. The stack is TanStack Start, AI SDK 6 (ToolLoopAgent), Prisma, and WorkOS.</p>
<p>The post <a href="https://www.marktechpost.com/2026/07/05/llamaindex-legal-kb-agentic-retrieval-over-index-v2-with-retrieve-find-read-and-grep-tools/">LlamaIndex ‘legal-kb’: Agentic Retrieval over Index v2 with retrieve, find, read, and grep Tools</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Diese versteckte App macht jedes Samsung Galaxy sofort besser]]></title>
<description><![CDATA[Samsung baut seit Jahren hervorragende Smartphones. Doch das volle Potenzial von One UI steckt nicht unbedingt in den Systemeinstellungen, sondern in einer App, die viele Galaxy-Nutzer nie installieren: Good Lock. Was die App alles kann, welche Module sich lohnen und wie Sie Good Lock einrichten,...]]></description>
<link>https://tsecurity.de/de/3646381/it-nachrichten/diese-versteckte-app-macht-jedes-samsung-galaxy-sofort-besser/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646381/it-nachrichten/diese-versteckte-app-macht-jedes-samsung-galaxy-sofort-besser/</guid>
<pubDate>Sun, 05 Jul 2026 09:32:34 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Samsung baut seit Jahren hervorragende Smartphones. Doch das volle Potenzial von One UI steckt nicht unbedingt in den Systemeinstellungen, sondern in einer App, die viele Galaxy-Nutzer nie installieren: <strong>Good Lock</strong>. Was die App alles kann, welche Module sich lohnen und wie Sie Good Lock einrichten, erfahren Sie hier.</p>



<h2 class="wp-block-heading toc">Was ist Samsung Good Lock?</h2>



<p>Good Lock ist ein offizieller Samsung-Dienst, der als Hub für eine Sammlung von Zusatzmodulen fungiert. Jedes dieser Module greift tief in einen bestimmten Bereich von One UI ein: den Sperrbildschirm, die Navigation, die Kamera, Benachrichtigungen, Multitasking und vieles mehr. Das Ergebnis ist ein Anpassungsgrad, der sonst nur Custom-ROMs vorbehalten war.</p>



<p>Die App ist <strong>vollständig kostenlos</strong>, wird direkt von Samsung entwickelt und ist damit so sicher wie One UI selbst. Mit One UI 8 im Jahr 2026 hat Samsung vier neue Module hinzugefügt und zahlreiche bestehende aktualisiert.</p>



<h2 class="wp-block-heading toc">Für welche Galaxy-Geräte ist Good Lock verfügbar?</h2>



<p>Good Lock läuft <a href="https://www.pcwelt.de/article/1204479/test-das-beste-samsung-galaxy-smartphone.html" data-type="link" data-id="https://www.pcwelt.de/article/1204479/test-das-beste-samsung-galaxy-smartphone.html" target="_blank" rel="noreferrer noopener">auf allen Samsung Galaxy-Geräten</a> mit <strong>One UI 6 oder neuer</strong>. Konkret bedeutet das:</p>



<ul class="wp-block-list">
<li><strong>Galaxy S-Serie</strong>: S23, S23+, S23 Ultra und neuer (inkl. S26-Reihe)</li>



<li><strong>Galaxy Z-Serie</strong>: Z Flip 5 und Z Fold 5 aufwärts</li>



<li><strong>Galaxy A-Serie</strong>: Ausgewählte Modelle mit One UI 6+</li>



<li><strong>Galaxy Tab</strong>: Tab S9 und neuer</li>
</ul>



<p>Good Lock ist im <a href="https://www.awin1.com/cread.php?awinmid=14815&amp;awinaffid=486277&amp;clickref=rss&amp;platform=dl&amp;ued=https://galaxystore.samsung.com/detail/com.samsung.android.goodlock" data-type="link" data-id="https://www.awin1.com/cread.php?awinmid=14815&amp;awinaffid=486277&amp;clickref=rss&amp;platform=dl&amp;ued=https://galaxystore.samsung.com/detail/com.samsung.android.goodlock" target="_blank" rel="noreferrer noopener">Samsung Galaxy Store</a> verfügbar und seit Ende 2025 alternativ auch über den <a href="https://play.google.com/store/apps/details?id=com.samsung.android.goodlock&amp;hl=de" data-type="link" data-id="https://play.google.com/store/apps/details?id=com.samsung.android.goodlock&amp;hl=de">Google Play Store</a>, womit die frühere Beschränkung auf bestimmte Länder entfällt. Einzelne Module können jedoch weiterhin regional eingeschränkt sein.</p>



<p><strong>Wichtig:</strong> Die einzelnen Module werden nicht automatisch installiert. Sie wählen selbst, welche Module Sie aktivieren möchten. Das spart Speicherplatz und hält das System übersichtlich.</p>



<h4 class="wp-block-heading">Die besten aktuellen Angebote für das Samsung Galaxy S26</h4>



				<div class="wp-block-price-comparison price-comparison">
		
		<div class="new_products_tab tabcontent ">

			<div class="price-comparison__record price-comparison__record--header">
				<div>
					<span>Shop</span>
				</div>
								<div class="price-comparison__price">
					<span>Preis</span>
				</div>
			</div>

								<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/24204.png" alt="coolblue" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>629,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=5RhXdKdI83ftiDOfdN0LnJe3tbSWKwr5aE5gRwf5O7p6RmIsvl8L8VovW2rD7AzJop5eUIvJnUoVAesFtOqK6EjMMr4I4bcHmza08zmpKe2a6wSRIJwKsekr84RqXb6_YPkBeTsXFjzgIkq1OUjwH4&amp;mid=686084161694&amp;id=686084161694&amp;ts=20260705&amp;log=rss" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=5RhXdKdI83ftiDOfdN0LnJe3tbSWKwr5aE5gRwf5O7p6RmIsvl8L8VovW2rD7AzJop5eUIvJnUoVAesFtOqK6EjMMr4I4bcHmza08zmpKe2a6wSRIJwKsekr84RqXb6_YPkBeTsXFjzgIkq1OUjwH4&amp;mid=686084161694&amp;id=686084161694&amp;ts=20260705&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="629,00 €" data-vars-product-vendor="coolblue" aria-label="Deal anschauen bei coolblue für 629,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  amazon_vendor">
						<div class="price-comparison__image">
															<img decoding="async" src="https://www.pcwelt.de/wp-content/themes/idg-base-theme/dist/static/img/amazon-logo.svg" alt="Amazon" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>639,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://www.amazon.de/dp/B0GPDRTBFQ?tag=pcwelt.de-21&amp;linkCode=ogi&amp;th=1&amp;psc=1&amp;ascsubtag=rss" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://www.amazon.de/dp/B0GPDRTBFQ?tag=pcwelt.de-21&amp;linkCode=ogi&amp;th=1&amp;psc=1&amp;ascsubtag=rss" data-vendor-api="amazon" data-vars-product-price="639,00 €" data-vars-product-vendor="Amazon" aria-label="Deal anschauen bei Amazon für 639,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/4541.png" alt="notebooksbilliger" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>645,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=2M_hVxkBGOjgFdiMIpCMzN6uCqCNO8-tL7nY_gEpKI5He66dKLCcTskzmk7s2ctpvSl923nsGZ8vE30bjvaFmhcExcfMRGQgECdBHof2fasebWCvty-nT7AHXdywI10YkyWbwcakYeT&amp;mid=686062104468&amp;id=686062104468&amp;ts=20260705&amp;log=rss" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=2M_hVxkBGOjgFdiMIpCMzN6uCqCNO8-tL7nY_gEpKI5He66dKLCcTskzmk7s2ctpvSl923nsGZ8vE30bjvaFmhcExcfMRGQgECdBHof2fasebWCvty-nT7AHXdywI10YkyWbwcakYeT&amp;mid=686062104468&amp;id=686062104468&amp;ts=20260705&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="645,00 €" data-vars-product-vendor="notebooksbilliger" aria-label="Deal anschauen bei notebooksbilliger für 645,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/12137.png" alt="Boomstore" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>681,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=IkDanvohS2tvsU1Wdh-mdc5Hd99OQeF7THsqZXwye-WEbEokfk-c7B4WO4b3TQhTLoFn43uV-nFaEmlykUvpU44ctEsCbqg6S9ygKvebEHEx1W2pOuolXrkpeyIRTOAb2V11tAmrzs1&amp;mid=686472923573&amp;id=686472923573&amp;ts=20260705&amp;log=rss" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=IkDanvohS2tvsU1Wdh-mdc5Hd99OQeF7THsqZXwye-WEbEokfk-c7B4WO4b3TQhTLoFn43uV-nFaEmlykUvpU44ctEsCbqg6S9ygKvebEHEx1W2pOuolXrkpeyIRTOAb2V11tAmrzs1&amp;mid=686472923573&amp;id=686472923573&amp;ts=20260705&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="681,00 €" data-vars-product-vendor="Boomstore" aria-label="Deal anschauen bei Boomstore für 681,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__hidden-records-wrapper">
									<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/21515.png" alt="JB-Computer" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>687,30 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=oRTBV_k8k-BtiDOfdN0LnJe3tbSWKwr5Zd5k8UHf2Hu6RmIsvl8L8VHKuRs3tP2bop5eUIvJnUoVAesFtOqK6EjMMr4I4bcHmza08zmpKe2a6wSRIJwKsfziX486kitPenRmPhh8kBN&amp;mid=686413404106&amp;id=686413404106&amp;ts=20260705&amp;log=rss" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=oRTBV_k8k-BtiDOfdN0LnJe3tbSWKwr5Zd5k8UHf2Hu6RmIsvl8L8VHKuRs3tP2bop5eUIvJnUoVAesFtOqK6EjMMr4I4bcHmza08zmpKe2a6wSRIJwKsfziX486kitPenRmPhh8kBN&amp;mid=686413404106&amp;id=686413404106&amp;ts=20260705&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="687,30 €" data-vars-product-vendor="JB-Computer" aria-label="Deal anschauen bei JB-Computer für 687,30 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://s24.media/shop/11af34f513114e17ab24f15ca5083429" alt="Baur Versand" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>699,99 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://lg.s24.cloud/catalog/9116/189565/9597578911" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://lg.s24.cloud/catalog/9116/189565/9597578911" data-vendor-api="shopping24" data-vars-product-price="699,99 €" data-vars-product-vendor="Baur Versand" aria-label="Deal anschauen bei Baur Versand für 699,99 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://www.pcwelt.de/wp-content/themes/idg-base-theme/dist/static/img/samsung-logo.svg" alt="Samsung" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>999,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://www.awin1.com/cread.php?awinmid=14815&amp;awinaffid=486277&amp;clickref=rss&amp;platform=dl&amp;ued=https://www.samsung.com/de/smartphones/galaxy-s26/buy/" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://www.awin1.com/cread.php?awinmid=14815&amp;awinaffid=486277&amp;clickref=rss&amp;platform=dl&amp;ued=https://www.samsung.com/de/smartphones/galaxy-s26/buy/" data-vars-product-price="999,00 €" data-vars-product-vendor="Samsung" aria-label="Deal anschauen bei Samsung für 999,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
						
									</div>
									<div class="price-comparison__record price-comparison__record--footer">
					<span class="price-comparison__footer-text">
													Preisvergleich (über 24.000 Shops weltweit)												</span>
											<button class="price-comparison__view-more-button">
							Weitere Angebote						</button>
									</div>
		</div>

		<div class="refurbished_products_tab tabcontent">
			<div class="refurbished-padding price-comparison__record price-comparison__record--header">
				<div>
					<span>Produkt</span>
				</div>
				<div class="price-comparison__price">
					<span>Preis</span>
				</div>
			</div>
							<div class="price-comparison__record price-comparison__record--footer">
					<span class="price-comparison__footer-text">
					Preisvergleich von Backmarket						</span>
									</div>
		</div>
		</div>
		


<h2 class="wp-block-heading toc">So installieren Sie Good Lock</h2>



<ol class="wp-block-list">
<li>Öffnen Sie den <strong>Galaxy Store</strong> auf Ihrem Samsung-Gerät (oder Google Play Store).</li>



<li>Suchen Sie nach “<a href="https://www.awin1.com/cread.php?awinmid=14815&amp;awinaffid=486277&amp;clickref=rss&amp;platform=dl&amp;ued=https://galaxystore.samsung.com/detail/com.samsung.android.goodlock" data-type="link" data-id="https://www.awin1.com/cread.php?awinmid=14815&amp;awinaffid=486277&amp;clickref=rss&amp;platform=dl&amp;ued=https://galaxystore.samsung.com/detail/com.samsung.android.goodlock">Good Lock</a>“. Das Icon zeigt vier farbige, ineinandergreifende Puzzleteile.</li>



<li>Installieren und öffnen Sie die App.</li>



<li>Wählen Sie die gewünschten Module direkt in Good Lock aus und laden Sie sie per Tap herunter.</li>
</ol>



<p><strong>Tipp:</strong> Installieren Sie nicht alle Module auf einmal. Starten Sie mit zwei oder drei, die Ihrem konkreten Bedarf entsprechen. </p>



<h2 class="wp-block-heading toc">Wie ist Good Lock aufgebaut?</h2>



<p>Good Lock selbst ist nur die Schaltzentrale. Nach der Installation sehen Sie eine übersichtliche Oberfläche mit vier Bereichen:</p>



<ul class="wp-block-list">
<li><strong>Make up</strong>: Module zur optischen Anpassung, etwa Themes, Sperrbildschirm und Hintergrundbilder.</li>



<li><strong>Life up</strong>: Module für Funktionen und Effizienz, zum Beispiel Navigation, Kamera, Multitasking und Audio.</li>



<li><strong>Clock</strong>: Eigenständige Kategorie für Uhren-Module (zum Beispiel ClockFace für das Always-On-Display).</li>



<li><strong>Extensions</strong>: Zusatzmodule, die quer durch die beiden Hauptkategorien “Make up” und “Life up” verfügbar sind.</li>
</ul>



<p>Tippen Sie auf ein Modul, können Sie es direkt dort herunterladen und installieren, also ohne Umweg über den Galaxy Store. Insgesamt stehen aktuell <strong>mehr als 20 Module</strong> zur Verfügung.</p>


<div class="extendedBlock-wrapper block-coreImage left"><figure data-wp-context='{"imageId":"6a4a08620d406"}' data-wp-interactive="core/image" class="wp-block-image alignleft size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/vs.png?w=1200" alt="Good Lock Overview" class="wp-image-3171243" width="1200" height="675" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Ein Überblick über die Good Lock-App von Samsung.</p>
</figcaption></figure><p class="imageCredit">PC-Welt</p></div>



<h2 class="wp-block-heading toc">Die wichtigsten Module im Überblick</h2>



<h3 class="wp-block-heading">Theme Park</h3>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4a08620db79"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/theme-park.png?w=1200" alt="good lock theme park" class="wp-image-3171247" width="1200" height="763" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Good Lock: Erstellen Sie eigene Themes &amp; Designs mit Theme Park.</p><br></figcaption></figure><p class="imageCredit">PC-Welt</p></div>



<p>Theme Park ist der Einstieg in die optische Personalisierung. Das Modul ermöglicht es, eigene Themes zu erstellen: Farben, Icon-Formen, Hintergrundbilder und Schriftarten lassen sich frei kombinieren. Vorhandene Icon-Packs aus dem Play Store können eingebunden und verwaltet werden.</p>



<p>Seit 2026 gibt es sogar einen <strong>KI-Theme-Generator</strong>. Sie beschreiben per Text, wie Ihr Theme aussehen soll, und die KI erstellt automatisch ein passendes Farbschema inklusive Icons und Hintergrundbild.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h3 class="wp-block-heading">One Hand Operation+</h3>



<p>Falls Sie, so wie ich, ein Galaxy S Ultra oder Z Fold besitzen, haben Sie bestimmt schon bemerkt: Einhändige Bedienung ist eine Herausforderung. One Hand Operation+ löst das Problem mit sechs konfigurierbaren Edge-Gesten (drei pro Seite). Jede Geste kann individuell belegt werden: Zurück, App-Übersicht, Screenshot, Taschenlampe, Benachrichtigungen und mehr.</p>



<p>Das Besondere daran ist, dass das Modul parallel zur normalen Navigationsleiste funktioniert und diese um zusätzliche Wischgesten ergänzt.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h3 class="wp-block-heading">LockStar</h3>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4a08620e236"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/lockstar.png?w=1200" alt="Lockstar Good Lock" class="wp-image-3171249" width="1200" height="614" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Good Lock: Mit dem “LockStar” Modul personalisieren Sie Ihren Sperrbildschirm.</p>
</figcaption></figure><p class="imageCredit">PC-Welt</p></div>



<p>Der Sperrbildschirm ist das Erste, was Sie sehen, wenn Sie Ihr Smartphone in die Hand nehmen. One UI lässt ihn aber nur begrenzt anpassen. LockStar öffnet hier deutlich mehr Spielraum. Per WYSIWYG-Editor ziehen Sie Uhr, Datum, Widgets und App-Shortcuts frei auf dem Bildschirm hin und her, sowohl im Hoch- als auch im Querformat. Elemente, die Ihnen nicht gefallen, blenden Sie einfach aus.</p>



<p>Besonders nützlich: LockStar schaltet <strong>App-Widgets auf dem Sperrbildschirm</strong> frei, die Samsung standardmäßig nicht erlaubt. So sehen Sie etwa den Kalender, den Schrittzähler oder die Wettervorschau direkt auf dem gesperrten Display, ohne das Smartphone erst zu entsperren. Auch App-Shortcuts lassen sich frei platzieren. Ein Tipp auf das Kamera-Symbol startet die Kamera, ohne den Entsperrvorgang zu durchlaufen.</p>



<p>Neu im Jahr 2026 sind außerdem animierte <strong>Entsperreffekte</strong>. Die neue Animation Swirl dreht den Sperrbildschirm beim Entsperren herein, und weitere Stile wie Curtain, Ripple, Mosaic oder Wave sorgen dafür, dass selbst das Entsperren des Telefons ein kleines visuelles Erlebnis wird.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h3 class="wp-block-heading">MultiStar</h3>



<p>MultiStar erweitert die Multitasking-Funktionen erheblich. Jede App kann im geteilten Bildschirm oder als Popup-Fenster geöffnet werden (auch solche, die das offiziell nicht unterstützen). Neu seit 2026 sind <strong>App-Paare auf dem Homescreen</strong>, die zwei Apps gleichzeitig im Split-Screen starten.</p>



<p>Für Foldable-Nutzer unverzichtbar: MultiStar steuert, wie Apps beim Auf- und Zuklappen zwischen Cover- und Hauptbildschirm wechseln. Samsung DeX-Nutzer profitieren von Optionen wie höheren Auflösungen oder mehr als fünf gleichzeitigen Apps auf dem verbundenen Display.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h3 class="wp-block-heading">RegiStar</h3>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4a08620e8ec"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/registar.png?w=1200" alt="RegiStar Good Lock" class="wp-image-3171258" width="1200" height="794" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Good Lock: Passen Sie mit dem RegiStar Modul ganz einfach Ihre Galaxy-Einstellungen an.</p>
</figcaption></figure><p class="imageCredit">PC-Welt</p></div>



<p>RegiStar ist das Modul für alle, denen die Standardbelegung von Tasten und Gesten nicht weit genug geht. Das bekannteste Feature ist die <strong>Backtap-Geste</strong>: Wenn Sie zweimal auf die Rückseite Ihres Smartphones tippen, öffnet sich eine frei wählbare App oder Funktion (etwa die Taschenlampe, ein Screenshot oder Expert RAW). Gerade wenn die Ein-/Aus-Taste bereits für Gemini oder die Kamera reserviert ist, schafft Backtap eine praktische dritte Steuermöglichkeit, die vollkommen unsichtbar bleibt.</p>



<p>Überdies lässt sich mit RegiStar auch die <strong>Seitentaste</strong> neu belegen: Doppeltippen und langes Drücken können unabhängig voneinander mit eigenen Aktionen verknüpft werden. Wer möchte, startet so per langem Druck direkt eine bestimmte App statt den Sprachassistenten.</p>



<p>Weniger bekannt, aber ebenso nützlich: Mit RegiStar können Sie das <strong>Einstellungsmenü von One UI umstrukturieren</strong>. Bereiche, die Sie nie benötigen, lassen sich ausblenden und häufig genutzte nach oben schieben. Die integrierte <strong>Einstellungshistorie</strong> protokolliert dabei alle kürzlich vorgenommenen Änderungen im System.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h3 class="wp-block-heading">NavStar</h3>



<p>Die Navigationsleiste sieht man täglich, doch anpassen lässt sie sich in One UI kaum. NavStar ändert das. Sofern Sie die klassische Tastennavigation nutzen, können Sie Layout, Reihenfolge und Farbe der Schaltflächen frei gestalten, den Hintergrund der Leiste einfärben und eine zusätzliche Schaltfläche einblenden, mit der sich die Leiste bei Bedarf auf Knopfdruck verstecken lässt. </p>



<p>Wenn Sie per Wischgesten navigieren, lassen sich die Empfindlichkeit und der Aktionsbereich für die linke und rechte Seite unabhängig voneinander einstellen. Das ist praktisch, wenn Sie etwa links mehr Spielraum für die Zurück-Geste möchten. Außerdem entscheiden Sie, ob der Strich am unteren Bildschirmrand sichtbar bleibt oder dezent ausblendet.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h3 class="wp-block-heading">Camera Assistant</h3>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4a08620ef6c"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/camera-assistant.png?w=1200" alt="good lock camera assistant" class="wp-image-3171263" width="1200" height="820" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>“Camera Assistant” ermöglicht es, versteckte Kamerafunktionen freizuschalten.</p>
</figcaption></figure><p class="imageCredit">PC-Welt</p></div>



<p>Camera Assistant schaltet versteckte Kamerafunktionen frei. Auf der Galaxy S26-Reihe aktiviert das Modul den <strong>24-Megapixel-Modus</strong>, der KI-Fusionsverarbeitung nutzt: schärfer als 12 MP, kleinere Dateien als 50 MP. Ein guter Sweetspot für den Alltag. Zu den weiteren Funktionen zählen unter anderem folgende:</p>



<ul class="wp-block-list">
<li><strong>Fokus-Peaking</strong> im Pro-Modus markiert scharf gestellte Bildbereiche farbig, was besonders bei manueller Fokussierung hilft.</li>



<li><strong>Serienbilder mit Intervall</strong> ermöglichen zeitgesteuerte Aufnahmeserien, etwa für Zeitraffer-Vorbereitungen. </li>



<li><strong>Auto-HDR</strong> aktiviert sich automatisch, wenn die Kamera starke Helligkeitsunterschiede erkennt</li>



<li><strong>Automatisches Objektivwechseln</strong> lässt das Gerät je nach Motiv und Zoomstufe selbst das optimale Objektiv wählen.</li>



<li><strong>Der</strong> <strong>Astro-Modus-Shortcut</strong> macht den Nachtfotografie-Modus direkt erreichbar.</li>



<li><strong>Benutzerdefinierte Auflösungsvoreinstellungen</strong> erlauben es, bevorzugte Megapixel-Stufen dauerhaft zu speichern und schnell umzuschalten.</li>
</ul>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h3 class="wp-block-heading">NotiStar</h3>



<p>Benachrichtigungen verschwinden schnell – manchmal zu schnell. NotiStar löst dieses Problem mit einer vollständigen <strong>Benachrichtigungshistorie</strong>, die alle eingegangenen Mitteilungen speichert, bis Sie sie selbst löschen. Auch versehentlich weggewischte Benachrichtigungen lassen sich so jederzeit nachlesen.</p>



<p>Weiterhin bietet NotiStar eine personalisierte <strong>Filterfunktion</strong>: Sie legen fest, von welchen Apps Sie Benachrichtigungen sehen möchten und von welchen nicht. Noch präziser wird es mit Keyword-Filtern: So können Sie beispielsweise einstellen, dass Sie von einer bestimmten App nur dann benachrichtigt werden, wenn die Nachricht ein bestimmtes Wort enthält, etwa “Rechnung” oder “Termin”. Benachrichtigungen, die den Filter nicht erfüllen, werden verworfen oder nur in der Historie gespeichert, ohne dass sie Sie aktiv stören.</p>



<p>Auch für den Sperrbildschirm ist NotiStar praktisch. Dort greift es nämlich ebenfalls, sodass Sie genau steuern, was auf dem gesperrten Display sichtbar ist. Im Februar 2026 hat Samsung das Modul mit einer überarbeiteten Benachrichtigungsverwaltung aktualisiert, die die Übersicht über mehrere Apps hinweg nochmals verbessert.</p>



<h2 class="wp-block-heading toc">Weitere empfehlenswerte Module</h2>



<ul class="wp-block-list">
<li><strong>Home Up</strong>: Anpassung des Launchers wie Rastergröße, App-Drawer, Share-Menü bereinigen </li>



<li><strong>Keys Cafe</strong>: Tastaturlayout, Tastatureffekte und Sounds </li>



<li><strong>QuickStar</strong>: Statusleisten-Symbole hinzufügen oder entfernen, Quick-Settings direkt öffnen </li>



<li><strong>Routines+</strong>: Erweiterte Bixby-Automationen mit Touch-Makros und App-basierten Auslösern </li>



<li><strong>Wonderland</strong>: Lebendige Parallax-Hintergrundbilder mit Bewegungseffekten </li>



<li><strong>ClockFace</strong>: Individuelle Uhr für Always-On-Display und Sperrbildschirm </li>



<li><strong>Game Booster+</strong>: Gamepad-Touch-Mapping, AP-Taktbegrenzung, Game-Intro-Schnellvorlauf </li>



<li><strong>Pentastic</strong>: S-Pen-Zeigerstile und Air-Command-Anpassungen (für S-Pen-Geräte) </li>



<li><strong>Nice Catch</strong>: Systemprotokoll für Benachrichtigungen, Vibrationen und Einstellungsänderungen</li>
</ul>



<p>Sollte das alles noch nicht ausreichen, finden Sie hier noch mehr Tipps, um Ihr Galaxy zu optimieren: <a href="https://www.pcwelt.de/article/2957766/android-tricks-versteckte-funktionen-ausprobieren.html" target="_blank" rel="noreferrer noopener">Diese 11 versteckten Android-Funktionen sollten Sie sofort ausprobieren</a>.</p>



<p>Und falls Sie ein Galaxy S26 besitzen: <a href="https://www.pcwelt.de/article/3136236/galaxy-s26-ultra-tipps-tricks.html" target="_blank" rel="noreferrer noopener">Die besten Tipps und Tricks für Samsung Galaxy S26</a>.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Diese versteckte App macht jedes Samsung Galaxy sofort besser]]></title>
<description><![CDATA[Samsung baut seit Jahren hervorragende Smartphones. Doch das volle Potenzial von One UI steckt nicht unbedingt in den Systemeinstellungen, sondern in einer App, die viele Galaxy-Nutzer nie installieren: Good Lock. Was die App alles kann, welche Module sich lohnen und wie Sie Good Lock einrichten,...]]></description>
<link>https://tsecurity.de/de/3640219/it-nachrichten/diese-versteckte-app-macht-jedes-samsung-galaxy-sofort-besser/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640219/it-nachrichten/diese-versteckte-app-macht-jedes-samsung-galaxy-sofort-besser/</guid>
<pubDate>Thu, 02 Jul 2026 07:48:05 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Samsung baut seit Jahren hervorragende Smartphones. Doch das volle Potenzial von One UI steckt nicht unbedingt in den Systemeinstellungen, sondern in einer App, die viele Galaxy-Nutzer nie installieren: <strong>Good Lock</strong>. Was die App alles kann, welche Module sich lohnen und wie Sie Good Lock einrichten, erfahren Sie hier.</p>



<h2 class="wp-block-heading toc">Was ist Samsung Good Lock?</h2>



<p>Good Lock ist ein offizieller Samsung-Dienst, der als Hub für eine Sammlung von Zusatzmodulen fungiert. Jedes dieser Module greift tief in einen bestimmten Bereich von One UI ein: den Sperrbildschirm, die Navigation, die Kamera, Benachrichtigungen, Multitasking und vieles mehr. Das Ergebnis ist ein Anpassungsgrad, der sonst nur Custom-ROMs vorbehalten war.</p>



<p>Die App ist <strong>vollständig kostenlos</strong>, wird direkt von Samsung entwickelt und ist damit so sicher wie One UI selbst. Mit One UI 8 im Jahr 2026 hat Samsung vier neue Module hinzugefügt und zahlreiche bestehende aktualisiert.</p>



<h2 class="wp-block-heading toc">Für welche Galaxy-Geräte ist Good Lock verfügbar?</h2>



<p>Good Lock läuft <a href="https://www.pcwelt.de/article/1204479/test-das-beste-samsung-galaxy-smartphone.html" data-type="link" data-id="https://www.pcwelt.de/article/1204479/test-das-beste-samsung-galaxy-smartphone.html" target="_blank" rel="noreferrer noopener">auf allen Samsung Galaxy-Geräten</a> mit <strong>One UI 6 oder neuer</strong>. Konkret bedeutet das:</p>



<ul class="wp-block-list">
<li><strong>Galaxy S-Serie</strong>: S23, S23+, S23 Ultra und neuer (inkl. S26-Reihe)</li>



<li><strong>Galaxy Z-Serie</strong>: Z Flip 5 und Z Fold 5 aufwärts</li>



<li><strong>Galaxy A-Serie</strong>: Ausgewählte Modelle mit One UI 6+</li>



<li><strong>Galaxy Tab</strong>: Tab S9 und neuer</li>
</ul>



<p>Good Lock ist im <a href="https://www.awin1.com/cread.php?awinmid=14815&amp;awinaffid=486277&amp;clickref=rss&amp;platform=dl&amp;ued=https://galaxystore.samsung.com/detail/com.samsung.android.goodlock" data-type="link" data-id="https://www.awin1.com/cread.php?awinmid=14815&amp;awinaffid=486277&amp;clickref=rss&amp;platform=dl&amp;ued=https://galaxystore.samsung.com/detail/com.samsung.android.goodlock" target="_blank" rel="noreferrer noopener">Samsung Galaxy Store</a> verfügbar und seit Ende 2025 alternativ auch über den <a href="https://play.google.com/store/apps/details?id=com.samsung.android.goodlock&amp;hl=de" data-type="link" data-id="https://play.google.com/store/apps/details?id=com.samsung.android.goodlock&amp;hl=de">Google Play Store</a>, womit die frühere Beschränkung auf bestimmte Länder entfällt. Einzelne Module können jedoch weiterhin regional eingeschränkt sein.</p>



<p><strong>Wichtig:</strong> Die einzelnen Module werden nicht automatisch installiert. Sie wählen selbst, welche Module Sie aktivieren möchten. Das spart Speicherplatz und hält das System übersichtlich.</p>



<h4 class="wp-block-heading">Die besten aktuellen Angebote für das Samsung Galaxy S26</h4>



				<div class="wp-block-price-comparison price-comparison">
		
		<div class="new_products_tab tabcontent ">

			<div class="price-comparison__record price-comparison__record--header">
				<div>
					<span>Shop</span>
				</div>
								<div class="price-comparison__price">
					<span>Preis</span>
				</div>
			</div>

								<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://s24.media/shop/c841a72776cf42cc9c4936ce66ef1f0e" alt="alternate" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>629,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://lg.s24.cloud/catalog/9116/195854/9488934941" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://lg.s24.cloud/catalog/9116/195854/9488934941" data-vendor-api="shopping24" data-vars-product-price="629,00 €" data-vars-product-vendor="alternate" aria-label="Deal anschauen bei alternate für 629,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/24204.png" alt="coolblue" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>629,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=5RhXdKdI83ftiDOfdN0LnJe3tbSWKwr5aE5gRwf5O7p6RmIsvl8L8VovW2rD7AzJop5eUIvJnUoVAesFtOqK6EjMMr4I4bcHmza08zmpKe2a6wSRIJwKsekr84RqXb6_YPkBeTsXFjzgIkq1OUjwH4&amp;mid=686084161694&amp;id=686084161694&amp;ts=20260702&amp;log=rss" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=5RhXdKdI83ftiDOfdN0LnJe3tbSWKwr5aE5gRwf5O7p6RmIsvl8L8VovW2rD7AzJop5eUIvJnUoVAesFtOqK6EjMMr4I4bcHmza08zmpKe2a6wSRIJwKsekr84RqXb6_YPkBeTsXFjzgIkq1OUjwH4&amp;mid=686084161694&amp;id=686084161694&amp;ts=20260702&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="629,00 €" data-vars-product-vendor="coolblue" aria-label="Deal anschauen bei coolblue für 629,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/4541.png" alt="notebooksbilliger" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>645,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=2M_hVxkBGOjgFdiMIpCMzN6uCqCNO8-tL7nY_gEpKI5He66dKLCcTskzmk7s2ctpvSl923nsGZ8vE30bjvaFmhcExcfMRGQgECdBHof2fasebWCvty-nT7AHXdywI10YkyWbwcakYeT&amp;mid=686062104468&amp;id=686062104468&amp;ts=20260702&amp;log=rss" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=2M_hVxkBGOjgFdiMIpCMzN6uCqCNO8-tL7nY_gEpKI5He66dKLCcTskzmk7s2ctpvSl923nsGZ8vE30bjvaFmhcExcfMRGQgECdBHof2fasebWCvty-nT7AHXdywI10YkyWbwcakYeT&amp;mid=686062104468&amp;id=686062104468&amp;ts=20260702&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="645,00 €" data-vars-product-vendor="notebooksbilliger" aria-label="Deal anschauen bei notebooksbilliger für 645,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  amazon_vendor">
						<div class="price-comparison__image">
															<img decoding="async" src="https://www.pcwelt.de/wp-content/themes/idg-base-theme/dist/static/img/amazon-logo.svg" alt="Amazon" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>653,99 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://www.amazon.de/dp/B0GPDRTBFQ?tag=pcwelt.de-21&amp;linkCode=ogi&amp;th=1&amp;psc=1&amp;ascsubtag=rss" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://www.amazon.de/dp/B0GPDRTBFQ?tag=pcwelt.de-21&amp;linkCode=ogi&amp;th=1&amp;psc=1&amp;ascsubtag=rss" data-vendor-api="amazon" data-vars-product-price="653,99 €" data-vars-product-vendor="Amazon" aria-label="Deal anschauen bei Amazon für 653,99 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__hidden-records-wrapper">
									<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/12137.png" alt="Boomstore" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>681,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=IkDanvohS2tvsU1Wdh-mdc5Hd99OQeF7THsqZXwye-WEbEokfk-c7B4WO4b3TQhTLoFn43uV-nFaEmlykUvpU44ctEsCbqg6S9ygKvebEHEx1W2pOuolXrkpeyIRTOAb2V11tAmrzs1&amp;mid=686472923573&amp;id=686472923573&amp;ts=20260702&amp;log=rss" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=IkDanvohS2tvsU1Wdh-mdc5Hd99OQeF7THsqZXwye-WEbEokfk-c7B4WO4b3TQhTLoFn43uV-nFaEmlykUvpU44ctEsCbqg6S9ygKvebEHEx1W2pOuolXrkpeyIRTOAb2V11tAmrzs1&amp;mid=686472923573&amp;id=686472923573&amp;ts=20260702&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="681,00 €" data-vars-product-vendor="Boomstore" aria-label="Deal anschauen bei Boomstore für 681,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/21515.png" alt="JB-Computer" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>687,30 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=oRTBV_k8k-BtiDOfdN0LnJe3tbSWKwr5Zd5k8UHf2Hu6RmIsvl8L8VHKuRs3tP2bop5eUIvJnUoVAesFtOqK6EjMMr4I4bcHmza08zmpKe2a6wSRIJwKsfziX486kitPenRmPhh8kBN&amp;mid=686413404106&amp;id=686413404106&amp;ts=20260702&amp;log=rss" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=oRTBV_k8k-BtiDOfdN0LnJe3tbSWKwr5Zd5k8UHf2Hu6RmIsvl8L8VHKuRs3tP2bop5eUIvJnUoVAesFtOqK6EjMMr4I4bcHmza08zmpKe2a6wSRIJwKsfziX486kitPenRmPhh8kBN&amp;mid=686413404106&amp;id=686413404106&amp;ts=20260702&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="687,30 €" data-vars-product-vendor="JB-Computer" aria-label="Deal anschauen bei JB-Computer für 687,30 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://www.pcwelt.de/wp-content/themes/idg-base-theme/dist/static/img/samsung-logo.svg" alt="Samsung" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>999,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://www.awin1.com/cread.php?awinmid=14815&amp;awinaffid=486277&amp;clickref=rss&amp;platform=dl&amp;ued=https://www.samsung.com/de/smartphones/galaxy-s26/buy/" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://www.awin1.com/cread.php?awinmid=14815&amp;awinaffid=486277&amp;clickref=rss&amp;platform=dl&amp;ued=https://www.samsung.com/de/smartphones/galaxy-s26/buy/" data-vars-product-price="999,00 €" data-vars-product-vendor="Samsung" aria-label="Deal anschauen bei Samsung für 999,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
						
									</div>
									<div class="price-comparison__record price-comparison__record--footer">
					<span class="price-comparison__footer-text">
													Preisvergleich (über 24.000 Shops weltweit)												</span>
											<button class="price-comparison__view-more-button">
							Weitere Angebote						</button>
									</div>
		</div>

		<div class="refurbished_products_tab tabcontent">
			<div class="refurbished-padding price-comparison__record price-comparison__record--header">
				<div>
					<span>Produkt</span>
				</div>
				<div class="price-comparison__price">
					<span>Preis</span>
				</div>
			</div>
							<div class="price-comparison__record price-comparison__record--footer">
					<span class="price-comparison__footer-text">
					Preisvergleich von Backmarket						</span>
									</div>
		</div>
		</div>
		


<h2 class="wp-block-heading toc">So installieren Sie Good Lock</h2>



<ol class="wp-block-list">
<li>Öffnen Sie den <strong>Galaxy Store</strong> auf Ihrem Samsung-Gerät (oder Google Play Store).</li>



<li>Suchen Sie nach “<a href="https://www.awin1.com/cread.php?awinmid=14815&amp;awinaffid=486277&amp;clickref=rss&amp;platform=dl&amp;ued=https://galaxystore.samsung.com/detail/com.samsung.android.goodlock" data-type="link" data-id="https://www.awin1.com/cread.php?awinmid=14815&amp;awinaffid=486277&amp;clickref=rss&amp;platform=dl&amp;ued=https://galaxystore.samsung.com/detail/com.samsung.android.goodlock">Good Lock</a>“. Das Icon zeigt vier farbige, ineinandergreifende Puzzleteile.</li>



<li>Installieren und öffnen Sie die App.</li>



<li>Wählen Sie die gewünschten Module direkt in Good Lock aus und laden Sie sie per Tap herunter.</li>
</ol>



<p><strong>Tipp:</strong> Installieren Sie nicht alle Module auf einmal. Starten Sie mit zwei oder drei, die Ihrem konkreten Bedarf entsprechen. </p>



<h2 class="wp-block-heading toc">Wie ist Good Lock aufgebaut?</h2>



<p>Good Lock selbst ist nur die Schaltzentrale. Nach der Installation sehen Sie eine übersichtliche Oberfläche mit vier Bereichen:</p>



<ul class="wp-block-list">
<li><strong>Make up</strong>: Module zur optischen Anpassung, etwa Themes, Sperrbildschirm und Hintergrundbilder.</li>



<li><strong>Life up</strong>: Module für Funktionen und Effizienz, zum Beispiel Navigation, Kamera, Multitasking und Audio.</li>



<li><strong>Clock</strong>: Eigenständige Kategorie für Uhren-Module (zum Beispiel ClockFace für das Always-On-Display).</li>



<li><strong>Extensions</strong>: Zusatzmodule, die quer durch die beiden Hauptkategorien “Make up” und “Life up” verfügbar sind.</li>
</ul>



<p>Tippen Sie auf ein Modul, können Sie es direkt dort herunterladen und installieren, also ohne Umweg über den Galaxy Store. Insgesamt stehen aktuell <strong>mehr als 20 Module</strong> zur Verfügung.</p>


<div class="extendedBlock-wrapper block-coreImage left"><figure data-wp-context='{"imageId":"6a45fb5edff02"}' data-wp-interactive="core/image" class="wp-block-image alignleft size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/vs.png?w=1200" alt="Good Lock Overview" class="wp-image-3171243" width="1200" height="675" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Ein Überblick über die Good Lock-App von Samsung.</p>
</figcaption></figure><p class="imageCredit">PC-Welt</p></div>



<h2 class="wp-block-heading toc">Die wichtigsten Module im Überblick</h2>



<h3 class="wp-block-heading">Theme Park</h3>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a45fb5ee0d74"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/theme-park.png?w=1200" alt="good lock theme park" class="wp-image-3171247" width="1200" height="763" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Good Lock: Erstellen Sie eigene Themes &amp; Designs mit Theme Park.</p><br></figcaption></figure><p class="imageCredit">PC-Welt</p></div>



<p>Theme Park ist der Einstieg in die optische Personalisierung. Das Modul ermöglicht es, eigene Themes zu erstellen: Farben, Icon-Formen, Hintergrundbilder und Schriftarten lassen sich frei kombinieren. Vorhandene Icon-Packs aus dem Play Store können eingebunden und verwaltet werden.</p>



<p>Seit 2026 gibt es sogar einen <strong>KI-Theme-Generator</strong>. Sie beschreiben per Text, wie Ihr Theme aussehen soll, und die KI erstellt automatisch ein passendes Farbschema inklusive Icons und Hintergrundbild.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h3 class="wp-block-heading">One Hand Operation+</h3>



<p>Falls Sie, so wie ich, ein Galaxy S Ultra oder Z Fold besitzen, haben Sie bestimmt schon bemerkt: Einhändige Bedienung ist eine Herausforderung. One Hand Operation+ löst das Problem mit sechs konfigurierbaren Edge-Gesten (drei pro Seite). Jede Geste kann individuell belegt werden: Zurück, App-Übersicht, Screenshot, Taschenlampe, Benachrichtigungen und mehr.</p>



<p>Das Besondere daran ist, dass das Modul parallel zur normalen Navigationsleiste funktioniert und diese um zusätzliche Wischgesten ergänzt.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h3 class="wp-block-heading">LockStar</h3>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a45fb5ee2058"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/lockstar.png?w=1200" alt="Lockstar Good Lock" class="wp-image-3171249" width="1200" height="614" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Good Lock: Mit dem “LockStar” Modul personalisieren Sie Ihren Sperrbildschirm.</p>
</figcaption></figure><p class="imageCredit">PC-Welt</p></div>



<p>Der Sperrbildschirm ist das Erste, was Sie sehen, wenn Sie Ihr Smartphone in die Hand nehmen. One UI lässt ihn aber nur begrenzt anpassen. LockStar öffnet hier deutlich mehr Spielraum. Per WYSIWYG-Editor ziehen Sie Uhr, Datum, Widgets und App-Shortcuts frei auf dem Bildschirm hin und her, sowohl im Hoch- als auch im Querformat. Elemente, die Ihnen nicht gefallen, blenden Sie einfach aus.</p>



<p>Besonders nützlich: LockStar schaltet <strong>App-Widgets auf dem Sperrbildschirm</strong> frei, die Samsung standardmäßig nicht erlaubt. So sehen Sie etwa den Kalender, den Schrittzähler oder die Wettervorschau direkt auf dem gesperrten Display, ohne das Smartphone erst zu entsperren. Auch App-Shortcuts lassen sich frei platzieren. Ein Tipp auf das Kamera-Symbol startet die Kamera, ohne den Entsperrvorgang zu durchlaufen.</p>



<p>Neu im Jahr 2026 sind außerdem animierte <strong>Entsperreffekte</strong>. Die neue Animation Swirl dreht den Sperrbildschirm beim Entsperren herein, und weitere Stile wie Curtain, Ripple, Mosaic oder Wave sorgen dafür, dass selbst das Entsperren des Telefons ein kleines visuelles Erlebnis wird.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h3 class="wp-block-heading">MultiStar</h3>



<p>MultiStar erweitert die Multitasking-Funktionen erheblich. Jede App kann im geteilten Bildschirm oder als Popup-Fenster geöffnet werden (auch solche, die das offiziell nicht unterstützen). Neu seit 2026 sind <strong>App-Paare auf dem Homescreen</strong>, die zwei Apps gleichzeitig im Split-Screen starten.</p>



<p>Für Foldable-Nutzer unverzichtbar: MultiStar steuert, wie Apps beim Auf- und Zuklappen zwischen Cover- und Hauptbildschirm wechseln. Samsung DeX-Nutzer profitieren von Optionen wie höheren Auflösungen oder mehr als fünf gleichzeitigen Apps auf dem verbundenen Display.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h3 class="wp-block-heading">RegiStar</h3>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a45fb5ee3047"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/registar.png?w=1200" alt="RegiStar Good Lock" class="wp-image-3171258" width="1200" height="794" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Good Lock: Passen Sie mit dem RegiStar Modul ganz einfach Ihre Galaxy-Einstellungen an.</p>
</figcaption></figure><p class="imageCredit">PC-Welt</p></div>



<p>RegiStar ist das Modul für alle, denen die Standardbelegung von Tasten und Gesten nicht weit genug geht. Das bekannteste Feature ist die <strong>Backtap-Geste</strong>: Wenn Sie zweimal auf die Rückseite Ihres Smartphones tippen, öffnet sich eine frei wählbare App oder Funktion (etwa die Taschenlampe, ein Screenshot oder Expert RAW). Gerade wenn die Ein-/Aus-Taste bereits für Gemini oder die Kamera reserviert ist, schafft Backtap eine praktische dritte Steuermöglichkeit, die vollkommen unsichtbar bleibt.</p>



<p>Überdies lässt sich mit RegiStar auch die <strong>Seitentaste</strong> neu belegen: Doppeltippen und langes Drücken können unabhängig voneinander mit eigenen Aktionen verknüpft werden. Wer möchte, startet so per langem Druck direkt eine bestimmte App statt den Sprachassistenten.</p>



<p>Weniger bekannt, aber ebenso nützlich: Mit RegiStar können Sie das <strong>Einstellungsmenü von One UI umstrukturieren</strong>. Bereiche, die Sie nie benötigen, lassen sich ausblenden und häufig genutzte nach oben schieben. Die integrierte <strong>Einstellungshistorie</strong> protokolliert dabei alle kürzlich vorgenommenen Änderungen im System.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h3 class="wp-block-heading">NavStar</h3>



<p>Die Navigationsleiste sieht man täglich, doch anpassen lässt sie sich in One UI kaum. NavStar ändert das. Sofern Sie die klassische Tastennavigation nutzen, können Sie Layout, Reihenfolge und Farbe der Schaltflächen frei gestalten, den Hintergrund der Leiste einfärben und eine zusätzliche Schaltfläche einblenden, mit der sich die Leiste bei Bedarf auf Knopfdruck verstecken lässt. </p>



<p>Wenn Sie per Wischgesten navigieren, lassen sich die Empfindlichkeit und der Aktionsbereich für die linke und rechte Seite unabhängig voneinander einstellen. Das ist praktisch, wenn Sie etwa links mehr Spielraum für die Zurück-Geste möchten. Außerdem entscheiden Sie, ob der Strich am unteren Bildschirmrand sichtbar bleibt oder dezent ausblendet.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h3 class="wp-block-heading">Camera Assistant</h3>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a45fb5ee3dc0"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/camera-assistant.png?w=1200" alt="good lock camera assistant" class="wp-image-3171263" width="1200" height="820" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>“Camera Assistant” ermöglicht es, versteckte Kamerafunktionen freizuschalten.</p>
</figcaption></figure><p class="imageCredit">PC-Welt</p></div>



<p>Camera Assistant schaltet versteckte Kamerafunktionen frei. Auf der Galaxy S26-Reihe aktiviert das Modul den <strong>24-Megapixel-Modus</strong>, der KI-Fusionsverarbeitung nutzt: schärfer als 12 MP, kleinere Dateien als 50 MP. Ein guter Sweetspot für den Alltag. Zu den weiteren Funktionen zählen unter anderem folgende:</p>



<ul class="wp-block-list">
<li><strong>Fokus-Peaking</strong> im Pro-Modus markiert scharf gestellte Bildbereiche farbig, was besonders bei manueller Fokussierung hilft.</li>



<li><strong>Serienbilder mit Intervall</strong> ermöglichen zeitgesteuerte Aufnahmeserien, etwa für Zeitraffer-Vorbereitungen. </li>



<li><strong>Auto-HDR</strong> aktiviert sich automatisch, wenn die Kamera starke Helligkeitsunterschiede erkennt</li>



<li><strong>Automatisches Objektivwechseln</strong> lässt das Gerät je nach Motiv und Zoomstufe selbst das optimale Objektiv wählen.</li>



<li><strong>Der</strong> <strong>Astro-Modus-Shortcut</strong> macht den Nachtfotografie-Modus direkt erreichbar.</li>



<li><strong>Benutzerdefinierte Auflösungsvoreinstellungen</strong> erlauben es, bevorzugte Megapixel-Stufen dauerhaft zu speichern und schnell umzuschalten.</li>
</ul>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h3 class="wp-block-heading">NotiStar</h3>



<p>Benachrichtigungen verschwinden schnell – manchmal zu schnell. NotiStar löst dieses Problem mit einer vollständigen <strong>Benachrichtigungshistorie</strong>, die alle eingegangenen Mitteilungen speichert, bis Sie sie selbst löschen. Auch versehentlich weggewischte Benachrichtigungen lassen sich so jederzeit nachlesen.</p>



<p>Weiterhin bietet NotiStar eine personalisierte <strong>Filterfunktion</strong>: Sie legen fest, von welchen Apps Sie Benachrichtigungen sehen möchten und von welchen nicht. Noch präziser wird es mit Keyword-Filtern: So können Sie beispielsweise einstellen, dass Sie von einer bestimmten App nur dann benachrichtigt werden, wenn die Nachricht ein bestimmtes Wort enthält, etwa “Rechnung” oder “Termin”. Benachrichtigungen, die den Filter nicht erfüllen, werden verworfen oder nur in der Historie gespeichert, ohne dass sie Sie aktiv stören.</p>



<p>Auch für den Sperrbildschirm ist NotiStar praktisch. Dort greift es nämlich ebenfalls, sodass Sie genau steuern, was auf dem gesperrten Display sichtbar ist. Im Februar 2026 hat Samsung das Modul mit einer überarbeiteten Benachrichtigungsverwaltung aktualisiert, die die Übersicht über mehrere Apps hinweg nochmals verbessert.</p>



<h2 class="wp-block-heading toc">Weitere empfehlenswerte Module</h2>



<ul class="wp-block-list">
<li><strong>Home Up</strong>: Anpassung des Launchers wie Rastergröße, App-Drawer, Share-Menü bereinigen </li>



<li><strong>Keys Cafe</strong>: Tastaturlayout, Tastatureffekte und Sounds </li>



<li><strong>QuickStar</strong>: Statusleisten-Symbole hinzufügen oder entfernen, Quick-Settings direkt öffnen </li>



<li><strong>Routines+</strong>: Erweiterte Bixby-Automationen mit Touch-Makros und App-basierten Auslösern </li>



<li><strong>Wonderland</strong>: Lebendige Parallax-Hintergrundbilder mit Bewegungseffekten </li>



<li><strong>ClockFace</strong>: Individuelle Uhr für Always-On-Display und Sperrbildschirm </li>



<li><strong>Game Booster+</strong>: Gamepad-Touch-Mapping, AP-Taktbegrenzung, Game-Intro-Schnellvorlauf </li>



<li><strong>Pentastic</strong>: S-Pen-Zeigerstile und Air-Command-Anpassungen (für S-Pen-Geräte) </li>



<li><strong>Nice Catch</strong>: Systemprotokoll für Benachrichtigungen, Vibrationen und Einstellungsänderungen</li>
</ul>



<p>Sollte das alles noch nicht ausreichen, finden Sie hier noch mehr Tipps, um Ihr Galaxy zu optimieren: <a href="https://www.pcwelt.de/article/2957766/android-tricks-versteckte-funktionen-ausprobieren.html" target="_blank" rel="noreferrer noopener">Diese 11 versteckten Android-Funktionen sollten Sie sofort ausprobieren</a>.</p>



<p>Und falls Sie ein Galaxy S26 besitzen: <a href="https://www.pcwelt.de/article/3136236/galaxy-s26-ultra-tipps-tricks.html" target="_blank" rel="noreferrer noopener">Die besten Tipps und Tricks für Samsung Galaxy S26</a>.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Diese versteckte App macht jedes Samsung Galaxy sofort besser]]></title>
<description><![CDATA[Samsung baut seit Jahren hervorragende Smartphones. Doch das volle Potenzial von One UI steckt nicht unbedingt in den Systemeinstellungen, sondern in einer App, die viele Galaxy-Nutzer nie installieren: Good Lock. Was die App alles kann, welche Module sich lohnen und wie Sie Good Lock einrichten,...]]></description>
<link>https://tsecurity.de/de/3635754/it-nachrichten/diese-versteckte-app-macht-jedes-samsung-galaxy-sofort-besser/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635754/it-nachrichten/diese-versteckte-app-macht-jedes-samsung-galaxy-sofort-besser/</guid>
<pubDate>Tue, 30 Jun 2026 15:32:21 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Samsung baut seit Jahren hervorragende Smartphones. Doch das volle Potenzial von One UI steckt nicht unbedingt in den Systemeinstellungen, sondern in einer App, die viele Galaxy-Nutzer nie installieren: <strong>Good Lock</strong>. Was die App alles kann, welche Module sich lohnen und wie Sie Good Lock einrichten, erfahren Sie hier.</p>



<h2 class="wp-block-heading toc">Was ist Samsung Good Lock?</h2>



<p>Good Lock ist ein offizieller Samsung-Dienst, der als Hub für eine Sammlung von Zusatzmodulen fungiert. Jedes dieser Module greift tief in einen bestimmten Bereich von One UI ein: den Sperrbildschirm, die Navigation, die Kamera, Benachrichtigungen, Multitasking und vieles mehr. Das Ergebnis ist ein Anpassungsgrad, der sonst nur Custom-ROMs vorbehalten war.</p>



<p>Die App ist <strong>vollständig kostenlos</strong>, wird direkt von Samsung entwickelt und ist damit so sicher wie One UI selbst. Mit One UI 8 im Jahr 2026 hat Samsung vier neue Module hinzugefügt und zahlreiche bestehende aktualisiert.</p>



<h2 class="wp-block-heading toc">Für welche Galaxy-Geräte ist Good Lock verfügbar?</h2>



<p>Good Lock läuft <a href="https://www.pcwelt.de/article/1204479/test-das-beste-samsung-galaxy-smartphone.html" data-type="link" data-id="https://www.pcwelt.de/article/1204479/test-das-beste-samsung-galaxy-smartphone.html" target="_blank" rel="noreferrer noopener">auf allen Samsung Galaxy-Geräten</a> mit <strong>One UI 6 oder neuer</strong>. Konkret bedeutet das:</p>



<ul class="wp-block-list">
<li><strong>Galaxy S-Serie</strong>: S23, S23+, S23 Ultra und neuer (inkl. S26-Reihe)</li>



<li><strong>Galaxy Z-Serie</strong>: Z Flip 5 und Z Fold 5 aufwärts</li>



<li><strong>Galaxy A-Serie</strong>: Ausgewählte Modelle mit One UI 6+</li>



<li><strong>Galaxy Tab</strong>: Tab S9 und neuer</li>
</ul>



<p>Good Lock ist im <a href="https://www.awin1.com/cread.php?awinmid=14815&amp;awinaffid=486277&amp;clickref=rss&amp;platform=dl&amp;ued=https://galaxystore.samsung.com/detail/com.samsung.android.goodlock" data-type="link" data-id="https://www.awin1.com/cread.php?awinmid=14815&amp;awinaffid=486277&amp;clickref=rss&amp;platform=dl&amp;ued=https://galaxystore.samsung.com/detail/com.samsung.android.goodlock" target="_blank" rel="noreferrer noopener">Samsung Galaxy Store</a> verfügbar und seit Ende 2025 alternativ auch über den <a href="https://play.google.com/store/apps/details?id=com.samsung.android.goodlock&amp;hl=de" data-type="link" data-id="https://play.google.com/store/apps/details?id=com.samsung.android.goodlock&amp;hl=de">Google Play Store</a>, womit die frühere Beschränkung auf bestimmte Länder entfällt. Einzelne Module können jedoch weiterhin regional eingeschränkt sein.</p>



<p><strong>Wichtig:</strong> Die einzelnen Module werden nicht automatisch installiert. Sie wählen selbst, welche Module Sie aktivieren möchten. Das spart Speicherplatz und hält das System übersichtlich.</p>



<h4 class="wp-block-heading">Die besten aktuellen Angebote für das Samsung Galaxy S26</h4>



				<div class="wp-block-price-comparison price-comparison">
		
		<div class="new_products_tab tabcontent ">

			<div class="price-comparison__record price-comparison__record--header">
				<div>
					<span>Shop</span>
				</div>
								<div class="price-comparison__price">
					<span>Preis</span>
				</div>
			</div>

								<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/4541.png" alt="notebooksbilliger" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>645,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=2M_hVxkBGOjgFdiMIpCMzN6uCqCNO8-tL7nY_gEpKI5He66dKLCcTskzmk7s2ctpvSl923nsGZ8vE30bjvaFmhcExcfMRGQgECdBHof2fasebWCvty-nT7AHXdywI10YkyWbwcakYeT&amp;mid=686062104468&amp;id=686062104468&amp;ts=20260630&amp;log=rss" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=2M_hVxkBGOjgFdiMIpCMzN6uCqCNO8-tL7nY_gEpKI5He66dKLCcTskzmk7s2ctpvSl923nsGZ8vE30bjvaFmhcExcfMRGQgECdBHof2fasebWCvty-nT7AHXdywI10YkyWbwcakYeT&amp;mid=686062104468&amp;id=686062104468&amp;ts=20260630&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="645,00 €" data-vars-product-vendor="notebooksbilliger" aria-label="Deal anschauen bei notebooksbilliger für 645,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  amazon_vendor">
						<div class="price-comparison__image">
															<img decoding="async" src="https://www.pcwelt.de/wp-content/themes/idg-base-theme/dist/static/img/amazon-logo.svg" alt="Amazon" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>653,99 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://www.amazon.de/dp/B0GPDRTBFQ?tag=pcwelt.de-21&amp;linkCode=ogi&amp;th=1&amp;psc=1&amp;ascsubtag=rss" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://www.amazon.de/dp/B0GPDRTBFQ?tag=pcwelt.de-21&amp;linkCode=ogi&amp;th=1&amp;psc=1&amp;ascsubtag=rss" data-vendor-api="amazon" data-vars-product-price="653,99 €" data-vars-product-vendor="Amazon" aria-label="Deal anschauen bei Amazon für 653,99 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://s24.media/shop/11af34f513114e17ab24f15ca5083429" alt="Baur Versand" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>679,99 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://lg.s24.cloud/catalog/9116/189565/9597578911" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://lg.s24.cloud/catalog/9116/189565/9597578911" data-vendor-api="shopping24" data-vars-product-price="679,99 €" data-vars-product-vendor="Baur Versand" aria-label="Deal anschauen bei Baur Versand für 679,99 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/934.png" alt="baur.de" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>679,99 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=_K2euBFgD2xVf28VzW0Dp4eF8ZBoGX1q7oclkqNGPtB1g7_hVoNHUkzJ7qk5fi_BFKfpa4qJRMyifaNTjVLvixX1TOnIqOwJA2V-OBS6X81SacX3_ODkWrISnBARmtrczkp3az1ABJkAZJDmuINrRwl0EGfRgUmYznRzjb2RSOS&amp;mid=686076524991&amp;id=686076524991&amp;ts=20260630&amp;log=rss" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=_K2euBFgD2xVf28VzW0Dp4eF8ZBoGX1q7oclkqNGPtB1g7_hVoNHUkzJ7qk5fi_BFKfpa4qJRMyifaNTjVLvixX1TOnIqOwJA2V-OBS6X81SacX3_ODkWrISnBARmtrczkp3az1ABJkAZJDmuINrRwl0EGfRgUmYznRzjb2RSOS&amp;mid=686076524991&amp;id=686076524991&amp;ts=20260630&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="679,99 €" data-vars-product-vendor="baur.de" aria-label="Deal anschauen bei baur.de für 679,99 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__hidden-records-wrapper">
									<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/3667.png" alt="OTTO" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>679,99 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=ToyoE3Qog-EXVSmyu4TSBO4UKYrRUyPbHn5RGr8i_UEDftWI6HGQteiX-dvICJsBwFHOlsImnQSXBMXHzERkICGVoUEnRc6u9avFq6OT0rA7VT824OXt7uONAUhNTIj6j4iYt2zObaKLfJYdwB_xfA&amp;mid=686062118215&amp;id=686062118215&amp;ts=20260630&amp;log=rss" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=ToyoE3Qog-EXVSmyu4TSBO4UKYrRUyPbHn5RGr8i_UEDftWI6HGQteiX-dvICJsBwFHOlsImnQSXBMXHzERkICGVoUEnRc6u9avFq6OT0rA7VT824OXt7uONAUhNTIj6j4iYt2zObaKLfJYdwB_xfA&amp;mid=686062118215&amp;id=686062118215&amp;ts=20260630&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="679,99 €" data-vars-product-vendor="OTTO" aria-label="Deal anschauen bei OTTO für 679,99 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/12137.png" alt="Boomstore" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>681,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=IkDanvohS2tvsU1Wdh-mdc5Hd99OQeF7THsqZXwye-WEbEokfk-c7B4WO4b3TQhTLoFn43uV-nFaEmlykUvpU44ctEsCbqg6S9ygKvebEHEx1W2pOuolXrkpeyIRTOAb2V11tAmrzs1&amp;mid=686472923573&amp;id=686472923573&amp;ts=20260630&amp;log=rss" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=IkDanvohS2tvsU1Wdh-mdc5Hd99OQeF7THsqZXwye-WEbEokfk-c7B4WO4b3TQhTLoFn43uV-nFaEmlykUvpU44ctEsCbqg6S9ygKvebEHEx1W2pOuolXrkpeyIRTOAb2V11tAmrzs1&amp;mid=686472923573&amp;id=686472923573&amp;ts=20260630&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="681,00 €" data-vars-product-vendor="Boomstore" aria-label="Deal anschauen bei Boomstore für 681,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/21515.png" alt="JB-Computer" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>687,30 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=oRTBV_k8k-BtiDOfdN0LnJe3tbSWKwr5Zd5k8UHf2Hu6RmIsvl8L8VHKuRs3tP2bop5eUIvJnUoVAesFtOqK6EjMMr4I4bcHmza08zmpKe2a6wSRIJwKsfziX486kitPenRmPhh8kBN&amp;mid=686413404106&amp;id=686413404106&amp;ts=20260630&amp;log=rss" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=oRTBV_k8k-BtiDOfdN0LnJe3tbSWKwr5Zd5k8UHf2Hu6RmIsvl8L8VHKuRs3tP2bop5eUIvJnUoVAesFtOqK6EjMMr4I4bcHmza08zmpKe2a6wSRIJwKsfziX486kitPenRmPhh8kBN&amp;mid=686413404106&amp;id=686413404106&amp;ts=20260630&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="687,30 €" data-vars-product-vendor="JB-Computer" aria-label="Deal anschauen bei JB-Computer für 687,30 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/10729.png" alt="expert TechnoMarkt" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>759,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=OXcFQDJvwPyf7aDQSDOyE5FKGokce325hq5LL3gM66IY-582rLDAxQL84zXWnZWKQFHOlsImnQSXBMXHzERkIBAnQR6H9n2rHm1gr7cvp0-K65NXJdFDS4n0AtweNGU7w&amp;mid=686472936462&amp;id=686472936462&amp;ts=20260630&amp;log=rss" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=OXcFQDJvwPyf7aDQSDOyE5FKGokce325hq5LL3gM66IY-582rLDAxQL84zXWnZWKQFHOlsImnQSXBMXHzERkIBAnQR6H9n2rHm1gr7cvp0-K65NXJdFDS4n0AtweNGU7w&amp;mid=686472936462&amp;id=686472936462&amp;ts=20260630&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="759,00 €" data-vars-product-vendor="expert TechnoMarkt" aria-label="Deal anschauen bei expert TechnoMarkt für 759,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://www.pcwelt.de/wp-content/themes/idg-base-theme/dist/static/img/samsung-logo.svg" alt="Samsung" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>999,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://www.awin1.com/cread.php?awinmid=14815&amp;awinaffid=486277&amp;clickref=rss&amp;platform=dl&amp;ued=https://www.samsung.com/de/smartphones/galaxy-s26/buy/" data-vars-product-name="Samsung Galaxy S26" data-vars-product-id="3101364" data-vars-category="Smartphones" data-vars-manufacturer-id="11290" data-vars-manufacturer="Samsung" data-vars-vendor="billiger,gtin,amazon,mpn,Samsung" data-vars-po="billiger,gtin,amazon,mpn" data-product="3101364" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://www.awin1.com/cread.php?awinmid=14815&amp;awinaffid=486277&amp;clickref=rss&amp;platform=dl&amp;ued=https://www.samsung.com/de/smartphones/galaxy-s26/buy/" data-vars-product-price="999,00 €" data-vars-product-vendor="Samsung" aria-label="Deal anschauen bei Samsung für 999,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
						
									</div>
									<div class="price-comparison__record price-comparison__record--footer">
					<span class="price-comparison__footer-text">
													Preisvergleich (über 24.000 Shops weltweit)												</span>
											<button class="price-comparison__view-more-button">
							Weitere Angebote						</button>
									</div>
		</div>

		<div class="refurbished_products_tab tabcontent">
			<div class="refurbished-padding price-comparison__record price-comparison__record--header">
				<div>
					<span>Produkt</span>
				</div>
				<div class="price-comparison__price">
					<span>Preis</span>
				</div>
			</div>
							<div class="price-comparison__record price-comparison__record--footer">
					<span class="price-comparison__footer-text">
					Preisvergleich von Backmarket						</span>
									</div>
		</div>
		</div>
		


<h2 class="wp-block-heading toc">So installieren Sie Good Lock</h2>



<ol class="wp-block-list">
<li>Öffnen Sie den <strong>Galaxy Store</strong> auf Ihrem Samsung-Gerät (oder Google Play Store).</li>



<li>Suchen Sie nach “<a href="https://www.awin1.com/cread.php?awinmid=14815&amp;awinaffid=486277&amp;clickref=rss&amp;platform=dl&amp;ued=https://galaxystore.samsung.com/detail/com.samsung.android.goodlock" data-type="link" data-id="https://www.awin1.com/cread.php?awinmid=14815&amp;awinaffid=486277&amp;clickref=rss&amp;platform=dl&amp;ued=https://galaxystore.samsung.com/detail/com.samsung.android.goodlock">Good Lock</a>“. Das Icon zeigt vier farbige, ineinandergreifende Puzzleteile.</li>



<li>Installieren und öffnen Sie die App.</li>



<li>Wählen Sie die gewünschten Module direkt in Good Lock aus und laden Sie sie per Tap herunter.</li>
</ol>



<p><strong>Tipp:</strong> Installieren Sie nicht alle Module auf einmal. Starten Sie mit zwei oder drei, die Ihrem konkreten Bedarf entsprechen. </p>



<h2 class="wp-block-heading toc">Wie ist Good Lock aufgebaut?</h2>



<p>Good Lock selbst ist nur die Schaltzentrale. Nach der Installation sehen Sie eine übersichtliche Oberfläche mit vier Bereichen:</p>



<ul class="wp-block-list">
<li><strong>Make up</strong>: Module zur optischen Anpassung, etwa Themes, Sperrbildschirm und Hintergrundbilder.</li>



<li><strong>Life up</strong>: Module für Funktionen und Effizienz, zum Beispiel Navigation, Kamera, Multitasking und Audio.</li>



<li><strong>Clock</strong>: Eigenständige Kategorie für Uhren-Module (zum Beispiel ClockFace für das Always-On-Display).</li>



<li><strong>Extensions</strong>: Zusatzmodule, die quer durch die beiden Hauptkategorien “Make up” und “Life up” verfügbar sind.</li>
</ul>



<p>Tippen Sie auf ein Modul, können Sie es direkt dort herunterladen und installieren, also ohne Umweg über den Galaxy Store. Insgesamt stehen aktuell <strong>mehr als 20 Module</strong> zur Verfügung.</p>


<div class="extendedBlock-wrapper block-coreImage left"><figure data-wp-context='{"imageId":"6a43c5342b68a"}' data-wp-interactive="core/image" class="wp-block-image alignleft size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/vs.png?w=1200" alt="Good Lock Overview" class="wp-image-3171243" width="1200" height="675" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Ein Überblick über die Good Lock-App von Samsung.</p>
</figcaption></figure><p class="imageCredit">PC-Welt</p></div>



<h2 class="wp-block-heading toc">Die wichtigsten Module im Überblick</h2>



<h3 class="wp-block-heading">Theme Park</h3>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a43c5342be1c"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/theme-park.png?w=1200" alt="good lock theme park" class="wp-image-3171247" width="1200" height="763" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Good Lock: Erstellen Sie eigene Themes &amp; Designs mit Theme Park.</p><br></figcaption></figure><p class="imageCredit">PC-Welt</p></div>



<p>Theme Park ist der Einstieg in die optische Personalisierung. Das Modul ermöglicht es, eigene Themes zu erstellen: Farben, Icon-Formen, Hintergrundbilder und Schriftarten lassen sich frei kombinieren. Vorhandene Icon-Packs aus dem Play Store können eingebunden und verwaltet werden.</p>



<p>Seit 2026 gibt es sogar einen <strong>KI-Theme-Generator</strong>. Sie beschreiben per Text, wie Ihr Theme aussehen soll, und die KI erstellt automatisch ein passendes Farbschema inklusive Icons und Hintergrundbild.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h3 class="wp-block-heading">One Hand Operation+</h3>



<p>Falls Sie, so wie ich, ein Galaxy S Ultra oder Z Fold besitzen, haben Sie bestimmt schon bemerkt: Einhändige Bedienung ist eine Herausforderung. One Hand Operation+ löst das Problem mit sechs konfigurierbaren Edge-Gesten (drei pro Seite). Jede Geste kann individuell belegt werden: Zurück, App-Übersicht, Screenshot, Taschenlampe, Benachrichtigungen und mehr.</p>



<p>Das Besondere daran ist, dass das Modul parallel zur normalen Navigationsleiste funktioniert und diese um zusätzliche Wischgesten ergänzt.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h3 class="wp-block-heading">LockStar</h3>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a43c5342c552"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/lockstar.png?w=1200" alt="Lockstar Good Lock" class="wp-image-3171249" width="1200" height="614" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Good Lock: Mit dem “LockStar” Modul personalisieren Sie Ihren Sperrbildschirm.</p>
</figcaption></figure><p class="imageCredit">PC-Welt</p></div>



<p>Der Sperrbildschirm ist das Erste, was Sie sehen, wenn Sie Ihr Smartphone in die Hand nehmen. One UI lässt ihn aber nur begrenzt anpassen. LockStar öffnet hier deutlich mehr Spielraum. Per WYSIWYG-Editor ziehen Sie Uhr, Datum, Widgets und App-Shortcuts frei auf dem Bildschirm hin und her, sowohl im Hoch- als auch im Querformat. Elemente, die Ihnen nicht gefallen, blenden Sie einfach aus.</p>



<p>Besonders nützlich: LockStar schaltet <strong>App-Widgets auf dem Sperrbildschirm</strong> frei, die Samsung standardmäßig nicht erlaubt. So sehen Sie etwa den Kalender, den Schrittzähler oder die Wettervorschau direkt auf dem gesperrten Display, ohne das Smartphone erst zu entsperren. Auch App-Shortcuts lassen sich frei platzieren. Ein Tipp auf das Kamera-Symbol startet die Kamera, ohne den Entsperrvorgang zu durchlaufen.</p>



<p>Neu im Jahr 2026 sind außerdem animierte <strong>Entsperreffekte</strong>. Die neue Animation Swirl dreht den Sperrbildschirm beim Entsperren herein, und weitere Stile wie Curtain, Ripple, Mosaic oder Wave sorgen dafür, dass selbst das Entsperren des Telefons ein kleines visuelles Erlebnis wird.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h3 class="wp-block-heading">MultiStar</h3>



<p>MultiStar erweitert die Multitasking-Funktionen erheblich. Jede App kann im geteilten Bildschirm oder als Popup-Fenster geöffnet werden (auch solche, die das offiziell nicht unterstützen). Neu seit 2026 sind <strong>App-Paare auf dem Homescreen</strong>, die zwei Apps gleichzeitig im Split-Screen starten.</p>



<p>Für Foldable-Nutzer unverzichtbar: MultiStar steuert, wie Apps beim Auf- und Zuklappen zwischen Cover- und Hauptbildschirm wechseln. Samsung DeX-Nutzer profitieren von Optionen wie höheren Auflösungen oder mehr als fünf gleichzeitigen Apps auf dem verbundenen Display.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h3 class="wp-block-heading">RegiStar</h3>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a43c5342cc76"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/registar.png?w=1200" alt="RegiStar Good Lock" class="wp-image-3171258" width="1200" height="794" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Good Lock: Passen Sie mit dem RegiStar Modul ganz einfach Ihre Galaxy-Einstellungen an.</p>
</figcaption></figure><p class="imageCredit">PC-Welt</p></div>



<p>RegiStar ist das Modul für alle, denen die Standardbelegung von Tasten und Gesten nicht weit genug geht. Das bekannteste Feature ist die <strong>Backtap-Geste</strong>: Wenn Sie zweimal auf die Rückseite Ihres Smartphones tippen, öffnet sich eine frei wählbare App oder Funktion (etwa die Taschenlampe, ein Screenshot oder Expert RAW). Gerade wenn die Ein-/Aus-Taste bereits für Gemini oder die Kamera reserviert ist, schafft Backtap eine praktische dritte Steuermöglichkeit, die vollkommen unsichtbar bleibt.</p>



<p>Überdies lässt sich mit RegiStar auch die <strong>Seitentaste</strong> neu belegen: Doppeltippen und langes Drücken können unabhängig voneinander mit eigenen Aktionen verknüpft werden. Wer möchte, startet so per langem Druck direkt eine bestimmte App statt den Sprachassistenten.</p>



<p>Weniger bekannt, aber ebenso nützlich: Mit RegiStar können Sie das <strong>Einstellungsmenü von One UI umstrukturieren</strong>. Bereiche, die Sie nie benötigen, lassen sich ausblenden und häufig genutzte nach oben schieben. Die integrierte <strong>Einstellungshistorie</strong> protokolliert dabei alle kürzlich vorgenommenen Änderungen im System.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h3 class="wp-block-heading">NavStar</h3>



<p>Die Navigationsleiste sieht man täglich, doch anpassen lässt sie sich in One UI kaum. NavStar ändert das. Sofern Sie die klassische Tastennavigation nutzen, können Sie Layout, Reihenfolge und Farbe der Schaltflächen frei gestalten, den Hintergrund der Leiste einfärben und eine zusätzliche Schaltfläche einblenden, mit der sich die Leiste bei Bedarf auf Knopfdruck verstecken lässt. </p>



<p>Wenn Sie per Wischgesten navigieren, lassen sich die Empfindlichkeit und der Aktionsbereich für die linke und rechte Seite unabhängig voneinander einstellen. Das ist praktisch, wenn Sie etwa links mehr Spielraum für die Zurück-Geste möchten. Außerdem entscheiden Sie, ob der Strich am unteren Bildschirmrand sichtbar bleibt oder dezent ausblendet.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h3 class="wp-block-heading">Camera Assistant</h3>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a43c5342d351"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/camera-assistant.png?w=1200" alt="good lock camera assistant" class="wp-image-3171263" width="1200" height="820" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>“Camera Assistant” ermöglicht es, versteckte Kamerafunktionen freizuschalten.</p>
</figcaption></figure><p class="imageCredit">PC-Welt</p></div>



<p>Camera Assistant schaltet versteckte Kamerafunktionen frei. Auf der Galaxy S26-Reihe aktiviert das Modul den <strong>24-Megapixel-Modus</strong>, der KI-Fusionsverarbeitung nutzt: schärfer als 12 MP, kleinere Dateien als 50 MP. Ein guter Sweetspot für den Alltag. Zu den weiteren Funktionen zählen unter anderem folgende:</p>



<ul class="wp-block-list">
<li><strong>Fokus-Peaking</strong> im Pro-Modus markiert scharf gestellte Bildbereiche farbig, was besonders bei manueller Fokussierung hilft.</li>



<li><strong>Serienbilder mit Intervall</strong> ermöglichen zeitgesteuerte Aufnahmeserien, etwa für Zeitraffer-Vorbereitungen. </li>



<li><strong>Auto-HDR</strong> aktiviert sich automatisch, wenn die Kamera starke Helligkeitsunterschiede erkennt</li>



<li><strong>Automatisches Objektivwechseln</strong> lässt das Gerät je nach Motiv und Zoomstufe selbst das optimale Objektiv wählen.</li>



<li><strong>Der</strong> <strong>Astro-Modus-Shortcut</strong> macht den Nachtfotografie-Modus direkt erreichbar.</li>



<li><strong>Benutzerdefinierte Auflösungsvoreinstellungen</strong> erlauben es, bevorzugte Megapixel-Stufen dauerhaft zu speichern und schnell umzuschalten.</li>
</ul>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h3 class="wp-block-heading">NotiStar</h3>



<p>Benachrichtigungen verschwinden schnell – manchmal zu schnell. NotiStar löst dieses Problem mit einer vollständigen <strong>Benachrichtigungshistorie</strong>, die alle eingegangenen Mitteilungen speichert, bis Sie sie selbst löschen. Auch versehentlich weggewischte Benachrichtigungen lassen sich so jederzeit nachlesen.</p>



<p>Weiterhin bietet NotiStar eine personalisierte <strong>Filterfunktion</strong>: Sie legen fest, von welchen Apps Sie Benachrichtigungen sehen möchten und von welchen nicht. Noch präziser wird es mit Keyword-Filtern: So können Sie beispielsweise einstellen, dass Sie von einer bestimmten App nur dann benachrichtigt werden, wenn die Nachricht ein bestimmtes Wort enthält, etwa “Rechnung” oder “Termin”. Benachrichtigungen, die den Filter nicht erfüllen, werden verworfen oder nur in der Historie gespeichert, ohne dass sie Sie aktiv stören.</p>



<p>Auch für den Sperrbildschirm ist NotiStar praktisch. Dort greift es nämlich ebenfalls, sodass Sie genau steuern, was auf dem gesperrten Display sichtbar ist. Im Februar 2026 hat Samsung das Modul mit einer überarbeiteten Benachrichtigungsverwaltung aktualisiert, die die Übersicht über mehrere Apps hinweg nochmals verbessert.</p>



<h2 class="wp-block-heading toc">Weitere empfehlenswerte Module</h2>



<ul class="wp-block-list">
<li><strong>Home Up</strong>: Anpassung des Launchers wie Rastergröße, App-Drawer, Share-Menü bereinigen </li>



<li><strong>Keys Cafe</strong>: Tastaturlayout, Tastatureffekte und Sounds </li>



<li><strong>QuickStar</strong>: Statusleisten-Symbole hinzufügen oder entfernen, Quick-Settings direkt öffnen </li>



<li><strong>Routines+</strong>: Erweiterte Bixby-Automationen mit Touch-Makros und App-basierten Auslösern </li>



<li><strong>Wonderland</strong>: Lebendige Parallax-Hintergrundbilder mit Bewegungseffekten </li>



<li><strong>ClockFace</strong>: Individuelle Uhr für Always-On-Display und Sperrbildschirm </li>



<li><strong>Game Booster+</strong>: Gamepad-Touch-Mapping, AP-Taktbegrenzung, Game-Intro-Schnellvorlauf </li>



<li><strong>Pentastic</strong>: S-Pen-Zeigerstile und Air-Command-Anpassungen (für S-Pen-Geräte) </li>



<li><strong>Nice Catch</strong>: Systemprotokoll für Benachrichtigungen, Vibrationen und Einstellungsänderungen</li>
</ul>



<p>Sollte das alles noch nicht ausreichen, finden Sie hier noch mehr Tipps, um Ihr Galaxy zu optimieren: <a href="https://www.pcwelt.de/article/2957766/android-tricks-versteckte-funktionen-ausprobieren.html" target="_blank" rel="noreferrer noopener">Diese 11 versteckten Android-Funktionen sollten Sie sofort ausprobieren</a>.</p>



<p>Und falls Sie ein Galaxy S26 besitzen: <a href="https://www.pcwelt.de/article/3136236/galaxy-s26-ultra-tipps-tricks.html" target="_blank" rel="noreferrer noopener">Die besten Tipps und Tricks für Samsung Galaxy S26</a>.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Die größten Paradoxa der Softwareentwicklung]]></title>
<description><![CDATA[Paradoxe Erlebnisse sind für Softwareentwickler Alltag.Rosemarie Mosteller | shutterstock.com



Vergleicht man den Bau von Brücken mit der Softwareentwicklung, zeigen sich bedeutende Unterschiede: Denn auch wenn keine Brücke – ähnlich wie ein Softwareprojekt – der anderen bis aufs „Haar“ gleicht...]]></description>
<link>https://tsecurity.de/de/3631887/it-security-nachrichten/die-groessten-paradoxa-der-softwareentwicklung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3631887/it-security-nachrichten/die-groessten-paradoxa-der-softwareentwicklung/</guid>
<pubDate>Mon, 29 Jun 2026 06:07:06 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2025/04/Rosemarie-Mosteller_shutterstock_1976381543_16z9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Signs of Paradoxons 16z9" class="wp-image-3963773" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Paradoxe Erlebnisse sind für Softwareentwickler Alltag.</figcaption></figure><p class="imageCredit">Rosemarie Mosteller | shutterstock.com</p></div>



<p>Vergleicht man den Bau von Brücken mit der Softwareentwicklung, zeigen sich bedeutende Unterschiede: Denn auch wenn keine Brücke – ähnlich wie ein Softwareprojekt – der anderen bis aufs „Haar“ gleicht, werden sie aus bekannten Materialien mit bekannten Eigenschaften geschaffen.  </p>



<p>Im Gegensatz dazu beinhaltet der Softwareentwicklungsprozess wesentlich mehr „<a href="https://www.computerwoche.de/article/3610320/darum-ist-software-verbuggt.html">unknown Unknowns</a>“. Was dazu führt, dass er jede Menge Paradoxa beinhaltet, mit denen Developer teilweise nur schwer umgehen können. Wichtig ist aber vor allem, sich ihre Existenz bewusst zu machen – nur so lassen sich die daraus entstehenden Fallstricke umgehen. Insbesondere, wenn es dabei um die folgenden vier Paradoxa geht.</p>



<h2 class="wp-block-heading">1. Ohne Plan, aber mit Deadline</h2>



<p>Zielführend einzuschätzen, wie lange ein Softwareprojekt dauern wird, ist wahrscheinlich die größte Herausforderung für Softwareentwickler überhaupt. Denn darüber lässt sich keine abschließende, verbindliche Aussage treffen. Sicher, man kann <a href="https://www.computerwoche.de/article/2833936/darum-versagt-ihre-aufwandsschaetzung.html">den ungefähren Aufwand schätzen</a> – das geht im Regelfall allerdings daneben. Meistens wird der zeitliche Aufwand drastisch unterschätzt.</p>



<p>Wird die gesetzte Deadline dann verpasst, ärgern sich vor allem die Kunden. Sie stecken nicht in der Haut der Devs und durchblicken die Abläufe und möglichen Hindernisse (im Regelfall) nicht. Also sind sie frustriert, weil ihre Software nicht zum vereinbarten Zeitpunkt ausgeliefert wird.  </p>



<p>Auch sämtliche Versuche, mit schicken, agilen Methoden wie Story Points oder Planing Poker zielführender vorhersagen zu wollen, wann ein Softwareprojekt abgeschlossen wird, bringen <s>nichts</s> wenig. Wir scheinen einfach nicht in der Lage, <a href="https://en.wikipedia.org/wiki/Hofstadter%27s_law">Hofstadters Gesetz</a> (der Verzögerung) zu überwinden.</p>



<h2 class="wp-block-heading">2. Mehr Mannstärke, mehr Verzug</h2>



<p>Stellt ein Manager einer Fabrik fest, dass die monatliche Quote für abgefüllte Zahnpastatuben in Gefahr ist, setzt er mehr Arbeiter ein, um die Vorgabe zu erfüllen. Ähnlich verhält es sich beim Hausbau: Wenn Sie doppelt so viele Häuser wie im Vorjahr bauen wollen, hilft es in der Regel, die Vorleistungen – Arbeit und Material – zu verdoppeln.</p>



<p>Im Fall der Softwareentwicklung verhält sich das völlig anders, wie Frederick Brooks bereits 1975 in seinem Buch „Vom Mythos des Mann-Monats“ herausgearbeitet hat. Demnach hilft es wenig, verzögerte Softwareprojekte mit zusätzlicher Mannstärke retten zu wollen. Im Gegenteil: Gemäß dem <a href="https://de.wikipedia.org/wiki/Frederick_P._Brooks">Brooks’schen Gesetz</a> verzögert das das Projekt nur noch zusätzlich. Schließlich können neu hinzukommende Teammitglieder nicht sofort zum Projekt beitragen. Sie benötigen Zeit, um sich in den Kontext komplexer Systeme einzuarbeiten, was oft auch zusätzliche Kommunikationsmaßnahmen nach sich zieht. Am Ende verzögert sich dann nicht nur alles noch weiter – es kostet auch mehr.</p>



<h2 class="wp-block-heading">3. Mehr Skills, weniger Programmier-Tasks</h2>



<p>Als Softwareentwickler umfassende Expertise aufzubauen und sämtliche erforderlichen Regeln und Feinheiten zu verinnerlichen, um <a href="https://www.computerwoche.de/article/2824308/so-entwickeln-sie-besser.html">wartbaren, sauberen Code</a> zu schreiben, nimmt etliche Jahre in Anspruch. Dabei erscheint es auch relativ paradox, dass die Programmieraufgaben mit steigender Erfahrung eher weniger werden: Statt zu programmieren, sitzen leitende Entwickler vor allem in Design-Meetings, überprüfen den Code anderer und übernehmen weitere Führungsaufgaben.  </p>



<p>Das heißt zwar nicht, dass <a href="https://www.computerwoche.de/article/2834999/3-dinge-die-senior-developer-auszeichnen.html">Senior Developer</a> einen kleineren Beitrag leisten. Schließlich sorgen sie in Führungspositionen dafür, dass zeitgemäß und zielführend gearbeitet wird und tragen so wesentlich zum Team- und Unternehmenserfolg bei. Aber am Ende schreiben sie dennoch weniger Code.</p>



<h2 class="wp-block-heading">4. Bessere Tools, keine Zeitvorteile</h2>



<p>Vergleicht man die Webentwicklung von heute mit performanten Tools wie <a href="https://www.computerwoche.de/article/2833386/die-besten-javascript-frameworks-im-vergleich.html">React</a>, <a href="https://www.computerwoche.de/article/3834789/astro-tutorial-plug-play-webentwicklung.html">Astro</a> und Next.js mit dem Gebaren von vor 30 Jahren (Stichwort <a href="https://en.wikipedia.org/wiki/Common_Gateway_Interface">Common Gateway Interface</a>), wird klar, dass wir uns seitdem um Lichtjahre weiterentwickelt haben. Doch obwohl unsere Tools immer besser und die Prozessoren immer schneller werden, scheinen sich Softwareprojekte insgesamt nicht zu beschleunigen. Das wirft Fragen auf:</p>



<ul class="wp-block-list">
<li>Unsere Websites sehen zwar immer besser aus, aber sind wir wirklich produktiver?</li>



<li>Laufen unsere Websites schneller und verarbeiten sie Daten besser?</li>
</ul>



<p>Natürlich abstrahieren die Frameworks und Bibliotheken von heute viele Komplexitäten. Sie führen aber auch zu neuen Problemen. Zum Beispiel langen Build-Pipelines, Konfigurationsalbträumen oder Abhängigkeitsproblemen. (fm)</p>



<p><strong>Sie wollen weitere interessante Beiträge zu diversen Themen aus der IT-Welt lesen? </strong><a href="https://www.computerwoche.de/newsletter-anmeldung/"><strong>Unsere kostenlosen Newsletter</strong></a><strong> liefern Ihnen alles, was IT-Profis wissen sollten – direkt in Ihre Inbox!</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-50146 | withastro up to 6.3.2 data-astro-template cross site scripting]]></title>
<description><![CDATA[A vulnerability was found in withastro astro up to 6.3.2. It has been rated as problematic. The affected element is an unknown function. The manipulation of the argument data-astro-template leads to basic cross site scripting.

This vulnerability is referenced as CVE-2026-50146. Remote exploitati...]]></description>
<link>https://tsecurity.de/de/3629802/sicherheitsluecken/cve-2026-50146-withastro-up-to-632-data-astro-template-cross-site-scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3629802/sicherheitsluecken/cve-2026-50146-withastro-up-to-632-data-astro-template-cross-site-scripting/</guid>
<pubDate>Sat, 27 Jun 2026 17:39:04 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/withastro:astro">withastro astro up to 6.3.2</a>. It has been rated as <a href="https://vuldb.com/kb/risk">problematic</a>. The affected element is an unknown function. The manipulation of the argument <em>data-astro-template</em> leads to basic cross site scripting.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2026-50146">CVE-2026-50146</a>. Remote exploitation of the attack is possible. No exploit is available.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[Top 16 Gaming Headset Angebote zum Amazon Prime Day - Delamar]]></title>
<description><![CDATA[Wir haben 16 Deals bei Amazon händisch und redaktionell für dich ausgewählt. Die größte prozentuale Ersparnis bietet das Razer Barracuda X mit 45% Rabatt. Beim Logitech G Astro A50 LIGHTSPEED sparst Du sogar bis zu 140,99€.]]></description>
<link>https://tsecurity.de/de/3625791/it-nachrichten/top-16-gaming-headset-angebote-zum-amazon-prime-day-delamar/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3625791/it-nachrichten/top-16-gaming-headset-angebote-zum-amazon-prime-day-delamar/</guid>
<pubDate>Thu, 25 Jun 2026 22:17:47 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wir haben 16 Deals bei Amazon händisch und redaktionell für dich ausgewählt. Die größte prozentuale Ersparnis bietet das Razer Barracuda X mit 45% Rabatt. Beim Logitech G Astro A50 LIGHTSPEED sparst Du sogar bis zu 140,99€.]]></content:encoded>
</item>
<item>
<title><![CDATA[IBM, Red Hat, Palo Alto team to secure open-source software]]></title>
<description><![CDATA[IBM, its RedHat subsidiary, and Palo Alto Networks are teaming up to help enterprises identify vulnerabilities in open-source software and deploy safeguards against threats, particularly those generated by AI.



The joint effort will rely on Palo Alto’s network-based virtual patching technology,...]]></description>
<link>https://tsecurity.de/de/3622647/it-security-nachrichten/ibm-red-hat-palo-alto-team-to-secure-open-source-software/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622647/it-security-nachrichten/ibm-red-hat-palo-alto-team-to-secure-open-source-software/</guid>
<pubDate>Wed, 24 Jun 2026 21:38:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>IBM, its RedHat subsidiary, and <a href="https://www.networkworld.com/article/4089591/arista-palo-alto-bolster-ai-data-center-security.html">Palo Alto Networks</a> are teaming up to help enterprises identify vulnerabilities in open-source software and deploy safeguards against threats, particularly those generated by <a href="https://www.networkworld.com/article/4089591/arista-palo-alto-bolster-ai-data-center-security.html">AI</a>.</p>



<p>The joint effort will rely on Palo Alto’s network-based virtual patching technology, which is found in its <a href="https://www.networkworld.com/article/4084195/palo-alto-networks-readies-security-for-ai-first-world.html">Prisma security software</a>, and IBM/Red Hat’s Project Lightwell, a software remediation initiative designed to help enterprises secure open-source software. Vulnerability intelligence from both vendors will also contribute to threat detection and remediation, the companies stated.  </p>



<p>Announced in May, <a href="https://newsroom.ibm.com/2026-05-28-ibm-and-red-hat-commit-5-billion-to-redefine-the-future-of-open-source-in-the-ai-era">Project Lighthouse</a> is IBM and Red Hat’s $5 billion project to develop what IBM calls a “trusted enterprise clearinghouse combined with a global force of engineers to identify and fix vulnerabilities at scale.”</p>



<p>“The clearinghouse will serve as a security coordination layer, using advanced AI capabilities to validate and test fixes across an unprecedented volume of open source code,” IBM stated in May. “These capabilities will be offered through commercial subscriptions, allowing enterprises to integrate secure patches directly into their existing software supply chains with enterprise-grade validation and lifecycle management.”</p>



<p>Open-source software (OSS) underpins modern enterprise infrastructure, with more than 90% of Fortune 500 companies relying on OSS, IBM stated, citing a <a href="https://worldmetrics.org/opensource-statistics/">Worldmetric</a> study.</p>



<p>IBM and Red Hat said they are working with a variety of early adopters on Project Lightwell, including Bank of America, BNY, Citi, Goldman Sachs, JPMorgan Chase, Mastercard, Morgan Stanley, RBC, State Street, Visa and Wells Fargo.</p>



<p>Key elements of the Palo Alto/IBM/Red Hat initiative include:</p>



<ul class="wp-block-list">
<li><strong>Vulnerability coverage: </strong>Protection across open-source software, commercial applications, operational technology environments, and connected devices.</li>



<li><strong>Preemptive coverage: </strong>Organizations can receive virtual patch protections before official software patches become available, helping reduce exposure while remediation is underway.</li>



<li><strong>Rapid protection</strong>: When a new vulnerability is discovered, network-level protections can be deployed the same day, with a long-term goal of reducing the time from validated discovery to protection.   </li>
</ul>



<p>The companies said they also plan to establish secure processes for sharing vulnerability information across participating software vendors, technology providers, and security teams. The idea is to accelerate protection development and provide anonymized telemetry on real-world exploitation attempts, the companies stated.</p>



<p>“AI has compressed the window between vulnerability discovery and exploit from weeks to minutes. Traditional patching cannot keep pace,” said Nikesh Arora, CEO and chairman of Palo Alto Networks, in a statement. “By collaborating with IBM and Red Hat, we are shifting the advantage back to defenders. This powerful combination allows us to neutralize threats in the network while providing uninterrupted business continuity for our global clients.”</p>



<p>IBM and Palo Alto have a long-running relationship of integrating security and enterprise-class networks. Recently, IBM and Palo Alto said they would combine to offer a service, <a href="https://www.paloaltonetworks.com/company/press/2025/palo-alto-networks-and-ibm-plan-to-launch-joint-solution-to-accelerate-enterprise-wide-quantum-safe-readiness">Quantum-Safe Readiness</a>, that would let enterprise customers identify cryptographic exposure, understand <a href="https://www.networkworld.com/article/4131660/ibm-research-when-ai-and-quantum-merge.html">quantum-computing</a> related risks, and accelerate their use of quantum-safe security technology.</p>



<p>In addition, the companies <a href="https://www.ibm.com/new/announcements/introducing-the-rapid-ai-security-assessment-secure-your-ai-innovation-with-ibm-and-palo-alto-networks">earlier this year</a> said they would combine to offer a service designed to help enterprises discover, assess, and prioritize security and compliance risks for their artificial intelligence implementations in the cloud.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI-SPM buyer’s guide: 14 tools to secure your AI infrastructure]]></title>
<description><![CDATA[Widespread enterprise adoption of AI has created a pressing need for security solutions — a tall order given that AI’s reach into organizational infrastructure and data is enormous and continues to grow.



Moreover, where an organization sits on the AI maturity curve impacts its security needs. ...]]></description>
<link>https://tsecurity.de/de/3620469/it-security-nachrichten/ai-spm-buyers-guide-14-tools-to-secure-your-ai-infrastructure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3620469/it-security-nachrichten/ai-spm-buyers-guide-14-tools-to-secure-your-ai-infrastructure/</guid>
<pubDate>Wed, 24 Jun 2026 09:09:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Widespread enterprise adoption of AI has created a pressing need for security solutions — a tall order given that AI’s reach into organizational infrastructure and data is enormous and continues to grow.</p>



<p>Moreover, where an organization sits on the AI maturity curve impacts its security needs. Trail of Bits CEO Dan Guide <a href="https://www.youtube.com/watch?v=kgwvAyF7qsA">describes the AI journey as a migration</a> from AI-assisted, where AI tools are used on existing workflows; through AI-augmented, which uses new workflows based on AI; to the AI-native organization, where AI “becomes a core participant in the delivery and operations of a business.”</p>



<p>Those three stages require very different approaches to securing AI. They also present challenges for AI security vendors, whose platforms must fit in multiple places in a corporate network and interact with a broad spectrum of applications — especially as agentic AI expands. As analyst <a href="https://www.linkedin.com/pulse/guide-ai-agent-governance-enterprise-david-linthicum-tkcve/">David Linthicum recently posted</a>, “the conversation now has to shift from model fascination to operational discipline. The question is how those agents should be governed once they begin touching workflows that affect customers, employees, suppliers, compliance, and revenue.” </p>



<p>Making matters worse is that the average enterprise manages 37 agents, with more than half running without security oversight or logging, according to <a href="https://www.microsoft.com/en-us/security/security-insider/emerging-trends/cyber-pulse-ai-security-report#Introduction">Microsoft’s 2026 Cyber Pulse report</a>, which also found that, while 80% of Fortune 500 companies use active AI agents, only 10% have a clear strategy for managing them.</p>



<p>That lack of strategy also opens the door for attackers to abuse corporate AI systems for malicious purposes, as the recent <a href="https://krebsonsecurity.com/2026/06/hackers-used-metas-ai-support-bot-to-seize-instagram-accounts/">exploit of Meta’s account recovery using chatbots</a> demonstrated.</p>



<p>The trick to securing AI systems is in understanding how much protection is needed and where it should be applied in the expanding AI universe. While one could rent a well-meaning AI agent called <a href="https://agentalent.ai/agents/fa682e11-52a6-4dc9-9ae8-63816d876cc9">Sentry for $7,400 per month</a> to automate the daily work of a SOC analyst, many organizations rolling out AI across their business would be best served by considering AI security posture management (AI-SPM) tools.</p>



<p>Over the past two years, this emerging field has matured, with many security vendors incorporating or acquiring SPM features as part of their general security product portfolio.</p>



<p>Some vendors, such as SentinelOne and Concentric, don’t specifically sell AI-SPM per se, but offer an SPM tool that is part of a larger package of AI security services. Others offer AI-SPM in conjunction with their other SPM tools or <a href="https://www.csoonline.com/article/573629/cnapp-buyers-guide-top-tools-compared.html">CNAPP security offerings</a>. Some vendors, such as Cyera and Palo Alto, offer multiple AI-SPM packaging alternatives with differing feature sets.</p>



<p>Choosing the right product requires careful examination of the roster of features and integrations each product offers to ensure that it doesn’t duplicate existing security tooling or worse, leave important coverage gaps.</p>



<p>Here we take a deeper look at the AI-SPM product category, with a breakdown of offerings from 14 of the leading vendors in this increasingly important security ecosystem.</p>



<h2 class="wp-block-heading">AI security posture management explained</h2>



<p><a href="https://www.cio.com/article/2503234/how-guardrails-allow-enterprises-to-deploy-safe-effective-ai.html">AI security posture management</a> is an evolving cybersecurity discipline focused on ensuring the integrity and security of AI and machine learning systems. AI-SPM encompasses strategies, tools, and techniques for monitoring, assessing, and enhancing the security of AI models, data, pipelines, applications, and services, even as threats to those entities continually evolve.</p>



<p>In the past, security posture management tools were designed for two situations: to protect general cloud operations against misconfigurations and abuse, which is the province of <a href="https://www.csoonline.com/article/657138/how-to-choose-the-best-cloud-security-posture-management-tools.html">cloud security posture management</a> tools; and to protect against data leakage or malware infections, which is the province of <a href="https://www.csoonline.com/article/2075321/top-12-data-security-posture-management-tools.html">data security posture management</a> tools. With the rise of AI and large language models (LLMs), a third SPM product category is needed to check AI cloud services and their SDKs (like <a href="https://www.csoonline.com/article/4181094/hugging-face-transformers-rce-flaw-enables-stealthy-compromise-via-ai-model-configs.html">Hugging Face Transformers</a> or Azure Open AI SDK) to prevent model abuses. This is because numerous studies have documented how AI training data can be the subject of an attack or how bad data can be injected into models to manipulate results, including creating malicious backdoors for attackers to use to enter your enterprise.</p>



<p>The latest reports about attacks on AI and AI abuse can help you better understand the scope of security challenges rapidly evolving today. MITRE continues to enhance its comprehensive database of adversary tactics — <a href="https://atlas.mitre.org/">Adversarial Threat Landscape for Artificial-Intelligence Systems (ATLAS)</a> — based on real-world attack observations. ATLAS currently spans 170 techniques and 57 case studies. <a href="https://airisk.mit.edu/">MIT researchers also maintain a growing database of more than 1,700 AI-related risks</a> that they have observed from various AI sources. Another great source of AI-related attack methods is from the Open Worldwide Application Security Project (OWASP), which maintains a <a href="https://genai.owasp.org/resource/owasp-top-10-for-llm-applications-2025/">Top 10 list of LLM exploits.</a> Security managers should examine them before choosing any AI-SPM product. They should also consult Richard Stiennon’s <a href="http://guardiansofthemachineage.com/">Guardians of the Machine Age</a>, the most comprehensive collection of general security vendors, listing more than 100 AI security vendors. The printed book offers a deeper dive into the specifics of these tools.</p>



<p>The AI-SPM vendor landscape is quickly evolving, as incumbent security vendors have made numerous acquisitions. Palo Alto Networks bought Protect.ai last year; Cato Networks acquired Aim.security; Orca acquired Opus for AI agentic security; SentinelOne acquired Prompt.Security; Varonis acquired a variety of companies, including Cyral, SlashNext, and <a href="http://alltrue.ai/">AllTrue.ai</a>; and Google acquired Wiz.</p>



<h2 class="wp-block-heading">Why enterprises need AI-SPM</h2>



<p>AI-SPMs have been designed to protect enterprise networks and applications from a range of threats to AI systems. Just like no modern business would assemble a network without an appropriate firewall, AI-SPMs “ensure that AI models stay explainable, fair, accountable, transparent and equitable,” Forrester analyst Andras Cser tells CSO. “Further good security hygiene dictates that AI infrastructure should not be allowed to be used as a steppingstone for hackers for lateral movement and data exfiltration, and should include policies to prevent and fix configuration drift.”</p>



<p>AI-SPM can also help organizations standardize on a series of AI policies, procedures, tools, and workflows that can boost their security. Guido’s talk — linked above — is chock full of suggestions on how Trail of Bits accomplished this.</p>



<h2 class="wp-block-heading">Major AI-SPM trends and product features</h2>



<p>All AI-SPM vendors make use of agentless configurations, accessing cloud-based models and leaving data on their existing platforms. This is both a security measure and to avoid moving the massive data repositories involved across the internet.</p>



<p>AI-SPM vendors also make use of AI-related mechanisms to classify and track these vast data collections and to protect them against potential abuse and attack. Many have integrated their AI-SPM solutions in one of three directions:</p>



<ul class="wp-block-list">
<li>Bolting AI-SPM onto their existing cloud or data SPM platforms with rules, compliance checking, best practices, and protection policies that bridge all three types of security postures.</li>



<li>Stitching AI-SPM into their general AI security product that can be used to formulate AI-specific policies and perform AI-based red team and penetration testing in an effort to protect AI pipelines and workloads and uncover ways that shared AI services and platforms could be compromised.</li>



<li>Incorporating AI-SPM to help identify sensitive data referenced by an AI model and to examine training data exposed to a third-party or external application.</li>
</ul>



<p>Some vendors, especially established security vendors such as CrowdStrike, Proofpoint, Palo Alto, Varonis, and Wiz, have hundreds of third-party integrations that cover the AI waterfront (such as AI assistants and model suppliers) and general IT security arena (such as development pipelines, data feeds, and tools such as SOAR and SIEM). All three types of integrations can provide better guiderails and limit an AI’s blast radius.</p>



<p>But AI-SPM is still evolving. Some vendors’ tools just perform a top-level inspection of one or two services from each of the big three cloud platforms’ AI services (Amazon, for example, has dozens of AI-related service offerings), whereas others (such as Palo Alto Networks, Cato, Cyera, Varonis, and Wiz) take a deeper dive, performing a more comprehensive examination of AI data from the AI vendors themselves and other model sources.</p>



<p>There are two open source efforts as well: <a href="https://orca.security/resources/blog/orca-ai-goat-open-source-environment-owasp-risks/">Orca’s GOAT</a> is a free learning platform that is based on the OWASP top 10 risks. Palo Alto’s Protect.ai has its collection of <a href="https://github.com/protectai">open-source tools on GitHub</a> for scanning models and discovering AI interactions and automated red teaming called ProtectAI OSS. However, neither of these projects has been recently updated.</p>



<h2 class="wp-block-heading">How to choose an AI-SPM tool</h2>



<p>Here are several considerations when deciding on the best AI-SPM tool for your enterprise: </p>



<ol class="wp-block-list">
<li><strong>Does the vendor work with your existing security tool collection?</strong> This has two dimensions: integrating with other SPM products (such as data or cloud protection), and integrating with third-party tools such as SOARs, SIEMs, or DLP products. We have included some vendors that don’t have a specific AI-related SPM (such as Concentric and CrowdStrike) but have deeply embedded AI protection into their platforms.</li>



<li><strong>How deep is the coverage across the cloud platform providers?</strong> The big three (AWS, Azure, and GCP) have many services that touch various aspects of AI, and some products only work with a few of them, or only connect with PaaS security “hubs.”</li>



<li><strong>Does the vendor continuously scan your infrastructure looking for vulnerabilities?</strong> AI can be quickly adopted and is very dynamic, so discrete scans are less useful.</li>



<li><strong>How important is having a tool that can help with <a href="https://url.usb.m.mimecastprotect.com/s/9zsRCB1MnMHEEY8nHNiwc2W8AV?domain=csoonline.com">AI red teaming</a>?</strong> Understanding the dynamic nature of how AI operates means having a different approach to penetration testing, and this can be a very useful feature. Only a few vendors offer this feature (such as Concentric, Palo Alto Networks, and Varonis).</li>
</ol>



<h2 class="wp-block-heading">Leading AI-SPM vendors and products</h2>



<p>We reached out to a range of leading AI-SPM security vendors to demonstrate their AI-related tools. Below are more details about each of the 14 we had the opportunity to preview. We have also summarized each vendor’s offerings in the features table, which also provides links, when available, to pricing and third-party integration details. Several vendors didn’t respond to our inquiries, including Baffle.io, Invicti, SecurityCompass, Tonic Security, and Zscaler.</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td><strong>Vendor</strong></td><td><strong>Product/URL</strong></td><td><strong>Entry-level pricing</strong></td><td><strong>Packaging</strong></td><td><strong>Integrations link</strong></td><td><strong>App runtime security</strong></td><td><strong>Continuous scanning?</strong></td><td><strong>MCP/Agent protection?</strong></td><td><strong>AI Red Teaming?</strong></td></tr><tr><td>Arthur.ai</td><td><a href="https://www.arthur.ai/platform">Arthur Platform</a></td><td><a href="https://www.arthur.ai/pricing">Free and paid versions</a></td><td>Single product</td><td><a href="https://www.arthur.ai/any-ai-any-use-case">Deep PaaS coverage</a></td><td>Yes</td><td>Yes</td><td>Yes</td><td>No</td></tr><tr><td>Cato Networks</td><td><a href="https://www.catonetworks.com/platform/ai-security-for-end-users/">AI Security for End Users</a></td><td></td><td>SASE platform</td><td><a href="https://support.catonetworks.com/hc/en-us/articles/13975273800733-Cato-Data-Third-Party-Supported-Integrations">Numerous</a></td><td>Yes</td><td>Yes</td><td>Yes</td><td>No</td></tr><tr><td>Concentric</td><td>No specific AI-SPM product</td><td><a href="https://aws.amazon.com/marketplace/pp/prodview-nxjxmrwq7bkea?nc2=type_a_top_search">AWS $50,000/yr, varies</a></td><td><a href="https://concentric.ai/product-overview/">Part of its DSPM platform</a></td><td><a href="https://concentric.ai/integrations/">Numerous</a></td><td>No</td><td>Yes</td><td>No</td><td>Yes</td></tr><tr><td>CrowdStrike</td><td>No specific AI-SPM product</td><td></td><td><a href="https://www.crowdstrike.com/en-us/platform/cloud-security/ai-spm/">Part of Falcon AI platform</a></td><td><a href="https://marketplace.crowdstrike.com/">Numerous</a></td><td>Yes</td><td>Yes</td><td>Yes</td><td><a href="https://www.crowdstrike.com/en-us/press-releases/crowdstrike-launches-ai-red-team-services-secure-ai-systems/">Separate service</a></td></tr><tr><td>Cyera</td><td><a href="https://www.cyera.com/platform/ai-guardian">AI Guardian</a></td><td><a href="https://aws.amazon.com/marketplace/pp/prodview-mc6f4tbu6otj4?sr=0-1&amp;ref_=beagle&amp;applicationId=AWSMPContessa">AWS $50,000/yr</a></td><td>Sold in two bundles, see description</td><td><a href="https://www.cyera.com/integrations">Numerous</a></td><td>Yes</td><td>Yes</td><td>Yes</td><td>No</td></tr><tr><td>Guardrail Technologies</td><td><a href="https://guardrail.tech/ai-traffic-light/">Traffic Light for Code and AI</a></td><td><a href="https://guardrail.tech/pricing/">Free and monthly plans</a></td><td>Also sell AI Command Center</td><td>Some</td><td>Yes</td><td>Yes</td><td>No</td><td>No</td></tr><tr><td>Microsoft</td><td><a href="https://www.microsoft.com/en-us/security/business/microsoft-purview">Purview</a></td><td>$12.60/user/mo</td><td>Part of larger CSPM platform</td><td>Some</td><td>Yes</td><td>No</td><td>Yes</td><td>No</td></tr><tr><td>OneTrust</td><td><a href="https://www.onetrust.com/solutions/ai-governance/">AI Governance</a></td><td>Subscriptions</td><td>Single product with SPM features</td><td>Some</td><td>Yes</td><td>Yes</td><td>No</td><td>No</td></tr><tr><td>Orca Security</td><td><a href="https://orca.security/platform/ai-security-posture-management/">AI-SPM</a></td><td><a href="https://aws.amazon.com/marketplace/pp/prodview-rogbt2k4b63xc?sr=0-1&amp;ref_=beagle&amp;applicationId=AWSMPContessa">AWS $84,000/yr</a></td><td>Has other AI security tools</td><td><a href="https://orca.security/integrations/">Numerous</a></td><td>Yes</td><td>Yes</td><td>Yes</td><td>No</td></tr><tr><td>Palo Alto Networks</td><td><a href="https://www.paloaltonetworks.com/prisma/prisma-ai-runtime-security">Prisma AI Security</a></td><td></td><td>Sold in two bundles, see description</td><td><a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/administration/configure-external-integrations-on-prisma-cloud/integrations-feature-support">Numerous</a></td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td></tr><tr><td>Proofpoint</td><td><a href="https://www.proofpoint.com/us/products/ai-access-security">AI Access Security</a></td><td><a href="https://aws.amazon.com/marketplace/pp/prodview-dcj7rctb55qie?sr=0-1&amp;ref_=beagle&amp;applicationId=AWSMPContessa">AWS $96,000/yr</a></td><td>People Protection Platform</td><td>Numerous</td><td>Yes</td><td>Yes</td><td>Yes</td><td>No</td></tr><tr><td>SentinelOne</td><td>No specific AI SPM product</td><td><a href="https://www.sentinelone.com/platform-packages/">$80/yr/endpoint</a></td><td><a href="https://www.sentinelone.com/platform/securing-ai/">Part of larger Singularity platform</a></td><td><a href="https://www.sentinelone.com/partners/singularity-marketplace/">Numerous</a></td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td></tr><tr><td>Varonis</td><td><a href="https://www.varonis.com/platform/ai-security">Atlas</a></td><td><a href="https://aws.amazon.com/marketplace/pp/prodview-eoyer6g2olf6k?sr=0-3&amp;ref_=beagle&amp;applicationId=AWSMPContessa">AWS $108,000/yr</a></td><td>Bundled with AI Inventory</td><td><a href="https://varonis.com/coverage">Hundreds</a></td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td></tr><tr><td>Wiz/Google</td><td><a href="https://www.wiz.io/blog/introducing-wiz-ai-app">AI App Protection Platform</a></td><td><a href="https://aws.amazon.com/marketplace/pp/prodview-ibgbkrqusncsm?sr=0-1&amp;ref_=beagle&amp;applicationId=AWSMPContessa">AWS $38,000/yr</a></td><td>Variety of bundles available</td><td>Numerous</td><td>Yes</td><td>Yes</td><td>Yes</td><td>No</td></tr></tbody></table> </div></figure>



<h3 class="wp-block-heading">Arthur.ai</h3>



<p><a href="https://url.usb.m.mimecastprotect.com/s/FchtCzq8n8HJJ54rf4fVc9Ae_i?domain=arthur.ai/">Arthur.ai’s</a> platform is a single product that offers deep PaaS coverage with both AWS and Google Cloud Platform, although unlike other AI-SPMs it doesn’t offer a wide range of third-party integrations. It includes application runtime security protection. It also scans network traffic continuously and watches for agent activity, along with policy guardrails to protect against prompt injection and sensitive data leakage. It includes behavioral analytics and governance that catch abusive agentic activities. There are <a href="https://url.usb.m.mimecastprotect.com/s/yx7UCA8LmLh77kERH8hOcGedvn?domain=arthur.ai">free and paid versions</a> starting at $10,000 annual plans for smaller networks.</p>



<h3 class="wp-block-heading">Cato Networks AI Security for End Users</h3>



<p><a href="https://www.catonetworks.com/platform/ai-security-for-end-users/">Cato Networks AI Security for End Users</a> is one of three separate AI security packages that work together with Cato’s SASE platform, the other two being protection for applications (both runtime and across the software development lifecycle) and for real-time agentic operations. The three AI packages are meant to be purchased together to provide audit trails showing what users are doing with their AI tools and to help understand and illustrate the risks. Cato’s tools can also prevent prompt injection and data leaks and find compliance blind spots. Its platform has a <a href="https://support.catonetworks.com/hc/en-us/articles/13975273800733-Cato-Data-Third-Party-Supported-Integrations">wide collection of third-party integrations</a>, including CrowdStrike, Microsoft, and Splunk SIEMs, and various data sources such as Google’s Chronicle and Rapid7. Cato Networks did not reveal pricing.</p>



<h3 class="wp-block-heading">Concentric AI and Data Security Governance</h3>



<p>Concentric sells a <a href="https://concentric.ai/product-overview/">DSPM platform</a> labelled “AI and Data Security Governance.” There is no specific AI tool, although AI pervades its product in a variety of places, including scanning various models for prompt injection, automated remediation, and the discovery and classification of data flows. It offers a <a href="https://concentric.ai/integrations/">wide collection of third-party integrations.</a> On the <a href="https://aws.amazon.com/marketplace/pp/prodview-nxjxmrwq7bkea?nc2=type_a_top_search">AWS Marketplace</a>, it sells an entry-level version for $50,000 per year that covers up to 25TB of data, with higher fees for larger data collections.</p>



<h3 class="wp-block-heading">CrowdStrike Falcon AI-SPM</h3>



<p><a href="https://www.crowdstrike.com/en-us/platform/cloud-security/ai-spm/">CrowdStrike Falcon AI-SPM</a> is not a separate product, but part of the overall Falcon Cloud security platform. It can correlate risk findings with other security services monitored by the full Falcon platform. It includes discovery of AI services and models across a variety of cloud platforms, including containers and virtual images, and can detect misconfigurations and dependencies with other software. It scans OpenAI, Amazon Bedrock, Amazon SageMaker, and Vertex AI models. <a href="https://marketplace.crowdstrike.com/">Falcon has more than 250 integrations</a> available to a wide collection of third-party security tools. You can request a free 15-day trial, but no further pricing information was disclosed.</p>



<h3 class="wp-block-heading">Cyera AI Guardian</h3>



<p>Cyera.io specializes in data file level classification. It packages its AI-SPM product in two separate bundles: either with its flagship <a href="https://www.cyera.io/platform/dspm">DSPM product</a> that has added what you might think of as AI-enriched data link protection as part of the default product’s features, or with a more complete set of security features called <a href="https://www.cyera.com/platform/ai-guardian">AI Guardian</a>. Cyera also offers a specialized add-on module used for Microsoft Copilot data scanning that can detect data used by insiders, for example. <a href="https://aws.amazon.com/marketplace/pp/prodview-mc6f4tbu6otj4?sr=0-1&amp;ref_=beagle&amp;applicationId=AWSMPContessa%20%5D">Cyera’s AWS Marketplace pricing can be found here</a> and starts at $50,000 per year. </p>



<h3 class="wp-block-heading">Guardrail Technologies Traffic Light for Code and AI</h3>



<p><a href="https://guardrail.tech/ai-traffic-light/">Guardrail Technologies Traffic Light for Code and AI</a> is designed to be a simple way to flag potential AI abuse by scanning AI-generated code and returning a red/yellow/green result to indicate potential for compromise. There is no remediation, but the tool integrates across the major AI vendors, including Anthropic, Azure Open AI, Hugging Face, and AWS Bedrock, and general security tools such as Wiz and Snyk. Guardrail has a custom AI security consulting business as well called AI Guardian. Very transparent pricing page and a 60-day free trial is available.</p>



<h3 class="wp-block-heading">Microsoft Purview</h3>



<p>Microsoft has bundled its various security posture tools into its <a href="https://www.microsoft.com/en-us/security/business/microsoft-purview">Purview offering</a>, which includes a series of AI-based Copilot apps, data SPM and classification tools, and data loss prevention extensions tuned to its various SaaS platforms such as 365, Azure, and Windows endpoints. This extends the AI security features that were originally part of its Defender for Cloud offerings. It has a limited number of third-party integrations. One-month free trials are available, and the entire suite is available for $12.60 per month per user. Microsoft has stepped up its involvement with AI with its Scout, a collection of autonomous AI agents built on top of OpenClaw. It is designed to work with its applications, using built-in security and privacy controls.</p>



<h3 class="wp-block-heading">OneTrust AI Governance</h3>



<p><a href="https://www.onetrust.com/solutions/ai-governance/">OneTrust offers AI Governance</a>, a platform that automates compliance and provides continuous monitoring of the AI landscape, across the software lifecycle starting with any AI usage at the beginning of any build. It can detect policy violations, and which AI agents are running. It offers a series of third-party integrations such as Amazon’s Bedrock and Sagemaker; Azure Foundry, ML Studio, and OpenAI; Databricks Unity Catalog and ML flow; and Google Vertex. Its subscription price is based on the number of admin users and number of AI inventory records, although no specifics were provided.</p>



<h3 class="wp-block-heading">Orca AI-SPM</h3>



<p><a href="https://orca.security/platform/ai-security/ai-spm/">Orca Security’s AI-SPM </a>is tightly integrated into the company’s security platform. It continues to expand its features, offering detections of more than 50 AI models, including training data and runtime threats, remediation, and support for Model Context Protocol to connect to other Orca-based telemetry. It <a href="https://orca.security/integrations/">continues to expand its nearly 100 integrations</a> across SIEM and SOAR systems and various cloud providers’ services. For example, it works with AWS S3, SQS, SNS, CodeBuild, CloudTrail, and Security Hub. It comes with dozens of best-practice security rules that initially focused on compliance. It also alerts when sensitive data is detected inside models and when secrets are exposed. Orca’s overall security platform shows an <a href="https://aws.amazon.com/marketplace/pp/prodview-rogbt2k4b63xc?sr=0-1&amp;ref_=beagle&amp;applicationId=AWSMPContessa">AWS Marketplace annual pricing that ranges from $84,000 to $360,000</a>, depending on the number of workloads scanned.</p>



<h3 class="wp-block-heading">Palo Alto Networks AIRS AI Security</h3>



<p>Palo Alto Networks has been busy acquiring point security vendors (Dig, ProtectAI, and an offer on Portkey) and incorporating their code into its two major product lines, Prisma and Cortex. You can purchase AI-SPM functionality in either Palo Alto product line, but they cover different aspects of the AI ecosystem. Cortex offers AI-SPM alongside the data and cloud SPMs integrated into the CNAPP suite. Prisma offers AI-SPM as part of a total AI security package called <a href="https://www.paloaltonetworks.com/prisma/prisma-ai-runtime-security">AIRS AI Security</a>, which includes runtime protection, model scanning, and a more comprehensive platform. We focus on AIRS AI, which supports top-level scans of Amazon, Google Cloud, and Azure AI services to discover AI content and can classify and examine model data and secrets and comes with many built-in AI-related policies. Prisma has a <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/administration/configure-external-integrations-on-prisma-cloud/integrations-feature-support">long list of third-party integrations</a>, including significant depth in AWS security services. That link will also take you to detailed instructions on how to set up these integrations. To complicate matters further, Palo Alto also sells a <a href="https://www.paloaltonetworks.com/sase/prisma-browser">separate Prisma secure browser extension</a> that works with these products to protect your endpoints, and that originated from technology it purchased from Talon Cyber Security in 2023. While pricing was not disclosed, our estimate is that AIRS will cost in the low six figures annually.</p>



<h3 class="wp-block-heading">Proofpoint People Protection Platform</h3>



<p>Proofpoint includes a <a href="https://www.proofpoint.com/us/products/ai-access-security">general AI security product</a> as part of its People Protection Platform that covers a wide range of protective services integrated across its other non-AI security tools. It provides runtime inspection of potential AI misconfigurations, as well as policies that include detection of agent, tools, and MCP connections, and it can generate forensic audits of AI interactions. Proofpoint’s general security platform starts at <a href="https://aws.amazon.com/marketplace/pp/prodview-dcj7rctb55qie?sr=0-1&amp;ref_=beagle&amp;applicationId=AWSMPContessa">$96,000 annually on AWS Marketplace</a>. It has several integrations with third-party services across the major cloud platform providers.</p>



<h3 class="wp-block-heading">SentinelOne Singularity Platform</h3>



<p><a href="https://www.sentinelone.com/platform/securing-ai/">SentinelOne’s Singularity platform</a> offers several AI protective features, including misconfiguration detection, attack path analysis, automated AI inventory and remediation, and integration with a variety of AI PaaS platforms such as Azure OpenAI, Google’s Vertex AI, and various AWS services. It is bundled within the company’s Cloud Native Security tool. Some of these features originated with Singularity’s purchase of Prompt.Security. Access to all the features requires purchasing the enterprise edition, which is offered with custom pricing, but lower feature tiers are available for $80 per year on <a href="https://www.sentinelone.com/platform-packages/">this public pricing page</a>. There are also <a href="https://www.sentinelone.com/partners/singularity-marketplace/">numerous integrations with its Marketplace</a>.</p>



<h3 class="wp-block-heading">Varonis Atlas AI Security</h3>



<p><a href="https://www.varonis.com/solutions/ai-security">Varonis Atlas AI Security</a> is a multipurpose security platform that offers a variety of modules, including red team/penetration testing, compliance, and third-party risk management. Its AI-SPM module is combined with an AI inventory scanner and can be used to help development teams classify data used in the AI ecosystem, such as scanning for bad AI behavior, leveraging identities improperly, and examining data flows. Automated remediation processes are built into the tool as well. There are several <a href="https://www.varonis.com/coverage">hundred third-party integrations available</a> for a wide collection of security tools, such as JFrog, Jira, Okta, and Salesforce. Varonis has two pricing components; one based on per user and per protected application and an additional price for resource consumption. Atlas is sold on the <a href="https://aws.amazon.com/marketplace/pp/prodview-ibgbkrqusncsm?sr=0-1&amp;ref_=beagle&amp;applicationId=AWSMPContessa">AWS Marketplace starting at $108,000 per year</a> and free risk assessments are available to qualified customers.</p>



<h3 class="wp-block-heading">Wiz/Google AI Application Protection Platform</h3>



<p>Google has acquired Wiz but kept its operation independent. It has a <a href="https://www.wiz.io/solutions/ai-spm">multipurpose security platform</a> that comes from a strong posture management (cloud and data) background. Its advanced version has been augmented with a comprehensive AI-related series of policies, detection algorithms, and pipeline, model, and data scanners. These are assembled into a separate AI dashboard page. It can also detect AI pipeline abuses, protect AI runtimes, identify and classify tools and agents, map dependencies graphically and suggest remediation steps. It also contains core AI-SPM features such as discovery, attack path analysis, and supply chains. Pricing for the Wiz Advanced bundle on <a href="https://aws.amazon.com/marketplace/pp/prodview-ibgbkrqusncsm?sr=0-1&amp;ref_=beagle&amp;applicationId=AWSMPContessa">AWS Marketplace is $38,000 annually</a>.</p>



<h2 class="wp-block-heading">What about AI-SPM pricing?</h2>



<p>Pricing and packaging of AI-SPM tools vary widely. Many vendors offer free trials limited to differing periods (an option that is also available on the AWS Marketplace). We pointed out the open-source alternatives earlier, which is also a good way to see how the products work, but we wouldn’t recommend relying on these tools given their lack of recent updates. The only vendors that have (mostly) transparent pricing are Guardrail Technologies (with both free and monthly plans) and SentinelOne (with various annual plans starting at $80 per endpoint). Most of the vendors didn’t want to provide pricing directly but have published pricing on the AWS Marketplace, which can give you a rough indication that most start in the low six figures for annual contracts. For a typical situation with 1,000 users the total could be in the low six-figure range annually.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Der Amazon Prime Day ist gestartet – diese Tagesangebote lohnen sich]]></title>
<description><![CDATA[Seit heute Mitternacht läuft bei Amazon der Amazon Prime Day 2026. Prime-Mitglieder haben jetzt vier Tage lang Zeit, von Bestpreisen für bekannte Markenprodukte zu profitieren. Der Prime Day endet am Freitag, den 26. Juni.



Die besten Tagesangebote am Amazon Prime Day



Rabatte gelten ausschli...]]></description>
<link>https://tsecurity.de/de/3617348/it-nachrichten/der-amazon-prime-day-ist-gestartet-diese-tagesangebote-lohnen-sich/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3617348/it-nachrichten/der-amazon-prime-day-ist-gestartet-diese-tagesangebote-lohnen-sich/</guid>
<pubDate>Tue, 23 Jun 2026 08:32:58 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Seit heute Mitternacht läuft bei Amazon der <strong>Amazon Prime Day 2026</strong>. Prime-Mitglieder haben jetzt vier Tage lang Zeit, von Bestpreisen für bekannte Markenprodukte zu profitieren. Der Prime Day endet am <strong>Freitag, den 26. Juni.</strong></p>



<p><a href="https://www.amazon.de/primeday?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Die besten Tagesangebote am Amazon Prime Day</a></p>



<h2 class="wp-block-heading">Rabatte gelten ausschließlich für Prime-Mitglieder</h2>



<p>Nur wer eine Amazon-Prime-Mitgliedschaft hat, kann auf die Tiefstpreise am Prime Day zugreifen. Aktuell kostet eine Prime-Mitgliedschaft <strong>8,99 Euro pro Monat</strong>. Man kann die Kosten aber umgehen, indem man einen <strong>Gratis-Probemonat</strong> abschließt und dann rechtzeitig wieder kündigt: <a href="https://www.amazon.de/gp/prime?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Prime-Abo jetzt kostenlos testen</a>.</p>



<h2 class="wp-block-heading">Die besten Angebote am 23. Juni</h2>



<p>Unsere Redaktion empfielt täglich die besten Deals aus den Bereichen Computer, IT, Smartphones, Smart Home und Digital Lifestyle. Am ersten Prime-Day-Tag gibt es Jahresbestpreise für viele Apple-Produkte wie dem Macbook Neo oder dem iPad Air. </p>



<p>Amazon-eigene Geräte wie der smarte Echo-Lautsprecher oder der Fire TV-Stick sind heute <strong>bis zu 65 Prozent günstiger</strong>. Außerdem sind Laptops, Tablets und Zubehör im Angebot. Bei folgenden Angeboten sollten Sie schnell sein, bevor sie vergriffen sind:</p>


<h2>📺 TVs, Streaming &amp; Heimkino</h2>
<ul>
<li><a href="https://www.amazon.de/dp/B0CZS4X2S8?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Samsung Crystal UHD 4K TV 98 Zoll</a> für 1.279 Euro</li>
<li><a href="https://www.amazon.de/dp/B0F2JBN3QH?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">LG OLED TV 65 Zoll</a> für 1.424 Euro</li>
<li><a href="https://www.amazon.de/dp/B0F457MQCQ?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Xiaomi TV 65 Zoll</a> für 369 Euro</li>
<li><a href="https://www.amazon.de/dp/B0F5BR3WSK?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Samsung Crystal TV 4K 43 Zoll</a> für 245 Euro</li>
<li><a href="https://www.amazon.de/dp/B0F457M449?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Xiaomi TV F Pro 32 Zoll</a> für 149 Euro</li>
<li><a href="https://www.amazon.de/dp/B07XTX5YBD?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Epson 4K-PRO-UHD-Projektor</a> für 1.180 Euro</li>
<li><a href="https://www.amazon.de/dp/B0D22SVP73?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Hisense 3.1 Kanal Soundbar</a> für 114 Euro</li>
<li><a href="https://www.amazon.de/dp/B09BZWZS6S?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Amazon Fire TV Cube</a> für 109,99 Euro</li>
<li><a href="https://www.amazon.de/dp/B0CW4HD359?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Amazon Fire TV Stick 4K Max</a> für 46,99 Euro</li>
<li><a href="https://www.amazon.de/dp/B0DJGCX6Q2?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Amazon Fire TV Stick HD</a> für 19,99 Euro</li>
</ul>
<h2>💻 Laptops, Tablets &amp; Computer</h2>
<h3>Laptops</h3>
<ul>
<li><a href="https://www.amazon.de/dp/B0DVZQ8TJV?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">HP Omen MAX Gaming Laptop</a> für 2.599 Euro</li>
<li><a href="https://www.amazon.de/dp/B0FFMJ72C3?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">ASUS Vivobook 17 Laptop</a> für 549 Euro</li>
<li><a href="https://www.amazon.de/dp/B0F29HYVJZ?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">ASUS Vivobook 16 Laptop</a> für 449 Euro</li>
<li><a href="https://www.amazon.de/dp/B0DSGB8C6M?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Lenovo IdeaPad Slim 3 Laptop</a> für 480 Euro</li>
<li><a href="https://www.amazon.de/dp/B0F9LFB3HM?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">HP Laptop 17,3 Zoll</a> für 329 Euro</li>
<li><a href="https://www.amazon.de/dp/B0GS5S368L?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Apple 13 Zoll MacBook Neo</a> für 739 Euro</li>
</ul>
<h3>Tablets &amp; Zubehör</h3>
<ul>
<li><a href="https://www.amazon.de/dp/B0DZ76WSYH?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Apple iPad Air 13 Zoll mit M3 Chip</a> für 899 Euro</li>
<li><a href="https://www.amazon.de/dp/B0DZ778WX5?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Apple iPad Air 11 Zoll mit M3 Chip</a> für 719 Euro</li>
<li><a href="https://www.amazon.de/dp/B0D3J7CKFR?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Apple Pencil Pro</a> für 109 Euro</li>
<li><a href="https://www.amazon.de/dp/B0797FYB3K?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Logitech Advanced Kombi Tastatur</a> für 34 Euro</li>
</ul>
<h3>Monitore &amp; Displays</h3>
<ul>
<li><a href="https://www.amazon.de/dp/B0DCGCWZZF?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Samsung 49 Zoll OLED Gaming Monitor</a> für 799,99 Euro</li>
<li><a href="https://www.amazon.de/dp/B0F29RH4RY?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Dell 27 Plus Monitor</a> für 273 Euro</li>
<li><a href="https://www.amazon.de/dp/B0F8DWCKQL?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Lenovo 27 Zoll QHD WLED Monitor</a> für 119 Euro</li>
<li><a href="https://www.amazon.de/dp/B0DZD8Y997?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Apple Studio Display</a> für 1.199 Euro</li>
</ul>
<h3>Alles von Apple</h3>
<ul>
<li><a href="https://www.amazon.de/dp/B0DL6LHYQM?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Apple Magic Keyboard</a> für 139 Euro</li>
<li><a href="https://www.amazon.de/dp/B0DL6W3MQX?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Apple Magic Trackpad</a> für 125 Euro</li>
<li><a href="https://www.amazon.de/dp/B0DL6KSW78?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Apple Magic Mouse</a> für 59,99 Euro</li>
<li><a href="https://www.amazon.de/dp/B0DZ76WSYH?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Apple iPad Air 13 Zoll mit M3 Chip</a> für 899 Euro</li>
<li><a href="https://www.amazon.de/dp/B0DZ778WX5?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Apple iPad Air 11 Zoll mit M3 Chip</a> für 719 Euro</li>
<li><a href="https://www.amazon.de/dp/B0D3J7CKFR?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Apple Pencil Pro</a> für 109 Euro</li>
<li><a href="https://www.amazon.de/dp/B0GS5S368L?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Apple 13 Zoll MacBook Neo</a> für 739 Euro</li>
<li><a href="https://www.amazon.de/dp/B0DZD8Y997?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Apple Studio Display</a> für 1.199 Euro</li>
</ul>
<h2>📱 Smartphones, Smartwatches &amp; Wearables</h2>
<ul>
<li><a href="https://www.amazon.de/dp/B0FHL3XZNR?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Google Pixel 10 Pro</a> für 699 Euro</li>
<li><a href="https://www.amazon.de/dp/B0GGC2HBBY?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Google Pixel 10a</a> für 449 Euro</li>
<li><a href="https://www.amazon.de/dp/B0FQFLMHSX?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Apple Watch Series 11</a> für 369 Euro</li>
<li><a href="https://www.amazon.de/dp/B0DB61XP8V?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">HUAWEI Watch D2</a> für 303 Euro</li>
<li><a href="https://www.amazon.de/dp/B0F2TT8Q7M?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Sony kabellose NC-Kopfhörer</a> für 349 Euro</li>
<li><a href="https://www.amazon.de/dp/B0D8LHH8CX?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Google Pixel Buds Pro 2</a> für 172 Euro</li>
</ul>
<h2>🎮 Gaming &amp; VR</h2>
<ul>
<li><a href="https://www.amazon.de/dp/B09N5CNS5T?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Meta Quest 3 512 GB</a> für 527 Euro</li>
<li><a href="https://www.amazon.de/dp/B0DBJ5PBLT?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Logitech G Astro A50 Gaming-Headset</a> für 194,99 Euro</li>
<li><a href="https://www.amazon.de/dp/B0DFKC99VL?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Intel Core Ultra 9 Desktop-Prozessor</a> für 469 Euro</li>
</ul>
<h2>☕ Küche, Kaffee &amp; Haushaltsgeräte</h2>
<h3>Kaffee</h3>
<ul>
<li><a href="https://www.amazon.de/dp/B08CBJCQ39?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Philips Espresso Kaffeevollautomat</a> für 424 Euro</li>
<li><a href="https://www.amazon.de/dp/B0B8JV43LL?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">De’Longhi Siebträgermaschine</a> für 349,90 Euro</li>
<li><a href="https://www.amazon.de/dp/B0FHL3C7KP?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Ninja Luxe Premier Kaffeemaschine</a> für 394,99 Euro</li>
</ul>
<h3>Küche</h3>
<ul>
<li><a href="https://www.amazon.de/dp/B0G64WRJGG?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Ninja CREAMi Eismaschine</a> für 299,98 Euro</li>
<li><a href="https://www.amazon.de/dp/B0FP2KH5FP?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Ninja CREAMi Deluxe Eismaschine</a> für 199,98 Euro</li>
<li><a href="https://www.amazon.de/dp/B0B8DV6CK5?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Philips 7000 PastaMaker</a> für 169 Euro</li>
<li><a href="https://www.amazon.de/dp/B08GHG6CP8?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Tefal Jamie Oliver Pfannenset</a> für 79,79 Euro</li>
</ul>
<h3>Heißluftfritteusen</h3>
<ul>
<li><a href="https://www.amazon.de/dp/B09ZYLM43B?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Ninja MAX Dual Zone Heißluftfritteuse</a> für 149 Euro</li>
<li><a href="https://www.amazon.de/dp/B0CZXXVKS7?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Ninja Heißluftfritteuse MAX PRO</a> für 89,99 Euro</li>
</ul>
<h2>🏠 Smart Home &amp; Amazon Geräte</h2>
<ul>
<li><a href="https://www.amazon.de/dp/B09B8X9RGM?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Echo Dot</a> für 29,99 Euro</li>
<li><a href="https://www.amazon.de/dp/B0DKLFHZDH?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Echo Dot Max</a> für 64,99 Euro</li>
<li><a href="https://www.amazon.de/dp/B0C2S2J7JP?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Echo Spot</a> für 49,99 Euro</li>
<li><a href="https://www.amazon.de/dp/B0B6GKHS2S?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Ring Innenkamera</a> für 24,99 Euro</li>
<li><a href="https://www.amazon.de/dp/B0D7QQ9JBT?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Philips Hue LED Lampen 3er Pack</a> für 99,97 Euro</li>
<li><a href="https://www.amazon.de/dp/B00A128S24?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">TP-Link Gigabit Netzwerk Switch</a> für 13,99 Euro</li>
</ul>
<h2>🤖 Saugroboter &amp; Staubsauger</h2>
<ul>
<li><a href="https://www.amazon.de/dp/B0GCGVJD71?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">ECOVACS DEEBOT T90</a> für 599 Euro</li>
<li><a href="https://www.amazon.de/dp/B0F53MJY8T?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">dreame L40 Ultra</a> für 449 Euro</li>
<li><a href="https://www.amazon.de/dp/B0H2JP5WVY?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">MOVA E50 Pro Ultra</a> für 429 Euro</li>
<li><a href="https://www.amazon.de/dp/B0DV5RRL9F?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">dreame H12 Nass- und Trockensauger</a> für 178,99 Euro</li>
<li><a href="https://www.amazon.de/dp/B0GVP7XY36?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Dyson V8 kabelloser Staubsauger</a> für 279 Euro</li>
</ul>
<h2>🌡️ Klima, Luft &amp; Wohnkomfort</h2>
<ul>
<li><a href="https://www.amazon.de/dp/B0CM8P9?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Comfee Mobiles Klimagerät</a> für 190,99 Euro</li>
<li><a href="https://www.amazon.de/dp/B0CTMNRY8?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Levoit Standventilator</a> für 109,98 Euro</li>
<li><a href="https://www.amazon.de/dp/B08L73QL1V?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Levoit Luftreiniger</a> für 119,98 Euro</li>
</ul>
<h2>🌳 Garten &amp; Outdoor</h2>
<ul>
<li><a href="https://www.amazon.de/dp/B0GD23KKHC?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">MOVA LiDAX 1200 Mähroboter</a> für 894 Euro</li>
<li><a href="https://www.amazon.de/dp/B078GRBYSP?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Einhell Akku-Sense Rasenmäher</a> für 141,99 Euro</li>
<li><a href="https://www.amazon.de/dp/B078H242FN?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Einhell City Akku-Rasenmäher</a> für 99,99 Euro</li>
<li><a href="https://www.amazon.de/dp/B0CGX9L9CL?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Bosch Professional Akku Bohrhammer</a> für 174,99 Euro</li>
</ul>
<h2>🛴 E-Mobility &amp; Drohnen</h2>
<ul>
<li><a href="https://www.amazon.de/dp/B0B3RWP3ZP?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Segway-Ninebot MAX G2 D E-Scooter</a> für 569 Euro</li>
<li><a href="https://www.amazon.de/dp/B0DWTBMB82?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Xiaomi E-Scooter 4 Lite</a> für 379,99 Euro</li>
<li><a href="https://www.amazon.de/dp/B0FKGSKZ1G?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">DJI Mini 5 Pro Fly Drohne</a> für 949 Euro</li>
</ul>
<h2>🖨️ Büro &amp; Drucker</h2>
<ul>
<li><a href="https://www.amazon.de/dp/B07SJHTWCY?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">HP Color Laser MF-Drucker</a> für 219,99 Euro</li>
</ul>
<h2>💾 Speicher &amp; Datenträger</h2>
<ul>
<li><a href="https://www.amazon.de/dp/B0DN6DK3X4?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">SanDisk Extreme PRO SSD 4 TB</a></li>
<li><a href="https://www.amazon.de/dp/B07VS8QCXC?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">Seagate Portable Drive SSD 5TB</a> für 140 Euro</li>
</ul>
<h2>🔋 Sonstiges</h2>
<ul>
<li><a href="https://www.amazon.de/dp/B01B8R6PF2?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">AA-Alkali-Hochleistungsbatterien</a> für 19,56 Euro</li>
<li><a href="https://www.amazon.de/dp/B0DXLBZF4Q?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow noopener sponsored">PHILIPS OneBlade elektrischer Rasierer</a> für 34,99 Euro</li>
</ul>


<p></p>



<h2 class="wp-block-heading">Attraktive Preise auch für Amazon-Kunden ohne Prime</h2>



<p>Auch für Amazon-Kunden ohne Prime-Abo gibt es derzeit einige Highlight-Angebote mit Jahresbestpreisen:</p>



<ul class="wp-block-list">
<li><a href="https://www.amazon.de/XIAOMI-Fitness-Tracker-Herzfrequenz-Schlaf%C3%BCberwachung-Dualband-GPS-Jungle-Green/dp/B08N64CBKG?tag=pcwelt.de-21&amp;ascsubtag=rss">Xiaomi Watch S5 für 152,99 statt 240 Euro</a></li>



<li><a href="https://www.amazon.de/Ninja-Eismaschine-Dessertmaschine-Smoothie-Bowls-NC302EU/dp/B0G26N7D9N?tag=pcwelt.de-21&amp;ascsubtag=rss">Ninja CREAMi Eismaschine für 189 statt zuvor 227 Euro</a></li>



<li><a href="https://www.amazon.de/dp/B0GR1B8B3S?tag=pcwelt.de-21&amp;ascsubtag=rss" data-type="link" data-id="https://www.amazon.de/dp/B0GR1B8B3S?tag=pcwelt.de-21&amp;ascsubtag=rss">Apple MacBook Air 15 für 1.439 statt zuvor 1.558 Euro</a></li>



<li><a href="https://www.amazon.de/dp/B0GR1RRJKF?tag=pcwelt.de-21&amp;ascsubtag=rss">Apple MacBook Pro für 2.098 statt 2.169 Euro</a></li>



<li><a href="https://www.amazon.de/dp/B0FQG8MFKP?tag=pcwelt.de-21&amp;ascsubtag=rss">Apple iPhone 17 Pro 256 GB für 1.169 statt 1.227 Euro</a></li>



<li><a href="https://www.amazon.de/Apple-iPhone-Pro-Batterielaufzeit-Kamera-System/dp/B0FQG1TSY1?tag=pcwelt.de-21&amp;ascsubtag=rss">Apple iPhone 17 Pro Max 256 GB für 1.349 statt 1.389 Euro</a></li>



<li><a href="https://www.amazon.de/dp/B0DGHQ1KVY?tag=pcwelt.de-21&amp;ascsubtag=rss">Apple AirPods Max Kopfhörer für 399 statt 439 Euro</a></li>



<li><a href="https://www.amazon.de/Windows-Computer-Ethernet-Business-Heimkino/dp/B0BCNMP3CX?tag=pcwelt.de-21&amp;ascsubtag=rss">Mini PC AMD Ryzen R2544 für 284 statt 299,90 Euro</a></li>
</ul>



<p>Viele weitere Deals finden Sie auf <a href="https://www.pcwelt.de/deals" data-type="link" data-id="https://www.pcwelt.de/deals" target="_blank" rel="noreferrer noopener">unserer Deals-Seite.</a></p>



<p><em>Empfehlung:</em> <a href="https://www.macwelt.de/article/2817043/beste-fruehe-apple-angebote-prime-day-2026.html" target="_blank" rel="noreferrer noopener">Die besten Apple-Angebote zum Prime Day 2026</a></p>



<h2 class="wp-block-heading">Was ist der Amazon Prime Day?</h2>



<p>Der <strong>Amazon Prime Day</strong> ist eine jährlich stattfindende Rabattaktion von Amazon, die sich <strong>exklusiv an Prime-Mitglieder richtet</strong>. Während dieses Zeitraums bietet Amazon stark reduzierte Preise auf eine große Bandbreite von Produkten – von Technik über Haushaltswaren bis hin zu Kleidung. Andere Shops bieten den Prime Day nicht an.</p>



<p>Der Prime Day gehört zu den wichtigsten Online-Shopping-Events des Jahres. Vor allem für Amazon zahlt es sich aus: Jahr für Jahr werden neue Umsatzrekorde gebrochen. Wohl auch deshalb wurde die Dauer von 2 auf inzwischen 4 Tage verlängert. Waren es 2019 noch ca. 5 Milliarden US-Dollar Amazon-Einnahmen weltweit, so schätzt man den Prime Day von 2025 auf ca. 15,3 Milliarden US-Dollar.</p>



<h2 class="wp-block-heading">So verpassen Sie keine Angebote am Prime Day</h2>



<p>In diesem Beitrag werden wir regelmäßig über die besten Angebote während des Prime Day aus den Bereichen Technik, IT, Smartphones, Home Entertainment und Smart Home informieren. Sie können sich den <strong>Artikel als Favorit bookmarken</strong>, um ihn jederzeit aufrufen zu können.</p>



<h3 class="wp-block-heading">Kostenloses Prime-Testabo abschließen</h3>



<p>Wer noch kein Amazon-Prime-Kunde ist, für den lohnt es sich, <strong>jetzt</strong> einen kostenlosen Testmonat auszuprobieren. Denn so kann man ab sofort die exklusiven Prime-Preise erhalten. Wer rechtzeitig kündigt vor Ablauf des Testzeitraums, der zahlt noch nicht mal für das Prime-Abo.</p>



<p><a href="https://www.amazon.de/gp/prime?tag=pcwelt.de-21&amp;ascsubtag=rss">Prime-Abo kostenlos testen</a></p>



<h3 class="wp-block-heading">Angebotsseite bei Amazon checken</h3>



<p>Sogenannte <a href="https://www.amazon.de/deals?ref_=nav_cs_gb&amp;bubble-id=deals-collection-lightning-deals&amp;tag=pcwelt.de-21&amp;ascsubtag=rss">Blitzdeals</a> sind nur für kurze Zeit und solange der Vorrat reicht, verfügbar. Deshalb lohnt es sich, regelmäßig die spezielle Amazon-Unterseite des Events zu besuchen:</p>



<p><a href="https://www.amazon.de/primeday?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Die besten Tagesangebote bei Amazon</a></p>



<p><a href="https://www.amazon.de/deals?ref_=nav_cs_gb&amp;bubble-id=deals-collection-lightning-deals&amp;tag=pcwelt.de-21&amp;ascsubtag=rss">Blitzangebote bei Amazon – nur kurz verfügbar</a></p>



<h3 class="wp-block-heading">Rufus – Amazons KI-Einkaufsassistent</h3>



<p>Sie können „<a href="https://www.amazon.de/Rufus/b?node=100898398031&amp;tag=pcwelt.de-21&amp;ascsubtag=rss">Rufus</a>“ aktivieren – Amazons KI-gestützten Einkaufsassistenten, der für Sie persönlich die besten Deals findet.<br>Mehr Infos zu Rufus: <a href="https://www.aboutamazon.com/news/retail/how-to-use-amazon-shopping-ai-assistant" target="_blank" rel="noreferrer noopener">How to use Rufus to check price history, find deals, auto-buy items</a></p>



<h3 class="wp-block-heading">Artikel auf persönliche Merkliste setzen</h3>



<p>Suchen Sie nach Wunschartikeln, die Sie beobachten wollen. Am besten setzen Sie das jeweilige Produkt auf Ihre Merkliste (Button „Auf die Liste“ unterhalb der Preisangabe drücken). So haben Sie Ihre Produkte während des Prime Day besser im Blick und sehen auf Anhieb, falls der Preis gesenkt werden sollte.</p>



<h3 class="wp-block-heading">Personalisierte Empfehlungen ansehen</h3>



<p>Amazon stellt personalisierte Angebote bereit, die sich am individuellen Kundenverhalten orientieren. Filtern Sie dazu auf der Angebotsseite nach „Für dich“.</p>



<p><a href="https://www.amazon.de/deals?tag=pcwelt.de-21&amp;ascsubtag=rss">Zur Angebotsseite</a></p>



<h3 class="wp-block-heading">Bestseller-Liste</h3>



<p>Es empfiehlt sich, immer mal die <a href="https://www.amazon.de/gp/bestsellers?tag=pcwelt.de-21&amp;ascsubtag=rss">Amazon Bestseller-Liste</a> zu durchforsten. Hier werden die meistgekauften Artikel gezeigt. Das Ranking wird regelmäßig angepasst und bildet die tagesaktuelle Nachfrage nach Produkten ab. Spannend ist auch die Amazon-Kategorie „Aufsteiger des Tages“. Interessante Produkte am besten gleich auf die Merkliste setzen.</p>



<h3 class="wp-block-heading"><strong>Mit PC-Welt keine Angebote verpassen</strong></h3>



<p>Abonnieren Sie unseren <a href="https://www.pcwelt.de/newsletter-anmeldung" data-type="link" data-id="https://www.pcwelt.de/newsletter-anmeldung" target="_blank" rel="noreferrer noopener">Schnäppchen-Newsletter</a>. Alle empfehlenswerten Prime Day Angebote aus den Bereichen IT, Tech, Digital Lifestyle und Smarthome finden Sie <strong>kurz vor Start des Prime Day </strong>in unserer Webseiten-Rubrik zum Prime Day:</p>



<p><a href="https://www.pcwelt.de/prime-day" data-type="link" data-id="https://www.pcwelt.de/deals" target="_blank" rel="noreferrer noopener">Die besten Deals am Prime Day – ausgewählt von der PC-Welt Redaktion</a></p>



<p><em><strong>Empfehlung:</strong></em> <a href="https://www.macwelt.de/article/2817043/beste-fruehe-apple-angebote-prime-day-2026.html" target="_blank" rel="noreferrer noopener">Die besten Apple-Angebote am Prime Day 2026</a></p>



<p><strong>Weitere Beiträge:</strong></p>



<ul class="wp-block-list">
<li><a href="https://www.pcwelt.de/article/3132274/alexa-ab-sofort-in-deutschland-verfuegbar-das-kann-sie-besser-als-chatgpt.html" target="_blank" rel="noreferrer noopener">Alexa+ ab sofort in Deutschland verfügbar</a></li>



<li><a href="https://www.aboutamazon.com/news/retail/how-to-use-amazon-shopping-ai-assistant" target="_blank" rel="noreferrer noopener">How to use Rufus to check price history, find deals, auto-buy items</a></li>



<li><a href="https://www.pcwelt.de/article/3076065/amazon-leo-internet-angebot-kommt-nach-deutschland-termin-steht-jetzt-fest.html" data-type="link" data-id="https://www.pcwelt.de/article/3076065/amazon-leo-internet-angebot-kommt-nach-deutschland-termin-steht-jetzt-fest.html" target="_blank" rel="noreferrer noopener">Amazons Internet-Angebot kommt nach Deutschland</a></li>



<li><a href="https://www.pcwelt.de/article/2636917/lenovo-laptop-7606-test-amazon-bestseller.html" data-type="link" data-id="https://www.pcwelt.de/article/2636917/lenovo-laptop-7606-test-amazon-bestseller.html" target="_blank" rel="noreferrer noopener">Amazon-Bestseller im Test: Lenovo Laptop 7606</a></li>



<li><a href="https://www.pcwelt.de/article/2914305/amazon-haul-neuer-online-shop-schnaeppchen-1-euro-bis-20-euro.html" data-type="link" data-id="https://www.pcwelt.de/article/2914305/amazon-haul-neuer-online-shop-schnaeppchen-1-euro-bis-20-euro.html" target="_blank" rel="noreferrer noopener">Neuer Amazon Online-Shop: Tausende Schnäppchen ab 1 Euro bei Amazon Haul</a></li>



<li><a href="https://www.pcwelt.de/article/3130644/reise-urlaub-gadgets-amazon-haul-basics-guenstig.html" data-type="link" data-id="https://www.pcwelt.de/article/3130644/reise-urlaub-gadgets-amazon-haul-basics-guenstig.html" target="_blank" rel="noreferrer noopener">10 praktische Reise-Gadgets, die sich lohnen</a></li>



<li><a href="https://www.pcwelt.de/article/3122095/seagate-portable-drive-5tb-externe-festplatte-im-deal-34-prozent-rabatt-angebot-amazon.html" data-type="link" data-id="https://www.pcwelt.de/article/3122095/seagate-portable-drive-5tb-externe-festplatte-im-deal-34-prozent-rabatt-angebot-amazon.html" target="_blank" rel="noreferrer noopener">Bestseller-Festplatte im Preisrutsch: Seagate-Modell mit 5 TB</a></li>
</ul>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-54298 | withastro up to 6.4.5 spreadAttributes cross site scripting (EUVD-2026-38336)]]></title>
<description><![CDATA[A vulnerability was found in withastro astro up to 6.4.5. It has been classified as problematic. This issue affects the function spreadAttributes. Performing a manipulation results in cross site scripting.

This vulnerability was named CVE-2026-54298. The attack may be initiated remotely. There i...]]></description>
<link>https://tsecurity.de/de/3617058/sicherheitsluecken/cve-2026-54298-withastro-up-to-645-spreadattributes-cross-site-scripting-euvd-2026-38336/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3617058/sicherheitsluecken/cve-2026-54298-withastro-up-to-645-spreadattributes-cross-site-scripting-euvd-2026-38336/</guid>
<pubDate>Tue, 23 Jun 2026 04:38:45 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/withastro:astro">withastro astro up to 6.4.5</a>. It has been classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This issue affects the function <code>spreadAttributes</code>. Performing a manipulation results in cross site scripting.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-54298">CVE-2026-54298</a>. The attack may be initiated remotely. There is no available exploit.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-54299 | withastro up to 6.4.5 Host Header request.url input validation (EUVD-2026-38337)]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in withastro astro up to 6.4.5. This impacts the function request.url of the component Host Header Handler. Performing a manipulation results in improper input validation.

This vulnerability is reported as CVE-2026-54299. The attack is pos...]]></description>
<link>https://tsecurity.de/de/3616991/sicherheitsluecken/cve-2026-54299-withastro-up-to-645-host-header-requesturl-input-validation-euvd-2026-38337/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616991/sicherheitsluecken/cve-2026-54299-withastro-up-to-645-host-header-requesturl-input-validation-euvd-2026-38337/</guid>
<pubDate>Tue, 23 Jun 2026 03:25:11 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/withastro:astro">withastro astro up to 6.4.5</a>. This impacts the function <code>request.url</code> of the component <em>Host Header Handler</em>. Performing a manipulation results in improper input validation.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2026-54299">CVE-2026-54299</a>. The attack is possible to be carried out remotely. No exploit exists.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Expanding Our Footprint: Local Cloud Availability for Prisma AIRS in Japan]]></title>
<description><![CDATA[Securing the Future of Japan’s AI Landscape The shift from static LLMs to autonomous agents has fundamentally changed the global threat surface. Frontier models like Anthropic’s Mythos can now autonomously discover hundreds … The post Expanding Our Footprint: Local Cloud…
Read more →
The post Exp...]]></description>
<link>https://tsecurity.de/de/3609742/it-security-nachrichten/expanding-our-footprint-local-cloud-availability-for-prisma-airs-in-japan/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609742/it-security-nachrichten/expanding-our-footprint-local-cloud-availability-for-prisma-airs-in-japan/</guid>
<pubDate>Fri, 19 Jun 2026 10:37:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Securing the Future of Japan’s AI Landscape The shift from static LLMs to autonomous agents has fundamentally changed the global threat surface. Frontier models like Anthropic’s Mythos can now autonomously discover hundreds … The post Expanding Our Footprint: Local Cloud…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/expanding-our-footprint-local-cloud-availability-for-prisma-airs-in-japan/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/expanding-our-footprint-local-cloud-availability-for-prisma-airs-in-japan/">Expanding Our Footprint: Local Cloud Availability for Prisma AIRS in Japan</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security-Tools für KI-Infrastrukturen – ein Kaufratgeber]]></title>
<description><![CDATA[Tools, die die KI-Infrastruktur unter die Lupe nehmen, optimieren und absichern, liegen im Trend. Unser Ratgeber führt Sie zur richtigen AI-Security-Posture-Management-Lösung.Julien Tromeur | shutterstock.com



Weil sich Generative-AI-Lösungen branchenübergreifend verbreiten, wächst das Sicherhe...]]></description>
<link>https://tsecurity.de/de/3609302/it-security-nachrichten/security-tools-fuer-ki-infrastrukturen-ein-kaufratgeber/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609302/it-security-nachrichten/security-tools-fuer-ki-infrastrukturen-ein-kaufratgeber/</guid>
<pubDate>Fri, 19 Jun 2026 05:20:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2024/10/1200x_6b59cb.png?w=1024" alt="KI-Infrastrukturen" class="wp-image-3560127" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Tools, die die KI-Infrastruktur unter die Lupe nehmen, optimieren und absichern, liegen im Trend. Unser Ratgeber führt Sie zur richtigen AI-Security-Posture-Management-Lösung.</figcaption></figure><p class="imageCredit">Julien Tromeur | shutterstock.com</p></div>



<p>Weil sich Generative-AI-Lösungen branchenübergreifend verbreiten, wächst das Sicherheitsbedürfnis der Anwender. Diesem gerecht zu werden, ist vor allem deshalb eine Challenge, weil die Technologie enormen Einfluss auf die IT-Infrastruktur und die Unternehmensdaten nimmt. Und weil kriminelle Cyberakteure längst erkannt haben, welches <a href="https://www.computerwoche.de/article/4155663/6-wege-uber-ki-gehackt-zu-werden.html" target="_blank">Potenzial</a> für sie in diesem Umstand schlummert.</p>



<p>Gefragt sind deshalb neue, breit gefächerte Schutz- und Notfallmaßnahmen sowie Sicherheitssoftware, die spezifisch darauf ausgelegt ist, KI-Infrastrukturen abzusichern. Das hat längst diverse Cybersecurity-Anbieter dazu bewogen, entsprechende Lösungen zu entwickeln. Oder bestehende Produkte mit entsprechenden Features anzureichern. Dieses Wachstumssegment des Security-Markts läuft auch unter der Bezeichnung “AI Security Posture Management” – kurz AI-SPM.</p>



<p>In diesem Artikel erfahren Sie:</p>



<ul class="wp-block-list">
<li>was Security-Lösungen ausmacht, die KI-Infrastrukturen absichern.</li>



<li>was AI-SPM-Tools leisten sollten und</li>



<li>welche Anbieter und Produkte in diesem Bereich wichtig sind.</li>
</ul>



<h2 class="wp-block-heading">CSPM, DSPM und AI-SPM</h2>



<p>AI Security Posture Management fokussiert darauf, die Integrität und Sicherheit von KI- und ML-Systemen zu gewährleisten. Dabei umfasst AI-SPM Strategien, Tools und Techniken, um Daten, Pipelines, Applikationen und Services mit Blick auf ihre Sicherheitslage:</p>



<ul class="wp-block-list">
<li>zu überwachen,</li>



<li>zu bewerten und</li>



<li>zu optimieren.</li>
</ul>



<p>Bisher wurden Security Posture Management Tools für zwei separate Bereiche entwickelt:</p>



<ul class="wp-block-list">
<li>Cloud Security Posture Management (CSPM-) Tools sollen den Cloud-Betrieb allgemein absichern, in erster Linie gegen Fehlkonfigurationen und Missbrauch.</li>



<li><a href="https://www.csoonline.com/article/3493645/data-security-posture-management-die-besten-dspm-tools.html" target="_blank">Data Security Posture Management</a> (DSPM-) Tools sollen vor Datenlecks und Malware-Infektionen schützen.</li>
</ul>



<p>Das Aufkommen von künstlicher Intelligenz (KI) und Large Language Models (LLMs) hat Bedarf für eine dritte Produktkategorie geschaffen, die gemanagte KI-Cloud-Services und ihre SDKs (beispielsweise Hugging Face Transformer oder Azure Open AI) überwacht und KI-Modellmissbrauch verhindert – AI-SPM.</p>



<p>Dass das nötig war, unterstreichen diverse Research-Erkenntnisse, -Beiträge und weitere Ressourcen:</p>



<ul class="wp-block-list">
<li>Eine <a href="https://konghq.com/resources/reports/ai-and-api-adoption-challenges" target="_blank" rel="noreferrer noopener">Studie des API-Spezialisten Kong</a> (Download gegen Daten) kommt zu dem Ergebnis, dass eine Mehrheit der Befragten Wege gefunden hat, Beschränkungen mit Blick auf die KI-Nutzung zu umgehen. Ein Viertel muss sich erst gar nicht mit so etwas wie Guidelines herumschlagen.</li>



<li>Die Non-Profit-Organisation MITRE stellt mit seiner <a href="https://atlas.mitre.org/" target="_blank" rel="noreferrer noopener">Adversarial Threat Landscape for Artificial Intelligence Systems</a> (ATLAS) eine umfassende Datenbank mit Angriffstaktiken zur Verfügung, die auf “in the wild”-Beobachtungen beruht.</li>



<li>Auch das MIT betreibt <a href="https://airisk.mit.edu/" target="_blank" rel="noreferrer noopener">eine aktive Datenbank</a>, die mehr als 1.700 Risiken in Zusammenhang mit KI-Systemen bereithält.</li>



<li>Eine weitere Quelle, um sich mit KI-bezogenen Angriffsmethoden auseinanderzusetzen, bietet das 2023 von OWASP veröffentlichte <a href="https://owasp.org/www-project-top-10-for-large-language-model-applications/assets/PDF/OWASP-Top-10-for-LLMs-2023-v1_1.pdf" target="_blank" rel="noreferrer noopener">LLM-Exploit-Ranking</a> (PDF). Die Non-Profit-Organisation hat zudem <a href="https://www.csoonline.com/article/3493126/genai-security-als-checkliste.html" target="_blank">eine Checkliste für GenAI-Sicherheit</a> veröffentlicht.</li>
</ul>



<p>Sich mit diesen Quellen auseinanderzusetzen, empfiehlt sich, bevor Sie sich für ein Sicherheits-Tool oder -Feature aus dem Bereich AI-SPM entscheiden.</p>



<h2 class="wp-block-heading">Was Security Posture Management für KI leisten sollte</h2>



<p>Tools im Bereich AI Security Posture Management:</p>



<ul class="wp-block-list">
<li>bieten im Regelfall agentenlose Konfigurationen,</li>



<li>greifen auf Cloud-basierte Modelle zu und</li>



<li>belassen Daten auf den vorhandenen Plattformen.</li>
</ul>



<p>Letzteres dient sowohl der Sicherheit als auch dazu, die Verlagerung der damit verbundenen, massiven Datenbestände zu vermeiden. Darüber hinaus spielen bei Security-Tools für KI-Infrastrukturen natürlich auch <strong>KI-bezogene Funktionen</strong> eine Rolle. Zum Beispiel um große Datenmengen zu klassifizieren, zu tracken und gegen mögliche Missbrauchs- und Angriffsversuche <a href="https://www.csoonline.com/article/3493625/studie-it-security-trends-2024mehr-schutz-gegen-und-fur-ki.html" target="_blank">abzusichern</a>.</p>



<p>Einige Anbieter haben ihre bestehenden CSPM- oder DSPM-Lösungen um AI-SPM-Features erweitert – inklusive <a href="https://www.csoonline.com/article/3495375/third-party-risk-management-so-vermeiden-sie-compliance-unheil.html" target="_blank">Compliance-Prüfverfahren</a>, Best Practices und Richtlinien, die alle drei Security-Posture-Management-Arten abdecken. Andere offerieren umfassendere Lösungen, die eine Vielzahl KI-bezogener Sicherheitsmaßnahmen beinhalten. Zum Beispiel, um:</p>



<ul class="wp-block-list">
<li>KI-Pipelines und Workloads schützen,</li>



<li>zu erkennen, wenn KI-Modelle sensible Daten referenzieren,</li>



<li>Trainingsdaten auf Manipulationen durch Dritte oder externe Applikationen zu überprüfen, und</li>



<li>KI-Services und -Plattformen abzusichern.</li>
</ul>



<h2 class="wp-block-heading">Wichtige AI-SPM-Anbieter</h2>



<p>Im Folgenden haben wir die AI-SPM-Produkte und -Features neun verschiedener Anbieter für Sie zusammengefasst. Sämtliche Lösungen versprechen, Ihre KI-Infrastruktur abzusichern, verlassen sich dazu jedoch auf unterschiedliche Ansätze. Dabei ist zu beachten, dass es sich um einen Markt handelt, der im Wachstum begriffen ist. Die Produkte sind also noch nicht so umfassend ausgestaltet und integriert, wie sie sein könnten. Zudem arbeiten diverse weitere Sicherheitsanbieter aktiv an ähnlichen Offerings.</p>



<ul class="wp-block-list">
<li><strong><a href="https://www.cyera.io/platform/dspm" target="_blank" rel="noreferrer noopener">Cyera.io</a></strong> ist auf Datenklassifizierung spezialisiert und hat eine DSPM-Plattform im Angebot, die um AI-SPM-Features erweitert wird. Die Lösung verspricht beispielsweise Einblicke, auf welche Datenklassen und Data Stores Microsoft-Copilot-Nutzer zugreifen können.</li>



<li><strong><a href="https://www.legitsecurity.com/ai-discovery" target="_blank" rel="noreferrer noopener">LegitSecurity</a></strong> hat sich auf die Fahnen geschrieben, das “AI Visibility Gap” schließen zu wollen. Dazu untersucht die AI-SPM-Plattform KI-Modelle, Code Repositories, kryptografische Secrets und andere KI-bezogene Instanzen. Auf dieser Grundlage entstehen schließlich Risk Scores, um entsprechend priorisieren zu können. Mit dieser Lösung können Sie beispielsweise nachvollziehen, welche User Github Copilot auf der Basis von unsicheren KI-Modellen verwenden.</li>



<li><strong><a href="https://learn.microsoft.com/en-us/azure/defender-for-cloud/ai-security-posture" target="_blank" rel="noreferrer noopener">Microsoft</a></strong> stellt AI-Security-Posture-Management-Funktionen im Rahmen einer Preview für sein CSPM-Angebot zur Verfügung. Das fertige Produkt soll Ende 2024 zur Verfügung stehen und zum Einsatz kommen, um GenAI-Applikationen in Multi- oder Hybrid-Cloud-Szenarien abzusichern. Dazu wird zum Beispiel eine GenAI-Softwarestückliste (AI BOM) erfasst.</li>



<li><strong><a href="https://orca.security/platform/ai-security-posture-management/" target="_blank" rel="noreferrer noopener">Orca Security</a></strong> verspricht mit seiner Mehrzweck-Sicherheitsplattform unter anderem eine “Ende-zu-Ende”-AI-SPM-Lösung. Diese scannt unter anderem mehr als 50 verschiedene KI-Modellquellen und schlägt Alarm, wenn sie dort – oder in Trainingsdaten-Repositories – sensible Informationen oder Geheimnisse entdeckt.</li>



<li><strong><a href="https://www.paloaltonetworks.com/prisma/cloud/ai-spm" target="_blank" rel="noreferrer noopener">Palo Alto Networks</a></strong> hat Ende 2023 die Übernahme des DSPM-Spezialisten Dig Security abgeschlossen und diesen inzwischen vollständig integriert. Das Ergebnis heißt Prisma Cloud AI-SPM und ermöglicht zum Beispiel Top-Level-Scans der KI-Services von AWS, Google Cloud und Azure. Zudem hat der Sicherheitsanbieter Mitte 2025 auch den KI-Sicherheitsanbieter Protect AI <a href="https://www.paloaltonetworks.com/company/press/2025/palo-alto-networks-completes-acquisition-of-protect-ai" target="_blank" rel="noreferrer noopener">übernommen</a>.</li>



<li><strong><a href="https://securiti.ai/products/ai-security-governance/" target="_blank" rel="noreferrer noopener">Securiti.ai</a></strong> verspricht mit seinem Produkt “AI Security &amp; Governance” Schutz für KI-Instanzen. Dieses ermöglicht zum Beispiel KI-Modellrisiken zu bewerten und zu klassifizieren, Compliance-Prüfungen vorzunehmen oder Kontrollmaßnahmen für Daten und KI-Systeme zu etablieren.</li>



<li><strong><a href="https://www.varonis.com/products/ai-security" target="_blank" rel="noreferrer noopener">Varonis</a></strong> hat seine Sicherheitsplattform ebenfalls um “AI Security” erweitert. Das ermöglicht unter anderem, risikobehaftete KI-Fehlkonfigurationen zu erkennen und zu beheben, KI-generierte Inhalte mit Sensibilitäts-Labels zu versehen sowie KI-Workloads oder Datenflüsse zu erkennen, die sensible Informationen beinhalten. Für Microsoft Copilot steht ein eigenes (aufpreispflichtiges) Modul <a href="https://www.varonis.com/de/coverage/microsoft-365-copilot" target="_blank" rel="noreferrer noopener">zur Verfügung</a> – demnächst sollen weitere für Salesforce Einstein und Google Gemini folgen.</li>



<li><strong><a href="https://www.wiz.io/de-de/solutions/ai-spm" target="_blank" rel="noreferrer noopener">Wiz Security</a></strong> verfügt über einschlägige DSPM- und CSPM-Erfahrungswerte und hat auch eine dedizierte KI-SPM-Lösung im Angebot. Diese verspricht zum Beispiel umfassende Einblicke in KI-Pipelines sowie Detektions-Möglichkeiten für Angriffspfade oder Fehlkonfigurationen.</li>
</ul>



<p><strong>Dieser Artikel ist <a href="https://www.csoonline.com/article/3518733/ai-spm-buyers-guide-artificial-intelligence-security-posture-management-tools-compared.html" target="_blank">im Original</a> bei unserer Schwesterpublikation CSOonline.com erschienen.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[astro.config.mjs Supply Chain Attack via Blockchain C2]]></title>
<description><![CDATA[2026-06-12 • SafeDep
     • SafeDep
     • js.jadesnow
    
    
    Open article on Malpedia]]></description>
<link>https://tsecurity.de/de/3607418/malware-trojaner-viren/astroconfigmjs-supply-chain-attack-via-blockchain-c2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607418/malware-trojaner-viren/astroconfigmjs-supply-chain-attack-via-blockchain-c2/</guid>
<pubDate>Thu, 18 Jun 2026 12:48:58 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!--  -->
<div>
    2026-06-12 • SafeDep
     • SafeDep
     • js.jadesnow
    
    <br>
    <a href="https://malpedia.caad.fkie.fraunhofer.de/library/907ea97d-6a68-4520-8ccf-bf5e91c007a6/">Open article on Malpedia</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Twistlock: Prisma Cloud Container Security Overview and Analysis for 2026]]></title>
<description><![CDATA[Prisma Cloud delivers container security, compliance, and runtime protection for cloud-native environments in 2026. The post Twistlock: Prisma Cloud Container Security Overview and Analysis for 2026 appeared first on eSecurity Planet. This article has been indexed from eSecurity Planet Read…
Read...]]></description>
<link>https://tsecurity.de/de/3606267/it-security-nachrichten/twistlock-prisma-cloud-container-security-overview-and-analysis-for-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606267/it-security-nachrichten/twistlock-prisma-cloud-container-security-overview-and-analysis-for-2026/</guid>
<pubDate>Thu, 18 Jun 2026 00:20:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Prisma Cloud delivers container security, compliance, and runtime protection for cloud-native environments in 2026. The post Twistlock: Prisma Cloud Container Security Overview and Analysis for 2026 appeared first on eSecurity Planet. This article has been indexed from eSecurity Planet Read…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/twistlock-prisma-cloud-container-security-overview-and-analysis-for-2026/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/twistlock-prisma-cloud-container-security-overview-and-analysis-for-2026/">Twistlock: Prisma Cloud Container Security Overview and Analysis for 2026</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Twistlock: Prisma Cloud Container Security Overview and Analysis for 2026]]></title>
<description><![CDATA[Prisma Cloud delivers container security, compliance, and runtime protection for cloud-native environments in 2026.
The post Twistlock: Prisma Cloud Container Security Overview and Analysis for 2026 appeared first on eSecurity Planet.]]></description>
<link>https://tsecurity.de/de/3606239/it-security-nachrichten/twistlock-prisma-cloud-container-security-overview-and-analysis-for-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606239/it-security-nachrichten/twistlock-prisma-cloud-container-security-overview-and-analysis-for-2026/</guid>
<pubDate>Wed, 17 Jun 2026 23:53:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Prisma Cloud delivers container security, compliance, and runtime protection for cloud-native environments in 2026.</p>
<p>The post <a href="https://www.esecurityplanet.com/products/twistlock/">Twistlock: Prisma Cloud Container Security Overview and Analysis for 2026</a> appeared first on <a href="https://www.esecurityplanet.com/">eSecurity Planet</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Web Development Tools – 8 innovative Optionen]]></title>
<description><![CDATA[Neue Wege in Sachen Web Development beschreiten? Mit diesen acht Tools klappt das bestens.dotshock | shutterstock.com



In der Webentwicklung gibt es keinen vorgegebenen Weg. In einer Sache sind sich jedoch alle einig: Es ist höchste Zeit für ein „Great Unbloating“: Das Web Development muss von ...]]></description>
<link>https://tsecurity.de/de/3600602/it-security-nachrichten/web-development-tools-8-innovative-optionen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600602/it-security-nachrichten/web-development-tools-8-innovative-optionen/</guid>
<pubDate>Tue, 16 Jun 2026 06:05:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2024/08/0_dotshock_shutterstock_2312374465_16z9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="App Developer Testing 16z9 SHUTTERSTOCK EDITORIAL GERMANY ONLY" class="wp-image-3497299" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Neue Wege in Sachen Web Development beschreiten? Mit diesen acht Tools klappt das bestens.</figcaption></figure><p class="imageCredit">dotshock | shutterstock.com</p></div>



<p>In der <a href="https://www.computerwoche.de/article/2802920/was-macht-ein-web-developer.html" target="_blank">Webentwicklung</a> gibt es keinen vorgegebenen Weg. In einer Sache sind sich jedoch alle einig: Es ist höchste Zeit für ein „Great Unbloating“: Das Web Development muss von schwerfälliger Komplexität befreit werden. Wie das funktionieren kann, zeigen die acht Tools, die wir Ihnen in diesem Beitrag vorstellen.</p>



<p>Diese zeichnet aus, dass sie sich (größtenteils) mit alternativen Ansätzen befassen, die das Bewährte in Frage stellen. Auch wenn Sie die hier vorgestellten Lösungen nicht direkt für Ihre Zwecke einsetzen können, lohnt es sich also dennoch, sie im Auge zu behalten.</p>



<h2 class="wp-block-heading">1. <a href="https://astro.build/" target="_blank" rel="noreferrer noopener">Astro</a></h2>



<p>Wenn man eine Gruppe klassischer Musiker mit Noten in einen Raum setzt und sie einfach spielen lässt, <em>könnte </em>das Ergebnis ein stimmiges Stück sein. Wahrscheinlich braucht es aber einen Dirigenten, der alles koordiniert. In Zusammenhang mit Frontend-Frameworks ist <a href="https://www.computerwoche.de/article/3834789/astro-tutorial-plug-play-webentwicklung.html" target="_blank">Astro</a> genau das – ein Maestro.</p>



<p>Astro kümmert sich um die „<a href="https://www.infoworld.com/article/2335507/reactive-javascript-the-evolution-of-front-end-architecture.html" target="_blank">Hydration</a>“ des Frontends, also den Prozess, die Shell reaktiv zu machen. Beim konventionellen Server-Side Rendering (SSR) sendet der Server nicht nur den HTML-Code, sondern auch die riesige Framework-Runtime über das Netzwerk – nur um der Seite Event-Listener hinzuzufügen. Mit Astro ist es möglich, Komponenten in React, Svelte, Vue oder Solid zu schreiben – der Compiler des Tools entfernt dabei das gesamte JavaScript, bevor es den Browser erreicht. Astro liefert standardmäßig Zero JS aus und verlässt sich auf seine „<a href="https://docs.astro.build/en/concepts/islands/" target="_blank" rel="noreferrer noopener">Island Architecture</a>“, um nur die spezifischen Komponenten zu hydrieren, die Interaktivität erfordern.</p>



<p>Da Astro die Interaktivität in separaten „Inseln“ isoliert, ist es im Vergleich zu einer monolithischen Single-Page-Anwendung grundsätzlich schwieriger, komplexe States (etwa eine komplexe Seitenleiste mit Filterfunktion, die mit einem separaten dynamischen Data Grid kommuniziert) zwischen diesen Inseln zu teilen. Wenn Sie eine hochgradig interaktive, Dashboard-lastige Applikation entwickeln, in der jede Komponente die andere beeinflusst, könnten sich die isolierten Inseln eher nach Zwangsjacke als nach Befreiung anfühlen.</p>



<p><strong>Auch interessant:</strong> <a href="https://www.computerwoche.de/article/2833386/die-besten-javascript-frameworks-im-vergleich.html" target="_blank">Qwik</a>. Während Astro verschlankt, indem es den JavaScript-Code vollständig entfernt, setzt Qwik auf Verzögerung: Es liefert sofort HTML und serialisiert den Anwendungsstatus. Dabei wird nur der für eine bestimmte Interaktion erforderliche JavaScript-Code genau in der Millisekunde heruntergeladen und ausgeführt, in der der User auf die entsprechende Schaltfläche klickt.</p>



<h2 class="wp-block-heading">2. <a href="https://biomejs.dev/" target="_blank" rel="noreferrer noopener">Biome</a></h2>



<p><a href="https://www.computerwoche.de/article/2816993/7-gruende-rust-zu-hassen-und-zu-lieben.html" target="_blank">Rust</a> ersetzt nach und nach die zugrundeliegende Infrastruktur im JavaScript-Ökosystem. Das verleiht dem Biome-Tool seine Hardware-ähnliche Geschwindigkeit. Das Alleinstellungsmerkmal dieses Dev-Werkzeugs ist es allerdings, die weitläufige Webentwicklungs-Toolchain zu vereinheitlichen.  </p>



<p>Wenn die <code>.eslintrc</code>– und <code>.prettierrc</code>-Dateien sowie die Dutzenden zugehörigen Plugins in Ihrem Projekt bereits zu einem dunklen, unzufriedenstellenden Sumpf verkommen sind, ist Biome der Ausweg: Das Tool besteht aus einer einzelnen Binary, die komplett verworrene Foramtierungs- und Linting-Ökosysteme substituiert – und damit einen Weg zu Codequalität eröffnet, der ganz ohne ein weit verzweigtes Netz von Abhängigkeiten auskommt. </p>



<p>Der wohl größte Nachteil von Biome ist dabei gleichzeitig auch das Feature, das das Tool so schlank macht: Die Erweiterbarkeit geht verloren.</p>



<p><strong>Auch interessant:</strong> <a href="https://rspack.rs/" target="_blank" rel="noreferrer noopener">Rspack</a>. Biome bereinigt das Linting, Rspack entschlackt den Build-Schritt. Auch dieses Tool basiert auf Rust für mehr Geschwindigkeit. Dabei nutzt es – etwa im Gegensatz zu Vite – den „bundled“ Dev-Modus.</p>



<h2 class="wp-block-heading">3. <a href="https://bun.com/" target="_blank" rel="noreferrer noopener">Bun</a></h2>



<p>Die meisten gut informierten JavaScript-Enthusiasten dürften längst mit Bun vertraut sein. Wenn Sie die faszinierende Kombination aus All-in-One-Lösung und atemberaubender Geschwindigkeit noch nicht selbst erlebt haben, wird es Zeit. </p>



<p>Wenn Sie an <a href="https://www.infoworld.com/article/2254485/what-is-nodejs-javascript-runtime-explained.html">Node</a> gewöhnt sind und Bun ausprobieren, werden Sie sehr wahrscheinlich sofort davon beeindruckt sein, wie schnell Befehle ausgeführt werden. Das Bun-Team hat zudem über mehrere Jahre hinweg umfangreiche Anstrengungen unternommen, um seine Engine eng an die APIs von Node anzupassen. Das macht Bun zu einer außergewöhnlichen technischen Errungenschaft, die jeder JavaScript-Entwickler zumindest explorieren sollte.</p>



<p>Obwohl Buns <a href="https://www.computerwoche.de/article/2821852/die-moderne-c-alternative.html" target="_blank">Zig</a>-basierte Engine in vielerlei Hinsicht ein direkter Ersatz für Node ist: Sie ist nicht perfekt – insbesondere angesichts der gigantischen Anzahl von Node-Packages, die existieren. Deshalb bleibt Node auch die beste bewährte, konservative, Engine für serverseitiges JavaScript.</p>



<p><strong>Auch interessant:</strong> <a href="https://www.infoworld.com/article/2256205/what-is-deno-a-better-nodejs.html">Deno</a>. Bun hat sich zwar zu Recht einen Ruf als innovatives Tool erarbeitet – allerdings wurde Deno still und leise um eine Reihe attraktiver Enterprise-Funktionen ergänzt – etwa eine integrierte Bereitstellungsplattform und das Frontend-Framework <a href="https://www.infoworld.com/article/3523813/intro-to-deno-fresh-a-fresh-take-on-full-stack-javascript.html" target="_blank">Deno Fresh</a>.</p>



<h2 class="wp-block-heading">4. <a href="https://htmx.org/" target="_blank" rel="noreferrer noopener">HTMX</a></h2>



<p>Wenn es um smarte Wege geht, das Web zu vereinfachen, könnte man <a href="https://www.computerwoche.de/article/2833138/dynamisches-html-ohne-javascript.html" target="_blank">HTMX</a> durchaus als Paradebeispiel anführen. Das Projekt greift die Kernmechanismen moderner Web-Clients wie <a href="https://developer.mozilla.org/en-US/docs/Glossary/AJAX" target="_blank" rel="noreferrer noopener">Ajax</a> sowie partielle Aktualisierungen auf und wandelt diese in einfache HTML-Attribute um. Das hat zur Folge, dass der State ausschließlich auf dem Server gespeichert wird, der dafür zuständig ist, die HTMX-Fragmente zu senden.</p>



<p>Natürlich läuft das nicht ohne Kompromisse ab. Einer ist die extreme Abhängigkeit vom Netzwerk: Da es keine Client-seitige State Machine gibt, ist der Browser ohne Verbindung zum Server hilflos. Es sei denn, Sie wagen sich an Experimente mit einem <a href="https://www.computerwoche.de/article/4142269/der-browser-wird-zur-datenbank.html" target="_blank">„local-first“-Data Store</a>. Kurz gesagt: Wenn Ihre App in den Anwendungsbereich von HTMX fällt, ist HTMX wahrscheinlich der direkteste „<a href="https://www.computerwoche.de/article/2827943/was-ist-rest.html" target="_blank">RESTful</a>-Weg“, um diese zu erstellen.</p>



<p><strong>Auch interessant:</strong> <a href="https://www.infoworld.com/article/4100499/intro-to-hotwire-interactive-javascript-built-from-html.html" target="_blank">Hotwire</a>. Als Tool-Sammlung, um Single-Page-Anwendungen unter Verwendung von HTML über das Netzwerk zu erstellen, verfügt Hotwire über großartige Funktionen wie Page Morphing. Getreu der klassischen „Free as in Speech“-Softwarekultur werden Ideen zwischen den Projektverantwortlichen von HTMX und Hotwire ausgetauscht.</p>



<h2 class="wp-block-heading">5. <a href="https://powersync.com/" target="_blank" rel="noreferrer noopener">PowerSync</a></h2>



<p>Auch wenn die „Local-First“-Datenrevolution, für die <a href="https://www.infoworld.com/article/4163910/the-front-end-architecture-trilemma-reactivity-vs-hypermedia-vs-local-first-apps.html" target="_blank">PowerSync</a> steht, einen ausgiebigen technischen Deepdive erfordert: Der Kernansatz besteht darin, die Art und Weise, wie Daten in der Webarchitektur fließen, grundlegend neu zu gestalten. Das sollte jeder Webentwickler im Blick behalten.  </p>



<p>Normalerweise erstellen Entwickler Architekturen, die eine komplexe Middleware erfordern. Diese fungiert als Vermittler zwischen einem reaktiven Client und dem Data Store. Die radikale Alternative mit PowerSync: Der Broker wird komplett umgangen, indem eine SQLite-Wasm-Datenbank direkt in den Browser integriert wird. Die Benutzeroberfläche arbeitet dabei synchron mit lokalen Daten unter Verwendung von <a href="https://www.computerwoche.de/article/2830650/9-gruende-gegen-sql.html" target="_blank">SQL</a>, die Latenzzeit beträgt null. Der gefürchtete Ladekreisel wird damit vollständig eliminiert. Im Hintergrund gleicht PowerSync den lokalen Speicher automatisch mit der zentralen Postgres-Datenbank ab. Das Tool händelt die komplexen Synchronisierungs-Algorithmen und Netzwerkschwankungen und macht Ihre Anwendung damit effektiv „offline-first“ – per Default.</p>



<p>Der Haken ist dabei, dass ein „Local-First“-Entwicklungsansatz eine massive Umstellung erfordert: Sie müssen Data Slices (ähnlich einer View) definieren, die jeder Client-User vorhält. Die PowerSync-Engine übernimmt zwar auch hierbei den Großteil der Arbeit, aber Dinge wie Schemamigrationen und Konfliktlösungen (wenn zwei Benutzer denselben Datensatz offline bearbeiten) erfordern ein deutlich aufwendigeres Setup als eine Standard-REST-API.</p>



<p><strong>Auch interessant:</strong> <a href="https://rxdb.info/" target="_blank" rel="noreferrer noopener">RxDB</a>. Dieses Tool ist eine etwas andere Variante eines „Local-First“-Datenspeichers. Während PowerSync stark auf Postgres, SQLite und Hintergrund-Daemons setzt, bietet RxDB eine NoSQL-, „Offline-First“- und reaktive Datenbank. Diese behandelt Queries als „observable“ Streams und führt UI-Aktualisierungen genau in der Millisekunde durch, in der sich die lokalen Daten ändern.</p>



<h2 class="wp-block-heading">6. <a href="https://github.com/RooCodeInc/Roo-Code" target="_blank" rel="noreferrer noopener">RooCode</a></h2>



<p>Der wesentliche Vorteil von RooCode ist, dass es sämtliche Ihrer KI-Anbieter koordinieren kann – und zwar kostenlos. Bei dem Tool handelt es sich um eine Erweiterung für <a href="https://www.computerwoche.de/article/2833165/10-tricks-fuer-visual-studio-code.html" target="_blank">Visual Studio Code</a>, die einen „AI Manager Layer“ bereitstellt. Dieser schlägt eine Brücke zwischen den allgemeinen Fähigkeiten des LLM und den Code-spezifischen Strukturen auf Projektebene.</p>



<p>Dabei erreicht RooCode zwar nicht die Performanz von Tools wie Cursor oder <a href="https://www.computerwoche.de/article/4107872/google-antigravity-ide-angetestet.html" target="_blank">Antigravity</a> – ist aber durchaus in der Lage, die meisten kleinen bis mittelgroßen Requests zu bewältigen. Und das mit einem Minimum an unnötigem Overhead: RooCode hält Sie fern von proprietären Ökosystemen und ermöglicht auch, eigene API-Keys einzubinden – von Anthropic, OpenAI oder auch lokalen Modellen, die auf der eigenen Hardware laufen.</p>



<p>Die versteckten Kosten bestehen – wie bei jedem KI-Coding-Assistenten – darin, dass das Tool die Rolle des Entwicklers vom Code-Autor zum -Redakteur verschiebt.</p>



<p><strong>Auch interessant:</strong> <a href="https://antigravity.google/" target="_blank" rel="noreferrer noopener">Antigravity</a>. RooCode ist eine leichtgewichtige Erweiterung, die Ihre bestehende Umgebung aufwertet. Googles Antigravity ist hingegen ein maßgeschneiderter Editor, der von Grund auf mit Fokus auf KI entwickelt wurde und deshalb auch für Agentic-AI-Workflows konzipiert ist.</p>



<h2 class="wp-block-heading">7. <a href="https://tanstack.com/query/latest" target="_blank" rel="noreferrer noopener">TanStack Query</a></h2>



<p>Selbst wenn Client-seitiges State Management kein Problem mehr darstellt (siehe nächstes Tool), bleibt eine große Lücke bestehen: die Synchronisierung über die Servergrenze hinweg. An diesem Punkt kommt TanStack Query ins Spiel. Distributed Computing ist ein notorisch heikles Problem. Standardmäßige reaktive Modelle speichern den State sowohl auf dem Client als auch auf dem Server. Diese inhärente architektonische Reibung versucht TanStack Query abzumildern, indem es als intelligente asynchrone Schicht fungiert.</p>



<p>Anstatt eine Vielzahl manueller Fetches zu verwenden, die an <code>useState</code>-Aktualisierungen geknüpft sind (zusammen mit anfälligen <code>isLoading</code>-Flags und komplexer Logik zur State-Synchronisation), abstrahiert TanStack Query die aufwendige Arbeit, die mit API-Antworten, Hintergrundaktualisierungen und der Duplikatsbereinigung von Anfragen verbunden ist. Übrig bleiben einige wenige, elegante Hooks. Diese teilen TanStack Query mit, woher die Daten bezogen werden sollen. Dabei nutzt das Tool ein Muster namens „stale-while-revalidate“. Soll heißen: Daten werden im Frontend zwischengespeichert, wiederverwendet (wodurch Reload-Wartezeiten entfallen) und im Hintergrund mit dem aktuellen State synchronisiert.</p>



<p>Der Haken daran ist allerdings, dass TanStack Query Sie dazu zwingt, sich einem der hartnäckigsten Informatik-Probleme direkt zu stellen: der <a href="https://medium.com/on-building-software/why-cache-invalidation-is-actually-hard-e8b5e9a83e45" target="_blank" rel="noreferrer noopener">Cache-Invalidierung</a>. Sie werden also Zeit damit verbringen, über „Query Keys“ zu sinnieren und damit, zu entscheiden, wann ein Datenelement als „veraltet“ gelten soll.</p>



<p><strong>Auch interessant:</strong> <a href="https://swr.vercel.app/" target="_blank" rel="noreferrer noopener">SWR</a>. Während TanStack Query ein absolutes Kraftpaket für komplexe Datenmanipulation ist, bleibt SWR ein Vorreiter des API-Minimalismus. Es tut genau das, was sein Name andeutet (stale-while-revalidate) – und das fast ohne lästige Konfiguration.</p>



<h2 class="wp-block-heading">8. <a href="https://zustand.docs.pmnd.rs/learn/getting-started/introduction" target="_blank" rel="noreferrer noopener">Zustand</a></h2>



<p>Falls Sie noch nicht mit dem Albtraum des großangelegten State Managements in einer reaktiven App konfrontiert wurden, ein kleiner Spoiler: Das kann ziemlich unangenehm werden. Oder Sie nutzen <a href="https://zustand.docs.pmnd.rs/learn/getting-started/introduction" target="_blank" rel="noreferrer noopener">Zustand</a> und verzichten einfach auf den zeremoniellen Boilerplate-Code aus Reducern, Providern und unhandlichen Context-Wrappern. Ersetzt wird das durch einen winzigen, brutal simplen, globalen Speicher.</p>



<p>Anstatt Ihren gesamten Anwendungsbaum in einen massiven React-Context-Provider zu zwängen (was manchmal zu einer Kaskade überflüssiger Neu-Renderings im gesamten DOM führt), nutzt Zustand benutzerdefinierte Hooks, um den State direkt an die spezifischen Komponenten zu binden, die ihn benötigen. Dabei strebt das Tool danach, die Spezifität im reaktiven VDOM-Modell zu erreichen (anstatt sie à la <a href="https://www.infoworld.com/article/4129648/reactive-state-management-with-javascript-signals.html" target="_blank">Signals</a> vollständig zu eliminieren). Sie definieren einen Store, rufen ihn auf – und die Reaktivität funktioniert einfach. Der Preis für diese Befreiung ist die Last der Disziplin: Zustand hindert Sie nicht daran, Ihren globalen Speicher in eine überfüllte Deponie zu verwandeln. Entwickler müssen Ihre eigenen Konventionen und Guardrails einziehen, um großangelegte Projekte überschaubar zu halten.</p>



<p><strong>Auch interessant:</strong> <a href="https://jotai.org/" target="_blank" rel="noreferrer noopener">Jotai</a>. Wenn Zustand der schlank gehaltene globale Store ist, dann ist Jotai der schlank gehaltene, atomare Ansatz. Dieses Tool verwaltet den State „von unten nach oben“ und berechnet Änderungen mit chirurgischer Präzision – ohne dabei massive Neu-Renderings im gesamten Application Tree auszulösen. (fm)</p>



<p><strong>Dieser Artikel ist </strong><a href="https://www.infoworld.com/article/4181872/8-cutting-edge-web-development-tools-you-dont-want-to-miss.html" target="_blank"><strong>im Original</strong></a><strong> bei unserer Schwesterpublikation Infoworld.com erschienen.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-0268 | Palo Alto Prisma Access Agent up to 26.2.0 on Linux improper protection of alternate path]]></title>
<description><![CDATA[A vulnerability was found in Palo Alto Prisma Access Agent up to 26.2.0 on Linux. It has been declared as problematic. This affects an unknown function. Such manipulation leads to improper protection of alternate path.

This vulnerability is traded as CVE-2026-0268. An attack has to be approached...]]></description>
<link>https://tsecurity.de/de/3598174/sicherheitsluecken/cve-2026-0268-palo-alto-prisma-access-agent-up-to-2620-on-linux-improper-protection-of-alternate-path/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598174/sicherheitsluecken/cve-2026-0268-palo-alto-prisma-access-agent-up-to-2620-on-linux-improper-protection-of-alternate-path/</guid>
<pubDate>Mon, 15 Jun 2026 08:06:21 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/palo_alto:prisma_access_agent">Palo Alto Prisma Access Agent up to 26.2.0</a> on Linux. It has been declared as <a href="https://vuldb.com/kb/risk">problematic</a>. This affects an unknown function. Such manipulation leads to improper protection of alternate path.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2026-0268">CVE-2026-0268</a>. An attack has to be approached locally. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-0269 | Palo Alto Cloud NGFW/PAN-OS/Panorama/Prisma Access unusual condition]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in Palo Alto Cloud NGFW, PAN-OS, Panorama and Prisma Access. Affected by this vulnerability is an unknown functionality. The manipulation results in improper check for unusual conditions.

This vulnerability is known as CVE-2026-0269. A...]]></description>
<link>https://tsecurity.de/de/3598172/sicherheitsluecken/cve-2026-0269-palo-alto-cloud-ngfwpan-ospanoramaprisma-access-unusual-condition/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598172/sicherheitsluecken/cve-2026-0269-palo-alto-cloud-ngfwpan-ospanoramaprisma-access-unusual-condition/</guid>
<pubDate>Mon, 15 Jun 2026 08:06:20 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/palo_alto:cloud_ngfw">Palo Alto Cloud NGFW, PAN-OS, Panorama and Prisma Access</a>. Affected by this vulnerability is an unknown functionality. The manipulation results in improper check for unusual conditions.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2026-0269">CVE-2026-0269</a>. Access to the local network is required for this attack. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-0271 | Palo Alto Prisma Access Agent up to 26.2.0 on Linux permission assignment]]></title>
<description><![CDATA[A vulnerability categorized as critical has been discovered in Palo Alto Prisma Access Agent up to 26.2.0 on Linux. The affected element is an unknown function. The manipulation results in incorrect permission assignment.

This vulnerability is identified as CVE-2026-0271. The attack is only poss...]]></description>
<link>https://tsecurity.de/de/3598170/sicherheitsluecken/cve-2026-0271-palo-alto-prisma-access-agent-up-to-2620-on-linux-permission-assignment/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598170/sicherheitsluecken/cve-2026-0271-palo-alto-prisma-access-agent-up-to-2620-on-linux-permission-assignment/</guid>
<pubDate>Mon, 15 Jun 2026 08:06:19 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">critical</a> has been discovered in <a href="https://vuldb.com/product/palo_alto:prisma_access_agent">Palo Alto Prisma Access Agent up to 26.2.0</a> on Linux. The affected element is an unknown function. The manipulation results in incorrect permission assignment.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2026-0271">CVE-2026-0271</a>. The attack is only possible with local access. There is not any exploit available.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-0266 | Palo Alto Cloud NGFW/PAN-OS/Prisma Access Web Interface cross site scripting]]></title>
<description><![CDATA[A vulnerability was found in Palo Alto Cloud NGFW, PAN-OS and Prisma Access. It has been rated as problematic. This vulnerability affects unknown code of the component Web Interface. The manipulation leads to cross site scripting.

This vulnerability is uniquely identified as CVE-2026-0266. The a...]]></description>
<link>https://tsecurity.de/de/3598168/sicherheitsluecken/cve-2026-0266-palo-alto-cloud-ngfwpan-osprisma-access-web-interface-cross-site-scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598168/sicherheitsluecken/cve-2026-0266-palo-alto-cloud-ngfwpan-osprisma-access-web-interface-cross-site-scripting/</guid>
<pubDate>Mon, 15 Jun 2026 08:06:17 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/palo_alto:cloud_ngfw">Palo Alto Cloud NGFW, PAN-OS and Prisma Access</a>. It has been rated as <a href="https://vuldb.com/kb/risk">problematic</a>. This vulnerability affects unknown code of the component <em>Web Interface</em>. The manipulation leads to cross site scripting.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2026-0266">CVE-2026-0266</a>. The attack is possible to be carried out remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-0273 | Palo Alto Cloud NGFW/PAN-OS/Prisma Access Management Web Interface os command injection (EUVD-2026-36149)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in Palo Alto Cloud NGFW, PAN-OS and Prisma Access. Affected is an unknown function of the component Management Web Interface. The manipulation leads to os command injection.

This vulnerability is traded as CVE-2026-0273. It is pos...]]></description>
<link>https://tsecurity.de/de/3589692/sicherheitsluecken/cve-2026-0273-palo-alto-cloud-ngfwpan-osprisma-access-management-web-interface-os-command-injection-euvd-2026-36149/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589692/sicherheitsluecken/cve-2026-0273-palo-alto-cloud-ngfwpan-osprisma-access-management-web-interface-os-command-injection-euvd-2026-36149/</guid>
<pubDate>Thu, 11 Jun 2026 08:58:26 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, has been found in <a href="https://vuldb.com/product/palo_alto:cloud_ngfw">Palo Alto Cloud NGFW, PAN-OS and Prisma Access</a>. Affected is an unknown function of the component <em>Management Web Interface</em>. The manipulation leads to os command injection.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2026-0273">CVE-2026-0273</a>. It is possible to initiate the attack remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-0272 | Palo Alto Cloud NGFW/PAN-OS/Prisma Access Command Line Interface authorization (EUVD-2026-36148)]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in Palo Alto Cloud NGFW, PAN-OS and Prisma Access. This impacts an unknown function of the component Command Line Interface. Executing a manipulation can lead to missing authorization.

This vulnerability appears as CVE-2026-0272. The physical d...]]></description>
<link>https://tsecurity.de/de/3589690/sicherheitsluecken/cve-2026-0272-palo-alto-cloud-ngfwpan-osprisma-access-command-line-interface-authorization-euvd-2026-36148/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589690/sicherheitsluecken/cve-2026-0272-palo-alto-cloud-ngfwpan-osprisma-access-command-line-interface-authorization-euvd-2026-36148/</guid>
<pubDate>Thu, 11 Jun 2026 08:58:22 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> was found in <a href="https://vuldb.com/product/palo_alto:cloud_ngfw">Palo Alto Cloud NGFW, PAN-OS and Prisma Access</a>. This impacts an unknown function of the component <em>Command Line Interface</em>. Executing a manipulation can lead to missing authorization.

This vulnerability appears as <a href="https://vuldb.com/cve/CVE-2026-0272">CVE-2026-0272</a>. The physical device can be targeted for the attack. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[Anzeige: Kompaktes Fernglas mit BAK4-Prisma für nur 22,11 Euro bei Amazon]]></title>
<description><![CDATA[Ein kompaktes Fernglas von Aurosports mit zehnfacher Vergrößerung, 25-Millimeter-Objektiv und BAK4-Prisma gibt es bei Amazon zum Sparpreis. (Technik/Hardware)]]></description>
<link>https://tsecurity.de/de/3584809/it-nachrichten/anzeige-kompaktes-fernglas-mit-bak4-prisma-fuer-nur-2211-euro-bei-amazon/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584809/it-nachrichten/anzeige-kompaktes-fernglas-mit-bak4-prisma-fuer-nur-2211-euro-bei-amazon/</guid>
<pubDate>Tue, 09 Jun 2026 16:32:34 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein kompaktes Fernglas von Aurosports mit zehnfacher Vergrößerung, 25-Millimeter-Objektiv und BAK4-Prisma gibt es bei Amazon zum Sparpreis. (<a href="https://www.golem.de/specials/technik-und-hardware/">Technik/Hardware</a>) <img src="https://cpx.golem.de/cpx.php?class=17&amp;aid=209575&amp;page=1&amp;ts=1781014742" alt="" width="1" height="1">]]></content:encoded>
</item>
<item>
<title><![CDATA[Fußball-WM auf Großleinwand: Diese Beamer lohnen sich – Kaufberatung]]></title>
<description><![CDATA[Als Alternative zum Fernsehgerät wird der Projektor immer beliebter. Sein Vorteil: Er hinterlässt keine schwarze Fläche im Wohnzimmer, wenn er nicht in Gebrauch ist. Vielfach lässt er sich an der Decke montieren oder unauffällig im Regal unterbringen. In beiden Fällen ist er so völlig aus dem Bli...]]></description>
<link>https://tsecurity.de/de/3584718/windows-tipps/fussball-wm-auf-grossleinwand-diese-beamer-lohnen-sich-kaufberatung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584718/windows-tipps/fussball-wm-auf-grossleinwand-diese-beamer-lohnen-sich-kaufberatung/</guid>
<pubDate>Tue, 09 Jun 2026 15:41:57 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Als Alternative zum Fernsehgerät wird der Projektor immer beliebter. Sein Vorteil: Er hinterlässt keine schwarze Fläche im Wohnzimmer, wenn er nicht in Gebrauch ist. Vielfach lässt er sich an der Decke montieren oder unauffällig im Regal unterbringen. In beiden Fällen ist er so völlig aus dem Blick oder bleibt dezent im Ambiente-Hintergrund, wenn Sie ihn nicht brauchen.</p>



<p>Vorbei sind auch die Zeiten, in denen ein Beamer unbedingt einen völlig abgedunkelten Heimkino-Raum vorausgesetzt hat, um seine Stärken komplett ausspielen zu können. Ideale Bedingungen schaden zwar auch heutzutage nicht. Allerdings sind aktuelle Projektoren viel heller und können so mit einem höheren Umgebungslicht weitaus besser umgehen. Damit empfehlen sie sich für Normalbedingungen in der Wohnung, aber auch für den Einsatz auf der Terrasse oder beim Campen.</p>



<p>Vermehrt nutzen Projektoren leistungsstarke LEDs oder Laserlicht anstelle von UHP-Lampen (Ultra High Pressure), auch als Hochdruck-Quecksilberlampen (HQL) bezeichnet. Die gasgefüllten Hochdrucklampen gibt es zwar noch, sie sind aber dank der <a href="https://www.bundesumweltministerium.de/gesetz/verordnung-eu-2017-852-ueber-quecksilber-und-zur-aufhebung-der-verordnung-eg-nr-1102-2008-abfallbezogene-regelungen" target="_blank" rel="noreferrer noopener">EU-Verordnung 2017/852 über Quecksilber</a> auf dem Rückzug. Denn seit Februar 2025 ist es nicht mehr erlaubt, Lampen mit weniger als 2.000 Lumen herzustellen oder zu importieren. Ab Februar 2027 folgt die nächste Stufe: Dann sind UHP-Lampen ab 2.000 Lumen mit einem EU-Herstellungs- und Importverbot belegt.</p>



<h2 class="wp-block-heading toc">Beamer mit UHP-Lampe: Mehrkosten einrechnen</h2>



<p>Derzeit finden sich nach wie vor noch Beamer mit UHP-Lampe auf dem Markt. Gerade in den Einstiegsmodellen mit Full-HD- und 4K-Auflösungen sitzt diese Lichtquelle teils noch im Inneren. Für ein Modell mit 1.920 × 1.080 Pixeln wie den <a href="https://www.amazon.de/Epson-CO-FH01-3LCD-Projektor-Farbhelligkeit-Bilddiagonale/dp/B0BWS6TZNL?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Epson CO-FH01</a> zahlen Sie deshalb auch vergleichsweise günstige 360 bis 400 Euro.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a28180b70b9e"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/Epson-CO-FH01.jpg?quality=50&amp;strip=all" alt="Epson CO-FH01" class="wp-image-3136838" width="676" height="334" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Der Epson CO-FH01 bietet großes Full-HD-Kino, einfache Bedienung und hohe Helligkeit zum Einstiegspreis.</p></figcaption></figure><p class="imageCredit">Epson</p></div>



<p>Beim Hersteller selbst finden sich jedoch oft keine Ersatzlampen mehr im Programm. <a href="https://www.beamer-parts.de/lampen/epson/epson-co-fh01/" target="_blank" rel="noreferrer noopener">Sie müssen sie über andere Anbieter beziehen</a>. Im Nachkauf können allein für die Ersatzlampe etwa 140 Euro fällig werden. Da das Angebot aufgrund des Verbots weiter sinken wird, sollten Sie gleichzeitig mit dem Beamer-Kauf für Lampennachschub sorgen und daher den Mehraufwand von Anfang an in Ihre Kalkulation aufnehmen.</p>



<p>Noch einen Punkt gilt es hier zu beachten: UHP-Lampen verlieren im Gebrauch kontinuierlich an Helligkeit. Eine Lampenlebensdauer wie beim genannten Epson-Modell von 6.000 Stunden bedeutet, dass die Lichtleistung in dieser Zeit um etwa 50 Prozent sinkt.</p>



<p>Das Gerät meldet, wenn der Lampenaustausch fällig wird. Sie können den Zeitraum verlängern, indem Sie den Beamer im Eco-Modus mit niedrigerer Helligkeit betreiben. Außerdem ist es beim Lampen-Projektor besonders wichtig, dass Sie ihn möglichst staubfrei halten. Verschmutzungen verkürzen die Lampen-Lebensdauer zusätzlich.</p>



<h2 class="wp-block-heading toc">LEDs als Grundlage für kompakte Mini-Beamer</h2>



<p>Starke LEDs als Lichtquelle haben bei Beamern wesentliche Vorteile: Auf diese Weise sind sehr kompakte Geräte möglich. Die Kategorie der Mini-Beamer konnte so überhaupt erst entstehen. Die Geräte liefern eine Bildhelligkeit von etwa 200 bis 600 Lumen. Das entspricht vergleichsweise niedrigen Werten, die sich in der Projektion schnell in einer etwas milchigen Darstellung niederschlagen.</p>



<p>Auch kommen sie meist nicht über den Videofarbraum REC709 oder sRGB hinaus. Das reicht für spontane Projektionen, bei denen es mehr auf den gemeinsamen Spaß als auf eine hohe Bildqualität ankommt.</p>



<p>Immerhin sind LED-Beamer vergleichsweise langlebig, was Sie an den Lebensdauer-Werten von 30.000 Stunden bei den Mini-Beamern erkennen. Es dauert damit sehr lange, bis die LEDs einen Helligkeitsverlust von 50 Prozent erleiden. Sollten Sie ein Gerät täglich vier Stunden verwenden, liegt der theoretische Wert bei 21 Jahren.</p>



<p>Bei einem Defekt können Sie den LED-Beamer jedoch entsorgen. Denn reparieren lassen sich die Licht-Einheiten nicht. Das ist bei Einstiegspreisen ab gut 200 Euro wie für den <a href="https://www.amazon.de/XGIMI-1080p-Projektor-Automatische-Trapezkorrektur-HD-Outdoor-Beamer/dp/B0FQ5LMMPK?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Xgimi Vibe One</a> für rund 250 Euro eventuell aber verkraftbar.</p>



<p>Da Sie einen Mini-Beamer möglichst flexibel einsetzen wollen, spricht für das genannte Modell auch der integrierte Akku. Wichtig sind in dieser Beamer-Kategorie außerdem ein leichter Aufbau und smarte Betriebssysteme.</p>



<p>Über Letztere erreichen Sie Streaming-Apps wie <a href="https://www.netflix.com/de/" target="_blank" rel="noreferrer noopener">Netflix</a> oder <a href="https://www.primevideo.com/" target="_blank" rel="noreferrer noopener">Amazon Prime Video</a>. Denselben Effekt haben Sie, wenn Sie das Smartphone auf den Beamer spiegeln können. Umfangreiche HDR-Unterstützung wie beim <a href="https://www.amazon.de/Samsung-Freestyle-2-Generation-Bluetooth/dp/B0D9XVH5FZ?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Samsung The Freestyle 2nd Gen</a> ist nicht selbstverständlich und schlägt sich daher auch im Preis nieder – hier liegt er bei etwa 490 Euro.</p>



<h2 class="wp-block-heading toc">Laserlicht und Mischformen fürs helle Wohnzimmer</h2>



<p>Im heimischen Wohnzimmer muss der Beamer gut mit Umgebungslicht umgehen können, da sich der Raum oft nicht vollständig abdunkeln lässt. Hier kommen Hochleistungs-Laserdioden ins Spiel. Sie unterscheiden sich im Wesentlichen durch die Anzahl der Lasereinheiten: Bei RGB-Laserprojektoren wird das Licht direkt von roten, grünen und blauen Lasern erzeugt.</p>



<p>Ihre Stärken sind lange Haltbarkeit, gleichmäßige Leinwand-Ausleuchtung und satte Farben. Da sie den sehr großen Farbraum BT.2020 nahezu abdecken, kommen sie bei hochwertigen 4K-Beamern zum Einsatz. Im Gehäuse beansprucht RGB-Laser jedoch mehr Platz.</p>



<p>Gerade größere Beamer fürs Heimkino nutzen auch eine Kombination aus blauem Laser und gelbem Phosphor (Advanced Laser Phosphor Display, ALPD). Bei einem Beamer mit Dual-Laser kommt zum blauen Laser ein zweiter mit rotem Licht, der die warmen Farbtöne sichtbar verstärkt. Sitzt nur ein Laser im Gerät, sorgen Farbfilter für die Grundfarben.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a28180b71aeb"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/LG-Hybrid-Lichttechnik-LED-und-Laser.jpg?quality=50&amp;strip=all" alt="Hybride Beamer-Lichtquellen" class="wp-image-3136821" width="709" height="397" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Hybride Beamer-Lichtquellen wie etwa beim LG Cinebeam HU710PW kombinieren rote und blaue LEDs mit einem blauen Laser, der zu Grün gewandelt wird, um Helligkeit und Farbdarstellung zu verbessern.</p></figcaption></figure><p class="imageCredit">LG</p></div>



<p>Möglich sind auch hybride Lichtquellen aus LED und Laser – ein Beispiel finden Sie im <a href="https://www.amazon.de/LG-Electronics-HU710PW-Projektions-Diagonale-Share-Funktion/dp/B09HCJJBPZ?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">LG Cinebeam HU710PW</a> für rund 1.400 Euro. Blaue und rote LEDs werden mit einem blauen Laser kombiniert, der durch ein sogenanntes G-Rap-Element in grünes Licht gewandelt wird. Die Mischform ermöglicht eine vergleichsweise kompakte Beamer-Bauform bei hoher Lichtausbeute von 2.000 Lumen und besserer Farbdarstellung als bei einem reinen LED-Projektor.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a28180b723c5"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/LG-HU710PW.jpg?quality=50&amp;strip=all&amp;w=1200" alt="LG HU710PW" class="wp-image-3136835" width="1200" height="656" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Der LG HU710PW kombiniert Laser- und LED-Technik mit starker Farbqualität und leisem Heimkino-Betrieb.</p></figcaption></figure><p class="imageCredit">LG</p></div>



<h2 class="wp-block-heading toc">Drei Verfahren zur Bilderzeugung: DLP, LCD, LCOS</h2>



<p>Allein durch die Lichtquelle entsteht noch kein Bild auf der Leinwand. Dazu muss das farbige Licht auf bilderzeugende Chips fallen – in drei grundlegenden Verfahren:</p>



<p>Die aktuell günstigste Projektionstechnik ist DLP (Digital Light Processing). Deshalb und wegen ihrer Kompaktheit wird sie auch von der Mehrheit der erschwinglichen Heimkinoprojektoren eingesetzt. Hier sind alle Beamer mit Chips von Texas Instruments ausgestattet. Die zentrale Einheit ist das Digital Micromirroring Device (DMD), das aus Millionen winziger Kippspiegel besteht, die das Licht zum Objektiv lenken.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a28180b72d27"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/DLP-Technik_Beamer-Discount.jpg?quality=50&amp;strip=all" alt="DLP-Technik" class="wp-image-3136822" width="914" height="619" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>DLP setzt Millionen winziger Kippspiegel ein, um Licht zu reflektieren und Bilder zu projizieren. DLP-Beamer sind kompakt, liefern gleichzeitig aber eine hohe Helligkeit.</p></figcaption></figure><p class="imageCredit">Beamer Discount</p></div>



<p>Jeder Einzelspiegel kann seine Position mehrere Tausend Mal pro Sekunde wechseln. Die Farben entstehen durch zugeschaltete Farbfilter – oft über ein Farbrad – oder direkt durch farbige Lichtquellen. </p>



<p>Die Teilbilder für RGB (Rot, Grün, Blau) treffen nacheinander auf die Leinwand. Deshalb können empfindliche Zuschauer an den Rändern Farbblitzer wahrnehmen (Regenbogeneffekt). Grundsätzlich ist die Projektion jedoch scharf mit kontrastreichen Bildern.</p>



<p>Bei LCD-Projektoren (Liquid Crystal Display) sitzen LC-Panels für jede Grundfarbe Rot, Grün und Blau, durch die das Licht gelenkt wird. Mithilfe von Spannung richten sich die Kristalle aus. Sie lassen das Licht entweder durch oder blockieren es. </p>



<p>Ein Prisma sorgt dafür, dass die Teilbilder übereinander auf die Leinwand fallen und so ein Bild ergeben. Sind die LCDs nicht ganz exakt ausgerichtet, können Bildfehler entstehen. Die Technik benötigt mehr Platz als DLP, ist gleichzeitig flexibler beim Aufstellen. Dafür sorgen Zoom und Lens Shift. Ohne Versetzen des Beamers lässt sich das Bild verschieben und verzerrungsfrei in die Leinwand einpassen.</p>



<p>LCOS (Liquid Crystal on Silicon) ist eine Verfeinerung der LCD-Projektion und kommt bei hochwertigen Heimkino-Beamern zum Einsatz. Anstelle von durchlässigen LC-Panels sitzen die Flüssigkristalle auf einem Silikon-Wafer. Trifft Licht auf die Schicht, entscheidet die Drehung der Kristalle, ob es reflektiert und damit hell zurückstrahlt oder absorbiert wird. So entstehen hervorragende Schwarzwerte.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a28180b73655"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/Sony-BRAVIA-Projektor-7-1.jpg?quality=50&amp;strip=all" alt="Sony BRAVIA Projektor 7" class="wp-image-3136834" width="1024" height="487" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Der Sony BRAVIA Projektor 7 liefert echtes Heimkino mit nativer 4K-Technik und beeindruckender HDR-Bildqualität.</p></figcaption></figure><p class="imageCredit">Sony</p></div>



<p>Auch lassen sich mit LCOS besonders hohe Auflösungen und Helligkeitswerte erzielen, die bei der HDR-Darstellung (High Dynamic Range) wichtig sind. Die Technik nennt sich bei Sony SXRD (Silicon X-tal Reflective Display), ein Modellbeispiel findet sich im <a href="https://www.billiger.de/search?filter=f_category_2062&amp;searchstring=Sony+Bravia+Projector+7+%28VPL-XW5100ES%29" target="_blank" rel="noreferrer noopener">Sony Bravia Projector 7 (VPL-XW5100ES)</a> für satte 7.000 Euro. Bei JVC nennt sie sich D-ILA (Direct Image Light Amplifier). Im Modellbeispiel des <a href="https://de.jvc.com/projektoren/d-ila-projektor/DLA-NZ800BE/" target="_blank" rel="noreferrer noopener">JVC DLA-NZ800</a> schraubt sich so die Auflösung sogar auf 8K, allerdings zu einem beeindruckenden Preis von etwa 16.000 Euro.</p>



<h2 class="wp-block-heading toc">Auflösung: Der Trick mit dem Pixel Shift</h2>



<p>Wer sich für einen Heimkino-Projektor interessiert, muss bei der Auflösung aufpassen und zwischen nativer und maximaler unterscheiden. Das gilt zwar nicht für Full-HD-Beamer, vielmehr aber für Auflösungen, die darüber liegen – etwa 4K. Denn außer in der Luxusklasse handelt es sich nicht um native 3.840 × 2.160 Pixel, sondern vielmehr um sogenanntes Pseudo-4K.</p>



<p>Dabei kommen Pixel-Shift-Verfahren zum Einsatz, die sich je nach Hersteller unterscheiden. Sie begegnen Ihnen als E-Shift, 4K Enhancement oder unter dem Kürzel XPR bei DLP-Beamern. Zugrunde liegt, dass mit den eingebauten Full-HD- oder 2K-Chips (2.048 × 1.080 Pixel) ein 4K-Bild erzeugt wird. Vereinfacht gesagt, werden die Bildpunkte sehr schnell – oft mit 120 Hertz oder mehr – horizontal und vertikal oder diagonal verschoben.</p>



<p>Der Beamer projiziert nicht nur ein Bild, sondern bis zu vier Bilder hintereinander. Die Teilbilder verschmelzen dank der Trägheit des Auges auf der Leinwand zu einem Gesamtbild mit 8,3 Millionen Pixeln.</p>



<p>Obwohl es sich nicht um natives 4K handelt, funktioniert der Eindruck der Pixelvervierfachung in der Regel gut. Das Beamer-Gehäuse lässt sich dadurch kompakter halten. Da jedoch die Pixel auf den Chips größer sind als bei nativem 4K, kann bei einem sehr nahen Sitzabstand ein Pixelraster zu sehen sein.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a28180b73f41"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/Acer-H6815BD.jpg?quality=50&amp;strip=all" alt="Acer H6815BD" class="wp-image-3136828" width="1005" height="552" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Der Acer H6815BD kombiniert 4K-Schärfe, hohe Helligkeit und Gaming-Features zum fairen Preis.</p></figcaption></figure><p class="imageCredit">Acer</p></div>



<p>Alle Modelle im 4K-Einstieg verwenden Pixel-Shift-Verfahren, starten dafür aber preislich bei weniger als 1.000 Euro – wie etwa das Modell <a href="https://www.amazon.de/H6815BD-Beamer-3-840-2-160-10-000/dp/B08NDQ8BC6?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Acer H6815BD</a> für etwa 750 Euro. Echte 4K-Beamer kosten ein Vielfaches. Der schon genannte Sony Bravia Projector 7 für rund 7.000 Euro steht dafür repräsentativ.</p>



<h2 class="wp-block-heading toc">Projektionsverhältnis: Abstandsspielraum zur Leinwand</h2>



<p>Am Projektionsverhältnis erkennen Sie, welche Bilddiagonale sich aus einem bestimmten Abstand zwischen Beamer und Leinwand erzielen lässt. Je kleiner es ausfällt, desto näher muss der Projektor zur Fläche platziert werden. Frontprojektoren benötigen grundsätzlich mehr Abstand als Ultrakurzdistanz-Beamer, die Hersteller wie Hisense auch als „Laser TV“ bezeichnen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a28180b745f2"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/Optoma-UHZ3600.jpg?quality=50&amp;strip=all" alt="Optoma UHZ3600" class="wp-image-3136827" width="1009" height="629" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Der Optoma UHZ3600 bringt mit Laser-Technik, 4K und hoher Helligkeit echtes Stadiongefühl ins Wohnzimmer.</p></figcaption></figure><p class="imageCredit">Optoma</p></div>



<p>Ein großzügiges Projektionsverhältnis finden Sie in den oberen Beamer-Klassen, zum Beispiel beim 4K-Modell <a href="https://www.heimkinoraum.de/beamer/nach-herstellern/optoma/optoma-uhz3600-laser-4k-hdr-3d-beamer-heimkinoraum-edition-5452" target="_blank" rel="noreferrer noopener">Optoma UHZ3600</a> für etwa 2.200 Euro. Hier liegt es bei 1,4 bis 2,2:1. Damit erhöht sich die Flexibilität beim Aufstellen des Geräts, da Sie das Bild mit einem optischen Zoom verlustfrei anpassen können, ohne es zu bewegen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a28180b74c4a"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/Projektionsverhaeltnis-Kurzdistanz_Jmgo.png?w=1200" alt="Projektionsverhältnis Kurzdistanz" class="wp-image-3136825" width="1200" height="1045" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Ultrakurzdistanz-Beamer haben ein geringes, festes Projektionsverhältnis. Um die Bild­diagonale zu verändern, bleibt nichts anderes übrig, als das Gerät </p>
<p>zu bewegen – weiter weg von oder näher hin zur Wand.</p>
</figcaption></figure><p class="imageCredit">JMGO</p></div>



<p>Feste Projektionsverhältnisse sind bei Mini-Beamern üblich – zum Beispiel 1,2:1. Hier übernimmt meist ein digitales Zoom das Verkleinern des Bildes, was zulasten der Bildqualität geht. Bei einem Ultrakurzdistanz-Beamer wie dem <a href="https://www.amazon.de/AWOL-VISION-LTV-3000-Pro-Kurzdistanz/dp/B0CTMGFHWB?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">AWOL Vision LTV-3000 Pro</a> für 2.300 Euro ist ebenfalls ein festes Projektionsverhältnis üblich – hier 0,25:1. Die Bildgröße lässt sich nur über den Abstand des Geräts zur Leinwand verändern.</p>



<h2 class="wp-block-heading toc">Wichtige Helfer fürs Ausrichten und Anschließen</h2>



<p>Bis die Projektion perfekt gelingt, dauert es meist eine gute Weile. Schneller geht’s mit Helfern: So unterstützt der Lens Shift, wenn der Beamer etwas versetzt zur Projektionsfläche stehen muss. Damit lässt sich das Objektiv im Gehäuse verschieben. Horizontaler Lens Shift kommt zum Einsatz, wenn etwa Köpfe von Betrachtern im Bild stören.</p>



<p>Vertikaler Lens Shift erleichtert das Justieren bei der Deckenmontage. Günstige Beamer bieten oft nur einen geringen Stellbereich. Teure Projektoren können das Objektiv oftmals sogar motorisch verschieben.</p>



<p>Mit der Trapezkorrektur (Keystone-Korrektur) erzeugen Sie ein genau rechtwinkliges Bild, auch wenn der Beamer nicht ganz gerade zur Projektionsfläche steht. Viele Beamer korrigieren das Bild automatisch. Die Funktion verringert zwar die Bildgröße, ist aber besonders bei Mini-Beamern für den Mobileinsatz praktisch.</p>



<p>Bei den Anschlüssen sollte Ihr Beamer mindestens einen HDMI-Eingang mitbringen. Das ist bei den vorgestellten Projektoren auch der Fall. Je größer die Gehäuse, desto höher ist die Anzahl an HDMI-Ports. Beachten Sie die Formen, denn besonders Mini-Beamer können den Port auch in Micro- oder Mini-Fassungen bieten – wie der Samsung The Freestyle.</p>



<p>Ähnlich wie bei Fernsehern haben Heimkino-Beamer mindestens einen HDMI-Anschluss, der mit ARC (Auto Return Channel) oder sogar eARC (Enhanced) gekennzeichnet ist. Darüber lässt sich der Beamer mit dem Soundsystem im Wohnzimmer verbinden. Das ist ratsam, denn die eingebauten Beamer-Lautsprecher sind in der Regel wenig heimkinotauglich.</p>



<p><strong>Lesetipps</strong></p>



<p><a href="https://www.pcwelt.de/article/3035714/dangbei-mp1-max-test.html" target="_blank" rel="noreferrer noopener">Dangbei MP1 Max im Test</a></p>



<p><a href="https://www.pcwelt.de/article/2762615/valerion-vision-master-pro-2-im-test-kino-qualitat-fur-zu-hause.html" target="_blank" rel="noreferrer noopener">Valerion Vision Master Pro 2</a></p>



<p><a href="https://www.pcwelt.de/article/2362710/awol-vision-ltv-3500-pro-test.html" target="_blank" rel="noreferrer noopener">AWOL Vision LTV-3500 Pro im Test</a></p>



<p><a href="https://www.pcwelt.de/article/2955459/epson-eh-tw7100-test.html" target="_blank" rel="noreferrer noopener">Epson EH-TW7100 im Test</a></p>



<p><a href="https://www.pcwelt.de/article/2925281/yaber-t2-plus-test-beamer.html" target="_blank" rel="noreferrer noopener">Yaber T2 Plus im Test</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[8 cutting-edge web development tools you don’t want to miss]]></title>
<description><![CDATA[There is no ordained path. The hope that we were converging on some kind of consensus in web development has been eradicated by recent, ingenious developments that point in almost every direction. Yet, if there is a central theme uniting these efforts, it is the desire to mitigate the layers of l...]]></description>
<link>https://tsecurity.de/de/3583920/ai-nachrichten/8-cutting-edge-web-development-tools-you-dont-want-to-miss/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583920/ai-nachrichten/8-cutting-edge-web-development-tools-you-dont-want-to-miss/</guid>
<pubDate>Tue, 09 Jun 2026 11:03:29 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>There is no ordained path. The hope that we were converging on some kind of consensus in web development has been eradicated by recent, ingenious developments that point in almost every direction. Yet, if there is a central theme uniting these efforts, it is the desire to mitigate the layers of liturgical embellishment that have grown up around the reactive canon. How can we look at things differently to attain the power that we need, without the heavy intricacy?</p>



<p>Here are eight cutting-edge web development tools that point the way. </p>



<h2 class="wp-block-heading">Front-end maestro</h2>



<p>If you put a bunch of classical musicians in a room together with sheet music and let them run, you <em>might </em>get to a cohesive piece—but you <em>probably </em>want a conductor, a maestro who coordinates all of the parts. That is <a href="https://www.infoworld.com/article/3842325/designing-a-dynamic-web-application-with-astro-js.html">Astro</a> for your front-end frameworks.</p>



<p>Astro addresses the “<a href="https://www.infoworld.com/article/2335507/reactive-javascript-the-evolution-of-front-end-architecture.html" data-type="link" data-id="https://www.infoworld.com/article/2335507/reactive-javascript-the-evolution-of-front-end-architecture.html">hydration</a>” of the front end, that is to say, the process of making the shell reactive. In conventional server-side rendering (SSR), like Next.js or Nuxt, the server not only sends the HTML, but also sends the massive framework runtime down the wire, just to attach event listeners to the page. Astro allows you to write components in React, Svelte, Vue, or Solid, and its compiler strips away all of the JavaScript before it reaches the browser. Astro ships zero JS by default, relying on its <a href="https://docs.astro.build/en/concepts/islands/" data-type="link" data-id="https://docs.astro.build/en/concepts/islands/">islands architecture</a> to hydrate only the specific components that demand interactivity. </p>



<p>Because Astro isolates interactivity into distinct islands, sharing complex state between those islands (e.g., a complex filtering sidebar communicating with a separate dynamic data grid) is fundamentally harder than it is in a monolithic single-page application. If you are building a highly interactive, dashboard-heavy app where every component affects every other component, Astro’s isolated islands might begin to feel more like a straitjacket than a liberation.</p>



<p>See also: <a href="https://www.infoworld.com/article/2337044/intro-to-qwik-a-superfast-javascript-framework.html" data-type="link" data-id="https://www.infoworld.com/article/2337044/intro-to-qwik-a-superfast-javascript-framework.html">Qwik</a>. If Astro unbloats by stripping away the JavaScript entirely, Qwik unbloats by delaying it. Qwik delivers instant HTML and serializes the application state, downloading and executing only the JavaScript code required for a specific interaction at the exact millisecond the user clicks a button.</p>



<h2 class="wp-block-heading">Biome: Lint like it’s 2026</h2>



<p><a href="https://www.infoworld.com/article/2255250/what-is-rust-safe-fast-and-easy-software-development.html" data-type="link" data-id="https://www.infoworld.com/article/2255250/what-is-rust-safe-fast-and-easy-software-development.html">Rust</a> is gradually replacing the underlying infrastructure in the JavaScript ecosystem. But while Rust gives <a href="https://biomejs.dev/">Biome</a> its close-to-the-metal speed, Biome’s true calling card is its unification of the sprawling toolchain under a cohesive umbrella.</p>



<p>The .eslintrc and .prettierrc files and the dozen associated plugins can become a dark and unhappy bog in a project. Biome is the way out of the mire. It is a single, blazingly fast binary that replaces your entire tangled formatting and linting ecosystem, providing a path to code quality that doesn’t require a sprawling web of dependencies.</p>



<p>Probably the biggest drawback to Biome is that you lose the wide-open extensibility—which is exactly the same feature that makes Biome lean.</p>



<p>See also: <a href="https://rspack.rs/">Rspack</a>. Biome cleans up the linting. Rspack unbloats the build step. Also built on Rust for speed, Rspack challenges the new “unbundled” esbuild-based dev mode championed by Vite and uses bundled dev mode.</p>



<h2 class="wp-block-heading">Bun: Fast and integrated back-end JavaScript</h2>



<p>Most cutting-edge JavaScript enthusiasts are already well-aware of <a href="https://www.infoworld.com/article/2338008/explore-bunjs-the-all-in-one-javascript-runtime.html">Bun</a>. For those who haven’t yet experienced Bun’s enthralling blend of one-stop shopping and blistering speed first-hand, it’s a virtually irrefutable must-try.</p>



<p>Fast is probably an understatement. If you are used to <a href="https://www.infoworld.com/article/2254485/what-is-nodejs-javascript-runtime-explained.html">Node</a> and you try out Bun, you will likely be immediately impressed with the speed at which commands execute. The Bun team has also made an extensive, multi-year effort to bring its engine into close compatibility with Node’s APIs. Overall, Bun is an extraordinary engineering effort that every JS developer should explore. </p>



<p>However, while Bun’s <a href="https://www.infoworld.com/article/2338081/meet-the-zig-programming-language.html">Zig</a>-based engine is in most respects a drop-in for Node, it isn’t perfect, especially when considering the gargantuan landscape of Node packages out there. Node remains the conservative, happy-path engine for server-side JavaScript. </p>



<p>See also: <a href="https://www.infoworld.com/article/2256205/what-is-deno-a-better-nodejs.html" data-type="link" data-id="https://www.infoworld.com/article/2256205/what-is-deno-a-better-nodejs.html">Deno</a>. Although Bun has justifiably earned a reputation for bleeding-edge innovation, Deno has quietly pressed ahead with an appealing set of enterprise features like an integrated deployment platform and a front-end framework (<a href="https://www.infoworld.com/article/3523813/intro-to-deno-fresh-a-fresh-take-on-full-stack-javascript.html">Deno Fresh</a>).</p>



<p>The Bun curious also may want to check out my interview with Bun creator <a href="https://www.infoworld.com/article/2338698/interview-with-jarred-sumner-buns-creator-talks-tech-funding-and-startups.html">Jared Sumner</a>.</p>



<h2 class="wp-block-heading">HTMX: Ajax KISS</h2>



<p>If we are talking about clever ways to de-complexify the web, <a href="https://www.infoworld.com/article/4150864/htmx-4-0-hypermedia-finds-a-new-gear.html">HTMX</a> could reasonably be considered the poster-child. It takes the core mechanisms of the modern web client, like <a href="https://developer.mozilla.org/en-US/docs/Glossary/AJAX" data-type="link" data-id="https://developer.mozilla.org/en-US/docs/Glossary/AJAX">Ajax</a> and partial updates, and turns them into simple HTML attributes. That means the state lives exclusively on the server, which is responsible for sending HTMX fragments.</p>



<p>Of course, there are trade-offs. Perhaps most unavoidable is the extreme dependence on the network. Because there is no client-side state machine, the browser will be orphaned and helpless without a connection to the server. That is, unless you <a href="https://www.infoworld.com/article/4163910/the-front-end-architecture-trilemma-reactivity-vs-hypermedia-vs-local-first-apps.html" data-type="link" data-id="https://www.infoworld.com/article/4163910/the-front-end-architecture-trilemma-reactivity-vs-hypermedia-vs-local-first-apps.html">get experimental</a> with a <a href="https://www.infoworld.com/article/4133648/the-browser-is-your-database-local-first-comes-of-age.html" data-type="link" data-id="https://www.infoworld.com/article/4133648/the-browser-is-your-database-local-first-comes-of-age.html">local-first datastore</a>.</p>



<p>Long story short: if your app falls into the realm of HTMX’s ability, HTMX is likely to be the most direct <a href="https://www.infoworld.com/article/2334742/what-is-rest-the-de-facto-web-architecture-standard.html">RESTful</a> way to build it. And HTMX can in fact handle quite a lot.</p>



<p>See also: <a href="https://www.infoworld.com/article/4100499/intro-to-hotwire-interactive-javascript-built-from-html.html" data-type="link" data-id="https://www.infoworld.com/article/4100499/intro-to-hotwire-interactive-javascript-built-from-html.html">Hotwire</a>. A collection of tools for building single-page-style applications using HTML over the wire, Hotwire has great features like page morphing, which can diff HTML instead of cold-loading it, with a simple import. True to classic “free as in speech” software culture, the HTMX and Hotwire projects freely exchange ideas. </p>



<h2 class="wp-block-heading">PowerSync: Data layer redo</h2>



<p>Although the local-first data revolution that <a href="https://www.infoworld.com/article/4163910/the-front-end-architecture-trilemma-reactivity-vs-hypermedia-vs-local-first-apps.html">PowerSync</a> represents implies a fairly serious engineering deep dive, its core proposal — to entirely reshape the way data moves in web architecture — is something a web developer needs to be aware of.</p>



<p>Usually, we create architectures that require a complex middleware to broker between a reactive client and the datastore. PowerSync proposes a radical alternative: bypass the middleman entirely by dropping a robust SQLite Wasm database directly into the browser.</p>



<p>The UI works on local data using <a href="https://www.infoworld.com/article/4140734/the-revenge-of-sql-how-a-50-year-old-language-reinvents-itself.html" data-type="link" data-id="https://www.infoworld.com/article/4140734/the-revenge-of-sql-how-a-50-year-old-language-reinvents-itself.html">familiar SQL</a>, synchronously. Latency is zero. The dreaded loading spinner vanishes entirely. In the background, PowerSync automatically reconciles your local store with your central Postgres database. It handles the complex syncing algorithms and network drops, effectively making your application offline-first by default.</p>



<p>The catch, of course, is that local-first development forces a massive mental shift. You have to define data slices (similar to a view) that each client user holds. The PowerSync engine does most of the hard work, but things like schema migrations and conflict resolution (when two users edit the same record while offline) require a significantly steeper initial setup than a standard REST API.</p>



<p>See also: <a href="https://www.infoworld.com/article/4133648/the-browser-is-your-database-local-first-comes-of-age.html" data-type="link" data-id="https://www.infoworld.com/article/4133648/the-browser-is-your-database-local-first-comes-of-age.html">RxDB</a>. RxDB is a slightly different flavor of local-first datastore. Whereas PowerSync relies heavily on Postgres, SQLite, and background daemons, RxDB provides a NoSQL, offline-first, reactive database that treats queries as observable streams, pushing UI updates the exact millisecond the local data changes. </p>



<h2 class="wp-block-heading">RooCode: Use any AI you want</h2>



<p>The beauty of <a href="https://www.infoworld.com/article/4019646/roo-code-review-a-first-look-at-autonomous-ai-powered-development-in-the-ide.html">RooCode</a> lies in its ability to orchestrate whatever AI providers you have—for free. RooCode is an extension to <a href="https://www.infoworld.com/article/2335960/what-is-visual-studio-code-microsofts-extensible-code-editor.html" data-type="link" data-id="https://www.infoworld.com/article/2335960/what-is-visual-studio-code-microsofts-extensible-code-editor.html">Visual Studio Code</a> that provides an AI manager layer. This layer bridges between the general abilities of the LLM and your code-specific, project-level structures.</p>



<p>RooCode is strong enough to be somewhat agentic in its capabilities. It doesn’t reach the powerhouse abilities of something like Cursor or Antigravity, but it is quite able to handle most small to medium-sized requests. And it does so with a minimum of unnecessary overhead. I find myself often using RooCode alongside my AI-assisted IDE to knock out lesser requirements, for less cost and without interrupting the flow of ongoing epics.</p>



<p>RooCode keeps you free of proprietary ecosystems. It allows you to plug in your own API keys—whether that is Claude, OpenAI, or even a local model running on your own hardware. </p>



<p>The hidden tax of any AI coding assistant, however, is that it fundamentally shifts your job description from “writer” to “editor.” The unbloating of keystrokes can paradoxically lead to massively bloated codebases if developers blindly accept AI-generated boilerplate without actively reviewing its architectural impact. It is incredibly easy to let an agent spin up 500 lines of complex React when 50 lines of plain JavaScript would have done.</p>



<p>See also: <a href="https://antigravity.google/" data-type="link" data-id="https://antigravity.google/">Antigravity</a>. RooCode is a lightweight extension that supercharges your existing environment. Google’s Antigravity is a custom-built editor designed from the ground up around AI, geared for agentic development workflows.</p>



<h2 class="wp-block-heading">TanStack Query: Syncing made simple(r)</h2>



<p>Even when client-side state management is addressed (see Zustand below), there is still a big, gaping hole in the plot: syncing across the server boundary. That is where <a href="https://tanstack.com/query/latest">TanStack Query</a> steps into the breach.</p>



<p>Distributed computing is a notoriously thorny problem, and in fact our standard reactive model walks right into these thorns by holding the same state in two different places: on the client and the server.  Tanstack Query tries to make this inherent architectural friction as painless as possible by acting as an intelligent asynchronous layer. </p>



<p>Instead of using a bunch of manual fetches tied to <code>useState</code> updates, along with fragile <code>isLoading</code> flags and complex state synchronization logic, TanStack Query abstracts the heavy lifting of API responses, background updates, and request deduplication into a few elegant hooks. You tell TanStack Query where to get the data, and it uses a pattern known as “stale-while-revalidate,” which means it will cache and reuse data on the front end (eliminating reload waits) and sync to the latest state in the background. </p>



<p>The catch, however, is that cache invalidation remains one of the hardest problems in computer science—and TanStack Query forces you to face it head-on. You will spend time thinking about “query keys” and deciding when a piece of data should be considered “stale.” No free lunches in software.</p>



<p>See also: <a href="https://swr.vercel.app/">SWR</a>. While TanStack Query is an absolute powerhouse for complex data manipulation, SWR remains a champion of API minimalism, doing exactly what its name implies (stale-while-revalidate) with almost zero configuration.</p>



<h2 class="wp-block-heading">Zustand: Minimalist state</h2>



<p>If you have yet to encounter the monstrosity of large-scale state management in a reactive app, then spoiler alert: it can be nasty. <a href="https://zustand.docs.pmnd.rs/learn/getting-started/introduction">Zustand</a> proposes to dispense with the ceremonial boilerplate of reducers, providers, and unwieldy context wrappers in favor of a tiny, brutally simple global store.</p>



<p>Instead of forcing your entire application tree into a massive React context provider (sometimes leading to cascades of superfluous re-renders across the DOM), Zustand uses custom hooks to tie state directly to the specific components that need it. Zustand strives to achieve the specificity in the VDOM reactive model (instead of eliminating it entirely a la <a href="https://www.infoworld.com/article/4129648/reactive-state-management-with-javascript-signals.html">Signals</a>).</p>



<p>You define a store, you call it, and the reactivity just works. It is an expression of the KISS philosophy applied to front-end architecture, scraping away the intricacies of Flux-like patterns. The trade-off for this liberation is the burden of discipline. Because Zustand is unopinionated, it won’t stop you from turning your global store into a cluttered junk drawer. You’ll need to impose your own conventions and guardrails to keep a large-scale project manageable.</p>



<p>See also: <a href="https://jotai.org/" data-type="link" data-id="https://jotai.org/">Jotai</a>. If Zustand is the unbloated global store, Jotai is the unbloated atomic approach. Jotai manages state from the bottom up, calculating changes with surgical precision without triggering massive re-renders across the application tree.</p>



<h2 class="wp-block-heading">New directions in web development</h2>



<p>The most remarkable thing about these eight tools is that they deal in large part with alternative approaches that challenge the familiar. Although you may not be able to adopt them immediately, you will want to keep an eye on them. They are key factors that will continue to influence the shape of web applications and how we build them.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-42349 | clerk javascript unusual condition (GHSA-w24r-5266-9c3c)]]></title>
<description><![CDATA[A vulnerability has been found in clerk javascript, shared, backend, nextjs, -react, react, vue, astro, nuxt, -expo, expo, react-router, tanstack-react-start, chrome-extension, fastify, express and hono and classified as critical. This impacts an unknown function. This manipulation causes imprope...]]></description>
<link>https://tsecurity.de/de/3572606/sicherheitsluecken/cve-2026-42349-clerk-javascript-unusual-condition-ghsa-w24r-5266-9c3c/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3572606/sicherheitsluecken/cve-2026-42349-clerk-javascript-unusual-condition-ghsa-w24r-5266-9c3c/</guid>
<pubDate>Thu, 04 Jun 2026 14:38:46 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/clerk:javascript">clerk javascript, shared, backend, nextjs, -react, react, vue, astro, nuxt, -expo, expo, react-router, tanstack-react-start, chrome-extension, fastify, express and hono</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. This impacts an unknown function. This manipulation causes improper check for unusual conditions.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2026-42349">CVE-2026-42349</a>. The attack can be initiated remotely. There is not any exploit available.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[Wöchentliches Security-Update: PAN-OS-Bypass, Gogs-RCE ohne Patch und KI-Phishing im Beschleunigungsmodus]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – In dieser Woche zeigt sich erneut, wie schnell aus einem „mittel-sicheren“ Fehler ein operativ verwertbarer Einfall werden kann: PAN-OS/Prisma-Access wird laut Warnungen aktiv für Authentifizierungs-Bypässe missbraucht, während bei Gogs ein kritischer Zero-Day bereits Remot...]]></description>
<link>https://tsecurity.de/de/3570551/it-security-nachrichten/woechentliches-security-update-pan-os-bypass-gogs-rce-ohne-patch-und-ki-phishing-im-beschleunigungsmodus/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3570551/it-security-nachrichten/woechentliches-security-update-pan-os-bypass-gogs-rce-ohne-patch-und-ki-phishing-im-beschleunigungsmodus/</guid>
<pubDate>Wed, 03 Jun 2026 20:37:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-weekly-security-recap-pan-os-gogs-ki-phishing.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-weekly-security-recap-pan-os-gogs-ki-phishing.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-weekly-security-recap-pan-os-gogs-ki-phishing-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-weekly-security-recap-pan-os-gogs-ki-phishing-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-weekly-security-recap-pan-os-gogs-ki-phishing-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-weekly-security-recap-pan-os-gogs-ki-phishing-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-weekly-security-recap-pan-os-gogs-ki-phishing-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – In dieser Woche zeigt sich erneut, wie schnell aus einem „mittel-sicheren“ Fehler ein operativ verwertbarer Einfall werden kann: PAN-OS/Prisma-Access wird laut Warnungen aktiv für Authentifizierungs-Bypässe missbraucht, während bei Gogs ein kritischer Zero-Day bereits Remote Code Execution ermöglicht – ohne verfügbaren Patch. Gleichzeitig sinkt mit KI-gestütztem Social Engineering die Hürde für Phishing […]</p>
<div><a href="https://www.it-boltwise.de/woechentliches-security-update-pan-os-bypass-gogs-rce-ohne-patch-und-ki-phishing-im-beschleunigungsmodus.html">... den vollständigen Artikel <strong>»Wöchentliches Security-Update: PAN-OS-Bypass, Gogs-RCE ohne Patch und KI-Phishing im Beschleunigungsmodus«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/woechentliches-security-update-pan-os-bypass-gogs-rce-ohne-patch-und-ki-phishing-im-beschleunigungsmodus.html">Wöchentliches Security-Update: PAN-OS-Bypass, Gogs-RCE ohne Patch und KI-Phishing im Beschleunigungsmodus</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[From God of War to Until Dawn – seven reveals from last night’s PlayStation event]]></title>
<description><![CDATA[The PS5 era has been in some ways disappointing for Sony – on Tuesday, the company revealed a slate of games they hope will change that• Don’t get Pushing Buttons delivered to your inbox? Sign up herePlayStation’s future has looked a little uncertain these past few years. Although the PS5 has sol...]]></description>
<link>https://tsecurity.de/de/3569394/it-nachrichten/from-god-of-war-to-until-dawn-seven-reveals-from-last-nights-playstation-event/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3569394/it-nachrichten/from-god-of-war-to-until-dawn-seven-reveals-from-last-nights-playstation-event/</guid>
<pubDate>Wed, 03 Jun 2026 13:47:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The PS5 era has been in some ways disappointing for Sony – on Tuesday, the company revealed a slate of games they hope will change that</p><p>• <a href="https://www.theguardian.com/info/ng-interactive/2021/nov/24/sign-up-for-pushing-buttons-keza-macdonalds-weekly-look-at-the-world-of-gaming"><strong>Don’t get Pushing Buttons delivered to your inbox? Sign up here</strong></a></p><p>PlayStation’s future has looked a little uncertain these past few years. Although the PS5 has sold well and been very profitable, the brand is far from the runaway market leader it was in the PS2 days. Earlier this week, Game File <a href="https://www.gamefile.news/p/playstation-first-party-sales-decline">dug into</a> Sony’s most recent earnings reports to illustrate how PlayStation has been selling fewer and fewer of its own flagship games since a peak during the pandemic. About 54.1m copies of games either developed or published by Sony were sold in the 2018 financial year; in 2025, it sold 32.1m.</p><p>Sony has put out some great homegrown games since the PS5 was released in 2020, from Astro Bot to <a href="https://www.theguardian.com/games/2025/oct/02/ghost-of-yotei-review-deliciously-brutal-and-stunningly-beautiful-revenge-quest">Ghost of Yōtei</a>, but it has also had some expensive and very public failures and cancellations; PlayStation boss Jim Ryan, who retired in 2024, placed big bets on live-service games and only a few panned out (hello, Helldivers). Sony also seems to have rolled back on releasing its single-player PS5 games on PC after a polite interval of time, suggesting it wants to preserve what advantage and exclusivity it has.</p> <a href="https://www.theguardian.com/games/2026/jun/03/god-of-war-laufey-playstation-state-of-play">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-0257: PAN-OS GlobalProtect Auth-Bypass ist aktiv ausgenutzt]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Palo Alto Networks warnt, dass CVE-2026-0257 in PAN-OS und Prisma Access bereits aktiv ausgenutzt wird. Die Schwachstelle erlaubt einen Authentifizierungs-Bypass im GlobalProtect-Portal und -Gateway und kann Angreifern das Einrichten nicht autorisierter VPN-Verbindungen erm...]]></description>
<link>https://tsecurity.de/de/3562562/it-security-nachrichten/cve-2026-0257-pan-os-globalprotect-auth-bypass-ist-aktiv-ausgenutzt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3562562/it-security-nachrichten/cve-2026-0257-pan-os-globalprotect-auth-bypass-ist-aktiv-ausgenutzt/</guid>
<pubDate>Mon, 01 Jun 2026 11:51:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-pan-os-globalprotect-auth-bypass-cve-2026-0257.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-pan-os-globalprotect-auth-bypass-cve-2026-0257.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-pan-os-globalprotect-auth-bypass-cve-2026-0257-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-pan-os-globalprotect-auth-bypass-cve-2026-0257-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-pan-os-globalprotect-auth-bypass-cve-2026-0257-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-pan-os-globalprotect-auth-bypass-cve-2026-0257-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-pan-os-globalprotect-auth-bypass-cve-2026-0257-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – Palo Alto Networks warnt, dass CVE-2026-0257 in PAN-OS und Prisma Access bereits aktiv ausgenutzt wird. Die Schwachstelle erlaubt einen Authentifizierungs-Bypass im GlobalProtect-Portal und -Gateway und kann Angreifern das Einrichten nicht autorisierter VPN-Verbindungen ermöglichen. Nach Angaben von Rapid7 reichen die beobachteten Aktivitäten bis Ende April/Anfang Mai zurück, mit einer zweiten Welle Anfang […]</p>
<div><a href="https://www.it-boltwise.de/cve-2026-0257-pan-os-globalprotect-auth-bypass-ist-aktiv-ausgenutzt.html">... den vollständigen Artikel <strong>»CVE-2026-0257: PAN-OS GlobalProtect Auth-Bypass ist aktiv ausgenutzt«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/cve-2026-0257-pan-os-globalprotect-auth-bypass-ist-aktiv-ausgenutzt.html">CVE-2026-0257: PAN-OS GlobalProtect Auth-Bypass ist aktiv ausgenutzt</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-0130 | Palo Alto Cloud NGFW/PAN-OS/Prisma Access Packet unusual condition]]></title>
<description><![CDATA[A vulnerability was found in Palo Alto Cloud NGFW, PAN-OS and Prisma Access and classified as critical. Affected by this issue is some unknown functionality of the component Packet Handler. Executing a manipulation can lead to improper check for unusual conditions.

The identification of this vul...]]></description>
<link>https://tsecurity.de/de/3561514/sicherheitsluecken/cve-2025-0130-palo-alto-cloud-ngfwpan-osprisma-access-packet-unusual-condition/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3561514/sicherheitsluecken/cve-2025-0130-palo-alto-cloud-ngfwpan-osprisma-access-packet-unusual-condition/</guid>
<pubDate>Mon, 01 Jun 2026 01:08:49 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/palo_alto:cloud_ngfw">Palo Alto Cloud NGFW, PAN-OS and Prisma Access</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. Affected by this issue is some unknown functionality of the component <em>Packet Handler</em>. Executing a manipulation can lead to improper check for unusual conditions.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2025-0130">CVE-2025-0130</a>. The attack may be launched remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Claude Mythos exposed a hard truth: Your enterprise patching process is way too slow]]></title>
<description><![CDATA[In 2024, researchers from the University of Illinois found that GPT-4, when provided with a common vulnerabilities and exposures (CVE) description, could autonomously exploit 87% of a curated 15-vulnerability one-day dataset. Without the description, it could only exploit 7%. This provided a “mar...]]></description>
<link>https://tsecurity.de/de/3561173/it-nachrichten/claude-mythos-exposed-a-hard-truth-your-enterprise-patching-process-is-way-too-slow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3561173/it-nachrichten/claude-mythos-exposed-a-hard-truth-your-enterprise-patching-process-is-way-too-slow/</guid>
<pubDate>Sun, 31 May 2026 19:17:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In 2024,<a href="https://arxiv.org/abs/2404.08144"> <u>researchers from the University of Illinois</u></a> found that GPT-4, when provided with a common vulnerabilities and exposures (CVE) description, could autonomously exploit 87% of a curated 15-vulnerability one-day dataset. Without the description, it could only exploit 7%. This provided a “margin of safety” for the industry because while AI could exploit known vulnerabilities, it could not discover them. </p><p>However, on April 7,<a href="https://www.anthropic.com/glasswing"> <u>Anthropic announced</u></a> that Claude Mythos Preview had closed that margin, with the model autonomously discovering thousands of zero-day vulnerabilities across major operating systems and browsers. Separately, Mythos scored 83.1% on the CyberGym vulnerability reproduction benchmark. In one campaign targeting OpenBSD across 1,000 scaffold runs, the total compute cost was less than $20,000. </p><p>Exploitation timelines are collapsing. Langflow’s CVE-2026-33017 (CVSS 9.8) was<a href="https://www.sysdig.com/blog/cve-2026-33017-how-attackers-compromised-langflow-ai-pipelines-in-20-hours"> <u>exploited 20 hours after disclosure</u></a> with no public proof-of-concept. Marimo’s CVE-2026-39987 (CVSS 9.3) was<a href="https://www.sysdig.com/blog/marimo-oss-python-notebook-rce-from-disclosure-to-exploitation-in-under-10-hours"> <u>hit in 9 hours and 41 minutes</u></a>.</p><p>The defensive infrastructure most organizations rely on wasn’t designed for this.<a href="https://www.rapid7.com/research/report/global-threat-landscape-report-2026/"> <u>Rapid7’s 2026 threat landscape report</u></a> states that the median time from CVE publication to CISA's known exploited vulnerabilities (KEV) listing is five days.<a href="https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026"> <u>Google’s M-Trends 2026</u></a> report found that exploitation is happening before a patch is even released. When the Langflow advisory was published, the first exploit arrived in 20 hours. When the Marimo advisory was published, it took under 10 hours. </p><p>The assumption that your patch window is safe because exploitation takes time is no longer true. Here are your building blocks.</p><h2><b>Replace CVSS-only prioritization with a three-layer filter</b></h2><p>Most vulnerability management programs still prioritize by CVSS score alone. CVSS quantifies a vulnerability’s “theoretical” severity without considering whether a vulnerability is being exploited in the wild or how quickly someone could weaponize it. A CVSS 8.8 vulnerability with a history of active exploitation (like Docker’s<a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34040"> <u>CVE-2026-34040</u></a>) gets lower priority than a CVSS 9.8 vulnerability that may never be exploited in the wild.</p><p>A<a href="https://arxiv.org/abs/2506.01220"> <u>recent study</u></a> validated against 28,377 real-world vulnerabilities offers a concrete replacement: A three-layer decision tree incorporating CISA KEV status, Exploit Prediction Scoring System (EPSS) scores, and CVSS, thus forming a singular prioritization filter.</p><h4><b>Three-Layer Vulnerability Prioritization Filter</b></h4><table><tbody><tr><td><p><b>Layer</b></p></td><td><p><b>Data source</b></p></td><td><p><b>Threshold</b></p></td><td><p><b>Action</b></p></td><td><p><b>SLA</b></p></td></tr><tr><td><p>1. Active exploitation</p></td><td><p>CISA KEV catalog</p></td><td><p>Listed</p></td><td><p>Immediate patching</p></td><td><p>Hours</p></td></tr><tr><td><p>2. Predicted exploitation</p></td><td><p>EPSS via FIRST.org</p></td><td><p>Score ≥ 0.088</p></td><td><p>Escalate to Tier 0 pipeline</p></td><td><p>24 hours</p></td></tr><tr><td><p>3. Severity baseline</p></td><td><p>CVSS via NVD</p></td><td><p>Score ≥ 7.0</p></td><td><p>Typical remediation</p></td><td><p>Per policy</p></td></tr></tbody></table><p><i>Validated result: 18x efficiency gain, 85.6% coverage of exploited vulnerabilities, ~95% reduction in urgent remediation workload. All three data sources are open and free.</i></p><p>The described integration is entirely automatable. It’s possible to build a script to query the CISA KEV API, the EPSS API from FIRST.org, and the <a href="https://nvd.nist.gov/">NVD</a>, and have that script run against your asset inventory for every published CVE. The human in this process should remain in the loop as an approver, but not as the trigger.</p><h2><b>Close the agent authorization gap</b></h2><p>Creating exploits quickly not only changes how patches are prioritized, but how controls are configured for all the agent-driven systems that now possess privileged credentials. Your authorization policies have not been assessed against the behavior of AI agents, and that is now a measurable risk. CVE-2026-34040 showed that Docker’s authorization plugin architecture silently bypasses every plugin when the request body exceeds 1MB. Common AuthZ plugins (OPA, Casbin, Prisma Cloud) are unaware of this type of bypass, which occurs in Docker’s middleware before the request reaches the plugin.</p><p>When<a href="https://www.cyera.com/blog/cyera-research-discovers-docker-authorization-bypass-that-silently-disables-security-policies"> <u>Cyera demonstrated this vulnerability</u></a>, they showed that an AI agent debugging infrastructure could infer the bypass path while completing a legitimate task, without any instruction to exploit anything.</p><p>The Internet Engineering Task Force (IETF) is working on authorization models for agents. The document<a href="https://datatracker.ietf.org/doc/draft-klrc-aiagent-auth/"> <u>draft-klrc-aiagent-auth-01</u></a>, published in March by participants from AWS, Zscaler, Ping Identity, and OpenAI, proposes the use of the current Secure Production Identity Framework for Everyone (SPIFFE) and OAuth 2.0 for AI agents to obtain dynamically provisioned and short-lived credentials. </p><p>Separately, the IETF<a href="https://datatracker.ietf.org/doc/draft-prakash-aip/"> <u>Agent Identity Protocol draft</u></a> (draft-prakash-aip-00) reports that out of about 2,000 surveyed model context protocol (MCP) servers, none had authentication. </p><p>But these standards are months to years away from implementation. For now, security teams must proactively incorporate agent-level test scenarios for all authorization boundaries, such as oversized requests, burst frequency, and multi-step escalation of privileged requests.</p><h2><b>Map your credential blast radius</b></h2><p>In a<a href="https://cloudsecurityalliance.org/press-releases/2026/04/16/more-than-half-of-organizations-experience-ai-agent-scope-violations-cloud-security-alliance-study-finds"> <u>survey conducted by CSA/Zenity</u></a> and published on April 16, 53% of organizations said they had already seen cases where AI agents exceeded their intended permissions, and 47% experienced a security incident involving an agent. </p><p>When AI builder tools such as<a href="https://thehackernews.com/2026/04/flowise-ai-agent-builder-under-active.html"> <u>Flowise</u></a> (CVE-2025-59528, CVSS 10.0), Langflow, or n8n become compromised, the blast radius extends far beyond the host. These tools contain API keys to frontier models, database credentials, vector store tokens, and OAuth tokens to business systems. A compromised AI builder host is not just a single-system breach. It is a credential harvest that unlocks authenticated access to every connected service.</p><p>Without credential dependency maps for each AI tool host, incident response for agent compromise is guesswork. For every instance, document each credential, the extent of its access, and the relevant credential rotation process. Also begin migrating static API keys to short-lived tokens where downstream services allow.</p><h2><b>Five actions for this quarter</b></h2><p><b>1. Deploy the three-layer KEV-EPSS-CVSS filter</b></p><p>Substitute CVSS-only prioritization according to the table above. Automate the collection of data from all three APIs as part of a scheduled script against your asset inventory. Desired outcome: 18 times more efficient, 85.6% coverage of exploited vulnerabilities, 95% reduction in urgent remediation workload.</p><p><b>2. Implement event-driven patching for Tier 0 services.</b> </p><p>Determine which services fall under the critical exposure tier: Services exposed directly to internet users, AI builder hosts, and container orchestration control plane. Trigger event-driven patching on a CVE publication instead of waiting for the next maintenance window for this tier. </p><p>Goal: deploy patch to canary within four hours of a CVE being declared critical. Use the CISA KEV and EPSS feeds to trigger event-driven patching. In situations where it is impossible to meet the goal of four-hour patching because of legacy dependencies, change-freeze windows, or rollback risk, immediately apply compensating controls such as removing internet exposure to the vulnerable service, rotating credentials for the vulnerable service, disabling affected functionality of the service (if applicable), and identifying an exception owner for the exposure until a patch can be deployed. </p><p>It is not acceptable to allow unbounded exposures for extended periods while awaiting a maintenance window.</p><p><b>3. Test authorization boundaries at agent scale.</b> </p><p>Create test cases for every API that AI agents may communicate with via AuthZ policies. Specifically, include test cases for requests exceeding 1MB, 5MB, and 10MB body sizes. This includes test cases for burst rate &gt; 100 requests per second and test cases for unusual parameter combinations (privileged flags, host mounts, capability additions). Additionally,<a href="https://www.csoonline.com/article/4157405/old-docker-authorization-bypass-pops-up-despite-previous-patch.html"> <u>patch to Docker Engine 29.3.1</u></a> to fix CVE-2026-34040.</p><p><b>4. Credential blast radius mapping for all AI builder hosts.</b> </p><p>Document each credential for each Langflow, Flowise, n8n, and custom AI pipeline instance. Classify each credential by its lifespan (static key vs. short-lived token). Identify what each credential can access. Set up alerts for anomalous IP or identity for any credential access.</p><p><b>5. Shadow AI discovery scan for this week.</b> </p><p>According to CSA data, there is a greater than 50% chance that your agents have exceeded their expected boundaries. Check your Security Information and Event Management (SIEM) and network monitoring tools for communications to the default ports of the AI builder: Langflow 7860, Flowise 3000, and n8n 5678. Any unauthorized instances are an unmonitored attack surface.</p><h2>The takeaway</h2><p>AI agents are emerging, and t<!-- -->he standards bodies are responding. The IETF has multiple drafts related to agent authentication and authorization. The<a href="https://www.coalitionforsecureai.org/"> <u>Coalition for Secure AI</u></a> has published its <a href="https://www.coalitionforsecureai.org/wp-content/uploads/2026/03/model-context-protocol-security-1.pdf"><u>MCP Security taxonomy</u></a> and <a href="https://www.coalitionforsecureai.org/announcing-the-cosai-principles-for-secure-by-design-agentic-systems/"><u>Secure-by-Design principles</u></a>. </p><p>But these standards move at standards-body speed, and the exploit window is now measured in hours. Organizations that implement the three-layer filter and event-driven patching this quarter will have a measurable reduction in exposure. Those who wait will be running calendar-based patch cycles against an adversary that operates in less than 20 hours. </p><p><i>Nik Kale is a principal engineer specializing in enterprise AI platforms and security</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[PAN-OS GlobalProtect Authentication Bypass Flaw Under Active Exploitation]]></title>
<description><![CDATA[A critical authentication bypass vulnerability in Palo Alto Networks PAN-OS and Prisma Access is now being actively exploited in the wild, prompting CISA to add CVE-2026-0257 to its Known Exploited Vulnerabilities (KEV) catalog on May 29, 2026. Palo Alto Networks published its security advisory o...]]></description>
<link>https://tsecurity.de/de/3558650/it-security-nachrichten/pan-os-globalprotect-authentication-bypass-flaw-under-active-exploitation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3558650/it-security-nachrichten/pan-os-globalprotect-authentication-bypass-flaw-under-active-exploitation/</guid>
<pubDate>Sat, 30 May 2026 09:51:40 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A critical authentication bypass vulnerability in Palo Alto Networks PAN-OS and Prisma Access is now being actively exploited in the wild, prompting CISA to add CVE-2026-0257 to its Known Exploited Vulnerabilities (KEV) catalog on May 29, 2026. Palo Alto Networks published its security advisory on May 13, 2026, warning that CVE-2026-0257 allows a remote unauthenticated […]</p>
<p>The post <a href="https://cyberpress.org/pan-os-globalprotect-authentication-bypass/">PAN-OS GlobalProtect Authentication Bypass Flaw Under Active Exploitation</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation]]></title>
<description><![CDATA[Palo Alto Networks has warned that a recently disclosed medium-severity security flaw impacting PAN-OS and Prisma Access has come under active exploitation in the wild.

The vulnerability, tracked as CVE-2026-0257 (CVSS score: 7.8), refers to a case of authentication bypass that could be exploite...]]></description>
<link>https://tsecurity.de/de/3558629/it-security-nachrichten/pan-os-globalprotect-authentication-bypass-cve-2026-0257-under-active-exploitation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3558629/it-security-nachrichten/pan-os-globalprotect-authentication-bypass-cve-2026-0257-under-active-exploitation/</guid>
<pubDate>Sat, 30 May 2026 09:37:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Palo Alto Networks has warned that a recently disclosed medium-severity security flaw impacting PAN-OS and Prisma Access has come under active exploitation in the wild.

The vulnerability, tracked as CVE-2026-0257 (CVSS score: 7.8), refers to a case of authentication bypass that could be exploited by bad actors to set up VPN connections.

"Authentication bypass vulnerabilities in the]]></content:encoded>
</item>
<item>
<title><![CDATA[PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation]]></title>
<description><![CDATA[Palo Alto Networks has warned that a recently disclosed medium-severity security flaw impacting PAN-OS and Prisma Access has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-0257 (CVSS score: 7.8), refers to a case of authentication bypass…
Read more →
The post P...]]></description>
<link>https://tsecurity.de/de/3558624/it-security-nachrichten/pan-os-globalprotect-authentication-bypass-cve-2026-0257-under-active-exploitation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3558624/it-security-nachrichten/pan-os-globalprotect-authentication-bypass-cve-2026-0257-under-active-exploitation/</guid>
<pubDate>Sat, 30 May 2026 09:37:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Palo Alto Networks has warned that a recently disclosed medium-severity security flaw impacting PAN-OS and Prisma Access has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-0257 (CVSS score: 7.8), refers to a case of authentication bypass…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/pan-os-globalprotect-authentication-bypass-cve-2026-0257-under-active-exploitation/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/pan-os-globalprotect-authentication-bypass-cve-2026-0257-under-active-exploitation/">PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Palo Alto PAN-OS Authentication Bypass Vulnerability Actively Exploited in the Wild]]></title>
<description><![CDATA[A critical authentication-bypass vulnerability affecting Palo Alto Networks PAN-OS and Prisma Access is being actively exploited by malicious actors. In response to mounting attacks, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-0257 to its Known Exploited Vulnerabili...]]></description>
<link>https://tsecurity.de/de/3558588/it-security-nachrichten/palo-alto-pan-os-authentication-bypass-vulnerability-actively-exploited-in-the-wild/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3558588/it-security-nachrichten/palo-alto-pan-os-authentication-bypass-vulnerability-actively-exploited-in-the-wild/</guid>
<pubDate>Sat, 30 May 2026 09:06:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A critical authentication-bypass vulnerability affecting Palo Alto Networks PAN-OS and Prisma Access is being actively exploited by malicious actors. In response to mounting attacks, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-0257 to its Known Exploited Vulnerabilities (KEV) catalog on May 29, 2026. While the flaw carries a medium CVSSv4 score, security researchers at […]</p>
<p>The post <a href="https://gbhackers.com/palo-alto-pan-os-authentication-bypass/">Palo Alto PAN-OS Authentication Bypass Vulnerability Actively Exploited in the Wild</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Palo Alto PAN-OS Authentication Bypass Vulnerability Actively Exploited in the Wild]]></title>
<description><![CDATA[A critical authentication-bypass vulnerability affecting Palo Alto Networks PAN-OS and Prisma Access is being actively exploited by malicious actors. In response to mounting attacks, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-0257 to its Known Exploited Vulnerabili...]]></description>
<link>https://tsecurity.de/de/3558586/it-security-nachrichten/palo-alto-pan-os-authentication-bypass-vulnerability-actively-exploited-in-the-wild/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3558586/it-security-nachrichten/palo-alto-pan-os-authentication-bypass-vulnerability-actively-exploited-in-the-wild/</guid>
<pubDate>Sat, 30 May 2026 09:06:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A critical authentication-bypass vulnerability affecting Palo Alto Networks PAN-OS and Prisma Access is being actively exploited by malicious actors. In response to mounting attacks, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-0257 to its Known Exploited Vulnerabilities (KEV) catalog…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/palo-alto-pan-os-authentication-bypass-vulnerability-actively-exploited-in-the-wild/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/palo-alto-pan-os-authentication-bypass-vulnerability-actively-exploited-in-the-wild/">Palo Alto PAN-OS Authentication Bypass Vulnerability Actively Exploited in the Wild</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Palo Alto Networks PAN-OS Authentication Vulnerability Bypass Exploited in the Wild]]></title>
<description><![CDATA[Palo Alto Networks authentication bypass vulnerability, CVE-2026-0257, affecting PAN-OS and Prisma Access, is now being actively exploited in the wild, with CISA adding it to the Known Exploited Vulnerabilities (KEV) catalog on May 29, 2026. Palo Alto Networks published its…
Read more →
The post ...]]></description>
<link>https://tsecurity.de/de/3558309/it-security-nachrichten/palo-alto-networks-pan-os-authentication-vulnerability-bypass-exploited-in-the-wild/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3558309/it-security-nachrichten/palo-alto-networks-pan-os-authentication-vulnerability-bypass-exploited-in-the-wild/</guid>
<pubDate>Sat, 30 May 2026 06:07:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Palo Alto Networks authentication bypass vulnerability, CVE-2026-0257, affecting PAN-OS and Prisma Access, is now being actively exploited in the wild, with CISA adding it to the Known Exploited Vulnerabilities (KEV) catalog on May 29, 2026. Palo Alto Networks published its…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/palo-alto-networks-pan-os-authentication-vulnerability-bypass-exploited-in-the-wild/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/palo-alto-networks-pan-os-authentication-vulnerability-bypass-exploited-in-the-wild/">Palo Alto Networks PAN-OS Authentication Vulnerability Bypass Exploited in the Wild</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Palo Alto Networks PAN-OS Authentication Vulnerability Bypass Exploited in the Wild]]></title>
<description><![CDATA[Palo Alto Networks authentication bypass vulnerability, CVE-2026-0257, affecting PAN-OS and Prisma Access, is now being actively exploited in the wild, with CISA adding it to the Known Exploited Vulnerabilities (KEV) catalog on May 29, 2026. Palo Alto Networks published its security advisory on M...]]></description>
<link>https://tsecurity.de/de/3558244/it-security-nachrichten/palo-alto-networks-pan-os-authentication-vulnerability-bypass-exploited-in-the-wild/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3558244/it-security-nachrichten/palo-alto-networks-pan-os-authentication-vulnerability-bypass-exploited-in-the-wild/</guid>
<pubDate>Sat, 30 May 2026 04:52:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Palo Alto Networks authentication bypass vulnerability, CVE-2026-0257, affecting PAN-OS and Prisma Access, is now being actively exploited in the wild, with CISA adding it to the Known Exploited Vulnerabilities (KEV) catalog on May 29, 2026. Palo Alto Networks published its security advisory on May 13, 2026, warning that CVE-2026-0257 enables a remote unauthenticated attacker to […]</p>
<p>The post <a href="https://cybersecuritynews.com/palo-alto-vulnerability-exploited/">Palo Alto Networks PAN-OS Authentication Vulnerability Bypass Exploited in the Wild</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rapid7 Observed Exploitation of PAN-OS GlobalProtect Authentication Bypass Vulnerability (CVE-2026-0257)]]></title>
<description><![CDATA[OverviewOn May 13, 2026, Palo Alto Networks published a security advisory for CVE-2026-0257, a medium severity authentication bypass affecting PAN-OS and Prisma Access when a specific configuration is present. Successful exploitation of this vulnerability allows a remote unauthenticated attacker ...]]></description>
<link>https://tsecurity.de/de/3557581/it-security-nachrichten/rapid7-observed-exploitation-of-pan-os-globalprotect-authentication-bypass-vulnerability-cve-2026-0257/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3557581/it-security-nachrichten/rapid7-observed-exploitation-of-pan-os-globalprotect-authentication-bypass-vulnerability-cve-2026-0257/</guid>
<pubDate>Sat, 30 May 2026 01:10:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Overview</h2><p><span>On May 13, 2026, Palo Alto Networks published a security </span><a href="https://security.paloaltonetworks.com/CVE-2026-0257"><span>advisory</span></a><span> for CVE-2026-0257, a medium severity authentication bypass affecting PAN-OS and Prisma Access when a specific configuration is present. Successful exploitation of this vulnerability allows a remote unauthenticated attacker to successfully establish a VPN connection through the GlobalProtect gateway of an affected appliance.</span></p><p></p><p><span>Rapid7 MDR identified successful exploitation across numerous customers, however we did not observe any indication of successful lateral movement from the devices. The earliest date for observed exploitation was May 17, 2026.  As of May 29, 2026,  this vulnerability has been added to the CISA KEV.</span></p><p></p><p><span>While the assigned CVSSv4 score indicates a </span><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:N/E:U/AU:N/R:A/V:D/RE:M/U:Amber"><span>medium</span></a><span> severity, due to the circumstances surrounding this vulnerability Rapid7 urges that organizations treat this as a critical vulnerability. An authentication bypass in an edge facing enterprise VPN appliance can have significant impact to affected organizations. As such, organizations running affected appliances are urged to upgrade to a vendor supplied patch on an urgent basis.</span></p><h2>Observed Attacker Behavior</h2><p><span>On 2026-05-18 01:51:37 UTC, Rapid7 MDR responded to a 'Suspicious VPN Authentication - Local Account Logon via Generic Non-Human Identity' alert. During the initial investigation, Rapid7 observed a suspicious cookie authentication to the local admin account across multiple customer environments from the same hosting provider, Vultr.</span></p><p><span></span></p><pre language="html">&lt;14&gt;May 18 01:51:37 palovpn-01 1,2026/05/18 01:51:37,010101010101,GLOBALPROTECT,0,2817,2026/05/18 01:51:37,vsys1,gateway-auth,login,Cookie,,admin,US,GP-CLIENT,104.207.144.154,0.0.0,0.0.0.0,0.0.0.0,aa:bb:cc:dd:ee:ff,,6.0.0,,Linux,"linux-64",1,,,"Auth latency: 78ms, profile: local_auth_profile",success,,0,,0,GP-Gateway,0101010101010101010,0x0,2026-05-18T01:51:37.264-05:00,,,,,,0,0,0,0,,palovpn-01,1,",</pre><p><span><em>GlobalProtect Authentication Log</em></span></p><p></p><p><span>Rapid7 MDR analyzed the Palo Alto tech support files across the impacted customers and observed that Cloud Authentication Service (CAS) was disabled and the GlobalProtect portal or gateway had authentication override cookies enabled. Based on these findings, MDR analysts concluded that this was likely exploitation of CVE-2026-0257. Subsequent analysis by Rapid7 Labs confirmed this was accurate by validating a successful proof-of-concept.</span></p><p></p><p><span>Rapid7 MDR observed a second wave of exploitation on May 21st. Due to the consistent MAC address, Rapid7 believes both waves of exploitation are likely from the same threat actor (TA). However, the second wave of compromises originated from the hosting provider, Dromatics Systems. In this wave of exploitation, Rapid7 observed VPN IP assignment following the cookie authentication, granting them access to the internal network. At this time, Rapid7 is unable to confirm why VPN assignment occurred only for a subset of exploited customers. </span>Across multiple customers, Rapid7 observed successful exploitation via authentication probes using forged cookies, but the appliance accepted the cookie without a full VPN session being established in 8 out of 10 impacted MDR customers.</p><p><span></span></p><pre language="html">&lt;14&gt;May 21 01:54:39 FW-PA-A 1,2026/05/21 01:54:38,010101010101,GLOBALPROTECT,0,2818,2026/05/21 01:54:38,vsys1,gateway-auth,login,Cookie,,admin,US,DESKTOP-GP01,146.19.216.125,0.0.0.0,0.0.0.0,0.0.0.0,aa:bb:cc:dd:ee:ff,,6.0.0,Windows,"Microsoft Windows 10 Pro , 64-bit",1,,,"Auth latency: 1019ms, profile: SAML-o365-GP",success,,0,,0,GlobalProtect_External_Gateway,0101010101010101010 ,0x8000000000000000,2026-05-21T01:54:39.142-05:00,,,,,,30,241,35,0,,FW-PA-A,1,,",</pre><p><span><em>GlobalProtect Authentication Log</em></span></p><h2>Technical Analysis</h2><p><span>Per the vendor advisory, we know the issue lies in a feature called “authentication override”. This feature allows a GlobalProtect portal or gateway to issue cookies to an authenticated user. The authenticated user can then use an authentication override cookie in future communications to the GlobalProtect portal or gateway in lieu of re-authenticating via credentials, akin to a bearer token. This is not a feature that is enabled by default.</span></p><p></p><p><span>We also know from reading the vendor advisory that the vulnerability requires a certain configuration in how certificates are used to encrypt and decrypt these authentication override cookies. Specifically, the certificate used to encrypt and decrypt authentication override cookies must not be the same certificate used for the GlobalProtect portal or gateway’s HTTPS service. This is a significant clue to how the vulnerability works.</span></p><p></p><p><span>To explore what an authentication override cookie looks like and how they are created, we can look at the implementation in the </span><span><span data-type="inlineCode">/usr/local/bin/gpsvc</span></span><span> binary which implements the GlobalProtect service (Our testing appliance was running PAN-OS </span><span><span data-type="inlineCode">10.2.8</span></span><span> in a vulnerable configuration). Inspecting the </span><span><span data-type="inlineCode">main_DoAuthLogin</span></span><span> function, we see that if a HTTP form value of either </span><span><span data-type="inlineCode">portal-userauthcookie</span></span><span> or </span><span><span data-type="inlineCode">portal-prelogonuserauthcookie</span></span><span> is present during a POST request to </span><span><span data-type="inlineCode">/ssl-vpn/login.esp</span></span><span>, authentication will be performed by a call to </span><span><span data-type="inlineCode">main_AuthWithCookie</span></span><span>. This function will take the incoming encrypted cookie value stored in either </span><span><span data-type="inlineCode">portal-userauthcookie</span></span><span> or </span><span><span data-type="inlineCode">portal-prelogonuserauthcookie</span></span><span>, decrypt it and extract the cookies user name, domain name, host id, client OS, remote address, and timestamp (as auth override cookies have a lifetime after which they will expire).</span></p><p><span></span></p><pre language="c">void __gostk main_AuthWithCookie(
        main_GpTask_0 *t,
        paloaltonetworks_com_libs_common_AuthProfile *authProfile,
        string authCookie,
        string key,
        string stage,
        uint32 cookieLifetime,
        uint32 eventId,
        uint32 netMask,
        bool checkSrcIp,
        main_authResult_0 *result,
        string defaultDescription)
{
// ...

  ts = 0;
  errorCode = 0;
  user = 0;
  domain = 0;
  hostId = 0;
  clientOs = 0;
  remoteAddr = 0;
  result-&gt;retCode = 0;
  startTime = time_Now();
  result-&gt;cookie_auth_status = -1;
  t-&gt;Variables.authMethod.len = 6;
if ( *(_DWORD *)&amp;runtime_writeBarrier.enabled )
    runtime_gcWriteBarrier();
else
t-&gt;Variables.authMethod.str = (uint8 *)"Cookie";
  str = authProfile-&gt;AuthProfileName.str;
  t-&gt;Variables.authProfile.len = authProfile-&gt;AuthProfileName.len;
if ( *(_DWORD *)&amp;runtime_writeBarrier.enabled )
    runtime_gcWriteBarrier();
else
t-&gt;Variables.authProfile.str = str;
  v27 = main_DecryptAppAuthCookie(t, authCookie, key, &amp;user, &amp;domain, &amp;hostId, &amp;clientOs, &amp;remoteAddr, &amp;ts);</pre><p></p><p><span>If we look at the </span><span><span data-type="inlineCode">main_DecryptAppAuthCookie</span></span><span> function we can begin to see the problem. The incoming encrypted cookie is base64 decoded and then decrypted using a private key. The decrypted content is then trusted implicitly, with no signature verification of any kind occurring after decryption.</span></p><p><span></span></p><pre language="c">error __gostk main_DecryptAppAuthCookie(
        main_GpTask_0 *t,
        string authCookie,
        string privateCert,
        string *user,
        string *domain,
        string *hostId,
        string *clientOs,
        string *remoteAddr,
        int64 *ts)
{
// ...

  if ( privateCert.len )
  {
    *(retval_95DD80 *)&amp;text[48] = paloaltonetworks_com_libs_common_DecryptRsaPrivateWithBase64Std(
                                    privateCert,
                                    (string)0LL,
                                    authCookie);</pre><p></p><p><span>The implication here is that anyone who knows the public key for the certificate used by the authentication override feature to encrypt and decrypt cookies, can successfully forge and encrypt an arbitrary authentication override cookie. The question then becomes, how does an attacker learn the correct public key to use in this attack?</span></p><p></p><p><span>This brings us back to the vendor's advisory where they state “do not reuse the portal or gateway certificate, and do not share this certificate with other features or users”.</span></p><p></p><p><span>If a GlobalProtect portal or gateway has reused the certificate for encrypting and decrypting cookies with another feature, such as the HTTPS service of the portal or gateway, then a remote unauthenticated attacker can discover the public key for that certificate. In doing so the attacker will be able to successfully forge and encrypt arbitrary authentication override cookies. As these forged cookies will be successfully decrypted server side, they will be trusted and an authentication bypass will be achieved. An attacker can use a valid forged authentication override cookie to login and establish a VPN connection.</span></p><p></p><p><span>In addition to Exposure Command and InsightVM customers being able to assess their exposure with authenticated checks, a publicly available </span><a href="https://github.com/sfewer-r7/CVE-2026-0257"><span>proof-of-concept script</span></a><span> to test if an appliance is vulnerable to CVE-2026-0257 has been developed by Rapid7 Labs. The script will retrieve all certificates in the chain for the HTTPS service of either a GlobalProtect portal or gateway. Each certificate in the chain is iterated over and an authentication override cookie is forged using each certificate's public key. This forged cookie is then tested against the GlobalProtect portal or gateway, and the script reports back if authentication was successful or not. </span></p><p></p><p><span>The usage of the script is shown below.</span></p><p><span></span></p><pre language="html">$ python3 forge_cookie.py --help
usage: forge_cookie.py [-h] --target TARGET [--port PORT] [--user USER] [--domain DOMAIN] [--host-id HOST_ID] [--client-os CLIENT_OS] [--client-ip CLIENT_IP] [--context {gateway,portal,both}] [--verbose]

Forge a GlobalProtect auth override cookie using the public key from TLS (CVE-2026-0257).

options:
  -h, --help            show this help message and exit
  --target TARGET       Target GP portal/gateway IP/hostname
  --port PORT           Target port (default: 443)
  --user USER           Username to forge cookie for (default: admin)
  --domain DOMAIN       Domain for cookie (default: empty)
  --host-id HOST_ID     Host ID for cookie (default: empty)
  --client-os CLIENT_OS
                        Client OS for cookie (default: Windows)
  --client-ip CLIENT_IP
                        Client IP in cookie (default: 0.0.0.0)
  --context {gateway,portal,both}
                        Context to test: gateway, portal, or both (default target)
  --verbose             Print full response</pre><p></p><p><span>A successful invocation of the script against a vulnerable appliance is shown below. We can see the target's GlobalProtect gateway accepted a forged authentication override cookie using the second certificate in the chain.</span></p><p><span></span></p><pre language="html">$ python3 forge_cookie.py --target 192.168.86.99 --user haxor
[*] Retrieving certificate chain from 192.168.86.99:443 ...
  Found 2 certificate(s) in chain:
  [0] CN=192.168.86.99 (RSA 2048 bits, CA=False)
  [1] CN=GP-Lab-CA (RSA 2048 bits, CA=True)

[*] Forging cookie for user 'haxor', testing each key

  Trying [0] CN=192.168.86.99
  [-] Failure - Gateway did not accepted the forged cookie
  [-] Failure - Portal did not accepted the forged cookie

  Trying [1] CN=GP-Lab-CA
  [+] Success - Gateway accepted the forged cookie
  Cookie: ng9ygxlaclylNXeSHcakXZPK06Fno0svVirz6RhRtA5mDmOaZyg/KMxUuM5lRvm1Rn1Z6vqaWQQPvQOHzwJnyldOmhUKy+HDMgIYtJ/kk3ypMqmFE7BbmPxnSKxKcQQbNIcxgkrhCwuJKwybuq0aaPVNzN9BSWmh1QmZj7oLjTEo9ExAXrm951mqYhh3+MgBCScaYqP23WzrC+vzqJB74sHoMUuFWIF8/sMYDMpvENOoI4nXAFCaRYSruW9FQQy5VTzNifNWkrYcdzDCXKiP8v4G098/2QoBbVoyHBZwbgHGBsRU3ZeSgoHjrhjxyotIshKVssUs8CRpuG2HlZBM0Q==</pre><p></p><p><span>We can observe the successful authentication via the management interface, as shown below. The two initial failures correspond to the first certificate being used which was the incorrect certificate.</span></p><p><span></span></p><figure><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt1913d15e22afec9d/6a19c11b937e6e3ee9aed268/pan-os-monitor-gpsrv.png" position="center" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="pan-os-monitor-gpsrv.png" asset-alt="pan-os-monitor-gpsrv.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt1913d15e22afec9d/6a19c11b937e6e3ee9aed268/pan-os-monitor-gpsrv.png" data-sys-asset-uid="blt1913d15e22afec9d" data-sys-asset-filename="pan-os-monitor-gpsrv.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="pan-os-monitor-gpsrv.png" sys-style-type="display"></figure><p><span><em>Figure 1: PAN-OS Management Interface</em></span></p><h2>Mitigation Guidance</h2><p><span>According to the Palo Alto Networks advisory, the following product versions are affected by CVE-2026-0257:</span></p><p></p><table><tbody><tr><td><p><span><strong>Product</strong></span></p></td><td><p><span><strong>Affected</strong></span></p></td><td><p><span><strong>Unaffected</strong></span></p></td></tr><tr><td><p><span>PAN-OS 12.1</span></p></td><td><p><span>&lt; 12.1.4-h6</span></p><p><span>&lt; 12.1.7</span></p></td><td><p><span>&gt;= 12.1.4-h6</span></p><p><span>&gt;= 12.1.7</span></p></td></tr><tr><td><p><span>PAN-OS 11.2</span></p></td><td><p><span>&lt; 11.2.4-h17</span></p><p><span>&lt; 11.2.7-h14</span></p><p><span>&lt; 11.2.10-h7</span></p><p><span>&lt; 11.2.12</span></p></td><td><p><span>&gt;= 11.2.4-h17</span></p><p><span>&gt;= 11.2.7-h14</span></p><p><span>&gt;= 11.2.10-h7</span></p><p><span>&gt;= 11.2.12</span></p></td></tr><tr><td><p><span>PAN-OS 11.1</span></p></td><td><p><span>&lt; 11.1.4-h33</span></p><p><span>&lt; 11.1.6-h32</span></p><p><span>&lt; 11.1.7-h6</span></p><p><span>&lt; 11.1.10-h25</span></p><p><span>&lt; 11.1.13-h5</span></p><p><span>&lt; 11.1.15</span></p></td><td><p><span>&gt;= 11.1.4-h33</span></p><p><span>&gt;= 11.1.6-h32</span></p><p><span>&gt;= 11.1.7-h6</span></p><p><span>&gt;= 11.1.10-h25</span></p><p><span>&gt;= 11.1.13-h5</span></p><p><span>&gt;= 11.1.15</span></p></td></tr><tr><td><p><span>PAN-OS 10.2</span></p></td><td><p><span>&lt; 10.2.7-h34</span></p><p><span>&lt; 10.2.10-h36</span></p><p><span>&lt; 10.2.13-h21</span></p><p><span>&lt; 10.2.16-h7</span></p><p><span>&lt; 10.2.18-h6</span></p></td><td><p><span>&gt;= 10.2.7-h34</span></p><p><span>&gt;= 10.2.10-h36</span></p><p><span>&gt;= 10.2.13-h21</span></p><p><span>&gt;= 10.2.16-h7</span></p><p><span>&gt;= 10.2.18-h6</span></p></td></tr><tr><td><p><span>Prisma Access 11.2.0</span></p></td><td><p><span>&lt; 11.2.7-h13</span></p></td><td><p><span>&gt;= 11.2.7-h13</span></p></td></tr><tr><td><p><span>Prisma Access 10.2.0</span></p></td><td><p><span>&lt; 10.2.10-h36</span></p></td><td><p><span>&gt;= 10.2.10-h36</span></p></td></tr></tbody></table><p></p><p><span>Affected products must have the authentication override feature enabled in either the GlobalProtect portal or gateway, and must reuse the authentication override cookie encryption and decryption certificate with another feature in order to be vulnerable. As a mitigation, affected products should either disable the authentication override feature or generate a new certificate to use exclusively for the authentication override feature.</span></p><p></p><p><span>Please refer to the vendor </span><a href="https://security.paloaltonetworks.com/CVE-2026-0257"><span>advisory</span></a><span> for the latest guidance.</span></p><h2>Rapid7 Customers</h2><h3><span>Managed Detection Response (MDR)</span></h3><p><span>The following detection rules are available for InsightIDR and Managed Detection Response (MDR) customers:</span></p><ul><li><p><span>Suspicious Authentication - Palo Alto GlobalProtect Cookie Authentication to Local Admin Account</span></p></li><li><p><span>Threat Intel (Rapid7 MDR SOC/IR) - VPN Authentication via Spoofed MAC Address</span></p></li><li><p><span>Threat Intel (Rapid7 MDR SOC/IR) - Indicator of Compromise Observed </span></p></li><li><p><span>Suspicious VPN Authentication - Palo Alto GlobalProtect Login via Default Hostname</span></p></li><li><p><span>Suspicious VPN Authentication - Local Account Logon via Generic Non-Human Identity</span></p></li><li><p><span>Suspicious VPN Authentication - Local Account</span></p></li><li><p><span>Suspicious Authentication - Vultr</span></p></li><li><p><span>Suspicious Authentication - Dromatics Systems</span></p></li></ul><h3><span>Exposure Command, InsightVM, and Nexpose</span></h3><p><span>Exposure Command, InsightVM, and Nexpose customers can assess exposure to CVE-2026-0257 using an authenticated check available since the May 15 content release.</span></p><h2>Known Indicators of Compromise</h2><p><span>Low-cost hosting providers; frequent origin of sustained threat campaigns.</span></p><p></p><table><tbody><tr><td><p><span><strong>Item</strong></span></p></td><td><p><span><strong>Description</strong></span></p></td></tr><tr><td><p><span>104.207.144.154</span></p></td><td><p><span>Threat actor source IP</span></p></td></tr><tr><td><p><span>146.19.216.119</span></p></td><td><p><span>Threat actor source IP</span></p></td></tr><tr><td><p><span>146.19.216.120</span></p></td><td><p><span>Threat actor source IP</span></p></td></tr><tr><td><p><span>146.19.216.125</span></p></td><td><p><span>Threat actor source IP</span></p></td></tr><tr><td><p><span>DESKTOP-GP01</span></p></td><td><p><span>Machinename observed in the GlobalProtect logs alongside Windows authentications first observed on May 21, 2026</span></p></td></tr><tr><td><p><span>GP-CLIENT</span></p></td><td><p><span>Machinename observed in the GlobalProtect logs alongside Linux authentications first observed on May 17, 2026</span></p></td></tr><tr><td><p><span>aa:bb:cc:dd:ee:ff</span></p></td><td><p><span>Spoofed MAC address observed in both waves of successful exploitation</span></p></td></tr></tbody></table><h2>Updates</h2><ul><li>May 29, 2026: Initial publication.</li><li>May 29, 2026: Added CISA KEV addition. </li></ul><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Russian Cosmonauts Just Livestreamed an Entire 5-hour Spacewalk]]></title>
<description><![CDATA[A routine spacewalk provided some spectacular views and intriguing astro-babble.]]></description>
<link>https://tsecurity.de/de/3554795/it-nachrichten/russian-cosmonauts-just-livestreamed-an-entire-5-hour-spacewalk/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3554795/it-nachrichten/russian-cosmonauts-just-livestreamed-an-entire-5-hour-spacewalk/</guid>
<pubDate>Thu, 28 May 2026 18:02:43 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A routine spacewalk provided some spectacular views and intriguing astro-babble.]]></content:encoded>
</item>
<item>
<title><![CDATA[Astro Forge: Ein möglicher Rückschlag für den Asteroidenbergbau]]></title>
<description><![CDATA[Der von dem Raumfahrt-Unternehmen Astro Forge anvisierte Asteroid dreht sich rasant und könnte eine Landung unmöglich machen. Ein Rückschlag für den Weltraumbergbau? (Weltraumbergbau, Raumfahrt)]]></description>
<link>https://tsecurity.de/de/3554152/it-nachrichten/astro-forge-ein-moeglicher-rueckschlag-fuer-den-asteroidenbergbau/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3554152/it-nachrichten/astro-forge-ein-moeglicher-rueckschlag-fuer-den-asteroidenbergbau/</guid>
<pubDate>Thu, 28 May 2026 14:48:03 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Der von dem Raumfahrt-Unternehmen Astro Forge anvisierte Asteroid dreht sich rasant und könnte eine Landung unmöglich machen. Ein Rückschlag für den Weltraumbergbau? (<a href="https://www.golem.de/specials/weltraumbergbau/">Weltraumbergbau</a>, <a href="https://www.golem.de/specials/raumfahrt/">Raumfahrt</a>) <img src="https://cpx.golem.de/cpx.php?class=17&amp;aid=209098&amp;page=1&amp;ts=1779972002" alt="" width="1" height="1">]]></content:encoded>
</item>
<item>
<title><![CDATA[DSPM buyer’s guide: Top 10 data security posture management tools]]></title>
<description><![CDATA[Data security posture management (DSPM) explained



Data security posture management (DSPM) tools help security teams examine their entire data environment to find shadow data, reducing the risk of data loss.



Tracking down sensitive data across both cloud and on-premises systems can be vexing...]]></description>
<link>https://tsecurity.de/de/3550105/it-security-nachrichten/dspm-buyers-guide-top-10-data-security-posture-management-tools/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3550105/it-security-nachrichten/dspm-buyers-guide-top-10-data-security-posture-management-tools/</guid>
<pubDate>Wed, 27 May 2026 09:08:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<h2 class="wp-block-heading">Data security posture management (DSPM) explained</h2>



<p>Data security posture management (DSPM) tools help security teams examine their entire data environment to find shadow data, reducing the risk of data loss.</p>



<p>Tracking down sensitive data across both cloud and on-premises systems can be vexing. Each environment presents its own challenges. Given the dynamic and ephemeral nature of cloud computing, cloud data is easily created, deleted, or moved around. The cloud attack surface is equally dynamic, making protection all the more difficult. On-premises data can be elusive, particularly when shadow AI usage creates mission-critical data stores outside IT’s purview. To address this latter point, most DSPM vendors are incorporating their own AI routines (or offering a separate <a href="https://www.csoonline.com/article/3518733/ai-spm-buyers-guide-artificial-intelligence-security-posture-management-tools-compared.html">AI SPM product, as we outlined here</a>).</p>



<p>But AI isn’t the only source of shadow data: for example, old data repositories left lurking on some cloud container or in-house server that has long been forgotten, not updated, or unaccounted for. The goal of DSPM products is to locate this shadow data and complement the more expansive <a href="https://www.csoonline.com/article/657138/how-to-choose-the-best-cloud-security-posture-management-tools.html">cloud security posture management (CSPM)</a> tools. But instead of focusing on protecting cloud infrastructures, DSPM tools focus exclusively on the role of data and how it is consumed by various cloud and on-premises services.</p>



<h2 class="wp-block-heading">How the DSPM market is evolving</h2>



<p>Over the past few years, DSPM tools have been developed to discover both known and unknown data, provide structure, and manage the security and privacy risks of potential data exposure. The market segment has seen a lot of mergers and acquisitions of late, including the following:</p>



<ul class="wp-block-list">
<li>Tenable acquired Eureka Security and Vulcan Cyber, folding them into its CNAPP Cloud Security platform</li>



<li>Palo Alto Networks acquired Dig</li>



<li>Rubrik acquired Laminar Security</li>



<li>Proofpoint acquired Normalyze</li>



<li>IBM acquired Polar Security, folding it into Guardium</li>



<li>Veeam acquired Securiti</li>



<li>Varonis acquired a variety of companies, including Cyral, SlashNext, and AllTrue.ai to enhance its DSPM and other products</li>



<li>Thales acquired Imperva and created its CipherTrust DSPM</li>



<li>Google acquired Wiz</li>
</ul>



<p>This activity shows how DSPM has become a hot commodity, as established security vendors are buying up niche vendors to expand how they identify and protect data.</p>



<p><a href="https://www.gartner.com/en/documents/6964866">According to Gartner</a>, DSPM tools bridge “the gap between data discovery/classification and the eventual implementation of automated remediation controls.”</p>



<p>The research firm outlines five use cases for DSPM: <a href="https://www.csoonline.com/article/569559/what-is-dlp-how-data-loss-prevention-software-works-and-why-you-need-it.html">data loss prevention (DLP)</a>, privacy and <a href="https://www.cio.com/article/202183/what-is-data-governance-a-best-practices-framework-for-managing-data-assets.html">data governance</a>, entitlement management, cloud posture management integration, and protecting AI-related workflows. DSPM has evolved to the point where “the products’ combined capabilities now bear only a slight resemblance to the capabilities of the vendors that pioneered DSPM, leading to uncertainty for customers as to what DSPM actually is,” Gartner says.</p>



<p>As a result, while all five use cases are key components of any DSPM strategy, not every DSPM tool will perform equally well — or even comprehensively — across the board.</p>



<p>Take DLP for example. It used to be the sole place where security tools would examine threats and try to combat risk from these threats. But as cloud estates have grown, and as AI training data exploded, enterprises need to move beyond plain-vanilla DLP and establish better ways to find evidence of an attack, stolen data, or AI-fueled phishing attempts.</p>



<p>Part of the problem is that, as Gartner reports, “traditional data security products have an insufficient view to discover previously unknown, undiscovered, or unidentified data repositories, and they fail to consistently discover sensitive data.” That is where integration into other security tools is essential — and why so many mergers and acquisitions have taken place to fill these gaps.</p>



<p>Another issue is that data usage can be messy: Many businesses have numerous data and application silos that don’t put data protection front and center. Moreover, organizations often lack consistent protections as their data spreads across clouds and applications — especially when it comes to finding its way into AI agents.</p>



<p>DSPM provides the locator function for these complex environments. Fixing the problems a DSPM tool finds is really the province of a various other security tools, such as <a href="https://www.csoonline.com/article/3622920/soar-buyers-guide-11-security-orchestration-automation-and-response-products-and-how-to-choose.html">security orchestration, automation, and response (SOAR)</a>; <a href="https://www.csoonline.com/article/566677/12-top-siem-tools-rated-and-compared.html">security information event management (SIEM)</a>; <a href="https://www.csoonline.com/article/573629/cnapp-buyers-guide-top-tools-compared.html">cloud-native application protection platforms (CNAPPs)</a>; and the like. Some DSPM vendors integrate or incorporate these “fix-it” tools with their products.</p>



<p>Overall, the DSPM market is experiencing a boom in interest, with the tools catching on quickly in the past few years. As late as 2022, Gartner found a miniscule market penetration of less than 1% across its clientele. More recently, the research firm <a href="https://www.paloaltonetworks.com/cyberpedia/dspm-market">found that DSPM’s growth over the past two years has outpaced every other cybersecurity category</a>.</p>



<h2 class="wp-block-heading"><a></a>What to look for in data security posture management (DSPM) tools</h2>



<p>DSPM tools require a significant amount of staffing resources to evaluate because they touch on so many aspects of your IT infrastructure. That’s a good thing, because you want these tools to seek out and find data no matter where it could be hiding.</p>



<p>Having a plan that prioritizes which data is most important to your organization will help focus your evaluation. It’s also important to document how each DSPM offering creates its data map and subsequent dashboards. You should also understand the specific cloud and on-premises services that are covered and which ones are on the vendor’s near-term product roadmap.</p>



<p>How each vendor describes where it goes looking for data is instructive. Every vendor supports some visibility into some of the cloud data repositories of Amazon Web Services, Google Cloud, and Microsoft Azure. But that doesn’t mean that they cover every service offered by each of the cloud providers that deals with data.</p>



<p>For example, AWS has its S3 storage, Relational Database Service, Redshift’s cloud data warehouse, Athena serverless SQL queries, and ElasticSearch managed data services, among several other places that operate on data. Veeam takes pains to delineate which services are covered in each cloud platform, but other DSPM providers are not as transparent. Varonis, meanwhile, uses a “universal data connector” that can seek out a wider range of structured data destinations, both cloud-based and on-premises. Some vendors acknowledge cloud services they don’t support. Be sure to note that this is a very dynamic situation as vendors are adding coverage areas continually as their customers demand them.</p>



<p>Tracking down data is just the beginning, however. Once found, the data must be cataloged, evaluated, and summarized in various dashboards. That could be tricky if done without tight security controls, which is why most DSPM vendors claim that “customer data always stays within the customer’s environment.” This typically means collecting metadata, rather than the data itself, using read-only access to the apps, services, and database structures. Vendors refer to this as “agentless” or “using API access.” This approach has the advantage of being able to scan huge volumes of data quickly to understand the nature of its usage and potential risk factors.</p>



<p>Once the data has been discovered and its metadata has been collected, the next step is to perform regular scans to see what changes have been made: Has data been copied to some dark corner of your cloud estate? Has someone just changed access rights to allow for greater or insecure access? These tools provide a single point of view across all the various cloud and on-premises data locations. The key word here is “regular.” Scans have default periods (such as daily or weekly) and can be activated when new data repositories are found.</p>



<p>How data is consumed in your production environment, including data pipelines, lakes, and warehouses, is another aspect to consider. This can involve creating data maps to classify this landscape as well as facilitating audits to enumerate who has access to which data resource and under what specific circumstances it was shared across your enterprise. Maps are not just pretty pictures but important visualizations that often show where shadow data was abandoned, for example.</p>



<p>On top of all these activities there is the entire field of <a href="https://www.cio.com/article/202183/what-is-data-governance-a-best-practices-framework-for-managing-data-assets.html">data governance</a>. DSPM products assign risks and apply consistent security policies to manage your entire data collection, and they work with other security tools to enforce these policies and remediate problems. Many of the vendors included below have begun offering continuous auditing as part of their DSPM governance package, which is a welcome development in this fast-changing world.</p>



<p>Each DSPM tool has several components, including agents and agentless collectors (useful for tracking on-premises data), a centralized management dashboard, scanners that detect and prioritize data collections, maps of data lineage and usage, and compliance assessments.</p>



<p>Most vendors offer their DSPM product in one or both wider contexts: to integrate with third-party security services (such as offered by Veeam and Wiz) or as part of their own security product portfolio with other add-on modules that include identity management, cloud management, detection and response, and log analysis tools (Palo Alto Networks, Varonis, and Wiz).</p>



<p>The specifics on these integrations are worth examining, as some vendors, such as Varonis, Wiz and Palo Alto Networks, have wider support than others. Understanding the scope, integration level, and what other protective features are included, and which are available at an extra cost will take some effort to figure out.</p>



<p>Products can be deployed as a complete SaaS cloud-based solution, run from on-premises servers or private virtual machines/containers, or in some combination.</p>



<p>Finally, there is the issue of pricing. All the products overviewed here are pricey. Few vendors were willing to share this information, indicating that prices are flexible and depend on numerous factors. Some vendors are now charging by the terabyte for DSPM, an interesting development that could result in higher usage costs. However, numerous vendors offer annual subscriptions on either or both the Amazon and Azure marketplaces, which typically start at $30,000 for the smallest of networks. Plan on spending at least $100,000 annually, with higher prices to analyze larger data collections.</p>



<h2 class="wp-block-heading">Leading vendors for data security posture management (DSPM)</h2>



<p>The market space of DSPM is evolving quickly. Based on our own research and research from Gartner, GigaOm, IDC, and other analyst firms, we’ve identified 10 DSPM tool providers worth investigating. We also contacted several other vendors for this article that did not respond to our inquiries, so they are not detailed here: BigID, Concentric, Flow Security, IBM, OneTrust, Rubrik, Symmetry Systems, and Theom.</p>



<h3 class="wp-block-heading">Cyera DSPM Platform</h3>



<p>Cyera’s <a href="https://www.cyera.com/platform/dspm">DSPM Platform</a> helps organizations discover, classify, and secure sensitive data across cloud, SaaS, AI, and on-premises environments. The platform — along with its <a href="https://url.usb.m.mimecastprotect.com/s/kPtAC0An9nfEYrjXTDhBU9F7FU?domain=cyera.com">DDR companion DataWatcher</a> — enables enterprises to control what data AI applications and agents can access, govern how that data is used, and reduce exposure risk across data at rest, in motion, and in use. Cyera provides agentless visibility into structured, semi-structured, and unstructured data, highly actionable risk and access intelligence dashboards, and more than 500 built-in data classifiers. The platform integrates with numerous security and data ecosystem tools, including Netskope, Splunk, Tines, Wiz, Collibra, DataHub, and Secoda, and supports on-prem/hybrid deployments for customers requiring in-environment scanning and regional data residency controls. Pricing on AWS for its Cloud Platform starts at $50,000 per year.</p>



<h3 class="wp-block-heading">Microsoft Purview DPSM</h3>



<p><a href="https://learn.microsoft.com/en-us/purview/data-security-posture-management-learn-about">Microsoft Purview DPSM</a> is part of a larger data protection effort that is in preview form and will be rolled out in June at the company’s Build conference. It consolidates separate data protection tools to provide a single place to monitor and enforce security policies, and create and monitor security objectives. Purview DPSM will integrate with DSPM tools from Cyera, BigID, and OneTrust, and it uses Copilot and other AI agents to identify and protect your data collections. It replaces older DSPM tools that are now labelled “classic” versions.</p>



<h3 class="wp-block-heading">Palo Alto Networks Cortex Cloud DSPM</h3>



<p><a href="https://www.paloaltonetworks.com/prisma/cloud/cloud-data-security">Palo Alto Networks’ Cortex Cloud DSPM</a> integrates with hundreds of SIEM, workflow, and ticketing solutions, as well as XDR and single sign-on (SSO). It comes with more than 600 prebuilt data classifiers, but more importantly, it works closely with various AI tooling to automate detection and remediation threats. It supports Microsoft 365, Snowflake, other SaaS services, a wide range of cloud providers, and on-premises file shares.</p>



<h3 class="wp-block-heading">Proofpoint DSPM</h3>



<p><a href="https://www.proofpoint.com/us/products/data-security-posture-management">Proofpoint DSPM</a> recently folded in the company’s Normalyze acquisition and added integration with Proofpoint’s DLP solution. The tool scans cloud, SaaS, and on-premises data sources. It uses AI tools to identify attack paths and classify high-value data and auto-remediates when identifying misconfigurations. It integrates out-of-the-box with APIs for SOAR, third-party ticketing, and notification and automation platforms, including Atlassian Jira, ServiceNow, Microsoft Purview, and Slack. It offers more than 300 data classifiers and protects AI workflows.</p>



<h3 class="wp-block-heading">Sentra End-to-End Data Security Platform</h3>



<p><a href="https://www.sentra.io/product">Sentra End-to-End Data Security Platform</a> provides both continuous compliance and a superset of DLP policies, offering deep support for most cloud computing services along with support for containers, virtual machines, and on-premises data sources. It has its own data detection and response (DDR) tool for near real-time detection and a series of actionable dashboards. There are lots of integrations with data management (Coralogix, DataDog, and DataHub), email, ITSM (Jira, PagerDuty, and ServiceNow), CNAPP (Wiz), collaboration (Atlan, Azure Boards, Monday.com, Slack, and Teams), IAM (Active Directory and Okta), incident response (Seemplicity), SIEM (Splunk), and on-premises file shares. It also has powerful data classifiers that leverage built-in AI features to provide metadata enrichment and context, along with automated risk mediation. <a href="https://aws.amazon.com/marketplace/pp/prodview-jn2l7wa5hwzqk?sr=0-1&amp;ref_=beagle&amp;applicationId=AWSMPContessa">Sentra has four pricing tiers on AWS</a>, starting at $50,000 per year.</p>



<h3 class="wp-block-heading">Tenable One Cloud Exposure</h3>



<p><a href="https://www.tenable.com/products/tenable-one">Tenable One Cloud Exposure</a> combines DSPM with threat detection and integrates with data lakes and warehouses such as Atlas, Salesforce, ServiceNow, Snowflake, and Jira-based ticketing systems. The tool continuously scans, categorizes, and remediates data across on-premises, cloud, and SaaS platforms to correlate identity, workload context, and potential threats. It also can dynamically verify and protect data that is externally reachable. Tenable has expanded its protective envelope to cover additional data types (such as secrets) and cloud providers.</p>



<h3 class="wp-block-heading">Thales CipherTrust DSPM</h3>



<p><a href="https://cpl.thalesgroup.com/encryption/data-security-posture-management">Thales CipherTrust DSPM </a>ties together visibility and remediation of your data located across both cloud and on-premises environments. It builds on its Imperva acquisition and can classify both structured and unstructured data and can map and protect data flows and encryption keys and secrets across the entire enterprise.</p>



<h3 class="wp-block-heading">Varonis DSPM</h3>



<p><a href="https://www.varonis.com/platform/dspm">Varonis</a> has been in the data security business for more than a decade and covers both on-premises and cloud data repositories. It provides <a href="https://www.varonis.com/coverage">several hundred integrations </a>with SIEM (e.g., Splunk), SOAR (e.g., Palo Alto XSOAR), firewalls, VPNs, web proxies, DNS services, Active Directory, Entra ID, Microsoft Purview Information Protection, and Okta. The product includes a managed DDR service that uses behavioral detection models and automated remediation. Varonis has been on an acquisition binge to broaden its security platform to include better phishing, compliance testing, and AI protection. <a href="https://aws.amazon.com/marketplace/pp/prodview-j6ereaak4ibwc?sr=0-1&amp;ref_=beagle&amp;applicationId=AWSMPContessa">Varonis AWS pricing</a> is $750 per TB per year.</p>



<h3 class="wp-block-heading">Veeam DSPM</h3>



<p>Since acquiring Securiti, Veeam has added a variety of breach and compliance management features to <a href="https://securiti.ai/dspm/">Veeam DSPM</a>, as well as on-premises protection to complement its data backup tooling. Its tool supports data streaming technologies such as Confluent, Google PubSub, Kafka, and Kinesis. It comes with 350 content classifiers that support multiple languages along with more than a thousand predefined detection rules, including AI-based data sources and uses. It integrates with a wide collection of cloud-native security services, cloud access security brokers (CASBs), CNAPPs, CSPMs, cloud infrastructure entitlement management (CIEM) systems, DLP systems, intrusion detection systems (IDSes), Kubernetes security posture management (KSPM) systems, SIEM systems, and compliance tools. It is priced per terabyte, starting at $450 per TB per year for structured data and $1,000 per TB per year for unstructured data, with volume discounts available.</p>



<h3 class="wp-block-heading">Wiz for DSPM</h3>



<p>Wiz maintains a solid brand and product identity, despite being acquired by Google. It packages its products differently from most vendors, offering three products to protect code, cloud assets, and to defend against threats. All three are needed for a <a href="https://www.wiz.io/solutions/dspm">complete DSPM solution</a>, which has been expanded to cover shadow data detection and AI-driven data classifiers. Wiz offers two licensing plans, but the full collection of DSPM features is available only on its more expensive Advanced plan. Wiz adds a lightweight agent called Runtime Sensor for detection and response. In addition to the usual cloud data sources, it also scans a variety of on-premises databases, such as MongoDB, MySQL, and PostgreSQL, as well as cloud versions, including Databricks. Wiz also integrates with more than 60 security products. <a href="https://aws.amazon.com/marketplace/pp/prodview-ibgbkrqusncsm?sr=0-1&amp;ref_=beagle&amp;applicationId=AWSMPContessa">Wiz’ AWS pricing</a> starts at $38,000 per yr to protect 100 workloads.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[NASA taps Blue Origin to deliver lunar rovers for Moon Base initiative]]></title>
<description><![CDATA[Blue Moon lander will carry Astrolab and Lunar Outpost moon buggies, while Firefly will drop off NASA's rocket-powered drones. Read More]]></description>
<link>https://tsecurity.de/de/3549536/it-nachrichten/nasa-taps-blue-origin-to-deliver-lunar-rovers-for-moon-base-initiative/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3549536/it-nachrichten/nasa-taps-blue-origin-to-deliver-lunar-rovers-for-moon-base-initiative/</guid>
<pubDate>Wed, 27 May 2026 02:32:44 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="1260" height="709" src="https://cdn.geekwire.com/wp-content/uploads/2026/05/260526-blue-astro-1260x709.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="Illustration: Blue Origin Blue Moon lander with Astrolab CLV-1 rover deployed to lunar surface" decoding="async" fetchpriority="high" srcset="https://cdn.geekwire.com/wp-content/uploads/2026/05/260526-blue-astro-1260x709.jpg 1260w, https://cdn.geekwire.com/wp-content/uploads/2026/05/260526-blue-astro-768x432.jpg 768w, https://cdn.geekwire.com/wp-content/uploads/2026/05/260526-blue-astro-1536x864.jpg 1536w, https://cdn.geekwire.com/wp-content/uploads/2026/05/260526-blue-astro.jpg 1920w" sizes="(max-width: 1260px) 100vw, 1260px"><br>Blue Moon lander will carry Astrolab and Lunar Outpost moon buggies, while Firefly will drop off NASA's rocket-powered drones. <a href="https://www.geekwire.com/2026/nasa-taps-blue-origin-to-deliver-lunar-rovers-for-moon-base-initiative/">Read More</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-30117 | scalar astro 0.1.13 Proxy Endpoint scalar_url unrestricted upload]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in scalar astro 0.1.13. The impacted element is an unknown function of the component Proxy Endpoint. Performing a manipulation of the argument scalar_url results in unrestricted upload.

This vulnerability is identified as CVE-2026...]]></description>
<link>https://tsecurity.de/de/3541893/sicherheitsluecken/cve-2026-30117-scalar-astro-0113-proxy-endpoint-scalarurl-unrestricted-upload/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3541893/sicherheitsluecken/cve-2026-30117-scalar-astro-0113-proxy-endpoint-scalarurl-unrestricted-upload/</guid>
<pubDate>Sat, 23 May 2026 14:08:56 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, has been found in <a href="https://vuldb.com/product/scalar:astro">scalar astro 0.1.13</a>. The impacted element is an unknown function of the component <em>Proxy Endpoint</em>. Performing a manipulation of the argument <em>scalar_url</em> results in unrestricted upload.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2026-30117">CVE-2026-30117</a>. The attack can be initiated remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-30118 | scalar astro 0.1.13 Proxy Endpoint scalar_url server-side request forgery]]></title>
<description><![CDATA[A vulnerability identified as critical has been detected in scalar astro 0.1.13. The impacted element is an unknown function of the component Proxy Endpoint. This manipulation of the argument scalar_url causes server-side request forgery.

This vulnerability appears as CVE-2026-30118. The attack ...]]></description>
<link>https://tsecurity.de/de/3541892/sicherheitsluecken/cve-2026-30118-scalar-astro-0113-proxy-endpoint-scalarurl-server-side-request-forgery/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3541892/sicherheitsluecken/cve-2026-30118-scalar-astro-0113-proxy-endpoint-scalarurl-server-side-request-forgery/</guid>
<pubDate>Sat, 23 May 2026 14:08:55 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">critical</a> has been detected in <a href="https://vuldb.com/product/scalar:astro">scalar astro 0.1.13</a>. The impacted element is an unknown function of the component <em>Proxy Endpoint</em>. This manipulation of the argument <em>scalar_url</em> causes server-side request forgery.

This vulnerability appears as <a href="https://vuldb.com/cve/CVE-2026-30118">CVE-2026-30118</a>. The attack may be initiated remotely. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[RTL Nachtjournal Spezial: Cybercrime - Fass ohne Boden? im Stream - Prisma]]></title>
<description><![CDATA[RTL Nachtjournal Spezial: Cybercrime - Fass ohne Boden? Gespräch, Talk • Fr., 22.05. • 18 Min.]]></description>
<link>https://tsecurity.de/de/3540032/it-security-nachrichten/rtl-nachtjournal-spezial-cybercrime-fass-ohne-boden-im-stream-prisma/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3540032/it-security-nachrichten/rtl-nachtjournal-spezial-cybercrime-fass-ohne-boden-im-stream-prisma/</guid>
<pubDate>Fri, 22 May 2026 17:21:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[RTL Nachtjournal Spezial: <b>Cybercrime</b> - Fass ohne Boden? Gespräch, Talk • Fr., 22.05. • 18 Min.]]></content:encoded>
</item>
<item>
<title><![CDATA[Das beste Zubehör für die Fritzbox: 10 Upgrades für maximalen Speed und Komfort]]></title>
<description><![CDATA[Die Fritzbox ist das Herzstück eines digitalen Zuhauses, ihr volles Potenzial lassen viele aber ungenutzt. Wer lediglich surft und telefoniert, verschenkt wertvolle Möglichkeiten in Sachen Reichweite, Stromersparnis und Komfort. Erst mit dem richtigen Zubehör wird die Box zur Schaltzentrale, die ...]]></description>
<link>https://tsecurity.de/de/3531952/it-nachrichten/das-beste-zubehoer-fuer-die-fritzbox-10-upgrades-fuer-maximalen-speed-und-komfort/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3531952/it-nachrichten/das-beste-zubehoer-fuer-die-fritzbox-10-upgrades-fuer-maximalen-speed-und-komfort/</guid>
<pubDate>Wed, 20 May 2026 09:02:46 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Die <a href="https://www.pcwelt.de/article/1157690/fritzbox-router-im-vergleich-das-beste-modell.html" target="_blank" rel="noreferrer noopener">Fritzbox</a> ist das Herzstück eines digitalen Zuhauses, ihr volles Potenzial lassen viele aber ungenutzt. Wer lediglich surft und telefoniert, verschenkt wertvolle Möglichkeiten in Sachen Reichweite, Stromersparnis und Komfort. Erst mit dem richtigen Zubehör wird die Box zur Schaltzentrale, die nicht nur Daten überträgt, sondern auch den Alltag spürbar erleichtert – von der automatisierten Heizungssteuerung bis zum blitzschnellen Datentransfer im ganzen Haus.</p>



<p>Wenn Sie bereits einen Router von Fritz (<a href="https://www.pcwelt.de/article/1157690/fritzbox-router-im-vergleich-das-beste-modell.html" target="_blank" rel="noreferrer noopener">hier finden Sie unsere Bestenliste</a>) im Einsatz haben, merken Sie mit dem richtigen Zubehör sofort: Wenn Hardware und Peripherie Hand in Hand gehen, wird aus einem einfachen Internet-Anschluss ein nahtloses Ökosystem. Für den Alltag heißt das: Mehr Speed, mehr Effizienz und spürbare Komfort-Upgrades.</p>



<p>In unserem Zubehör-Ratgeber zeigen wir Ihnen zehn essenzielle Upgrades, mit denen Sie Ihr Heimnetzwerk auf das nächste Level heben.</p>



<p><strong>Tipp:</strong> Wenn Sie noch keine Fritzbox im Einsatz haben oder aktuell noch DSL nutzen, aber demnächst auf Glasfaser umsteigen möchten, dann lohnt sich ein Blick auf die <a href="https://www.amazon.de/dp/B0D8JCN5P4?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Fritzbox 5690 Pro</a>. Sie ist bereits für das neue Wi-Fi 7 gerüstet und spielt in Kombination mit unseren Zubehör-Tipps alle Asse aus.</p>



<p><strong>Aktuell bester Preis: Fritzbox 5690 Pro</strong></p>



				<div class="wp-block-price-comparison price-comparison">
		
		<div class="new_products_tab tabcontent ">

			<div class="price-comparison__record price-comparison__record--header">
				<div>
					<span>Shop</span>
				</div>
								<div class="price-comparison__price">
					<span>Preis</span>
				</div>
			</div>

								<div class="price-comparison__record  amazon_vendor">
						<div class="price-comparison__image">
															<img decoding="async" src="https://www.pcwelt.de/wp-content/themes/idg-base-theme/dist/static/img/amazon-logo.svg" alt="Amazon" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>309,99 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://www.amazon.de/dp/B0D8JCN5P4?tag=pcwelt.de-21&amp;linkCode=ogi&amp;th=1&amp;psc=1&amp;ascsubtag=rss" data-vars-product-name="AVM Fritzbox 5690 Pro" data-vars-product-id="2405101" data-vars-category="Networking" data-vars-manufacturer-id="21582" data-vars-manufacturer="AVM" data-vars-vendor="billiger,gtin,amazon,mpn," data-vars-po="billiger,gtin,amazon,mpn" data-product="2405101" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://www.amazon.de/dp/B0D8JCN5P4?tag=pcwelt.de-21&amp;linkCode=ogi&amp;th=1&amp;psc=1&amp;ascsubtag=rss" data-vendor-api="amazon" data-vars-product-price="309,99 €" data-vars-product-vendor="Amazon" aria-label="Deal anschauen bei Amazon für 309,99 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/24204.png" alt="coolblue" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>317,90 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=yqp1z4psAAsRDMrEUYsO-k9BllzVCQG-wy7LvvFpNjQ5p11Pk4U7aVBOpvFgJYkk4kZKpwcYI7dOMwAcDUtQQJeNGuJzyNXcWrD5Eb6aXaxgTOX2NA30Aw&amp;mid=564277510513&amp;id=564277510513&amp;ts=20260520&amp;log=rss" data-vars-product-name="AVM Fritzbox 5690 Pro" data-vars-product-id="2405101" data-vars-category="Networking" data-vars-manufacturer-id="21582" data-vars-manufacturer="AVM" data-vars-vendor="billiger,gtin,amazon,mpn," data-vars-po="billiger,gtin,amazon,mpn" data-product="2405101" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=yqp1z4psAAsRDMrEUYsO-k9BllzVCQG-wy7LvvFpNjQ5p11Pk4U7aVBOpvFgJYkk4kZKpwcYI7dOMwAcDUtQQJeNGuJzyNXcWrD5Eb6aXaxgTOX2NA30Aw&amp;mid=564277510513&amp;id=564277510513&amp;ts=20260520&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="317,90 €" data-vars-product-vendor="coolblue" aria-label="Deal anschauen bei coolblue für 317,90 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/30167.png" alt="e-tec" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>329,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=Pxst9RwFb3sgFdiMIpCMzMt9j_8TwO0ub7nY_gEpKI5CgObUJArBEj_NYWZJZdx_FvUkBdykefIcugqDa2Db6bgTcnV5FGryGrD5Eb6aXaxgTOX2NA30Aw&amp;mid=671474524603&amp;id=671474524603&amp;ts=20260520&amp;log=rss" data-vars-product-name="AVM Fritzbox 5690 Pro" data-vars-product-id="2405101" data-vars-category="Networking" data-vars-manufacturer-id="21582" data-vars-manufacturer="AVM" data-vars-vendor="billiger,gtin,amazon,mpn," data-vars-po="billiger,gtin,amazon,mpn" data-product="2405101" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=Pxst9RwFb3sgFdiMIpCMzMt9j_8TwO0ub7nY_gEpKI5CgObUJArBEj_NYWZJZdx_FvUkBdykefIcugqDa2Db6bgTcnV5FGryGrD5Eb6aXaxgTOX2NA30Aw&amp;mid=671474524603&amp;id=671474524603&amp;ts=20260520&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="329,00 €" data-vars-product-vendor="e-tec" aria-label="Deal anschauen bei e-tec für 329,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/4541.png" alt="notebooksbilliger" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>329,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=0RYVsWIQcaZf7aDQSDOyE5H3DoUGjzQABq5LL3gM66IZGHiWoRPBpxmBykCtd_bvlvUkBdykefIcugqDa2Db6ZxmbS2sJ7y6o-DBcFDt3iDXHrVDtZ40WvfArEpuTJZxA&amp;mid=370318412784&amp;id=370318412784&amp;ts=20260520&amp;log=rss" data-vars-product-name="AVM Fritzbox 5690 Pro" data-vars-product-id="2405101" data-vars-category="Networking" data-vars-manufacturer-id="21582" data-vars-manufacturer="AVM" data-vars-vendor="billiger,gtin,amazon,mpn," data-vars-po="billiger,gtin,amazon,mpn" data-product="2405101" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=0RYVsWIQcaZf7aDQSDOyE5H3DoUGjzQABq5LL3gM66IZGHiWoRPBpxmBykCtd_bvlvUkBdykefIcugqDa2Db6ZxmbS2sJ7y6o-DBcFDt3iDXHrVDtZ40WvfArEpuTJZxA&amp;mid=370318412784&amp;id=370318412784&amp;ts=20260520&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="329,00 €" data-vars-product-vendor="notebooksbilliger" aria-label="Deal anschauen bei notebooksbilliger für 329,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__hidden-records-wrapper">
									<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/29931.png" alt="Tronyq" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>340,16 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=YIkHIJQ6GUSgFdiMIpCMzMgIXR9dBiDcKVI920OwGxfE1egQ3hdWilVOWy8Jyv08VvUkBdykefIrPbr6v5nlNPp0oEiJorkUzgpcsMoguwOrThlSymd6ezUuDccGN5haw&amp;mid=591630586698&amp;id=591630586698&amp;ts=20260520&amp;log=rss" data-vars-product-name="AVM Fritzbox 5690 Pro" data-vars-product-id="2405101" data-vars-category="Networking" data-vars-manufacturer-id="21582" data-vars-manufacturer="AVM" data-vars-vendor="billiger,gtin,amazon,mpn," data-vars-po="billiger,gtin,amazon,mpn" data-product="2405101" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=YIkHIJQ6GUSgFdiMIpCMzMgIXR9dBiDcKVI920OwGxfE1egQ3hdWilVOWy8Jyv08VvUkBdykefIrPbr6v5nlNPp0oEiJorkUzgpcsMoguwOrThlSymd6ezUuDccGN5haw&amp;mid=591630586698&amp;id=591630586698&amp;ts=20260520&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="340,16 €" data-vars-product-vendor="Tronyq" aria-label="Deal anschauen bei Tronyq für 340,16 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/5211.png" alt="OTTO Office" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>345,09 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=9nc5shEshLARDMrEUYsO-k9BllzVCQG-3Js6rFMEuqQ5p11Pk4U7aWOx6jC8C2nRlKfpa4qJRMyQbfXS4HUTmtC0E1HUKv6j1xV5uTwSyKHpWzrWr436i1DLLGalWtKWtHSaj7v6ObKkU7J3KOiD8s&amp;mid=423795873405&amp;id=423795873405&amp;ts=20260520&amp;log=rss" data-vars-product-name="AVM Fritzbox 5690 Pro" data-vars-product-id="2405101" data-vars-category="Networking" data-vars-manufacturer-id="21582" data-vars-manufacturer="AVM" data-vars-vendor="billiger,gtin,amazon,mpn," data-vars-po="billiger,gtin,amazon,mpn" data-product="2405101" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=9nc5shEshLARDMrEUYsO-k9BllzVCQG-3Js6rFMEuqQ5p11Pk4U7aWOx6jC8C2nRlKfpa4qJRMyQbfXS4HUTmtC0E1HUKv6j1xV5uTwSyKHpWzrWr436i1DLLGalWtKWtHSaj7v6ObKkU7J3KOiD8s&amp;mid=423795873405&amp;id=423795873405&amp;ts=20260520&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="345,09 €" data-vars-product-vendor="OTTO Office" aria-label="Deal anschauen bei OTTO Office für 345,09 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/3667.png" alt="OTTO" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>364,19 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=Vzqas_VdPAzVf28VzW0Dp4eF8ZBoGX1q15A8xTAzRoo1g7_hVoNHUkNR6XImhoGB4kZKpwcYI7dOMwAcDUtQQKm4kb0Jb4apXAUVhmKth6ReHZKkYGV-fKhsJep0H4bTOIuly3sYmy1&amp;mid=686037836840&amp;id=686037836840&amp;ts=20260520&amp;log=rss" data-vars-product-name="AVM Fritzbox 5690 Pro" data-vars-product-id="2405101" data-vars-category="Networking" data-vars-manufacturer-id="21582" data-vars-manufacturer="AVM" data-vars-vendor="billiger,gtin,amazon,mpn," data-vars-po="billiger,gtin,amazon,mpn" data-product="2405101" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=Vzqas_VdPAzVf28VzW0Dp4eF8ZBoGX1q15A8xTAzRoo1g7_hVoNHUkNR6XImhoGB4kZKpwcYI7dOMwAcDUtQQKm4kb0Jb4apXAUVhmKth6ReHZKkYGV-fKhsJep0H4bTOIuly3sYmy1&amp;mid=686037836840&amp;id=686037836840&amp;ts=20260520&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="364,19 €" data-vars-product-vendor="OTTO" aria-label="Deal anschauen bei OTTO für 364,19 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
						
									</div>
									<div class="price-comparison__record price-comparison__record--footer">
					<span class="price-comparison__footer-text">
													Preisvergleich (über 24.000 Shops weltweit)												</span>
											<button class="price-comparison__view-more-button">
							Weitere Angebote						</button>
									</div>
		</div>

		<div class="refurbished_products_tab tabcontent">
			<div class="refurbished-padding price-comparison__record price-comparison__record--header">
				<div>
					<span>Produkt</span>
				</div>
				<div class="price-comparison__price">
					<span>Preis</span>
				</div>
			</div>
							<div class="price-comparison__record price-comparison__record--footer">
					<span class="price-comparison__footer-text">
					Preisvergleich von Backmarket						</span>
									</div>
		</div>
		</div>
		


<h2 class="wp-block-heading">Fritzfon X6 (weiß oder schwarz)</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a0d5c2f18e9a"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/02/Fritzfon-X6-AVM.jpg?quality=50&amp;strip=all&amp;w=542" alt="Fritzfon X6 " class="wp-image-3054894" width="542" height="1199" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">AVM</p></div>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn shopping-cart-icon-white link-6-button" href="https://www.amazon.de/dp/B0CCRYQV63?tag=pcwelt.de-21&amp;ascsubtag=4-0-3127694-7-0-0-0-0&amp;ascsubtag=rss" target="_blank" rel="nofollow" data-vars-link-position="CTA Button" data-domain-name="amazon" data-subtag="4-0-3127694-7-0-0-0-0">Fritzfon X6 bei Amazon ansehen</a></div>


<p>Preis: rund 84 Euro</p>



<p><strong>Technik:</strong></p>



<ul class="wp-block-list">
<li>Hochwertiges 2,4-Zoll-Farbdisplay</li>



<li>HD-Telefonie und Full-Duplex-Freisprechen</li>



<li>Bis zu 16 Stunden Gesprächszeit / 10 Tage Stand-by</li>



<li>Integrierte Steuerung für Smart-Home-Anwendungen</li>



<li>Unterstützung für E-Mails, Webradio, Podcasts und Babyfon-Funktion</li>



<li>Helligkeits- und Bewegungssensor für das Display</li>



<li>Regelmäßige Sicherheits-Updates per Tastendruck</li>



<li>Frei belegbare Favoritentaste für Schnellzugriff</li>
</ul>



<p>Das <a href="https://www.amazon.de/dp/B0CCRYQV63?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Fritzfon X6</a> dient als direkte Schnittstelle zur Fritzbox und übernimmt Aufgaben, die weit über einfaches Telefonieren hinausgehen. Per Menü lassen sich WLAN-Schaltungen vornehmen, Smart-Home-Komponenten steuern oder die Wiedergabe des Mediaservers verwalten. Das Farbdisplay zeigt zudem Informationen wie Wetterdaten oder das <a href="https://www.pcwelt.de/article/2990258/fritzbox-tuersprechanlage-einrichten-how-to.html" target="_blank" rel="noreferrer noopener">Live-Bild einer kompatiblen Türsprechanlage</a> an.</p>



<p>Durch die nahtlose Integration in das Fritz-System können Telefonbücher und Anrufbeantworter der Box direkt genutzt werden. Das vereinfacht die Einrichtung im Vergleich zu herkömmlichen DECT-Telefonen anderer Hersteller erheblich.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h2 class="wp-block-heading">Asus Tri-Band Wi-Fi 7 USB-Adapter (ROG USB-BE92 BE6500)</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a0d5c2f1985b"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/04/Asus-Tri-Band-WiFi-7-USB-Adapter-ROG-USB-BE92-BE6500.jpg?quality=50&amp;strip=all&amp;w=394" alt="Asus Tri-Band WiFi 7 USB-Adapter (ROG USB-BE92 BE6500)" class="wp-image-3127831" width="394" height="1201" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Amazon/Asus</p></div>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn shopping-cart-icon-white link-6-button" href="https://www.amazon.de/dp/B09LCG53HN?tag=pcwelt.de-21&amp;ascsubtag=4-0-3127694-7-0-0-0-0&amp;ascsubtag=rss" target="_blank" rel="nofollow" data-vars-link-position="CTA Button" data-domain-name="amazon" data-subtag="4-0-3127694-7-0-0-0-0">Asus Tri-Band Wi-Fi 7 USB-Adapter bei Amazon ansehen</a></div>


<p>Preis: 73 Euro</p>



<p><strong>Technik:</strong></p>



<ul class="wp-block-list">
<li>Standard: Wi-Fi 7 (802.11be)</li>



<li>Frequenzbänder: Tri-Band (2,4 GHz, 5 GHz und 6 GHz)</li>



<li>Geschwindigkeit: Bis zu 6.500 Mbit/s Gesamtdatendurchsatz</li>



<li>Kanalbreite: 160 MHz im 6-GHz-Band</li>



<li>Funktionen: Multi-Link Operation (MLO) und 4K-QAM</li>



<li>Anschlüsse: Kompatibel mit USB-Typ-A und Typ-C</li>



<li>Sicherheit: Unterstützt das aktuelle WPA3-Protokoll</li>



<li>Extras: Unterstützung für OFDMA und MU-MIMO</li>
</ul>



<p>Die ersten Fritzbox-Modelle mit Wi-Fi 7 sind bereits auf dem Markt, dieser USB-Adapter stellt dabei die notwendige Brücke zum PC oder Laptop her. Während viele integrierte WLAN-Karten noch auf älteren Standards funken, ermöglicht der Adapter die Nutzung des störungsarmen 6-GHz-Bandes. Besonders in dicht besiedelten Gebieten mit vielen konkurrierenden Funknetzen sorgt das für eine stabilere Verbindung und geringere Latenzen.</p>



<p>Durch die Unterstützung von USB-A- und USB-C-Anschlüssen lässt sich der Stick flexibel an verschiedenen Hardware-Generationen betreiben, um die hohen Bandbreiten moderner Glasfaser-Anschlüsse auch drahtlos am Endgerät zu empfangen.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h2 class="wp-block-heading">Crucial X9 1 TB Externe SSD</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a0d5c2f1a179"}' data-wp-interactive="core/image" class="wp-block-image size-full is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/04/Crucial-X9-1TB-Externe-SSD-Festplatte.jpg?quality=50&amp;strip=all" alt="Crucial X9 1TB Externe SSD Festplatte" class="wp-image-3127836" width="676" height="601" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Crucial </p></div>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn shopping-cart-icon-white link-6-button" href="https://www.amazon.de/dp/B0CGW1FQV4?tag=pcwelt.de-21&amp;ascsubtag=4-0-3127694-7-0-0-0-0&amp;ascsubtag=rss" target="_blank" rel="nofollow" data-vars-link-position="CTA Button" data-domain-name="amazon" data-subtag="4-0-3127694-7-0-0-0-0">Crucial X9 1 TB Externe SSD bei Amazon ansehen</a></div>


<p>Preis: 140 Euro</p>



<p><strong>Technik:</strong></p>



<ul class="wp-block-list">
<li>Kapazität: 1 TB (auch bis 4 TB erhältlich)</li>



<li>Schnittstelle: USB-C 3.2 (kompatibel mit USB-A via Adapter)</li>



<li>Geschwindigkeit: Bis zu 1.050 MB/s Leserate</li>



<li>Robustheit: Stoß-, vibrations- und sturzsicher bis 2 Meter Höhe</li>



<li>Dateisystem-Support: Windows Dateiversionsverlauf, Apple Time Machine</li>



<li>Abmessungen: Sehr kompaktes Gehäusedesign (Portable SSD)</li>



<li>Software: Kostenfreie Testzeiträume für Adobe Acrobat Pro und Mylio Photos+ bei Registrierung</li>
</ul>



<p>Eine externe SSD wie die <a href="https://www.amazon.de/dp/B0CGW1FQV4?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Crucial X9</a> erweitert Ihre Fritzbox um einen einfachen Netzwerkspeicher (Fritz NAS). Selbst bei Top-Modellen wie der <a href="https://www.amazon.de/dp/B0D8JCN5P4?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">5690 Pro</a> bremst die Prozessorleistung des Routers die enorme theoretische Geschwindigkeit der SSD (über 1.000 MB/s) zwar aus, dennoch ist die Kombination für den Alltag ideal: Der Datentransfer ist deutlich flotter als mit alten USB-Sticks, die SSD arbeitet lautlos und verbraucht wenig Energie. Es ist also eine geschickte Lösung, um Fotos oder Dokumente zentral im Heimnetz zu sichern und verfügbar zu machen.</p>



<p><strong>Wichtig:</strong> Vor dem Kauf sollten Sie prüfen, ob Ihre Fritzbox über einen USB-3.0-Anschluss verfügt. Einsteiger-Modelle wie die <a href="http://www.amazon.de/dp/B09N8NJD66?tag=pcwelt.de-21&amp;ascsubtag=rss">Fritzbox 7510</a> bieten oft nur langsames USB 2.0, während Varianten ohne USB-Port gar nicht als Netzwerkspeicher genutzt werden können.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h2 class="wp-block-heading">Fritz Smart Thermo 302</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a0d5c2f1aafc"}' data-wp-interactive="core/image" class="wp-block-image size-full is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/11/NL_18_FRITZDECT302.jpg?quality=50&amp;strip=all" alt="FRITZ!DECT 302 Heizkörperregler" class="wp-image-2992300" width="600" height="400" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">FRITZ!</p></div>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn shopping-cart-icon-white link-6-button" href="https://www.amazon.de/dp/B0G2T5J493?tag=pcwelt.de-21&amp;ascsubtag=4-0-3127694-7-0-0-0-0&amp;ascsubtag=rss" target="_blank" rel="nofollow" data-vars-link-position="CTA Button" data-domain-name="amazon" data-subtag="4-0-3127694-7-0-0-0-0">Fritz Smart Thermo 302 bei Amazon ansehen</a></div>


<p>Preis: 69 Euro</p>



<p><strong>Technik:</strong></p>



<ul class="wp-block-list">
<li>Display: Kontraststarkes und drehbares E-Paper-Display</li>



<li>Funkstandard: DECT ULE (Reichweite bis zu 40 Meter)</li>



<li>Funktionen: Fenster-auf-Erkennung, Frostschutz, Kalkschutz, Boost-Modus</li>



<li>Bedienung: Tasten am Gerät, App, PC oder Fritzfon</li>



<li>Montage: Kompatibel mit gängigen Ventilen (M30x1,5), Adapter inklusive</li>



<li>Extras: Gruppenschaltung, individuelle Heizprofile, Urlaubsmodus</li>



<li>Energie: Betrieb über zwei AA-Batterien</li>
</ul>



<p>Der <a href="https://www.amazon.de/dp/B0G2T5J493?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Fritz Smart Thermo 302</a> macht die Heizung zum Teil des Heimnetzes und ermöglicht eine zeitgesteuerte Regulierung der Raumtemperatur. Die Einrichtung erfolgt direkt über die Fritzbox, wobei für jeden Wochentag individuelle Heiz- und Absenkphasen festgelegt werden können. Ein klarer Vorteil gegenüber WLAN-Lösungen ist dabei der sparsame DECT-Funk, der lange Batterielaufzeiten ermöglicht.</p>



<p>Weil der Regler die Fenster-offen-Erkennung direkt integriert hat, regelt er die Temperatur bei plötzlichem Abfall automatisch herunter, um Energie zu sparen. Besonders komfortabel ist die Steuerung per Fritzfon oder eine Gruppenschaltung, bei der mehrere Heizkörper synchron auf eine Zieltemperatur eingestellt werden.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h2 class="wp-block-heading">Fritz-Repeater 6000 (Wi-Fi 6)</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a0d5c2f1b46b"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/04/Fritz-Repeater-6000-WiFi-6.jpg?quality=50&amp;strip=all&amp;w=836" alt="Fritz-Repeater 6000 (WiFi 6)" class="wp-image-3127844" width="836" height="1200" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">FRITZ!</p></div>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn shopping-cart-icon-white link-6-button" href="https://www.amazon.de/dp/B092VWMBZ2?tag=pcwelt.de-21&amp;ascsubtag=4-0-3127694-7-0-0-0-0&amp;ascsubtag=rss" target="_blank" rel="nofollow" data-vars-link-position="CTA Button" data-domain-name="amazon" data-subtag="4-0-3127694-7-0-0-0-0">Fritz-Repeater 6000 (Wi-Fi 6) bei Amazon ansehen</a></div>


<p>Preis: 260 Euro</p>



<p><strong>Technik:</strong></p>



<ul class="wp-block-list">
<li>Standard: Wi-Fi 6 (WLAN AX)</li>



<li>Funkeinheiten: Drei (Triband-Technologie)</li>



<li>Geschwindigkeit: Bis zu 6.000 MBit/s (2.400 + 2.400 + 1.200 MBit/s)</li>



<li>Anschlüsse: 1x 2,5-Gigabit-LAN, 1x Gigabit-LAN</li>



<li>Funktionen: WLAN Mesh, intelligente Bandauswahl, WPS-Einrichtung</li>



<li>Sicherheit: WPA3-Verschlüsselung integriert</li>



<li>Bauweise: Standgerät mit externem Netzteil</li>
</ul>



<p>Der <a href="https://www.amazon.de/dp/B092VWMBZ2?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Fritz-Repeater 6000</a> ist das aktuell leistungsstärkste Modell im Fritz-Sortiment für Nutzer, die große Wohnflächen oder mehrere Etagen mit schnellem WLAN versorgen möchten (zumindest, <a href="https://www.pcwelt.de/article/3071845/fritz-schnellster-wlan-repeater-6700-pro-wifi-7-router-mwc-2026.html" target="_blank" rel="noreferrer noopener">bis der neue 6700 Pro in die Regale kommt</a>). Dank seiner drei Funkeinheiten steht hier ein eigenes Band exklusiv für die Kommunikation zwischen Router und Repeater zur Verfügung – der sonst übliche Geschwindigkeitsverlust wird dadurch halbiert.</p>



<p>Auch der 2,5-Gigabit-LAN-Port ist vorteilhaft: Er ermöglicht es, den Repeater per Kabel als schnellen Zugangspunkt (LAN-Brücke) zu nutzen oder datenhungrige Geräte wie Spielekonsolen oder PCs stabil anzubinden. Im Zusammenspiel mit einer <a href="https://www.pcwelt.de/article/1157690/fritzbox-router-im-vergleich-das-beste-modell.html" target="_blank" rel="noreferrer noopener">Fritzbox</a> bildet er ein nahtloses Mesh-Netzwerk, bei dem mobile Endgeräte automatisch immer mit dem stärksten Zugangspunkt verbunden werden.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h2 class="wp-block-heading">Fritz Smart Control 350 (magnetischer Tür-/Fensterkontakt)</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a0d5c2f1bd38"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/04/Fritz-Smart-Control-350.jpg?quality=50&amp;strip=all&amp;w=699" alt="Fritz Smart Control 350" class="wp-image-3127848" width="699" height="1200" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">FRITZ!</p></div>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn shopping-cart-icon-white link-6-button" href="https://www.amazon.de/dp/B0GHS4SMCJ?tag=pcwelt.de-21&amp;ascsubtag=4-0-3127694-7-0-0-0-0&amp;ascsubtag=rss" target="_blank" rel="nofollow" data-vars-link-position="CTA Button" data-domain-name="amazon" data-subtag="4-0-3127694-7-0-0-0-0">Fritz Smart Control 350 bei Amazon ansehen</a></div>


<p>Preis: 40 Euro</p>



<p><strong>Technik:</strong></p>



<ul class="wp-block-list">
<li>Typ: Magnetischer Sensor (zweiteilig: Sensor und Magnet)</li>



<li>Funkstandard: DECT ULE</li>



<li>Erkennung: Geöffnet, geschlossen oder gekippt (je nach Montage)</li>



<li>Montage: Klebestreifen für Rahmen oder Flügel</li>



<li>Energie: Betrieb mit 2x AAA-Batterien</li>



<li>Reichweite: Bis zu 40 Meter im Haus</li>



<li>Kompatibilität: Alle Fritzbox-Modelle mit DECT-Basis</li>
</ul>



<p>Mit dem <a href="https://www.amazon.de/dp/B0GHS4SMCJ?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Fritz Smart Control 350</a> verkauft Fritz einen dezenten Sensor, der den Status von Fenstern und Türen überwacht und diese Information an die Fritzbox weitergibt. Er dient als optimaler Partner für die smarten Heizkörperregler: Erkennt der Sensor ein offenes Fenster, kann die Heizung im jeweiligen Raum sofort automatisch heruntergeregelt werden. Das funktioniert effektiver als die rein temperaturbasierte Erkennung eines Thermostats.</p>



<p>Durch die kompakte Bauweise lässt sich der Magnet oft so im Rahmen montieren, dass er bei geschlossenem Fenster fast unsichtbar bleibt. Neben der Heizungssteuerung lassen sich auch einfache Sicherheits-Szenarien oder Push-Nachrichten aufs Smartphone einrichten, sobald eine Tür unbefugt geöffnet wird.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h2 class="wp-block-heading">Fritz DECT 210</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a0d5c2f1c79b"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/04/Fritz-Dect-210.jpg?quality=50&amp;strip=all&amp;w=831" alt="Fritz Dect 210" class="wp-image-3127852" width="831" height="1200" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">FRITZ!</p></div>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn shopping-cart-icon-white link-6-button" href="https://www.amazon.de/dp/B01MRZ60F0?tag=pcwelt.de-21&amp;ascsubtag=4-0-3127694-7-0-0-0-0&amp;ascsubtag=rss" target="_blank" rel="nofollow" data-vars-link-position="CTA Button" data-domain-name="amazon" data-subtag="4-0-3127694-7-0-0-0-0">Fritz DECT 210 bei Amazon ansehen</a></div>


<p>Preis: 42 Euro</p>



<p><strong>Technik:</strong></p>



<ul class="wp-block-list">
<li>Typ: Intelligente Steckdose für den Außenbereich</li>



<li>Schutzart: Spritzwasserschutz nach IP44</li>



<li>Belastbarkeit: Schaltet Geräte bis zu 3.450 Watt</li>



<li>Funkstandard: DECT ULE (Reichweite bis zu 300 Meter im Freien)</li>



<li>Funktionen: Messung von Energieverbrauch, Temperatur und Leistung</li>



<li>Schaltmodi: Zeitplan, Sonnenauf-/untergang, Google-Kalender, Zufall</li>



<li>Bedienung: App, Fritzfon, PC oder direkt am Gerät</li>
</ul>



<p>Smarte Funktionen im Garten, auf dem Balkon oder in der Garage: Die <a href="https://www.amazon.de/dp/B01MRZ60F0?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Fritz DECT 210</a> macht’s möglich. Dank des robusten Gehäuses inklusive Schutzklappe ist sie gegen Spritzwasser geschützt und hält auch wechselnden Temperaturen stand. Über die Fritzbox lässt sich die Steckdose schalten und als Energiemessgerät nutzen: Sie zeichnet den Stromverbrauch angeschlossener Geräte auf und wertet diesen in einer übersichtlichen Grafik aus.</p>



<p>Besonders praktisch für den Außenbereich ist die Astro-Funktion, die beispielsweise die Gartenbeleuchtung pünktlich zum Sonnenuntergang automatisch einschaltet, ohne dass man die Zeiten manuell nachjustieren muss.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h2 class="wp-block-heading">Fritz DECT-Repeater 100</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a0d5c2f1d212"}' data-wp-interactive="core/image" class="wp-block-image size-full is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/04/Fritz-DECT-Repeater-100.jpg?quality=50&amp;strip=all" alt="Fritz-DECT-Repeater 100" class="wp-image-3127854" width="665" height="821" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">FRITZ!</p></div>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn shopping-cart-icon-white link-6-button" href="https://www.amazon.de/dp/B00AQ9A9AQ?tag=pcwelt.de-21&amp;ascsubtag=4-0-3127694-7-0-0-0-0&amp;ascsubtag=rss" target="_blank" rel="nofollow" data-vars-link-position="CTA Button" data-domain-name="amazon" data-subtag="4-0-3127694-7-0-0-0-0">Fritz DECT-Repeater 100 bei Amazon ansehen</a></div>


<p>Preis:  78 Euro</p>



<p><strong>Technik:</strong></p>



<ul class="wp-block-list">
<li>Typ: Reichweitenverstärker für den DECT-Funk</li>



<li>Kapazität: Unterstützt bis zu drei Gespräche gleichzeitig</li>



<li>Funktionen: Überträgt HD-Telefonie, Internetradio und Podcasts</li>



<li>Sicherheit: Integrierte DECT-Verschlüsselung für abhörsichere Gespräche</li>



<li>Kompatibilität: Alle Fritzbox-Modelle mit DECT-Basis sowie GAP-Basistationen</li>



<li>Besonderheit: Integrierte Steckdose (kein Steckplatz geht verloren)</li>



<li>Einrichtung: Einfache Anmeldung per Tastendruck (WPS/DECT-Taste)</li>
</ul>



<p>Mit dem <a href="https://www.amazon.de/dp/B00AQ9A9AQ?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Fritz DECT-Repeater 100</a> gibt es eine Lösung für Haushalte, in denen das Funksignal des Telefons nicht bis in die letzte Ecke oder über mehrere Etagen reicht. Im Gegensatz zu einfachen Verstärkern unterstützt dieses Gerät bei Verbindung mit einer Fritzbox den vollen Funktionsumfang: Auch weit entfernt von der Basis bleiben HD-Telefonie, RSS-Feeds oder der Empfang von E-Mails am Fritzfon stabil.</p>



<p>Ebenfalls praktisch: das Gerät verfügt über eine integrierte Steckdose, damit steht der Anschluss an der Wand weiterhin für andere Elektrogeräte bereit. Durch die Unterstützung von automatischem Handover merkt man den Wechsel zwischen Basis und Repeater während eines Telefonats gar nicht.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h2 class="wp-block-heading">Fritz Smart Energy 250</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a0d5c2f1dbbe"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/04/Fritz-Smart-Energy-250.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Fritz Smart Energy 250" class="wp-image-3127856" width="1200" height="1200" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">FRITZ!</p></div>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn shopping-cart-icon-white link-6-button" href="https://www.amazon.de/dp/B0F1TNPHP4?tag=pcwelt.de-21&amp;ascsubtag=4-0-3127694-7-0-0-0-0&amp;ascsubtag=rss" target="_blank" rel="nofollow" data-vars-link-position="CTA Button" data-domain-name="amazon" data-subtag="4-0-3127694-7-0-0-0-0">Fritz Smart Energy 250 bei Amazon ansehen</a></div>


<p>Preis:  70 Euro</p>



<p><strong>Technik:</strong></p>



<ul class="wp-block-list">
<li>Typ: Intelligenter Stromsensor (Infrarot-Ausleseeinheit)</li>



<li>Schnittstelle: Magnetische Befestigung an der INFO-Schnittstelle</li>



<li>Funkstandard: DECT ULE</li>



<li>Stromversorgung: 2x AA-Batterien oder via USB-Anschluss</li>



<li>Kompatibilität: Für die meisten digitalen Stromzähler (Infrarot-Schnittstelle)</li>



<li>Auswertung: Fritz-App Smart Home, FritzOS oder Myfritz-Net</li>



<li>Features: Echtzeit-Verbrauchsdaten, historische Auswertung, Auslöser für Automationen</li>
</ul>



<p>Wer sich mehr Transparenz beim Stromverbrauch im ganzen Haushalt wünscht, greift zum <a href="https://www.amazon.de/dp/B0F1TNPHP4?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Fritz Smart Energy 250</a>. Anstatt manuell und mühsam den Zählerstand zu notieren, liest dieser Sensor die Daten direkt am digitalen Stromzähler aus und überträgt sie per Funk an die Fritzbox. Dadurch lässt sich der aktuelle Stromverbrauch jederzeit per App kontrollieren. Versteckten Energiefressern kommen Sie so besonders schnell auf die Schliche.</p>



<p>Besonders interessant für Smart-Home-Nutzer: Die gemessenen Werte können als Auslöser für verschiedene Szenarien dienen – so lässt sich beispielsweise eine Benachrichtigung einrichten, wenn die Leistungsaufnahme einen bestimmten Wert überschreitet.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h2 class="wp-block-heading">Fritz Powerline 1260</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a0d5c2f1e3e9"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/04/Fritz-Powerline-1260-Single-Adapter.jpg?quality=50&amp;strip=all&amp;w=679" alt="Fritz Powerline 1260 Single-Adapter" class="wp-image-3127861" width="679" height="1199" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">FRITZ!</p></div>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn shopping-cart-icon-white link-6-button" href="https://www.amazon.de/dp/B0752S866W?tag=pcwelt.de-21&amp;ascsubtag=4-0-3127694-7-0-0-0-0&amp;ascsubtag=rss" target="_blank" rel="nofollow" data-vars-link-position="CTA Button" data-domain-name="amazon" data-subtag="4-0-3127694-7-0-0-0-0">Fritz Powerline 1260 bei Amazon ansehen</a></div>


<p>Preis: 105 Euro</p>



<p><strong>Technik:</strong></p>



<ul class="wp-block-list">
<li>Typ: Powerline-Einzeladapter mit WLAN-Funktion</li>



<li>Geschwindigkeit (Stromnetz): Bis zu 1.200 MBit/s</li>



<li>WLAN: Dualband AC+N (bis zu 866 + 400 MBit/s)</li>



<li>Anschluss: 1x Gigabit-LAN-Port</li>



<li>Technologie: 2×2 MIMO (nutzt zwei Adernpaare im Stromnetz)</li>



<li>Sicherheit: WPA2-Verschlüsselung und ab Werk verschlüsselte Powerline-Verbindung</li>



<li>Mesh-Unterstützung: Automatische Übernahme der WLAN-Einstellungen der Fritzbox</li>
</ul>



<p><a href="https://www.amazon.de/dp/B0752S866W?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Fritz Powerline 1260</a> ist der Problemlöser für Räume, in denen weder WLAN-Signale noch Netzwerkkabel ankommen. Weil Daten damit über die Stromleitung transportiert werden, lassen sich selbst massive Wände oder weite Strecken zum Keller oder Dachboden überbrücken. An der Zielsteckdose fungiert der Adapter gleichzeitig als LAN-Anschluss für Geräte wie Smart-TVs oder Spielekonsolen und als WLAN-Access-Point. Innerhalb eines Fritz-Heimnetzes integriert er sich nahtlos in das Mesh-System, sodass mobile Geräte ohne Verbindungsabbruch zwischen Router und Powerline-Adapter wechseln können.</p>



<p><strong>Hinweis:</strong> Da es sich hier um einen Einzeladapter handelt, wird für den Aufbau eines Powerline-Netzwerks ein zweites Gegenstück (ein weiterer Powerline-Adapter) benötigt, das per LAN-Kabel mit der Fritzbox verbunden ist.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-4317 | Umami Software application 3.0.2 Request Parameter prisma.rawQuery/prisma.queryRawUnsafe sql injection]]></title>
<description><![CDATA[A vulnerability has been found in Umami Software application 3.0.2 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Request Parameter Handler. This manipulation of the argument prisma.rawQuery/prisma.queryRawUnsafe causes sql injection.

This...]]></description>
<link>https://tsecurity.de/de/3531220/sicherheitsluecken/cve-2026-4317-umami-software-application-302-request-parameter-prismarawqueryprismaqueryrawunsafe-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3531220/sicherheitsluecken/cve-2026-4317-umami-software-application-302-request-parameter-prismarawqueryprismaqueryrawunsafe-sql-injection/</guid>
<pubDate>Wed, 20 May 2026 02:50:21 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/umami_software_application">Umami Software application 3.0.2</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. Affected by this vulnerability is an unknown functionality of the component <em>Request Parameter Handler</em>. This manipulation of the argument <em>prisma.rawQuery/prisma.queryRawUnsafe</em> causes sql injection.

This vulnerability appears as <a href="https://vuldb.com/cve/CVE-2026-4317">CVE-2026-4317</a>. The attack may be initiated remotely. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[Das beste Zubehör für die Fritzbox: 10 Upgrades für maximalen Speed und Komfort]]></title>
<description><![CDATA[Die Fritzbox ist das Herzstück eines digitalen Zuhauses, ihr volles Potenzial lassen viele aber ungenutzt. Wer lediglich surft und telefoniert, verschenkt wertvolle Möglichkeiten in Sachen Reichweite, Stromersparnis und Komfort. Erst mit dem richtigen Zubehör wird die Box zur Schaltzentrale, die ...]]></description>
<link>https://tsecurity.de/de/3528026/it-nachrichten/das-beste-zubehoer-fuer-die-fritzbox-10-upgrades-fuer-maximalen-speed-und-komfort/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3528026/it-nachrichten/das-beste-zubehoer-fuer-die-fritzbox-10-upgrades-fuer-maximalen-speed-und-komfort/</guid>
<pubDate>Tue, 19 May 2026 08:47:17 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Die <a href="https://www.pcwelt.de/article/1157690/fritzbox-router-im-vergleich-das-beste-modell.html" target="_blank" rel="noreferrer noopener">Fritzbox</a> ist das Herzstück eines digitalen Zuhauses, ihr volles Potenzial lassen viele aber ungenutzt. Wer lediglich surft und telefoniert, verschenkt wertvolle Möglichkeiten in Sachen Reichweite, Stromersparnis und Komfort. Erst mit dem richtigen Zubehör wird die Box zur Schaltzentrale, die nicht nur Daten überträgt, sondern auch den Alltag spürbar erleichtert – von der automatisierten Heizungssteuerung bis zum blitzschnellen Datentransfer im ganzen Haus.</p>



<p>Wenn Sie bereits einen Router von Fritz (<a href="https://www.pcwelt.de/article/1157690/fritzbox-router-im-vergleich-das-beste-modell.html" target="_blank" rel="noreferrer noopener">hier finden Sie unsere Bestenliste</a>) im Einsatz haben, merken Sie mit dem richtigen Zubehör sofort: Wenn Hardware und Peripherie Hand in Hand gehen, wird aus einem einfachen Internet-Anschluss ein nahtloses Ökosystem. Für den Alltag heißt das: Mehr Speed, mehr Effizienz und spürbare Komfort-Upgrades.</p>



<p>In unserem Zubehör-Ratgeber zeigen wir Ihnen zehn essenzielle Upgrades, mit denen Sie Ihr Heimnetzwerk auf das nächste Level heben.</p>



<p><strong>Tipp:</strong> Wenn Sie noch keine Fritzbox im Einsatz haben oder aktuell noch DSL nutzen, aber demnächst auf Glasfaser umsteigen möchten, dann lohnt sich ein Blick auf die <a href="https://www.amazon.de/dp/B0D8JCN5P4?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Fritzbox 5690 Pro</a>. Sie ist bereits für das neue Wi-Fi 7 gerüstet und spielt in Kombination mit unseren Zubehör-Tipps alle Asse aus.</p>



<p><strong>Aktuell bester Preis: Fritzbox 5690 Pro</strong></p>



				<div class="wp-block-price-comparison price-comparison">
		
		<div class="new_products_tab tabcontent ">

			<div class="price-comparison__record price-comparison__record--header">
				<div>
					<span>Shop</span>
				</div>
								<div class="price-comparison__price">
					<span>Preis</span>
				</div>
			</div>

								<div class="price-comparison__record  amazon_vendor">
						<div class="price-comparison__image">
															<img decoding="async" src="https://www.pcwelt.de/wp-content/themes/idg-base-theme/dist/static/img/amazon-logo.svg" alt="Amazon" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>309,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://www.amazon.de/dp/B0D8JCN5P4?tag=pcwelt.de-21&amp;linkCode=ogi&amp;th=1&amp;psc=1&amp;ascsubtag=rss" data-vars-product-name="AVM Fritzbox 5690 Pro" data-vars-product-id="2405101" data-vars-category="Networking" data-vars-manufacturer-id="21582" data-vars-manufacturer="AVM" data-vars-vendor="billiger,gtin,amazon,mpn," data-vars-po="billiger,gtin,amazon,mpn" data-product="2405101" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://www.amazon.de/dp/B0D8JCN5P4?tag=pcwelt.de-21&amp;linkCode=ogi&amp;th=1&amp;psc=1&amp;ascsubtag=rss" data-vendor-api="amazon" data-vars-product-price="309,00 €" data-vars-product-vendor="Amazon" aria-label="Deal anschauen bei Amazon für 309,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/24204.png" alt="coolblue" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>317,90 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=yqp1z4psAAsRDMrEUYsO-k9BllzVCQG-wy7LvvFpNjQ5p11Pk4U7aVBOpvFgJYkk4kZKpwcYI7dOMwAcDUtQQJeNGuJzyNXcWrD5Eb6aXaxgTOX2NA30Aw&amp;mid=564277510513&amp;id=564277510513&amp;ts=20260519&amp;log=rss" data-vars-product-name="AVM Fritzbox 5690 Pro" data-vars-product-id="2405101" data-vars-category="Networking" data-vars-manufacturer-id="21582" data-vars-manufacturer="AVM" data-vars-vendor="billiger,gtin,amazon,mpn," data-vars-po="billiger,gtin,amazon,mpn" data-product="2405101" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=yqp1z4psAAsRDMrEUYsO-k9BllzVCQG-wy7LvvFpNjQ5p11Pk4U7aVBOpvFgJYkk4kZKpwcYI7dOMwAcDUtQQJeNGuJzyNXcWrD5Eb6aXaxgTOX2NA30Aw&amp;mid=564277510513&amp;id=564277510513&amp;ts=20260519&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="317,90 €" data-vars-product-vendor="coolblue" aria-label="Deal anschauen bei coolblue für 317,90 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/30167.png" alt="e-tec" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>329,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=Pxst9RwFb3sgFdiMIpCMzMt9j_8TwO0ub7nY_gEpKI5CgObUJArBEj_NYWZJZdx_FvUkBdykefIcugqDa2Db6bgTcnV5FGryGrD5Eb6aXaxgTOX2NA30Aw&amp;mid=671474524603&amp;id=671474524603&amp;ts=20260519&amp;log=rss" data-vars-product-name="AVM Fritzbox 5690 Pro" data-vars-product-id="2405101" data-vars-category="Networking" data-vars-manufacturer-id="21582" data-vars-manufacturer="AVM" data-vars-vendor="billiger,gtin,amazon,mpn," data-vars-po="billiger,gtin,amazon,mpn" data-product="2405101" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=Pxst9RwFb3sgFdiMIpCMzMt9j_8TwO0ub7nY_gEpKI5CgObUJArBEj_NYWZJZdx_FvUkBdykefIcugqDa2Db6bgTcnV5FGryGrD5Eb6aXaxgTOX2NA30Aw&amp;mid=671474524603&amp;id=671474524603&amp;ts=20260519&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="329,00 €" data-vars-product-vendor="e-tec" aria-label="Deal anschauen bei e-tec für 329,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/4541.png" alt="notebooksbilliger" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>329,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=0RYVsWIQcaZf7aDQSDOyE5H3DoUGjzQABq5LL3gM66IZGHiWoRPBpxmBykCtd_bvlvUkBdykefIcugqDa2Db6ZxmbS2sJ7y6o-DBcFDt3iDXHrVDtZ40WvfArEpuTJZxA&amp;mid=370318412784&amp;id=370318412784&amp;ts=20260519&amp;log=rss" data-vars-product-name="AVM Fritzbox 5690 Pro" data-vars-product-id="2405101" data-vars-category="Networking" data-vars-manufacturer-id="21582" data-vars-manufacturer="AVM" data-vars-vendor="billiger,gtin,amazon,mpn," data-vars-po="billiger,gtin,amazon,mpn" data-product="2405101" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=0RYVsWIQcaZf7aDQSDOyE5H3DoUGjzQABq5LL3gM66IZGHiWoRPBpxmBykCtd_bvlvUkBdykefIcugqDa2Db6ZxmbS2sJ7y6o-DBcFDt3iDXHrVDtZ40WvfArEpuTJZxA&amp;mid=370318412784&amp;id=370318412784&amp;ts=20260519&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="329,00 €" data-vars-product-vendor="notebooksbilliger" aria-label="Deal anschauen bei notebooksbilliger für 329,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__hidden-records-wrapper">
									<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/29931.png" alt="Tronyq" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>340,15 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=reCIPSDVfqOgFdiMIpCMzMgIXR9dBiDcBEUzqUgSNDwE1egQ3hdWilVOWy8Jyv08VvUkBdykefIrPbr6v5nlNPp0oEiJorkUzgpcsMoguwOrThlSymd6ezUuDccGN5haw&amp;mid=591630586698&amp;id=591630586698&amp;ts=20260519&amp;log=rss" data-vars-product-name="AVM Fritzbox 5690 Pro" data-vars-product-id="2405101" data-vars-category="Networking" data-vars-manufacturer-id="21582" data-vars-manufacturer="AVM" data-vars-vendor="billiger,gtin,amazon,mpn," data-vars-po="billiger,gtin,amazon,mpn" data-product="2405101" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=reCIPSDVfqOgFdiMIpCMzMgIXR9dBiDcBEUzqUgSNDwE1egQ3hdWilVOWy8Jyv08VvUkBdykefIrPbr6v5nlNPp0oEiJorkUzgpcsMoguwOrThlSymd6ezUuDccGN5haw&amp;mid=591630586698&amp;id=591630586698&amp;ts=20260519&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="340,15 €" data-vars-product-vendor="Tronyq" aria-label="Deal anschauen bei Tronyq für 340,15 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/5211.png" alt="OTTO Office" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>345,09 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=9nc5shEshLARDMrEUYsO-k9BllzVCQG-3Js6rFMEuqQ5p11Pk4U7aWOx6jC8C2nRlKfpa4qJRMyQbfXS4HUTmtC0E1HUKv6j1xV5uTwSyKHpWzrWr436i1DLLGalWtKWtHSaj7v6ObKkU7J3KOiD8s&amp;mid=423795873405&amp;id=423795873405&amp;ts=20260519&amp;log=rss" data-vars-product-name="AVM Fritzbox 5690 Pro" data-vars-product-id="2405101" data-vars-category="Networking" data-vars-manufacturer-id="21582" data-vars-manufacturer="AVM" data-vars-vendor="billiger,gtin,amazon,mpn," data-vars-po="billiger,gtin,amazon,mpn" data-product="2405101" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=9nc5shEshLARDMrEUYsO-k9BllzVCQG-3Js6rFMEuqQ5p11Pk4U7aWOx6jC8C2nRlKfpa4qJRMyQbfXS4HUTmtC0E1HUKv6j1xV5uTwSyKHpWzrWr436i1DLLGalWtKWtHSaj7v6ObKkU7J3KOiD8s&amp;mid=423795873405&amp;id=423795873405&amp;ts=20260519&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="345,09 €" data-vars-product-vendor="OTTO Office" aria-label="Deal anschauen bei OTTO Office für 345,09 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/3667.png" alt="OTTO" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>364,19 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=Vzqas_VdPAzVf28VzW0Dp4eF8ZBoGX1q15A8xTAzRoo1g7_hVoNHUkNR6XImhoGB4kZKpwcYI7dOMwAcDUtQQKm4kb0Jb4apXAUVhmKth6ReHZKkYGV-fKhsJep0H4bTOIuly3sYmy1&amp;mid=686037836840&amp;id=686037836840&amp;ts=20260519&amp;log=rss" data-vars-product-name="AVM Fritzbox 5690 Pro" data-vars-product-id="2405101" data-vars-category="Networking" data-vars-manufacturer-id="21582" data-vars-manufacturer="AVM" data-vars-vendor="billiger,gtin,amazon,mpn," data-vars-po="billiger,gtin,amazon,mpn" data-product="2405101" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=Vzqas_VdPAzVf28VzW0Dp4eF8ZBoGX1q15A8xTAzRoo1g7_hVoNHUkNR6XImhoGB4kZKpwcYI7dOMwAcDUtQQKm4kb0Jb4apXAUVhmKth6ReHZKkYGV-fKhsJep0H4bTOIuly3sYmy1&amp;mid=686037836840&amp;id=686037836840&amp;ts=20260519&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="364,19 €" data-vars-product-vendor="OTTO" aria-label="Deal anschauen bei OTTO für 364,19 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
						
									</div>
									<div class="price-comparison__record price-comparison__record--footer">
					<span class="price-comparison__footer-text">
													Preisvergleich (über 24.000 Shops weltweit)												</span>
											<button class="price-comparison__view-more-button">
							Weitere Angebote						</button>
									</div>
		</div>

		<div class="refurbished_products_tab tabcontent">
			<div class="refurbished-padding price-comparison__record price-comparison__record--header">
				<div>
					<span>Produkt</span>
				</div>
				<div class="price-comparison__price">
					<span>Preis</span>
				</div>
			</div>
							<div class="price-comparison__record price-comparison__record--footer">
					<span class="price-comparison__footer-text">
					Preisvergleich von Backmarket						</span>
									</div>
		</div>
		</div>
		


<h2 class="wp-block-heading">Fritzfon X6 (weiß oder schwarz)</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a0c07437c86e"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/02/Fritzfon-X6-AVM.jpg?quality=50&amp;strip=all&amp;w=542" alt="Fritzfon X6 " class="wp-image-3054894" width="542" height="1199" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">AVM</p></div>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn shopping-cart-icon-white link-6-button" href="https://www.amazon.de/dp/B0CCRYQV63?tag=pcwelt.de-21&amp;ascsubtag=4-0-3127694-7-0-0-0-0&amp;ascsubtag=rss" target="_blank" rel="nofollow" data-vars-link-position="CTA Button" data-domain-name="amazon" data-subtag="4-0-3127694-7-0-0-0-0">Fritzfon X6 bei Amazon ansehen</a></div>


<p>Preis: rund 84 Euro</p>



<p><strong>Technik:</strong></p>



<ul class="wp-block-list">
<li>Hochwertiges 2,4-Zoll-Farbdisplay</li>



<li>HD-Telefonie und Full-Duplex-Freisprechen</li>



<li>Bis zu 16 Stunden Gesprächszeit / 10 Tage Stand-by</li>



<li>Integrierte Steuerung für Smart-Home-Anwendungen</li>



<li>Unterstützung für E-Mails, Webradio, Podcasts und Babyfon-Funktion</li>



<li>Helligkeits- und Bewegungssensor für das Display</li>



<li>Regelmäßige Sicherheits-Updates per Tastendruck</li>



<li>Frei belegbare Favoritentaste für Schnellzugriff</li>
</ul>



<p>Das <a href="https://www.amazon.de/dp/B0CCRYQV63?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Fritzfon X6</a> dient als direkte Schnittstelle zur Fritzbox und übernimmt Aufgaben, die weit über einfaches Telefonieren hinausgehen. Per Menü lassen sich WLAN-Schaltungen vornehmen, Smart-Home-Komponenten steuern oder die Wiedergabe des Mediaservers verwalten. Das Farbdisplay zeigt zudem Informationen wie Wetterdaten oder das <a href="https://www.pcwelt.de/article/2990258/fritzbox-tuersprechanlage-einrichten-how-to.html" target="_blank" rel="noreferrer noopener">Live-Bild einer kompatiblen Türsprechanlage</a> an.</p>



<p>Durch die nahtlose Integration in das Fritz-System können Telefonbücher und Anrufbeantworter der Box direkt genutzt werden. Das vereinfacht die Einrichtung im Vergleich zu herkömmlichen DECT-Telefonen anderer Hersteller erheblich.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h2 class="wp-block-heading">Asus Tri-Band Wi-Fi 7 USB-Adapter (ROG USB-BE92 BE6500)</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a0c07437d356"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/04/Asus-Tri-Band-WiFi-7-USB-Adapter-ROG-USB-BE92-BE6500.jpg?quality=50&amp;strip=all&amp;w=394" alt="Asus Tri-Band WiFi 7 USB-Adapter (ROG USB-BE92 BE6500)" class="wp-image-3127831" width="394" height="1201" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Amazon/Asus</p></div>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn shopping-cart-icon-white link-6-button" href="https://www.amazon.de/dp/B09LCG53HN?tag=pcwelt.de-21&amp;ascsubtag=4-0-3127694-7-0-0-0-0&amp;ascsubtag=rss" target="_blank" rel="nofollow" data-vars-link-position="CTA Button" data-domain-name="amazon" data-subtag="4-0-3127694-7-0-0-0-0">Asus Tri-Band Wi-Fi 7 USB-Adapter bei Amazon ansehen</a></div>


<p>Preis: 73 Euro</p>



<p><strong>Technik:</strong></p>



<ul class="wp-block-list">
<li>Standard: Wi-Fi 7 (802.11be)</li>



<li>Frequenzbänder: Tri-Band (2,4 GHz, 5 GHz und 6 GHz)</li>



<li>Geschwindigkeit: Bis zu 6.500 Mbit/s Gesamtdatendurchsatz</li>



<li>Kanalbreite: 160 MHz im 6-GHz-Band</li>



<li>Funktionen: Multi-Link Operation (MLO) und 4K-QAM</li>



<li>Anschlüsse: Kompatibel mit USB-Typ-A und Typ-C</li>



<li>Sicherheit: Unterstützt das aktuelle WPA3-Protokoll</li>



<li>Extras: Unterstützung für OFDMA und MU-MIMO</li>
</ul>



<p>Die ersten Fritzbox-Modelle mit Wi-Fi 7 sind bereits auf dem Markt, dieser USB-Adapter stellt dabei die notwendige Brücke zum PC oder Laptop her. Während viele integrierte WLAN-Karten noch auf älteren Standards funken, ermöglicht der Adapter die Nutzung des störungsarmen 6-GHz-Bandes. Besonders in dicht besiedelten Gebieten mit vielen konkurrierenden Funknetzen sorgt das für eine stabilere Verbindung und geringere Latenzen.</p>



<p>Durch die Unterstützung von USB-A- und USB-C-Anschlüssen lässt sich der Stick flexibel an verschiedenen Hardware-Generationen betreiben, um die hohen Bandbreiten moderner Glasfaser-Anschlüsse auch drahtlos am Endgerät zu empfangen.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h2 class="wp-block-heading">Crucial X9 1 TB Externe SSD</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a0c07437de25"}' data-wp-interactive="core/image" class="wp-block-image size-full is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/04/Crucial-X9-1TB-Externe-SSD-Festplatte.jpg?quality=50&amp;strip=all" alt="Crucial X9 1TB Externe SSD Festplatte" class="wp-image-3127836" width="676" height="601" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Crucial </p></div>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn shopping-cart-icon-white link-6-button" href="https://www.amazon.de/dp/B0CGW1FQV4?tag=pcwelt.de-21&amp;ascsubtag=4-0-3127694-7-0-0-0-0&amp;ascsubtag=rss" target="_blank" rel="nofollow" data-vars-link-position="CTA Button" data-domain-name="amazon" data-subtag="4-0-3127694-7-0-0-0-0">Crucial X9 1 TB Externe SSD bei Amazon ansehen</a></div>


<p>Preis: 140 Euro</p>



<p><strong>Technik:</strong></p>



<ul class="wp-block-list">
<li>Kapazität: 1 TB (auch bis 4 TB erhältlich)</li>



<li>Schnittstelle: USB-C 3.2 (kompatibel mit USB-A via Adapter)</li>



<li>Geschwindigkeit: Bis zu 1.050 MB/s Leserate</li>



<li>Robustheit: Stoß-, vibrations- und sturzsicher bis 2 Meter Höhe</li>



<li>Dateisystem-Support: Windows Dateiversionsverlauf, Apple Time Machine</li>



<li>Abmessungen: Sehr kompaktes Gehäusedesign (Portable SSD)</li>



<li>Software: Kostenfreie Testzeiträume für Adobe Acrobat Pro und Mylio Photos+ bei Registrierung</li>
</ul>



<p>Eine externe SSD wie die <a href="https://www.amazon.de/dp/B0CGW1FQV4?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Crucial X9</a> erweitert Ihre Fritzbox um einen einfachen Netzwerkspeicher (Fritz NAS). Selbst bei Top-Modellen wie der <a href="https://www.amazon.de/dp/B0D8JCN5P4?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">5690 Pro</a> bremst die Prozessorleistung des Routers die enorme theoretische Geschwindigkeit der SSD (über 1.000 MB/s) zwar aus, dennoch ist die Kombination für den Alltag ideal: Der Datentransfer ist deutlich flotter als mit alten USB-Sticks, die SSD arbeitet lautlos und verbraucht wenig Energie. Es ist also eine geschickte Lösung, um Fotos oder Dokumente zentral im Heimnetz zu sichern und verfügbar zu machen.</p>



<p><strong>Wichtig:</strong> Vor dem Kauf sollten Sie prüfen, ob Ihre Fritzbox über einen USB-3.0-Anschluss verfügt. Einsteiger-Modelle wie die <a href="http://www.amazon.de/dp/B09N8NJD66?tag=pcwelt.de-21&amp;ascsubtag=rss">Fritzbox 7510</a> bieten oft nur langsames USB 2.0, während Varianten ohne USB-Port gar nicht als Netzwerkspeicher genutzt werden können.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h2 class="wp-block-heading">Fritz Smart Thermo 302</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a0c07437e8e0"}' data-wp-interactive="core/image" class="wp-block-image size-full is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/11/NL_18_FRITZDECT302.jpg?quality=50&amp;strip=all" alt="FRITZ!DECT 302 Heizkörperregler" class="wp-image-2992300" width="600" height="400" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">FRITZ!</p></div>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn shopping-cart-icon-white link-6-button" href="https://www.amazon.de/dp/B0G2T5J493?tag=pcwelt.de-21&amp;ascsubtag=4-0-3127694-7-0-0-0-0&amp;ascsubtag=rss" target="_blank" rel="nofollow" data-vars-link-position="CTA Button" data-domain-name="amazon" data-subtag="4-0-3127694-7-0-0-0-0">Fritz Smart Thermo 302 bei Amazon ansehen</a></div>


<p>Preis: 69 Euro</p>



<p><strong>Technik:</strong></p>



<ul class="wp-block-list">
<li>Display: Kontraststarkes und drehbares E-Paper-Display</li>



<li>Funkstandard: DECT ULE (Reichweite bis zu 40 Meter)</li>



<li>Funktionen: Fenster-auf-Erkennung, Frostschutz, Kalkschutz, Boost-Modus</li>



<li>Bedienung: Tasten am Gerät, App, PC oder Fritzfon</li>



<li>Montage: Kompatibel mit gängigen Ventilen (M30x1,5), Adapter inklusive</li>



<li>Extras: Gruppenschaltung, individuelle Heizprofile, Urlaubsmodus</li>



<li>Energie: Betrieb über zwei AA-Batterien</li>
</ul>



<p>Der <a href="https://www.amazon.de/dp/B0G2T5J493?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Fritz Smart Thermo 302</a> macht die Heizung zum Teil des Heimnetzes und ermöglicht eine zeitgesteuerte Regulierung der Raumtemperatur. Die Einrichtung erfolgt direkt über die Fritzbox, wobei für jeden Wochentag individuelle Heiz- und Absenkphasen festgelegt werden können. Ein klarer Vorteil gegenüber WLAN-Lösungen ist dabei der sparsame DECT-Funk, der lange Batterielaufzeiten ermöglicht.</p>



<p>Weil der Regler die Fenster-offen-Erkennung direkt integriert hat, regelt er die Temperatur bei plötzlichem Abfall automatisch herunter, um Energie zu sparen. Besonders komfortabel ist die Steuerung per Fritzfon oder eine Gruppenschaltung, bei der mehrere Heizkörper synchron auf eine Zieltemperatur eingestellt werden.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h2 class="wp-block-heading">Fritz-Repeater 6000 (Wi-Fi 6)</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a0c07437f323"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/04/Fritz-Repeater-6000-WiFi-6.jpg?quality=50&amp;strip=all&amp;w=836" alt="Fritz-Repeater 6000 (WiFi 6)" class="wp-image-3127844" width="836" height="1200" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">FRITZ!</p></div>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn shopping-cart-icon-white link-6-button" href="https://www.amazon.de/dp/B092VWMBZ2?tag=pcwelt.de-21&amp;ascsubtag=4-0-3127694-7-0-0-0-0&amp;ascsubtag=rss" target="_blank" rel="nofollow" data-vars-link-position="CTA Button" data-domain-name="amazon" data-subtag="4-0-3127694-7-0-0-0-0">Fritz-Repeater 6000 (Wi-Fi 6) bei Amazon ansehen</a></div>


<p>Preis: 260 Euro</p>



<p><strong>Technik:</strong></p>



<ul class="wp-block-list">
<li>Standard: Wi-Fi 6 (WLAN AX)</li>



<li>Funkeinheiten: Drei (Triband-Technologie)</li>



<li>Geschwindigkeit: Bis zu 6.000 MBit/s (2.400 + 2.400 + 1.200 MBit/s)</li>



<li>Anschlüsse: 1x 2,5-Gigabit-LAN, 1x Gigabit-LAN</li>



<li>Funktionen: WLAN Mesh, intelligente Bandauswahl, WPS-Einrichtung</li>



<li>Sicherheit: WPA3-Verschlüsselung integriert</li>



<li>Bauweise: Standgerät mit externem Netzteil</li>
</ul>



<p>Der <a href="https://www.amazon.de/dp/B092VWMBZ2?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Fritz-Repeater 6000</a> ist das aktuell leistungsstärkste Modell im Fritz-Sortiment für Nutzer, die große Wohnflächen oder mehrere Etagen mit schnellem WLAN versorgen möchten (zumindest, <a href="https://www.pcwelt.de/article/3071845/fritz-schnellster-wlan-repeater-6700-pro-wifi-7-router-mwc-2026.html" target="_blank" rel="noreferrer noopener">bis der neue 6700 Pro in die Regale kommt</a>). Dank seiner drei Funkeinheiten steht hier ein eigenes Band exklusiv für die Kommunikation zwischen Router und Repeater zur Verfügung – der sonst übliche Geschwindigkeitsverlust wird dadurch halbiert.</p>



<p>Auch der 2,5-Gigabit-LAN-Port ist vorteilhaft: Er ermöglicht es, den Repeater per Kabel als schnellen Zugangspunkt (LAN-Brücke) zu nutzen oder datenhungrige Geräte wie Spielekonsolen oder PCs stabil anzubinden. Im Zusammenspiel mit einer <a href="https://www.pcwelt.de/article/1157690/fritzbox-router-im-vergleich-das-beste-modell.html" target="_blank" rel="noreferrer noopener">Fritzbox</a> bildet er ein nahtloses Mesh-Netzwerk, bei dem mobile Endgeräte automatisch immer mit dem stärksten Zugangspunkt verbunden werden.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h2 class="wp-block-heading">Fritz Smart Control 350 (magnetischer Tür-/Fensterkontakt)</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a0c07437fc1b"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/04/Fritz-Smart-Control-350.jpg?quality=50&amp;strip=all&amp;w=699" alt="Fritz Smart Control 350" class="wp-image-3127848" width="699" height="1200" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">FRITZ!</p></div>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn shopping-cart-icon-white link-6-button" href="https://www.amazon.de/dp/B0GHS4SMCJ?tag=pcwelt.de-21&amp;ascsubtag=4-0-3127694-7-0-0-0-0&amp;ascsubtag=rss" target="_blank" rel="nofollow" data-vars-link-position="CTA Button" data-domain-name="amazon" data-subtag="4-0-3127694-7-0-0-0-0">Fritz Smart Control 350 bei Amazon ansehen</a></div>


<p>Preis: 40 Euro</p>



<p><strong>Technik:</strong></p>



<ul class="wp-block-list">
<li>Typ: Magnetischer Sensor (zweiteilig: Sensor und Magnet)</li>



<li>Funkstandard: DECT ULE</li>



<li>Erkennung: Geöffnet, geschlossen oder gekippt (je nach Montage)</li>



<li>Montage: Klebestreifen für Rahmen oder Flügel</li>



<li>Energie: Betrieb mit 2x AAA-Batterien</li>



<li>Reichweite: Bis zu 40 Meter im Haus</li>



<li>Kompatibilität: Alle Fritzbox-Modelle mit DECT-Basis</li>
</ul>



<p>Mit dem <a href="https://www.amazon.de/dp/B0GHS4SMCJ?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Fritz Smart Control 350</a> verkauft Fritz einen dezenten Sensor, der den Status von Fenstern und Türen überwacht und diese Information an die Fritzbox weitergibt. Er dient als optimaler Partner für die smarten Heizkörperregler: Erkennt der Sensor ein offenes Fenster, kann die Heizung im jeweiligen Raum sofort automatisch heruntergeregelt werden. Das funktioniert effektiver als die rein temperaturbasierte Erkennung eines Thermostats.</p>



<p>Durch die kompakte Bauweise lässt sich der Magnet oft so im Rahmen montieren, dass er bei geschlossenem Fenster fast unsichtbar bleibt. Neben der Heizungssteuerung lassen sich auch einfache Sicherheits-Szenarien oder Push-Nachrichten aufs Smartphone einrichten, sobald eine Tür unbefugt geöffnet wird.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h2 class="wp-block-heading">Fritz DECT 210</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a0c0743804fc"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/04/Fritz-Dect-210.jpg?quality=50&amp;strip=all&amp;w=831" alt="Fritz Dect 210" class="wp-image-3127852" width="831" height="1200" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">FRITZ!</p></div>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn shopping-cart-icon-white link-6-button" href="https://www.amazon.de/dp/B01MRZ60F0?tag=pcwelt.de-21&amp;ascsubtag=4-0-3127694-7-0-0-0-0&amp;ascsubtag=rss" target="_blank" rel="nofollow" data-vars-link-position="CTA Button" data-domain-name="amazon" data-subtag="4-0-3127694-7-0-0-0-0">Fritz DECT 210 bei Amazon ansehen</a></div>


<p>Preis: 42 Euro</p>



<p><strong>Technik:</strong></p>



<ul class="wp-block-list">
<li>Typ: Intelligente Steckdose für den Außenbereich</li>



<li>Schutzart: Spritzwasserschutz nach IP44</li>



<li>Belastbarkeit: Schaltet Geräte bis zu 3.450 Watt</li>



<li>Funkstandard: DECT ULE (Reichweite bis zu 300 Meter im Freien)</li>



<li>Funktionen: Messung von Energieverbrauch, Temperatur und Leistung</li>



<li>Schaltmodi: Zeitplan, Sonnenauf-/untergang, Google-Kalender, Zufall</li>



<li>Bedienung: App, Fritzfon, PC oder direkt am Gerät</li>
</ul>



<p>Smarte Funktionen im Garten, auf dem Balkon oder in der Garage: Die <a href="https://www.amazon.de/dp/B01MRZ60F0?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Fritz DECT 210</a> macht’s möglich. Dank des robusten Gehäuses inklusive Schutzklappe ist sie gegen Spritzwasser geschützt und hält auch wechselnden Temperaturen stand. Über die Fritzbox lässt sich die Steckdose schalten und als Energiemessgerät nutzen: Sie zeichnet den Stromverbrauch angeschlossener Geräte auf und wertet diesen in einer übersichtlichen Grafik aus.</p>



<p>Besonders praktisch für den Außenbereich ist die Astro-Funktion, die beispielsweise die Gartenbeleuchtung pünktlich zum Sonnenuntergang automatisch einschaltet, ohne dass man die Zeiten manuell nachjustieren muss.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h2 class="wp-block-heading">Fritz DECT-Repeater 100</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a0c074380efb"}' data-wp-interactive="core/image" class="wp-block-image size-full is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/04/Fritz-DECT-Repeater-100.jpg?quality=50&amp;strip=all" alt="Fritz-DECT-Repeater 100" class="wp-image-3127854" width="665" height="821" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">FRITZ!</p></div>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn shopping-cart-icon-white link-6-button" href="https://www.amazon.de/dp/B00AQ9A9AQ?tag=pcwelt.de-21&amp;ascsubtag=4-0-3127694-7-0-0-0-0&amp;ascsubtag=rss" target="_blank" rel="nofollow" data-vars-link-position="CTA Button" data-domain-name="amazon" data-subtag="4-0-3127694-7-0-0-0-0">Fritz DECT-Repeater 100 bei Amazon ansehen</a></div>


<p>Preis:  78 Euro</p>



<p><strong>Technik:</strong></p>



<ul class="wp-block-list">
<li>Typ: Reichweitenverstärker für den DECT-Funk</li>



<li>Kapazität: Unterstützt bis zu drei Gespräche gleichzeitig</li>



<li>Funktionen: Überträgt HD-Telefonie, Internetradio und Podcasts</li>



<li>Sicherheit: Integrierte DECT-Verschlüsselung für abhörsichere Gespräche</li>



<li>Kompatibilität: Alle Fritzbox-Modelle mit DECT-Basis sowie GAP-Basistationen</li>



<li>Besonderheit: Integrierte Steckdose (kein Steckplatz geht verloren)</li>



<li>Einrichtung: Einfache Anmeldung per Tastendruck (WPS/DECT-Taste)</li>
</ul>



<p>Mit dem <a href="https://www.amazon.de/dp/B00AQ9A9AQ?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Fritz DECT-Repeater 100</a> gibt es eine Lösung für Haushalte, in denen das Funksignal des Telefons nicht bis in die letzte Ecke oder über mehrere Etagen reicht. Im Gegensatz zu einfachen Verstärkern unterstützt dieses Gerät bei Verbindung mit einer Fritzbox den vollen Funktionsumfang: Auch weit entfernt von der Basis bleiben HD-Telefonie, RSS-Feeds oder der Empfang von E-Mails am Fritzfon stabil.</p>



<p>Ebenfalls praktisch: das Gerät verfügt über eine integrierte Steckdose, damit steht der Anschluss an der Wand weiterhin für andere Elektrogeräte bereit. Durch die Unterstützung von automatischem Handover merkt man den Wechsel zwischen Basis und Repeater während eines Telefonats gar nicht.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h2 class="wp-block-heading">Fritz Smart Energy 250</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a0c07438182f"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/04/Fritz-Smart-Energy-250.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Fritz Smart Energy 250" class="wp-image-3127856" width="1200" height="1200" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">FRITZ!</p></div>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn shopping-cart-icon-white link-6-button" href="https://www.amazon.de/dp/B0F1TNPHP4?tag=pcwelt.de-21&amp;ascsubtag=4-0-3127694-7-0-0-0-0&amp;ascsubtag=rss" target="_blank" rel="nofollow" data-vars-link-position="CTA Button" data-domain-name="amazon" data-subtag="4-0-3127694-7-0-0-0-0">Fritz Smart Energy 250 bei Amazon ansehen</a></div>


<p>Preis:  70 Euro</p>



<p><strong>Technik:</strong></p>



<ul class="wp-block-list">
<li>Typ: Intelligenter Stromsensor (Infrarot-Ausleseeinheit)</li>



<li>Schnittstelle: Magnetische Befestigung an der INFO-Schnittstelle</li>



<li>Funkstandard: DECT ULE</li>



<li>Stromversorgung: 2x AA-Batterien oder via USB-Anschluss</li>



<li>Kompatibilität: Für die meisten digitalen Stromzähler (Infrarot-Schnittstelle)</li>



<li>Auswertung: Fritz-App Smart Home, FritzOS oder Myfritz-Net</li>



<li>Features: Echtzeit-Verbrauchsdaten, historische Auswertung, Auslöser für Automationen</li>
</ul>



<p>Wer sich mehr Transparenz beim Stromverbrauch im ganzen Haushalt wünscht, greift zum <a href="https://www.amazon.de/dp/B0F1TNPHP4?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Fritz Smart Energy 250</a>. Anstatt manuell und mühsam den Zählerstand zu notieren, liest dieser Sensor die Daten direkt am digitalen Stromzähler aus und überträgt sie per Funk an die Fritzbox. Dadurch lässt sich der aktuelle Stromverbrauch jederzeit per App kontrollieren. Versteckten Energiefressern kommen Sie so besonders schnell auf die Schliche.</p>



<p>Besonders interessant für Smart-Home-Nutzer: Die gemessenen Werte können als Auslöser für verschiedene Szenarien dienen – so lässt sich beispielsweise eine Benachrichtigung einrichten, wenn die Leistungsaufnahme einen bestimmten Wert überschreitet.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h2 class="wp-block-heading">Fritz Powerline 1260</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a0c0743823d6"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/04/Fritz-Powerline-1260-Single-Adapter.jpg?quality=50&amp;strip=all&amp;w=679" alt="Fritz Powerline 1260 Single-Adapter" class="wp-image-3127861" width="679" height="1199" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">FRITZ!</p></div>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn shopping-cart-icon-white link-6-button" href="https://www.amazon.de/dp/B0752S866W?tag=pcwelt.de-21&amp;ascsubtag=4-0-3127694-7-0-0-0-0&amp;ascsubtag=rss" target="_blank" rel="nofollow" data-vars-link-position="CTA Button" data-domain-name="amazon" data-subtag="4-0-3127694-7-0-0-0-0">Fritz Powerline 1260 bei Amazon ansehen</a></div>


<p>Preis: 105 Euro</p>



<p><strong>Technik:</strong></p>



<ul class="wp-block-list">
<li>Typ: Powerline-Einzeladapter mit WLAN-Funktion</li>



<li>Geschwindigkeit (Stromnetz): Bis zu 1.200 MBit/s</li>



<li>WLAN: Dualband AC+N (bis zu 866 + 400 MBit/s)</li>



<li>Anschluss: 1x Gigabit-LAN-Port</li>



<li>Technologie: 2×2 MIMO (nutzt zwei Adernpaare im Stromnetz)</li>



<li>Sicherheit: WPA2-Verschlüsselung und ab Werk verschlüsselte Powerline-Verbindung</li>



<li>Mesh-Unterstützung: Automatische Übernahme der WLAN-Einstellungen der Fritzbox</li>
</ul>



<p><a href="https://www.amazon.de/dp/B0752S866W?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Fritz Powerline 1260</a> ist der Problemlöser für Räume, in denen weder WLAN-Signale noch Netzwerkkabel ankommen. Weil Daten damit über die Stromleitung transportiert werden, lassen sich selbst massive Wände oder weite Strecken zum Keller oder Dachboden überbrücken. An der Zielsteckdose fungiert der Adapter gleichzeitig als LAN-Anschluss für Geräte wie Smart-TVs oder Spielekonsolen und als WLAN-Access-Point. Innerhalb eines Fritz-Heimnetzes integriert er sich nahtlos in das Mesh-System, sodass mobile Geräte ohne Verbindungsabbruch zwischen Router und Powerline-Adapter wechseln können.</p>



<p><strong>Hinweis:</strong> Da es sich hier um einen Einzeladapter handelt, wird für den Aufbau eines Powerline-Netzwerks ein zweites Gegenstück (ein weiterer Powerline-Adapter) benötigt, das per LAN-Kabel mit der Fritzbox verbunden ist.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sender verliert Fußball-WM-Lizenz wegen "hemmungsloser Piraterie"]]></title>
<description><![CDATA[Über 20 Jahre lang galt der Sender Astro in Malaysia als die feste Heimat für die Fußball-Weltmeisterschaft. Doch nun kapituliert der Pay-TV-Gigant vor der ausufernden Piraterie und überlässt die WM 2026 dem staatlichen Free-TV.			(Weiter lesen)]]></description>
<link>https://tsecurity.de/de/3526217/it-security-nachrichten/sender-verliert-fussball-wm-lizenz-wegen-hemmungsloser-piraterie/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3526217/it-security-nachrichten/sender-verliert-fussball-wm-lizenz-wegen-hemmungsloser-piraterie/</guid>
<pubDate>Mon, 18 May 2026 16:08:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://winfuture.de/news,158757.html"><img hspace="5" border="0" align="left" alt="Filesharing, Piraterie, Fußball, Fifa, Tor, Piracy, Fussball, Wm, Totenkopf, EM, UEFA, Piraten, Ball, Strand, Fußballfeld, Burg, Piratenschiff" width="1920" height="1080" src="https://i.wfcdn.de/teaser/1920/90803.jpg"></a>
			Über 20 Jahre lang galt der Sender Astro in Malaysia als die feste Heimat für die Fußball-Weltmeisterschaft. Doch nun kapituliert der Pay-TV-Gigant vor der ausufernden <a href="https://winfuture.de/special/filesharing/" title="Filesharing Special">Piraterie</a> und überlässt die WM 2026 dem staatlichen Free-TV.			(<a href="https://winfuture.de/news,158757.html">Weiter lesen</a>)]]></content:encoded>
</item>
<item>
<title><![CDATA[Das beste Zubehör für die Fritzbox: 10 Upgrades für maximalen Speed und Komfort]]></title>
<description><![CDATA[Die Fritzbox ist das Herzstück eines digitalen Zuhauses, ihr volles Potenzial lassen viele aber ungenutzt. Wer lediglich surft und telefoniert, verschenkt wertvolle Möglichkeiten in Sachen Reichweite, Stromersparnis und Komfort. Erst mit dem richtigen Zubehör wird die Box zur Schaltzentrale, die ...]]></description>
<link>https://tsecurity.de/de/3525300/windows-tipps/das-beste-zubehoer-fuer-die-fritzbox-10-upgrades-fuer-maximalen-speed-und-komfort/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3525300/windows-tipps/das-beste-zubehoer-fuer-die-fritzbox-10-upgrades-fuer-maximalen-speed-und-komfort/</guid>
<pubDate>Mon, 18 May 2026 10:40:31 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Die <a href="https://www.pcwelt.de/article/1157690/fritzbox-router-im-vergleich-das-beste-modell.html" target="_blank" rel="noreferrer noopener">Fritzbox</a> ist das Herzstück eines digitalen Zuhauses, ihr volles Potenzial lassen viele aber ungenutzt. Wer lediglich surft und telefoniert, verschenkt wertvolle Möglichkeiten in Sachen Reichweite, Stromersparnis und Komfort. Erst mit dem richtigen Zubehör wird die Box zur Schaltzentrale, die nicht nur Daten überträgt, sondern auch den Alltag spürbar erleichtert – von der automatisierten Heizungssteuerung bis zum blitzschnellen Datentransfer im ganzen Haus.</p>



<p>Wenn Sie bereits einen Router von Fritz (<a href="https://www.pcwelt.de/article/1157690/fritzbox-router-im-vergleich-das-beste-modell.html" target="_blank" rel="noreferrer noopener">hier finden Sie unsere Bestenliste</a>) im Einsatz haben, merken Sie mit dem richtigen Zubehör sofort: Wenn Hardware und Peripherie Hand in Hand gehen, wird aus einem einfachen Internet-Anschluss ein nahtloses Ökosystem. Für den Alltag heißt das: Mehr Speed, mehr Effizienz und spürbare Komfort-Upgrades.</p>



<p>In unserem Zubehör-Ratgeber zeigen wir Ihnen zehn essenzielle Upgrades, mit denen Sie Ihr Heimnetzwerk auf das nächste Level heben.</p>



<p><strong>Tipp:</strong> Wenn Sie noch keine Fritzbox im Einsatz haben oder aktuell noch DSL nutzen, aber demnächst auf Glasfaser umsteigen möchten, dann lohnt sich ein Blick auf die <a href="https://www.amazon.de/dp/B0D8JCN5P4?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Fritzbox 5690 Pro</a>. Sie ist bereits für das neue Wi-Fi 7 gerüstet und spielt in Kombination mit unseren Zubehör-Tipps alle Asse aus.</p>



<p><strong>Aktuell bester Preis: Fritzbox 5690 Pro</strong></p>



				<div class="wp-block-price-comparison price-comparison">
		
		<div class="new_products_tab tabcontent ">

			<div class="price-comparison__record price-comparison__record--header">
				<div>
					<span>Shop</span>
				</div>
								<div class="price-comparison__price">
					<span>Preis</span>
				</div>
			</div>

								<div class="price-comparison__record  amazon_vendor">
						<div class="price-comparison__image">
															<img decoding="async" src="https://www.pcwelt.de/wp-content/themes/idg-base-theme/dist/static/img/amazon-logo.svg" alt="Amazon" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>309,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://www.amazon.de/dp/B0D8JCN5P4?tag=pcwelt.de-21&amp;linkCode=ogi&amp;th=1&amp;psc=1&amp;ascsubtag=rss" data-vars-product-name="AVM Fritzbox 5690 Pro" data-vars-product-id="2405101" data-vars-category="Networking" data-vars-manufacturer-id="21582" data-vars-manufacturer="AVM" data-vars-vendor="billiger,gtin,amazon,mpn," data-vars-po="billiger,gtin,amazon,mpn" data-product="2405101" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://www.amazon.de/dp/B0D8JCN5P4?tag=pcwelt.de-21&amp;linkCode=ogi&amp;th=1&amp;psc=1&amp;ascsubtag=rss" data-vendor-api="amazon" data-vars-product-price="309,00 €" data-vars-product-vendor="Amazon" aria-label="Deal anschauen bei Amazon für 309,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/10729.png" alt="expert TechnoMarkt" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>309,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=coDfD83cfZegFdiMIpCMzPSD3RBPspIsb7nY_gEpKI5rZW8l3gogb3guO08Lv6VtVvUkBdykefIcugqDa2Db6ZxmbS2sJ7y6o-DBcFDt3iDXHrVDtZ40WvfArEpuTJZxA&amp;mid=379810961554&amp;id=379810961554&amp;ts=20260518&amp;log=rss" data-vars-product-name="AVM Fritzbox 5690 Pro" data-vars-product-id="2405101" data-vars-category="Networking" data-vars-manufacturer-id="21582" data-vars-manufacturer="AVM" data-vars-vendor="billiger,gtin,amazon,mpn," data-vars-po="billiger,gtin,amazon,mpn" data-product="2405101" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=coDfD83cfZegFdiMIpCMzPSD3RBPspIsb7nY_gEpKI5rZW8l3gogb3guO08Lv6VtVvUkBdykefIcugqDa2Db6ZxmbS2sJ7y6o-DBcFDt3iDXHrVDtZ40WvfArEpuTJZxA&amp;mid=379810961554&amp;id=379810961554&amp;ts=20260518&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="309,00 €" data-vars-product-vendor="expert TechnoMarkt" aria-label="Deal anschauen bei expert TechnoMarkt für 309,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/24204.png" alt="coolblue" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>317,90 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=yqp1z4psAAsRDMrEUYsO-k9BllzVCQG-wy7LvvFpNjQ5p11Pk4U7aVBOpvFgJYkk4kZKpwcYI7dOMwAcDUtQQJeNGuJzyNXcWrD5Eb6aXaxgTOX2NA30Aw&amp;mid=564277510513&amp;id=564277510513&amp;ts=20260518&amp;log=rss" data-vars-product-name="AVM Fritzbox 5690 Pro" data-vars-product-id="2405101" data-vars-category="Networking" data-vars-manufacturer-id="21582" data-vars-manufacturer="AVM" data-vars-vendor="billiger,gtin,amazon,mpn," data-vars-po="billiger,gtin,amazon,mpn" data-product="2405101" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=yqp1z4psAAsRDMrEUYsO-k9BllzVCQG-wy7LvvFpNjQ5p11Pk4U7aVBOpvFgJYkk4kZKpwcYI7dOMwAcDUtQQJeNGuJzyNXcWrD5Eb6aXaxgTOX2NA30Aw&amp;mid=564277510513&amp;id=564277510513&amp;ts=20260518&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="317,90 €" data-vars-product-vendor="coolblue" aria-label="Deal anschauen bei coolblue für 317,90 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/30167.png" alt="e-tec" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>329,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=Pxst9RwFb3sgFdiMIpCMzMt9j_8TwO0ub7nY_gEpKI5CgObUJArBEj_NYWZJZdx_FvUkBdykefIcugqDa2Db6bgTcnV5FGryGrD5Eb6aXaxgTOX2NA30Aw&amp;mid=671474524603&amp;id=671474524603&amp;ts=20260518&amp;log=rss" data-vars-product-name="AVM Fritzbox 5690 Pro" data-vars-product-id="2405101" data-vars-category="Networking" data-vars-manufacturer-id="21582" data-vars-manufacturer="AVM" data-vars-vendor="billiger,gtin,amazon,mpn," data-vars-po="billiger,gtin,amazon,mpn" data-product="2405101" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=Pxst9RwFb3sgFdiMIpCMzMt9j_8TwO0ub7nY_gEpKI5CgObUJArBEj_NYWZJZdx_FvUkBdykefIcugqDa2Db6bgTcnV5FGryGrD5Eb6aXaxgTOX2NA30Aw&amp;mid=671474524603&amp;id=671474524603&amp;ts=20260518&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="329,00 €" data-vars-product-vendor="e-tec" aria-label="Deal anschauen bei e-tec für 329,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__hidden-records-wrapper">
									<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/4541.png" alt="notebooksbilliger" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>329,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=0RYVsWIQcaZf7aDQSDOyE5H3DoUGjzQABq5LL3gM66IZGHiWoRPBpxmBykCtd_bvlvUkBdykefIcugqDa2Db6ZxmbS2sJ7y6o-DBcFDt3iDXHrVDtZ40WvfArEpuTJZxA&amp;mid=370318412784&amp;id=370318412784&amp;ts=20260518&amp;log=rss" data-vars-product-name="AVM Fritzbox 5690 Pro" data-vars-product-id="2405101" data-vars-category="Networking" data-vars-manufacturer-id="21582" data-vars-manufacturer="AVM" data-vars-vendor="billiger,gtin,amazon,mpn," data-vars-po="billiger,gtin,amazon,mpn" data-product="2405101" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=0RYVsWIQcaZf7aDQSDOyE5H3DoUGjzQABq5LL3gM66IZGHiWoRPBpxmBykCtd_bvlvUkBdykefIcugqDa2Db6ZxmbS2sJ7y6o-DBcFDt3iDXHrVDtZ40WvfArEpuTJZxA&amp;mid=370318412784&amp;id=370318412784&amp;ts=20260518&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="329,00 €" data-vars-product-vendor="notebooksbilliger" aria-label="Deal anschauen bei notebooksbilliger für 329,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/29931.png" alt="Tronyq" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>329,30 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=uKqsYZ8R-LsgFdiMIpCMzMt9j_8TwO0ubGvn5zzBpQxE1egQ3hdWilVOWy8Jyv08VvUkBdykefIrPbr6v5nlNPp0oEiJorkUzgpcsMoguwOrThlSymd6ezUuDccGN5haw&amp;mid=591630586698&amp;id=591630586698&amp;ts=20260518&amp;log=rss" data-vars-product-name="AVM Fritzbox 5690 Pro" data-vars-product-id="2405101" data-vars-category="Networking" data-vars-manufacturer-id="21582" data-vars-manufacturer="AVM" data-vars-vendor="billiger,gtin,amazon,mpn," data-vars-po="billiger,gtin,amazon,mpn" data-product="2405101" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=uKqsYZ8R-LsgFdiMIpCMzMt9j_8TwO0ubGvn5zzBpQxE1egQ3hdWilVOWy8Jyv08VvUkBdykefIrPbr6v5nlNPp0oEiJorkUzgpcsMoguwOrThlSymd6ezUuDccGN5haw&amp;mid=591630586698&amp;id=591630586698&amp;ts=20260518&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="329,30 €" data-vars-product-vendor="Tronyq" aria-label="Deal anschauen bei Tronyq für 329,30 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/3667.png" alt="OTTO" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>343,99 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=RXovikaWyXDVf28VzW0Dp4eF8ZBoGX1q3N1H2_DwCzj1g7_hVoNHUkNR6XImhoGB4kZKpwcYI7dOMwAcDUtQQKm4kb0Jb4apXKGWTI90JdS_1phC4hwcxU&amp;mid=685903284419&amp;id=685903284419&amp;ts=20260518&amp;log=rss" data-vars-product-name="AVM Fritzbox 5690 Pro" data-vars-product-id="2405101" data-vars-category="Networking" data-vars-manufacturer-id="21582" data-vars-manufacturer="AVM" data-vars-vendor="billiger,gtin,amazon,mpn," data-vars-po="billiger,gtin,amazon,mpn" data-product="2405101" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=RXovikaWyXDVf28VzW0Dp4eF8ZBoGX1q3N1H2_DwCzj1g7_hVoNHUkNR6XImhoGB4kZKpwcYI7dOMwAcDUtQQKm4kb0Jb4apXKGWTI90JdS_1phC4hwcxU&amp;mid=685903284419&amp;id=685903284419&amp;ts=20260518&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="343,99 €" data-vars-product-vendor="OTTO" aria-label="Deal anschauen bei OTTO für 343,99 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/5211.png" alt="OTTO Office" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>345,09 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=9nc5shEshLARDMrEUYsO-k9BllzVCQG-3Js6rFMEuqQ5p11Pk4U7aWOx6jC8C2nRlKfpa4qJRMyQbfXS4HUTmtC0E1HUKv6j1xV5uTwSyKHpWzrWr436i1DLLGalWtKWtHSaj7v6ObKkU7J3KOiD8s&amp;mid=423795873405&amp;id=423795873405&amp;ts=20260518&amp;log=rss" data-vars-product-name="AVM Fritzbox 5690 Pro" data-vars-product-id="2405101" data-vars-category="Networking" data-vars-manufacturer-id="21582" data-vars-manufacturer="AVM" data-vars-vendor="billiger,gtin,amazon,mpn," data-vars-po="billiger,gtin,amazon,mpn" data-product="2405101" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=9nc5shEshLARDMrEUYsO-k9BllzVCQG-3Js6rFMEuqQ5p11Pk4U7aWOx6jC8C2nRlKfpa4qJRMyQbfXS4HUTmtC0E1HUKv6j1xV5uTwSyKHpWzrWr436i1DLLGalWtKWtHSaj7v6ObKkU7J3KOiD8s&amp;mid=423795873405&amp;id=423795873405&amp;ts=20260518&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="345,09 €" data-vars-product-vendor="OTTO Office" aria-label="Deal anschauen bei OTTO Office für 345,09 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
						
									</div>
									<div class="price-comparison__record price-comparison__record--footer">
					<span class="price-comparison__footer-text">
													Preisvergleich (über 24.000 Shops weltweit)												</span>
											<button class="price-comparison__view-more-button">
							Weitere Angebote						</button>
									</div>
		</div>

		<div class="refurbished_products_tab tabcontent">
			<div class="refurbished-padding price-comparison__record price-comparison__record--header">
				<div>
					<span>Produkt</span>
				</div>
				<div class="price-comparison__price">
					<span>Preis</span>
				</div>
			</div>
							<div class="price-comparison__record price-comparison__record--footer">
					<span class="price-comparison__footer-text">
					Preisvergleich von Backmarket						</span>
									</div>
		</div>
		</div>
		


<h2 class="wp-block-heading">Fritzfon X6 (weiß oder schwarz)</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a0aceecbee2e"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/02/Fritzfon-X6-AVM.jpg?quality=50&amp;strip=all&amp;w=542" alt="Fritzfon X6 " class="wp-image-3054894" width="542" height="1199" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">AVM</p></div>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn shopping-cart-icon-white link-6-button" href="https://www.amazon.de/dp/B0CCRYQV63?tag=pcwelt.de-21&amp;ascsubtag=4-0-3127694-7-0-0-0-0&amp;ascsubtag=rss" target="_blank" rel="nofollow" data-vars-link-position="CTA Button" data-domain-name="amazon" data-subtag="4-0-3127694-7-0-0-0-0">Fritzfon X6 bei Amazon ansehen</a></div>


<p>Preis: rund 84 Euro</p>



<p><strong>Technik:</strong></p>



<ul class="wp-block-list">
<li>Hochwertiges 2,4-Zoll-Farbdisplay</li>



<li>HD-Telefonie und Full-Duplex-Freisprechen</li>



<li>Bis zu 16 Stunden Gesprächszeit / 10 Tage Stand-by</li>



<li>Integrierte Steuerung für Smart-Home-Anwendungen</li>



<li>Unterstützung für E-Mails, Webradio, Podcasts und Babyfon-Funktion</li>



<li>Helligkeits- und Bewegungssensor für das Display</li>



<li>Regelmäßige Sicherheits-Updates per Tastendruck</li>



<li>Frei belegbare Favoritentaste für Schnellzugriff</li>
</ul>



<p>Das <a href="https://www.amazon.de/dp/B0CCRYQV63?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Fritzfon X6</a> dient als direkte Schnittstelle zur Fritzbox und übernimmt Aufgaben, die weit über einfaches Telefonieren hinausgehen. Per Menü lassen sich WLAN-Schaltungen vornehmen, Smart-Home-Komponenten steuern oder die Wiedergabe des Mediaservers verwalten. Das Farbdisplay zeigt zudem Informationen wie Wetterdaten oder das <a href="https://www.pcwelt.de/article/2990258/fritzbox-tuersprechanlage-einrichten-how-to.html" target="_blank" rel="noreferrer noopener">Live-Bild einer kompatiblen Türsprechanlage</a> an.</p>



<p>Durch die nahtlose Integration in das Fritz-System können Telefonbücher und Anrufbeantworter der Box direkt genutzt werden. Das vereinfacht die Einrichtung im Vergleich zu herkömmlichen DECT-Telefonen anderer Hersteller erheblich.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h2 class="wp-block-heading">Asus Tri-Band Wi-Fi 7 USB-Adapter (ROG USB-BE92 BE6500)</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a0aceecbf696"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/04/Asus-Tri-Band-WiFi-7-USB-Adapter-ROG-USB-BE92-BE6500.jpg?quality=50&amp;strip=all&amp;w=394" alt="Asus Tri-Band WiFi 7 USB-Adapter (ROG USB-BE92 BE6500)" class="wp-image-3127831" width="394" height="1201" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Amazon/Asus</p></div>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn shopping-cart-icon-white link-6-button" href="https://www.amazon.de/dp/B09LCG53HN?tag=pcwelt.de-21&amp;ascsubtag=4-0-3127694-7-0-0-0-0&amp;ascsubtag=rss" target="_blank" rel="nofollow" data-vars-link-position="CTA Button" data-domain-name="amazon" data-subtag="4-0-3127694-7-0-0-0-0">Asus Tri-Band Wi-Fi 7 USB-Adapter bei Amazon ansehen</a></div>


<p>Preis: 73 Euro</p>



<p><strong>Technik:</strong></p>



<ul class="wp-block-list">
<li>Standard: Wi-Fi 7 (802.11be)</li>



<li>Frequenzbänder: Tri-Band (2,4 GHz, 5 GHz und 6 GHz)</li>



<li>Geschwindigkeit: Bis zu 6.500 Mbit/s Gesamtdatendurchsatz</li>



<li>Kanalbreite: 160 MHz im 6-GHz-Band</li>



<li>Funktionen: Multi-Link Operation (MLO) und 4K-QAM</li>



<li>Anschlüsse: Kompatibel mit USB-Typ-A und Typ-C</li>



<li>Sicherheit: Unterstützt das aktuelle WPA3-Protokoll</li>



<li>Extras: Unterstützung für OFDMA und MU-MIMO</li>
</ul>



<p>Die ersten Fritzbox-Modelle mit Wi-Fi 7 sind bereits auf dem Markt, dieser USB-Adapter stellt dabei die notwendige Brücke zum PC oder Laptop her. Während viele integrierte WLAN-Karten noch auf älteren Standards funken, ermöglicht der Adapter die Nutzung des störungsarmen 6-GHz-Bandes. Besonders in dicht besiedelten Gebieten mit vielen konkurrierenden Funknetzen sorgt das für eine stabilere Verbindung und geringere Latenzen.</p>



<p>Durch die Unterstützung von USB-A- und USB-C-Anschlüssen lässt sich der Stick flexibel an verschiedenen Hardware-Generationen betreiben, um die hohen Bandbreiten moderner Glasfaser-Anschlüsse auch drahtlos am Endgerät zu empfangen.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h2 class="wp-block-heading">Crucial X9 1 TB Externe SSD</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a0aceecbfe04"}' data-wp-interactive="core/image" class="wp-block-image size-full is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/04/Crucial-X9-1TB-Externe-SSD-Festplatte.jpg?quality=50&amp;strip=all" alt="Crucial X9 1TB Externe SSD Festplatte" class="wp-image-3127836" width="676" height="601" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Crucial </p></div>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn shopping-cart-icon-white link-6-button" href="https://www.amazon.de/dp/B0CGW1FQV4?tag=pcwelt.de-21&amp;ascsubtag=4-0-3127694-7-0-0-0-0&amp;ascsubtag=rss" target="_blank" rel="nofollow" data-vars-link-position="CTA Button" data-domain-name="amazon" data-subtag="4-0-3127694-7-0-0-0-0">Crucial X9 1 TB Externe SSD bei Amazon ansehen</a></div>


<p>Preis: 140 Euro</p>



<p><strong>Technik:</strong></p>



<ul class="wp-block-list">
<li>Kapazität: 1 TB (auch bis 4 TB erhältlich)</li>



<li>Schnittstelle: USB-C 3.2 (kompatibel mit USB-A via Adapter)</li>



<li>Geschwindigkeit: Bis zu 1.050 MB/s Leserate</li>



<li>Robustheit: Stoß-, vibrations- und sturzsicher bis 2 Meter Höhe</li>



<li>Dateisystem-Support: Windows Dateiversionsverlauf, Apple Time Machine</li>



<li>Abmessungen: Sehr kompaktes Gehäusedesign (Portable SSD)</li>



<li>Software: Kostenfreie Testzeiträume für Adobe Acrobat Pro und Mylio Photos+ bei Registrierung</li>
</ul>



<p>Eine externe SSD wie die <a href="https://www.amazon.de/dp/B0CGW1FQV4?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Crucial X9</a> erweitert Ihre Fritzbox um einen einfachen Netzwerkspeicher (Fritz NAS). Selbst bei Top-Modellen wie der <a href="https://www.amazon.de/dp/B0D8JCN5P4?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">5690 Pro</a> bremst die Prozessorleistung des Routers die enorme theoretische Geschwindigkeit der SSD (über 1.000 MB/s) zwar aus, dennoch ist die Kombination für den Alltag ideal: Der Datentransfer ist deutlich flotter als mit alten USB-Sticks, die SSD arbeitet lautlos und verbraucht wenig Energie. Es ist also eine geschickte Lösung, um Fotos oder Dokumente zentral im Heimnetz zu sichern und verfügbar zu machen.</p>



<p><strong>Wichtig:</strong> Vor dem Kauf sollten Sie prüfen, ob Ihre Fritzbox über einen USB-3.0-Anschluss verfügt. Einsteiger-Modelle wie die <a href="http://www.amazon.de/dp/B09N8NJD66?tag=pcwelt.de-21&amp;ascsubtag=rss">Fritzbox 7510</a> bieten oft nur langsames USB 2.0, während Varianten ohne USB-Port gar nicht als Netzwerkspeicher genutzt werden können.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h2 class="wp-block-heading">Fritz Smart Thermo 302</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a0aceecc053d"}' data-wp-interactive="core/image" class="wp-block-image size-full is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/11/NL_18_FRITZDECT302.jpg?quality=50&amp;strip=all" alt="FRITZ!DECT 302 Heizkörperregler" class="wp-image-2992300" width="600" height="400" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">FRITZ!</p></div>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn shopping-cart-icon-white link-6-button" href="https://www.amazon.de/dp/B0G2T5J493?tag=pcwelt.de-21&amp;ascsubtag=4-0-3127694-7-0-0-0-0&amp;ascsubtag=rss" target="_blank" rel="nofollow" data-vars-link-position="CTA Button" data-domain-name="amazon" data-subtag="4-0-3127694-7-0-0-0-0">Fritz Smart Thermo 302 bei Amazon ansehen</a></div>


<p>Preis: 69 Euro</p>



<p><strong>Technik:</strong></p>



<ul class="wp-block-list">
<li>Display: Kontraststarkes und drehbares E-Paper-Display</li>



<li>Funkstandard: DECT ULE (Reichweite bis zu 40 Meter)</li>



<li>Funktionen: Fenster-auf-Erkennung, Frostschutz, Kalkschutz, Boost-Modus</li>



<li>Bedienung: Tasten am Gerät, App, PC oder Fritzfon</li>



<li>Montage: Kompatibel mit gängigen Ventilen (M30x1,5), Adapter inklusive</li>



<li>Extras: Gruppenschaltung, individuelle Heizprofile, Urlaubsmodus</li>



<li>Energie: Betrieb über zwei AA-Batterien</li>
</ul>



<p>Der <a href="https://www.amazon.de/dp/B0G2T5J493?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Fritz Smart Thermo 302</a> macht die Heizung zum Teil des Heimnetzes und ermöglicht eine zeitgesteuerte Regulierung der Raumtemperatur. Die Einrichtung erfolgt direkt über die Fritzbox, wobei für jeden Wochentag individuelle Heiz- und Absenkphasen festgelegt werden können. Ein klarer Vorteil gegenüber WLAN-Lösungen ist dabei der sparsame DECT-Funk, der lange Batterielaufzeiten ermöglicht.</p>



<p>Weil der Regler die Fenster-offen-Erkennung direkt integriert hat, regelt er die Temperatur bei plötzlichem Abfall automatisch herunter, um Energie zu sparen. Besonders komfortabel ist die Steuerung per Fritzfon oder eine Gruppenschaltung, bei der mehrere Heizkörper synchron auf eine Zieltemperatur eingestellt werden.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h2 class="wp-block-heading">Fritz-Repeater 6000 (Wi-Fi 6)</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a0aceecc0bdc"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/04/Fritz-Repeater-6000-WiFi-6.jpg?quality=50&amp;strip=all&amp;w=836" alt="Fritz-Repeater 6000 (WiFi 6)" class="wp-image-3127844" width="836" height="1200" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">FRITZ!</p></div>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn shopping-cart-icon-white link-6-button" href="https://www.amazon.de/dp/B092VWMBZ2?tag=pcwelt.de-21&amp;ascsubtag=4-0-3127694-7-0-0-0-0&amp;ascsubtag=rss" target="_blank" rel="nofollow" data-vars-link-position="CTA Button" data-domain-name="amazon" data-subtag="4-0-3127694-7-0-0-0-0">Fritz-Repeater 6000 (Wi-Fi 6) bei Amazon ansehen</a></div>


<p>Preis: 260 Euro</p>



<p><strong>Technik:</strong></p>



<ul class="wp-block-list">
<li>Standard: Wi-Fi 6 (WLAN AX)</li>



<li>Funkeinheiten: Drei (Triband-Technologie)</li>



<li>Geschwindigkeit: Bis zu 6.000 MBit/s (2.400 + 2.400 + 1.200 MBit/s)</li>



<li>Anschlüsse: 1x 2,5-Gigabit-LAN, 1x Gigabit-LAN</li>



<li>Funktionen: WLAN Mesh, intelligente Bandauswahl, WPS-Einrichtung</li>



<li>Sicherheit: WPA3-Verschlüsselung integriert</li>



<li>Bauweise: Standgerät mit externem Netzteil</li>
</ul>



<p>Der <a href="https://www.amazon.de/dp/B092VWMBZ2?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Fritz-Repeater 6000</a> ist das aktuell leistungsstärkste Modell im Fritz-Sortiment für Nutzer, die große Wohnflächen oder mehrere Etagen mit schnellem WLAN versorgen möchten (zumindest, <a href="https://www.pcwelt.de/article/3071845/fritz-schnellster-wlan-repeater-6700-pro-wifi-7-router-mwc-2026.html" target="_blank" rel="noreferrer noopener">bis der neue 6700 Pro in die Regale kommt</a>). Dank seiner drei Funkeinheiten steht hier ein eigenes Band exklusiv für die Kommunikation zwischen Router und Repeater zur Verfügung – der sonst übliche Geschwindigkeitsverlust wird dadurch halbiert.</p>



<p>Auch der 2,5-Gigabit-LAN-Port ist vorteilhaft: Er ermöglicht es, den Repeater per Kabel als schnellen Zugangspunkt (LAN-Brücke) zu nutzen oder datenhungrige Geräte wie Spielekonsolen oder PCs stabil anzubinden. Im Zusammenspiel mit einer <a href="https://www.pcwelt.de/article/1157690/fritzbox-router-im-vergleich-das-beste-modell.html" target="_blank" rel="noreferrer noopener">Fritzbox</a> bildet er ein nahtloses Mesh-Netzwerk, bei dem mobile Endgeräte automatisch immer mit dem stärksten Zugangspunkt verbunden werden.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h2 class="wp-block-heading">Fritz Smart Control 350 (magnetischer Tür-/Fensterkontakt)</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a0aceecc12f0"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/04/Fritz-Smart-Control-350.jpg?quality=50&amp;strip=all&amp;w=699" alt="Fritz Smart Control 350" class="wp-image-3127848" width="699" height="1200" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">FRITZ!</p></div>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn shopping-cart-icon-white link-6-button" href="https://www.amazon.de/dp/B0GHS4SMCJ?tag=pcwelt.de-21&amp;ascsubtag=4-0-3127694-7-0-0-0-0&amp;ascsubtag=rss" target="_blank" rel="nofollow" data-vars-link-position="CTA Button" data-domain-name="amazon" data-subtag="4-0-3127694-7-0-0-0-0">Fritz Smart Control 350 bei Amazon ansehen</a></div>


<p>Preis: 40 Euro</p>



<p><strong>Technik:</strong></p>



<ul class="wp-block-list">
<li>Typ: Magnetischer Sensor (zweiteilig: Sensor und Magnet)</li>



<li>Funkstandard: DECT ULE</li>



<li>Erkennung: Geöffnet, geschlossen oder gekippt (je nach Montage)</li>



<li>Montage: Klebestreifen für Rahmen oder Flügel</li>



<li>Energie: Betrieb mit 2x AAA-Batterien</li>



<li>Reichweite: Bis zu 40 Meter im Haus</li>



<li>Kompatibilität: Alle Fritzbox-Modelle mit DECT-Basis</li>
</ul>



<p>Mit dem <a href="https://www.amazon.de/dp/B0GHS4SMCJ?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Fritz Smart Control 350</a> verkauft Fritz einen dezenten Sensor, der den Status von Fenstern und Türen überwacht und diese Information an die Fritzbox weitergibt. Er dient als optimaler Partner für die smarten Heizkörperregler: Erkennt der Sensor ein offenes Fenster, kann die Heizung im jeweiligen Raum sofort automatisch heruntergeregelt werden. Das funktioniert effektiver als die rein temperaturbasierte Erkennung eines Thermostats.</p>



<p>Durch die kompakte Bauweise lässt sich der Magnet oft so im Rahmen montieren, dass er bei geschlossenem Fenster fast unsichtbar bleibt. Neben der Heizungssteuerung lassen sich auch einfache Sicherheits-Szenarien oder Push-Nachrichten aufs Smartphone einrichten, sobald eine Tür unbefugt geöffnet wird.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h2 class="wp-block-heading">Fritz DECT 210</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a0aceecc19e0"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/04/Fritz-Dect-210.jpg?quality=50&amp;strip=all&amp;w=831" alt="Fritz Dect 210" class="wp-image-3127852" width="831" height="1200" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">FRITZ!</p></div>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn shopping-cart-icon-white link-6-button" href="https://www.amazon.de/dp/B01MRZ60F0?tag=pcwelt.de-21&amp;ascsubtag=4-0-3127694-7-0-0-0-0&amp;ascsubtag=rss" target="_blank" rel="nofollow" data-vars-link-position="CTA Button" data-domain-name="amazon" data-subtag="4-0-3127694-7-0-0-0-0">Fritz DECT 210 bei Amazon ansehen</a></div>


<p>Preis: 42 Euro</p>



<p><strong>Technik:</strong></p>



<ul class="wp-block-list">
<li>Typ: Intelligente Steckdose für den Außenbereich</li>



<li>Schutzart: Spritzwasserschutz nach IP44</li>



<li>Belastbarkeit: Schaltet Geräte bis zu 3.450 Watt</li>



<li>Funkstandard: DECT ULE (Reichweite bis zu 300 Meter im Freien)</li>



<li>Funktionen: Messung von Energieverbrauch, Temperatur und Leistung</li>



<li>Schaltmodi: Zeitplan, Sonnenauf-/untergang, Google-Kalender, Zufall</li>



<li>Bedienung: App, Fritzfon, PC oder direkt am Gerät</li>
</ul>



<p>Smarte Funktionen im Garten, auf dem Balkon oder in der Garage: Die <a href="https://www.amazon.de/dp/B01MRZ60F0?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Fritz DECT 210</a> macht’s möglich. Dank des robusten Gehäuses inklusive Schutzklappe ist sie gegen Spritzwasser geschützt und hält auch wechselnden Temperaturen stand. Über die Fritzbox lässt sich die Steckdose schalten und als Energiemessgerät nutzen: Sie zeichnet den Stromverbrauch angeschlossener Geräte auf und wertet diesen in einer übersichtlichen Grafik aus.</p>



<p>Besonders praktisch für den Außenbereich ist die Astro-Funktion, die beispielsweise die Gartenbeleuchtung pünktlich zum Sonnenuntergang automatisch einschaltet, ohne dass man die Zeiten manuell nachjustieren muss.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h2 class="wp-block-heading">Fritz DECT-Repeater 100</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a0aceecc2105"}' data-wp-interactive="core/image" class="wp-block-image size-full is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/04/Fritz-DECT-Repeater-100.jpg?quality=50&amp;strip=all" alt="Fritz-DECT-Repeater 100" class="wp-image-3127854" width="665" height="821" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">FRITZ!</p></div>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn shopping-cart-icon-white link-6-button" href="https://www.amazon.de/dp/B00AQ9A9AQ?tag=pcwelt.de-21&amp;ascsubtag=4-0-3127694-7-0-0-0-0&amp;ascsubtag=rss" target="_blank" rel="nofollow" data-vars-link-position="CTA Button" data-domain-name="amazon" data-subtag="4-0-3127694-7-0-0-0-0">Fritz DECT-Repeater 100 bei Amazon ansehen</a></div>


<p>Preis:  78 Euro</p>



<p><strong>Technik:</strong></p>



<ul class="wp-block-list">
<li>Typ: Reichweitenverstärker für den DECT-Funk</li>



<li>Kapazität: Unterstützt bis zu drei Gespräche gleichzeitig</li>



<li>Funktionen: Überträgt HD-Telefonie, Internetradio und Podcasts</li>



<li>Sicherheit: Integrierte DECT-Verschlüsselung für abhörsichere Gespräche</li>



<li>Kompatibilität: Alle Fritzbox-Modelle mit DECT-Basis sowie GAP-Basistationen</li>



<li>Besonderheit: Integrierte Steckdose (kein Steckplatz geht verloren)</li>



<li>Einrichtung: Einfache Anmeldung per Tastendruck (WPS/DECT-Taste)</li>
</ul>



<p>Mit dem <a href="https://www.amazon.de/dp/B00AQ9A9AQ?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Fritz DECT-Repeater 100</a> gibt es eine Lösung für Haushalte, in denen das Funksignal des Telefons nicht bis in die letzte Ecke oder über mehrere Etagen reicht. Im Gegensatz zu einfachen Verstärkern unterstützt dieses Gerät bei Verbindung mit einer Fritzbox den vollen Funktionsumfang: Auch weit entfernt von der Basis bleiben HD-Telefonie, RSS-Feeds oder der Empfang von E-Mails am Fritzfon stabil.</p>



<p>Ebenfalls praktisch: das Gerät verfügt über eine integrierte Steckdose, damit steht der Anschluss an der Wand weiterhin für andere Elektrogeräte bereit. Durch die Unterstützung von automatischem Handover merkt man den Wechsel zwischen Basis und Repeater während eines Telefonats gar nicht.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h2 class="wp-block-heading">Fritz Smart Energy 250</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a0aceecc284e"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/04/Fritz-Smart-Energy-250.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Fritz Smart Energy 250" class="wp-image-3127856" width="1200" height="1200" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">FRITZ!</p></div>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn shopping-cart-icon-white link-6-button" href="https://www.amazon.de/dp/B0F1TNPHP4?tag=pcwelt.de-21&amp;ascsubtag=4-0-3127694-7-0-0-0-0&amp;ascsubtag=rss" target="_blank" rel="nofollow" data-vars-link-position="CTA Button" data-domain-name="amazon" data-subtag="4-0-3127694-7-0-0-0-0">Fritz Smart Energy 250 bei Amazon ansehen</a></div>


<p>Preis:  70 Euro</p>



<p><strong>Technik:</strong></p>



<ul class="wp-block-list">
<li>Typ: Intelligenter Stromsensor (Infrarot-Ausleseeinheit)</li>



<li>Schnittstelle: Magnetische Befestigung an der INFO-Schnittstelle</li>



<li>Funkstandard: DECT ULE</li>



<li>Stromversorgung: 2x AA-Batterien oder via USB-Anschluss</li>



<li>Kompatibilität: Für die meisten digitalen Stromzähler (Infrarot-Schnittstelle)</li>



<li>Auswertung: Fritz-App Smart Home, FritzOS oder Myfritz-Net</li>



<li>Features: Echtzeit-Verbrauchsdaten, historische Auswertung, Auslöser für Automationen</li>
</ul>



<p>Wer sich mehr Transparenz beim Stromverbrauch im ganzen Haushalt wünscht, greift zum <a href="https://www.amazon.de/dp/B0F1TNPHP4?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Fritz Smart Energy 250</a>. Anstatt manuell und mühsam den Zählerstand zu notieren, liest dieser Sensor die Daten direkt am digitalen Stromzähler aus und überträgt sie per Funk an die Fritzbox. Dadurch lässt sich der aktuelle Stromverbrauch jederzeit per App kontrollieren. Versteckten Energiefressern kommen Sie so besonders schnell auf die Schliche.</p>



<p>Besonders interessant für Smart-Home-Nutzer: Die gemessenen Werte können als Auslöser für verschiedene Szenarien dienen – so lässt sich beispielsweise eine Benachrichtigung einrichten, wenn die Leistungsaufnahme einen bestimmten Wert überschreitet.</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h2 class="wp-block-heading">Fritz Powerline 1260</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a0aceecc2f81"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/04/Fritz-Powerline-1260-Single-Adapter.jpg?quality=50&amp;strip=all&amp;w=679" alt="Fritz Powerline 1260 Single-Adapter" class="wp-image-3127861" width="679" height="1199" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">FRITZ!</p></div>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn shopping-cart-icon-white link-6-button" href="https://www.amazon.de/dp/B0752S866W?tag=pcwelt.de-21&amp;ascsubtag=4-0-3127694-7-0-0-0-0&amp;ascsubtag=rss" target="_blank" rel="nofollow" data-vars-link-position="CTA Button" data-domain-name="amazon" data-subtag="4-0-3127694-7-0-0-0-0">Fritz Powerline 1260 bei Amazon ansehen</a></div>


<p>Preis: 105 Euro</p>



<p><strong>Technik:</strong></p>



<ul class="wp-block-list">
<li>Typ: Powerline-Einzeladapter mit WLAN-Funktion</li>



<li>Geschwindigkeit (Stromnetz): Bis zu 1.200 MBit/s</li>



<li>WLAN: Dualband AC+N (bis zu 866 + 400 MBit/s)</li>



<li>Anschluss: 1x Gigabit-LAN-Port</li>



<li>Technologie: 2×2 MIMO (nutzt zwei Adernpaare im Stromnetz)</li>



<li>Sicherheit: WPA2-Verschlüsselung und ab Werk verschlüsselte Powerline-Verbindung</li>



<li>Mesh-Unterstützung: Automatische Übernahme der WLAN-Einstellungen der Fritzbox</li>
</ul>



<p><a href="https://www.amazon.de/dp/B0752S866W?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Fritz Powerline 1260</a> ist der Problemlöser für Räume, in denen weder WLAN-Signale noch Netzwerkkabel ankommen. Weil Daten damit über die Stromleitung transportiert werden, lassen sich selbst massive Wände oder weite Strecken zum Keller oder Dachboden überbrücken. An der Zielsteckdose fungiert der Adapter gleichzeitig als LAN-Anschluss für Geräte wie Smart-TVs oder Spielekonsolen und als WLAN-Access-Point. Innerhalb eines Fritz-Heimnetzes integriert er sich nahtlos in das Mesh-System, sodass mobile Geräte ohne Verbindungsabbruch zwischen Router und Powerline-Adapter wechseln können.</p>



<p><strong>Hinweis:</strong> Da es sich hier um einen Einzeladapter handelt, wird für den Aufbau eines Powerline-Netzwerks ein zweites Gegenstück (ein weiterer Powerline-Adapter) benötigt, das per LAN-Kabel mit der Fritzbox verbunden ist.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-0265: Authentication Bypass in Palo Alto Networks PAN-OS]]></title>
<description><![CDATA[OverviewOn May 13, 2026, Palo Alto Networks published a security advisory for CVE-2026-0265, a signature verification vulnerability that facilitates authentication bypass on PAN-OS, the operating system that most Palo Alto Networks firewalls run. This vulnerability allows a remote unauthenticated...]]></description>
<link>https://tsecurity.de/de/3517781/it-security-nachrichten/cve-2026-0265-authentication-bypass-in-palo-alto-networks-pan-os/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3517781/it-security-nachrichten/cve-2026-0265-authentication-bypass-in-palo-alto-networks-pan-os/</guid>
<pubDate>Thu, 14 May 2026 21:52:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3><span>Overview</span></h3><p><span>On May 13, 2026, Palo Alto Networks published a </span><a href="https://security.paloaltonetworks.com/CVE-2026-0265" target="_blank"><span>security advisory</span></a><span> for </span><a href="https://www.cve.org/CVERecord?id=CVE-2026-0265" target="_blank"><span>CVE-2026-0265</span></a><span>, a </span><a href="https://cwe.mitre.org/data/definitions/347.html" target="_blank"><span>signature verification vulnerability</span></a><span> that facilitates authentication bypass on </span><a href="https://docs.paloaltonetworks.com/pan-os" target="_blank"><span>PAN-OS</span></a><span>, the operating system that most Palo Alto Networks firewalls run. This vulnerability allows a remote unauthenticated attacker with network access to bypass authentication when </span><a href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-new-features/identity-features/cloud-identity-engine" target="_blank"><span>Cloud Authentication Service (CAS)</span></a><span> is enabled and attached to a login interface; the vulnerable configuration is non-default but common. CVE-2026-0265 affects PAN-OS on PA-Series and VM-Series firewalls, as well as Panorama (virtual and M-Series) appliances. Cloud NGFW and Prisma Access are not affected.</span></p><p><span>Palo Alto Networks </span><a href="https://security.paloaltonetworks.com/CVE-2026-0265#Severity:%20HIGH" target="_blank"><span>assigned</span></a><span> CVE-2026-0265 a “High” 7.2 CVSS score. The advisory states that the vulnerability’s severity scoring depends on interface exposure; according to the vendor, risk is highest for unrestricted management interfaces equipped with CAS, while other login portals, such as GlobalProtect gateways, are lower risk. However, the researcher who reported the vulnerability, </span><a href="https://x.com/rootxharsh" target="_blank"><span>Harsh Jaiswal</span></a><span> of </span><a href="https://www.hacktron.ai/" target="_blank"><span>HacktronAI</span></a><span>, </span><span><strong>publicly disputed the vendor’s severity rating</strong></span><span>. Jaiswal </span><a href="https://x.com/rootxharsh/status/2054862374621032774" target="_blank"><span>stated</span></a><span> on social media that the vulnerability advisory misrepresents the criticality of the bug and the affected components; according to the HacktronAI research team, they successfully exploited CVE-2026-0265 to bypass authentication controls on multiple corporations’ GlobalProtect portals and establish VPN access. Jaiswal </span><a href="https://x.com/rootxharsh/status/2054924700971921635" target="_blank"><span>stated</span></a><span> that </span><span><strong>internet-facing components are affected</strong></span><span>, and HacktronAI </span><a href="https://x.com/rootxharsh/status/2054862374621032774" target="_blank"><span>plans to disclose</span></a><span> full technical details the week of May 18.</span></p><p><span>As of May 14, Palo Alto Networks has not confirmed exploitation in-the-wild of CVE-2026-0265, and there is no public proof-of-concept exploit available. However, given the researcher's statements about the practical exploitability of this vulnerability and the pending disclosure of technical details, this will likely evolve. PAN-OS software has been a frequent target for threat actors; on May 6, 2026, the PAN-OS vulnerability </span><a href="https://www.rapid7.com/blog/post/etr-critical-buffer-overflow-in-palo-alto-networks-pan-os-user-id-authentication-portal-cve-2026-0300/" target="_blank"><span>CVE-2026-0300</span></a><span> was </span><a href="https://www.cisa.gov/news-events/alerts/2026/05/06/cisa-adds-one-known-exploited-vulnerability-catalog" target="_blank"><span>added</span></a><span> to CISA's Known Exploited Vulnerabilities (KEV) catalog. Patches for many affected version streams </span><a href="https://security.paloaltonetworks.com/CVE-2026-0265#Solution" target="_blank"><span>were published</span></a><span> on May 13, and the remaining patches </span><a href="https://security.paloaltonetworks.com/CVE-2026-0265#Solution" target="_blank"><span>are expected</span></a><span> on May 28, 2026.</span></p><h3><span>Mitigation guidance</span></h3><p><span>Organizations running PA-Series or VM-Series firewalls, or Panorama (virtual and M-Series) appliances, with Cloud Authentication Service (CAS) enabled should upgrade to a fixed version on an emergency basis. Patches are partially available, with many version stream fixes published on May 13 and additional version stream coverage expected on May 28. The following table outlines the affected and fixed versions:</span></p><table><thead><tr><th><p><span><strong>PAN-OS version</strong></span></p></th><th><p><span><strong>Affected</strong></span></p></th><th><p><span><strong>Fixed</strong></span></p></th></tr></thead><tbody><tr><td><p><span>12.1</span></p></td><td><p><span>&lt; 12.1.4-h5</span></p><p><span>&lt; 12.1.7</span></p></td><td><p><span>&gt;= 12.1.4-h5</span></p><p><span>&gt;= 12.1.7 (ETA: 05/28)</span></p></td></tr><tr><td><p><span>11.2</span></p></td><td><p><span>&lt; 11.2.4-h17</span></p><p><span>&lt; 11.2.7-h13</span></p><p><span>&lt; 11.2.10-h6</span></p><p><span>&lt; 11.2.12</span></p></td><td><p><span>&gt;= 11.2.4-h17 (ETA: 05/28)</span></p><p><span>&gt;= 11.2.7-h13</span></p><p><span>&gt;= 11.2.10-h6</span></p><p><span>&gt;= 11.2.12 (ETA: 05/28)</span></p></td></tr><tr><td><p><span>11.1</span></p></td><td><p><span>&lt; 11.1.4-h33</span></p><p><span>&lt; 11.1.6-h32</span></p><p><span>&lt; 11.1.7-h6</span></p><p><span>&lt; 11.1.10-h25</span></p><p><span>&lt; 11.1.13-h5</span></p><p><span>&lt; 11.1.15</span></p></td><td><p><span>&gt;= 11.1.4-h33</span></p><p><span>&gt;= 11.1.6-h32</span></p><p><span>&gt;= 11.1.7-h6 (ETA: 05/28)</span></p><p><span>&gt;= 11.1.10-h25</span></p><p><span>&gt;= 11.1.13-h5</span></p><p><span>&gt;= 11.1.15 (ETA: 05/28)</span></p></td></tr><tr><td><p><span>10.2</span></p></td><td><p><span>&lt; 10.2.7-h34</span></p><p><span>&lt; 10.2.10-h36</span></p><p><span>&lt; 10.2.13-h21</span></p><p><span>&lt; 10.2.16-h7</span></p><p><span>&lt; 10.2.18-h6</span></p></td><td><p><span>&gt;= 10.2.7-h34 (ETA: 05/28)</span></p><p><span>&gt;= 10.2.10-h36</span></p><p><span>&gt;= 10.2.13-h21 (ETA: 05/28)</span></p><p><span>&gt;= 10.2.16-h7 (ETA: 05/28)</span></p><p><span>&gt;= 10.2.18-h6</span></p></td></tr><tr><td><p><span>Cloud NGFW</span></p></td><td><p><span>Not affected</span></p></td><td><p><span>N/A</span></p></td></tr><tr><td><p><span>Prisma Access</span></p></td><td><p><span>Not affected</span></p></td><td><p><span>N/A</span></p></td></tr></tbody></table><p><span>Older unsupported PAN-OS versions should be upgraded to a supported fixed version.</span></p><p><span>To determine if an environment is vulnerable, the official advisory </span><a href="https://security.paloaltonetworks.com/CVE-2026-0265#Required%20Configuration%20for%20Exposure" target="_blank"><span>provides instructions</span></a><span> to verify whether an authentication profile using CAS is enabled and attached to a login interface. Due to discrepancies in the information shared by the vendor and reporting researchers, Rapid7 advises patching instead of implementing workarounds, wherever possible.</span></p><p><span>For the latest official mitigation guidance, please refer to the </span><a href="https://security.paloaltonetworks.com/CVE-2026-0265" target="_blank"><span>vendor advisory</span></a><span>.</span></p><h3><span>Rapid7 customers</span></h3><p><span>Exposure Command, InsightVM, and Nexpose customers can assess exposure to CVE-2026-0265 with authenticated checks expected to be available in the May 15th content release.</span></p><h3><span>Updates</span></h3><ul><li><span><strong>May 14, 2026</strong></span><span>: Initial publication.</span></li></ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-0236 | Palo Alto Prisma Browser prior 146.16.6.165 AppleScript Interface code injection (EUVD-2026-30089)]]></title>
<description><![CDATA[A vulnerability categorized as critical has been discovered in Palo Alto Prisma Browser. This impacts an unknown function of the component AppleScript Interface. Executing a manipulation can lead to code injection.

This vulnerability appears as CVE-2026-0236. The attack requires local access. Th...]]></description>
<link>https://tsecurity.de/de/3515172/sicherheitsluecken/cve-2026-0236-palo-alto-prisma-browser-prior-146166165-applescript-interface-code-injection-euvd-2026-30089/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3515172/sicherheitsluecken/cve-2026-0236-palo-alto-prisma-browser-prior-146166165-applescript-interface-code-injection-euvd-2026-30089/</guid>
<pubDate>Thu, 14 May 2026 00:09:19 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">critical</a> has been discovered in <a href="https://vuldb.com/product/palo_alto:prisma_browser">Palo Alto Prisma Browser</a>. This impacts an unknown function of the component <em>AppleScript Interface</em>. Executing a manipulation can lead to code injection.

This vulnerability appears as <a href="https://vuldb.com/cve/CVE-2026-0236">CVE-2026-0236</a>. The attack requires local access. There is no available exploit.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-0261 | Palo Alto Cloud NGFW/PAN-OS/Prisma Access Management Web Interface os command injection (EUVD-2026-30107)]]></title>
<description><![CDATA[A vulnerability categorized as critical has been discovered in Palo Alto Cloud NGFW, PAN-OS and Prisma Access. This issue affects some unknown processing of the component Management Web Interface. Such manipulation leads to os command injection.

This vulnerability is documented as CVE-2026-0261....]]></description>
<link>https://tsecurity.de/de/3515171/sicherheitsluecken/cve-2026-0261-palo-alto-cloud-ngfwpan-osprisma-access-management-web-interface-os-command-injection-euvd-2026-30107/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3515171/sicherheitsluecken/cve-2026-0261-palo-alto-cloud-ngfwpan-osprisma-access-management-web-interface-os-command-injection-euvd-2026-30107/</guid>
<pubDate>Thu, 14 May 2026 00:09:18 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">critical</a> has been discovered in <a href="https://vuldb.com/product/palo_alto:cloud_ngfw">Palo Alto Cloud NGFW, PAN-OS and Prisma Access</a>. This issue affects some unknown processing of the component <em>Management Web Interface</em>. Such manipulation leads to os command injection.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2026-0261">CVE-2026-0261</a>. The attack needs to be performed locally. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-0262 | Palo Alto Cloud NGFW/PAN-OS/Prisma Access unusual condition (EUVD-2026-30108)]]></title>
<description><![CDATA[A vulnerability identified as critical has been detected in Palo Alto Cloud NGFW, PAN-OS and Prisma Access. Impacted is an unknown function. Performing a manipulation results in improper check for unusual conditions.

This vulnerability is reported as CVE-2026-0262. The attack is possible to be c...]]></description>
<link>https://tsecurity.de/de/3515165/sicherheitsluecken/cve-2026-0262-palo-alto-cloud-ngfwpan-osprisma-access-unusual-condition-euvd-2026-30108/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3515165/sicherheitsluecken/cve-2026-0262-palo-alto-cloud-ngfwpan-osprisma-access-unusual-condition-euvd-2026-30108/</guid>
<pubDate>Thu, 14 May 2026 00:09:10 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">critical</a> has been detected in <a href="https://vuldb.com/product/palo_alto:cloud_ngfw">Palo Alto Cloud NGFW, PAN-OS and Prisma Access</a>. Impacted is an unknown function. Performing a manipulation results in improper check for unusual conditions.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2026-0262">CVE-2026-0262</a>. The attack is possible to be carried out remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-0263 | Palo Alto Cloud NGFW/PAN-OS/Prisma Access IKEv2 out-of-bounds write (EUVD-2026-30064)]]></title>
<description><![CDATA[A vulnerability identified as critical has been detected in Palo Alto Cloud NGFW, PAN-OS and Prisma Access. Affected is an unknown function of the component IKEv2 Handler. The manipulation leads to out-of-bounds write.

This vulnerability is traded as CVE-2026-0263. It is possible to initiate the...]]></description>
<link>https://tsecurity.de/de/3515164/sicherheitsluecken/cve-2026-0263-palo-alto-cloud-ngfwpan-osprisma-access-ikev2-out-of-bounds-write-euvd-2026-30064/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3515164/sicherheitsluecken/cve-2026-0263-palo-alto-cloud-ngfwpan-osprisma-access-ikev2-out-of-bounds-write-euvd-2026-30064/</guid>
<pubDate>Thu, 14 May 2026 00:09:09 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">critical</a> has been detected in <a href="https://vuldb.com/product/palo_alto:cloud_ngfw">Palo Alto Cloud NGFW, PAN-OS and Prisma Access</a>. Affected is an unknown function of the component <em>IKEv2 Handler</em>. The manipulation leads to out-of-bounds write.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2026-0263">CVE-2026-0263</a>. It is possible to initiate the attack remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-0264 | Palo Alto Cloud NGFW/PAN-OS/Prisma Access DNS Proxy/DNS Server heap-based overflow (EUVD-2026-30065)]]></title>
<description><![CDATA[A vulnerability labeled as critical has been found in Palo Alto Cloud NGFW, PAN-OS and Prisma Access. Affected by this vulnerability is an unknown functionality of the component DNS Proxy/DNS Server. The manipulation results in heap-based buffer overflow.

This vulnerability is known as CVE-2026-...]]></description>
<link>https://tsecurity.de/de/3515163/sicherheitsluecken/cve-2026-0264-palo-alto-cloud-ngfwpan-osprisma-access-dns-proxydns-server-heap-based-overflow-euvd-2026-30065/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3515163/sicherheitsluecken/cve-2026-0264-palo-alto-cloud-ngfwpan-osprisma-access-dns-proxydns-server-heap-based-overflow-euvd-2026-30065/</guid>
<pubDate>Thu, 14 May 2026 00:09:08 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/palo_alto:cloud_ngfw">Palo Alto Cloud NGFW, PAN-OS and Prisma Access</a>. Affected by this vulnerability is an unknown functionality of the component <em>DNS Proxy/DNS Server</em>. The manipulation results in heap-based buffer overflow.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2026-0264">CVE-2026-0264</a>. It is possible to launch the attack remotely. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-0265 | Palo Alto Cloud NGFW/PAN-OS/Prisma Access Management Interface signature verification (EUVD-2026-30066)]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in Palo Alto Cloud NGFW, PAN-OS and Prisma Access. Affected by this issue is some unknown functionality of the component Management Interface. This manipulation causes improper verification of cryptographic signature.

This vulnerability is han...]]></description>
<link>https://tsecurity.de/de/3515162/sicherheitsluecken/cve-2026-0265-palo-alto-cloud-ngfwpan-osprisma-access-management-interface-signature-verification-euvd-2026-30066/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3515162/sicherheitsluecken/cve-2026-0265-palo-alto-cloud-ngfwpan-osprisma-access-management-interface-signature-verification-euvd-2026-30066/</guid>
<pubDate>Thu, 14 May 2026 00:09:06 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">critical</a> has been reported in <a href="https://vuldb.com/product/palo_alto:cloud_ngfw">Palo Alto Cloud NGFW, PAN-OS and Prisma Access</a>. Affected by this issue is some unknown functionality of the component <em>Management Interface</em>. This manipulation causes improper verification of cryptographic signature.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2026-0265">CVE-2026-0265</a>. The attack can be initiated remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-0237 | Palo Alto Prisma Browser prior 146.16.6.165 improper protection of alternate path (EUVD-2026-30062)]]></title>
<description><![CDATA[A vulnerability classified as critical was found in Palo Alto Prisma Browser. The impacted element is an unknown function. The manipulation results in improper protection of alternate path.

This vulnerability was named CVE-2026-0237. The attack needs to be approached locally. There is no availab...]]></description>
<link>https://tsecurity.de/de/3515161/sicherheitsluecken/cve-2026-0237-palo-alto-prisma-browser-prior-146166165-improper-protection-of-alternate-path-euvd-2026-30062/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3515161/sicherheitsluecken/cve-2026-0237-palo-alto-prisma-browser-prior-146166165-improper-protection-of-alternate-path-euvd-2026-30062/</guid>
<pubDate>Thu, 14 May 2026 00:09:05 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> was found in <a href="https://vuldb.com/product/palo_alto:prisma_browser">Palo Alto Prisma Browser</a>. The impacted element is an unknown function. The manipulation results in improper protection of alternate path.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-0237">CVE-2026-0237</a>. The attack needs to be approached locally. There is no available exploit.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-0257 | Palo Alto Cloud NGFW/PAN-OS/Prisma Access GlobalProtect Portal cookie validation (EUVD-2026-30104)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in Palo Alto Cloud NGFW, PAN-OS and Prisma Access. This affects an unknown part of the component GlobalProtect Portal. Such manipulation leads to cookies without validation.

This vulnerability is uniquely identified as CVE-2026-0257. The ...]]></description>
<link>https://tsecurity.de/de/3515101/sicherheitsluecken/cve-2026-0257-palo-alto-cloud-ngfwpan-osprisma-access-globalprotect-portal-cookie-validation-euvd-2026-30104/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3515101/sicherheitsluecken/cve-2026-0257-palo-alto-cloud-ngfwpan-osprisma-access-globalprotect-portal-cookie-validation-euvd-2026-30104/</guid>
<pubDate>Wed, 13 May 2026 23:36:05 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">critical</a> has been identified in <a href="https://vuldb.com/product/palo_alto:cloud_ngfw">Palo Alto Cloud NGFW, PAN-OS and Prisma Access</a>. This affects an unknown part of the component <em>GlobalProtect Portal</em>. Such manipulation leads to cookies without validation.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2026-0257">CVE-2026-0257</a>. The attack can be launched remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-0256 | Palo Alto Cloud NGFW/PAN-OS/Prisma Access Web Interface cross site scripting (EUVD-2026-30103)]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in Palo Alto Cloud NGFW, PAN-OS and Prisma Access. Impacted is an unknown function of the component Web Interface. Executing a manipulation can lead to cross site scripting.

This vulnerability is handled as CVE-2026-0256. The attack ca...]]></description>
<link>https://tsecurity.de/de/3515100/sicherheitsluecken/cve-2026-0256-palo-alto-cloud-ngfwpan-osprisma-access-web-interface-cross-site-scripting-euvd-2026-30103/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3515100/sicherheitsluecken/cve-2026-0256-palo-alto-cloud-ngfwpan-osprisma-access-web-interface-cross-site-scripting-euvd-2026-30103/</guid>
<pubDate>Wed, 13 May 2026 23:36:03 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">problematic</a> has been identified in <a href="https://vuldb.com/product/palo_alto:cloud_ngfw">Palo Alto Cloud NGFW, PAN-OS and Prisma Access</a>. Impacted is an unknown function of the component <em>Web Interface</em>. Executing a manipulation can lead to cross site scripting.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2026-0256">CVE-2026-0256</a>. The attack can be executed remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-0235 | Palo Alto Prisma Browser prior 146.16.6.165 unusual condition (EUVD-2026-30087)]]></title>
<description><![CDATA[A vulnerability was found in Palo Alto Prisma Browser. It has been rated as problematic. This vulnerability affects unknown code. This manipulation causes improper check for unusual conditions.

This vulnerability is registered as CVE-2026-0235. The attack needs to be launched locally. No exploit...]]></description>
<link>https://tsecurity.de/de/3515099/sicherheitsluecken/cve-2026-0235-palo-alto-prisma-browser-prior-146166165-unusual-condition-euvd-2026-30087/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3515099/sicherheitsluecken/cve-2026-0235-palo-alto-prisma-browser-prior-146166165-unusual-condition-euvd-2026-30087/</guid>
<pubDate>Wed, 13 May 2026 23:36:02 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/palo_alto:prisma_browser">Palo Alto Prisma Browser</a>. It has been rated as <a href="https://vuldb.com/kb/risk">problematic</a>. This vulnerability affects unknown code. This manipulation causes improper check for unusual conditions.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2026-0235">CVE-2026-0235</a>. The attack needs to be launched locally. No exploit is available.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-0258 | Palo Alto Cloud NGFW/PAN-OS/Prisma Access IKEv2 server-side request forgery (EUVD-2026-30105)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in Palo Alto Cloud NGFW, PAN-OS and Prisma Access. Impacted is an unknown function of the component IKEv2 Handler. The manipulation leads to server-side request forgery.

This vulnerability is referenced as CVE-2026-0258. Remote ex...]]></description>
<link>https://tsecurity.de/de/3515098/sicherheitsluecken/cve-2026-0258-palo-alto-cloud-ngfwpan-osprisma-access-ikev2-server-side-request-forgery-euvd-2026-30105/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3515098/sicherheitsluecken/cve-2026-0258-palo-alto-cloud-ngfwpan-osprisma-access-ikev2-server-side-request-forgery-euvd-2026-30105/</guid>
<pubDate>Wed, 13 May 2026 23:36:01 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, has been found in <a href="https://vuldb.com/product/palo_alto:cloud_ngfw">Palo Alto Cloud NGFW, PAN-OS and Prisma Access</a>. Impacted is an unknown function of the component <em>IKEv2 Handler</em>. The manipulation leads to server-side request forgery.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2026-0258">CVE-2026-0258</a>. Remote exploitation of the attack is possible. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[RTL Mediathek: Barbara Salesch - Das Strafgericht im Stream - Prisma]]></title>
<description><![CDATA[Barbara Salesch - Das Strafgericht - Hacker-Angriff auf Taxi - Tragischer Crash mit schwangerem Fahrgast. Doku-Soap, Serie • Do., 23.04. • 43 Min ...]]></description>
<link>https://tsecurity.de/de/3503297/hacking/rtl-mediathek-barbara-salesch-das-strafgericht-im-stream-prisma/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3503297/hacking/rtl-mediathek-barbara-salesch-das-strafgericht-im-stream-prisma/</guid>
<pubDate>Sat, 09 May 2026 17:26:48 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Barbara Salesch - Das Strafgericht - <b>Hacker</b>-Angriff auf Taxi - Tragischer Crash mit schwangerem Fahrgast. Doku-Soap, Serie • Do., 23.04. • 43 Min ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Proactive Preparation and Hardening Against Destructive Attacks: 2026 Edition]]></title>
<description><![CDATA[Written by: Matthew McWhirt, Bhavesh Dhake, Emilio Oropeza, Gautam Krishnan, Stuart Carrera, Greg Blaum, Michael Rudden

UPDATE (March 13): Added guidance around abuse or misuse of endpoint / MDM platforms.
Background
Threat actors leverage destructive malware to destroy data, eliminate evidence ...]]></description>
<link>https://tsecurity.de/de/3501421/it-security-nachrichten/proactive-preparation-and-hardening-against-destructive-attacks-2026-edition/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501421/it-security-nachrichten/proactive-preparation-and-hardening-against-destructive-attacks-2026-edition/</guid>
<pubDate>Fri, 08 May 2026 23:19:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><p>Written by: Matthew McWhirt, Bhavesh Dhake, Emilio Oropeza, Gautam Krishnan, Stuart Carrera, Greg Blaum, Michael Rudden</p>
<hr></div>
<div class="block-paragraph_advanced"><p><em>UPDATE (March 13): <span>Added guidance around abuse or misuse of endpoint / MDM platforms</span>.</em></p>
<h3><span>Background</span></h3>
<p><span>Threat actors leverage destructive malware to destroy data, eliminate evidence of malicious activity, or manipulate systems in a way that renders them inoperable. Destructive cyberattacks can be a powerful means to achieve strategic or tactical objectives; however, the risk of reprisal is likely to limit the frequency of use to very select incidents. Destructive cyberattacks can include destructive malware, wipers, or modified ransomware.</span></p>
<p><span><span>When conflict erupts, cyber attacks are an inexpensive and easily deployable weapon. It should come as no surprise that instability leads to increases in attacks. </span>This blog post provides proactive recommendations for organizations to prioritize for protecting against a destructive attack within an environment. The recommendations include practical and scalable methods that can help protect organizations from not only destructive attacks, but potential incidents where a threat actor is attempting to perform reconnaissance, escalate privileges, laterally move, maintain access, and achieve their mission. </span></p>
<p><span>The detection opportunities outlined in this blog post are meant to act as supplementary monitoring to existing security tools. Organizations should leverage endpoint and network security tools as additional preventative and detective measures. These tools use a broad spectrum of detective capabilities, including signatures and heuristics, to detect malicious activity with a reasonable degree of fidelity. The custom detection opportunities referenced in this blog post are correlated to specific threat actor behavior and are meant to trigger anomalous activity that is identified by its divergence from normal patterns. Effective monitoring is dependent on a thorough understanding of an organization's unique environment and usage of pre-established baselines.</span></p>
<h3><span>Organizational Resilience</span></h3>
<p><span>While the core focus of this blog post is aligned to technical- and tactical-focused security controls, technical preparation and recovery are not the </span><span>only</span><span> strategies. Organizations that include crisis preparation and orchestration as key components of security governance can naturally adopt a "living" resilience posture. This includes:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Out-of-Band Incident Command and Communication</strong><span>: Establish a pre-validated, "out-of-band" communication platform that is completely decoupled from the corporate identity plane. This ensures that the key stakeholders and third-party support teams can coordinate and communicate securely, even if the primary communication platform is unavailable.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Defined Operational Contingency and Recovery Plans: </strong><span>Establish baseline operational requirements, including manual procedures for vital business functions to ensure continuity during restoration or rebuild efforts. Organizations must also develop prioritized application recovery sequences and map the essential dependencies needed to establish a secure foundation for recovery goals.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Pre-Establish Trusted Third-Party Vendor Relationships: </strong><span>Based on the range of technologies and platforms vital to business operations, develop predefined agreements with external partners to ensure access to specialists for legal / contractual requirements, incident response, remediation, recovery, and ransomware negotiations.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Practice and Refine the Recovery: </strong><span>Conduct exercises that validate the end-to-end restoration of mission-critical services using isolated, immutable backups and out-of-band communication channels, ensuring that recovery timelines (RTO) and data integrity (RPO) are tested, practiced, and current. </span></p>
</li>
</ul>
<h3><span>Google Security Operations</span></h3>
<p><a href="https://cloud.google.com/security/products/security-operations"><span>Google Security Operations</span></a><span> (SecOps) customers have access to these broad category rules and more under the Mandiant Intel Emerging Threats, Mandiant Frontline Threats, Mandiant Hunting Rules, CDIR SCC Enhanced Data Destruction Alerts rule packs. The activity discussed in the blog post is detected in Google SecOps under the rule names:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>BABYWIPER File Erasure</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Secure Evidence Destruction And Cleanup Commands</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>CMD Launching Application Self Delete</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Copy Binary From Downloads</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Rundll32 Execution Of Dll Function Name Containing Special Character</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Services Launching Cmd</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>System Process Execution Via Scheduled Task</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Dllhost Masquerading</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Backdoor Writing Dll To Disk For Injection</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Multiple Exclusions Added To Windows Defender In Single Command</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Path Exclusion Added to Windows Defender</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Registry Change to CurrentControlSet Services</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Powershell Set Content Value Of 0</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Overwrite Disk Using DD Utility</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Bcdedit Modifications Via Command</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Disabling Crash Dump For Drive Wiping</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Suspicious Wbadmin Commands</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Fsutil File Zero Out</span></p>
</li>
</ul></div>
<div class="block-paragraph_advanced"><h3><span>Recommendations Summary</span></h3>
<p><span>Table 1 provides a high-level overview of guidance in this blog post.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Focus Area</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><a href="https://cloud.google.com/blog/topics/threat-intelligence/preparation-hardening-destructive-attacks#:~:text=1.%20External-Facing%20Assets"><span>External-Facing Assets</span></a></p>
</td>
<td>
<p><span>Protect against the risk of threat actors exploiting an externally facing vector or leveraging existing technology for unauthorized remote access.</span></p>
</td>
</tr>
<tr>
<td>
<p><a href="https://cloud.google.com/blog/topics/threat-intelligence/preparation-hardening-destructive-attacks#:~:text=2.%20Critical%20Asset%20Protections"><span>Critical Asset Protections</span></a></p>
</td>
<td>
<p><span>Protect specific high-value infrastructure and prepare for recovery from a destructive attack.</span></p>
</td>
</tr>
<tr>
<td>
<p><a href="https://cloud.google.com/blog/topics/threat-intelligence/preparation-hardening-destructive-attacks#:~:text=3.%20On-Premises%20Lateral%20Movement%20Protections"><span>On-Premises Lateral Movement Protections</span></a></p>
</td>
<td>
<p><span>Protect against a threat actor with initial access into an environment from moving laterally to further expand their scope of access and persistence.</span></p>
</td>
</tr>
<tr>
<td>
<p><a href="https://cloud.google.com/blog/topics/threat-intelligence/preparation-hardening-destructive-attacks#:~:text=4.%20Credential%20Exposure%20and%20Account%20Protections"><span>Credential Exposure and Account Protections</span></a></p>
</td>
<td>
<p><span>Protect against the exposure of privileged credentials to facilitate privilege escalation.</span></p>
</td>
</tr>
<tr>
<td>
<p><a href="https://cloud.google.com/blog/topics/threat-intelligence/preparation-hardening-destructive-attacks#:~:text=5.%20Preventing%20Destructive%20Actions%20in%20Kubernetes%20and%20CI%2FCD%20Pipelines"><span>Preventing Destructive Actions in Kubernetes and CI/CD Pipelines</span></a></p>
</td>
<td>
<p><span>Protect the integrity and availability of Kubernetes environments and CI/CD pipelines.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span><span>Table 1: </span><span>Overview of recommendations</span></span></div></div>
<div class="block-paragraph_advanced"><h3><span>1. External-Facing Assets</span></h3>
<h4><span>Identify, Enumerate, and Harden</span></h4>
<p><span>To protect against a threat actor exploiting vulnerabilities or misconfigurations via an external-facing vector, organizations must determine the scope of applications and organization-managed services that are externally accessible. Externally accessible applications and services (including both on-premises and cloud) are often targeted by threat actors for initial access by exploiting known vulnerabilities, brute-forcing common or default credentials, or authenticating using valid credentials. </span></p>
<p><span>To proactively identify and validate external-facing applications and services, consider:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Leveraging a </span><span>vulnerability scanning technology to identify assets and associated vulnerabilities. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Performing a focused vulnerability assessment or penetration test with the goal of identifying external-facing vectors that could be leveraged for authentication and access.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Verifying with technology vendors if the products leveraged by an organization for external-facing services require patches or updates to mitigate known vulnerabilities. </span></p>
</li>
</ul>
<p><span>Any identified vulnerabilities should not only be patched and hardened, but the identified technology platforms should also be reviewed to ensure that evidence of suspicious activity or technology/device modifications have not already occurred.</span></p>
<p><span>The following table provides an overview of capabilities to proactively review and identify external-facing assets and resources within common cloud-based infrastructures.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Cloud Provider</strong></p>
</td>
<td>
<p><strong>Attack Surface Discovery Capability</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Google Cloud</span></p>
</td>
<td>
<p><a href="https://cloud.google.com/security/products/security-command-center"><span>Security Command Center</span></a></p>
</td>
</tr>
<tr>
<td>
<p><span>Amazon Web Services</span></p>
</td>
<td>
<p><a href="https://docs.aws.amazon.com/inspector/latest/user/what-is-inspector.html" rel="noopener" target="_blank"><span>AWS Config / Inspector</span></a></p>
</td>
</tr>
<tr>
<td>
<p><span>Microsoft Azure</span></p>
</td>
<td>
<p><a href="https://learn.microsoft.com/en-us/azure/external-attack-surface-management/" rel="noopener" target="_blank"><span>Defender External Attack Surface Management (Defender EASM</span></a><span>)</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span><span>Table 2: Overview of cloud provider attack surface discovery capabilities</span></span></div></div>
<div class="block-paragraph_advanced"><h4><span>Enforce Multi-Factor Authentication</span></h4>
<p><span>External-facing assets that leverage single-factor authentication (SFA) are highly susceptible to brute-forcing attacks, password spraying, or unauthorized remote access using valid (stolen) credentials. External-facing applications and services that currently allow for SFA should be configured to support multi-factor authentication (MFA). Additionally, MFA should be leveraged for accessing not only on-premises external-facing managed infrastructure, but also for cloud-based resources (e.g., software-as-a-service [SaaS] such as Microsoft 365 [M365]). </span></p>
<p><span>When configuring multifactor authentication, the following methods are commonly considered (and ranked from most to least secure):</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Fast IDentity Online 2 (FIDO2)/WebAuthn security keys or passkeys</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Software/hardware Open Authentication (OAUTH) token</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Authenticator application (e.g., Duo/Microsoft [MS] Authenticator/Okta Verify)</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Time-based One Time Password (TOTP)</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Push notification (least preferred option) using number matching when possible</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Phone call</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Short Message Service (SMS) verification</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Email-based verification</span></p>
</li>
</ul>
<h4><span>Risks of Specific MFA Methods</span></h4>
<h5><span>Push Notifications</span></h5>
<p><span>If an organization is leveraging push notifications for MFA (e.g., a notification that requires acceptance via an application or automated call to a mobile device), threat actors can exploit this type of MFA configuration for attempted access, as a user may inadvertently accept a push notification on their device without the context of where the authentication was initiated. </span></p>
<h5><span>Phone/SMS Verification</span></h5>
<p><span>If an organization is leveraging phone calls or SMS-based verification for MFA, these methods are not encrypted and are susceptible to potentially being intercepted by a threat actor. These methods are also vulnerable if a threat actor is able to transfer an employee's phone number to an attacker-controlled subscriber identification module (SIM) card. This would result in the MFA notifications being routed to the threat actor instead of the intended employee. </span></p>
<h5><span>Email-Based Verification</span></h5>
<p><span>If an organization is leveraging email-based verification for validating access or for retrieving MFA codes, and a threat actor has already established the ability to access the email of their target, the actor could potentially also retrieve the email(s) to validate and complete the MFA process. </span></p>
<p><span>If any of these MFA methods are leveraged, consider:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Training remote users to never accept or respond to a logon notification when they are not actively attempting to log in.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Establishing a method for users to report suspicious MFA notifications, as this could be indicative of a compromised account.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Ensuring there are messaging policies in place to prevent the auto-forwarding of email messages outside the organization.</span></p>
</li>
</ul>
<h5><span>Time-Based One-Time Password</span></h5>
<p><span>Time-based one-time password (TOTP) relies on a shared secret, called a seed, known by both the authenticating system and the authenticator possessed by an end user. If a seed is compromised, the TOTP authenticator can be duplicated and used by a threat actor.</span></p>
<h4><span><span>Detection Opportunities for External-Facing Assets and MFA Attempts</span></span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Brute Force</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1110/" rel="noopener" target="_blank"><span>T1110 – Brute Force</span></a></p>
</td>
<td>
<p><span>Search for a single user with an excessive number of failed logins from external Internet Protocol (IP) addresses. </span></p>
<p><span>This risk can be mitigated by enforcing a strong password, MFA, and lockout policy.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Password Spray</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1110/003/" rel="noopener" target="_blank"><span>T1110.003 – Password Spray</span></a></p>
</td>
<td>
<p><span>Search for a high number of accounts with failed logins, typically from the similar origination addresses.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Multiple Failed MFA Same User</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1110/" rel="noopener" target="_blank"><span>T1110 – Brute Force</span></a></p>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
</td>
<td>
<p><span>Search for multiple failed MFA conditions for the same account. This may be indicative of a previously compromised credential.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Multiple Failed MFA Same Source</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1110/003/" rel="noopener" target="_blank"><span>T1110.003 – Password Spray</span></a></p>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
</td>
<td>
<p><span>Search for multiple failed MFA prompts for different users from the same source. This may be indicative of multiple compromised credentials and an attempt to "spray" MFA prompts/tokens for access.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>External Authentication from an Account with Elevated Privileges</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
</td>
<td>
<p><span>Privileged accounts should use internally managed and secured privileged access workstations for access and should not be accessible directly from an external (untrusted) source.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Adversary in the Middle (AiTM) Session Token Theft</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1557/" rel="noopener" target="_blank"><span>T1557 - Adversary in the Middle</span></a></p>
</td>
<td>
<p><span>Monitor for sign-ins where the authentication method succeeds but the session originates from an IP/ASN inconsistent with the user's prior sessions. </span></p>
<p><span>Detect logins from newly registered domains or known reverse-proxy infrastructure (EvilProxy, Tycoon 2FA). </span></p>
<p><span>Correlate sign-in logs for "isInteractive: true" sessions with anomalous user-agent strings or geographically impossible travel.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>MFA Fatigue / Prompt Bombing</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1621/" rel="noopener" target="_blank"><span>T1621 - MFA Request Generation</span></a></p>
</td>
<td>
<p><span>Search for accounts receiving more than five MFA push notifications within a 10-minute window without a corresponding successful authentication. </span></p>
</td>
</tr>
<tr>
<td>
<p><span>Post-Authentication MFA Device Registration</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1098/005/" rel="noopener" target="_blank"><span>T1098.005 - Account Manipulation - Device Registration</span></a></p>
</td>
<td>
<p><span>Monitor audit logs for new MFA device registrations (AuthenticationMethodRegistered) occurring within 60 minutes of a sign-in from a new IP or device. Attackers who steal session tokens via AiTM immediately register their own MFA device for persistent access.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>OAuth/Consent Phishing</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1550/001/" rel="noopener" target="_blank"><span>T1550.001 - Use Alternate Authentication Material</span></a></p>
</td>
<td>
<p><span>Monitor for OAuth application consent grants with high-privilege scopes (Mail.Read, Files.ReadWrite.All) from unrecognized application IDs.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span>Table 3: Detection opportunities for external-facing assets and MFA attempts</span></p>
</div></div>
<div class="block-paragraph_advanced"><h3><span>2. Critical Asset Protections</span></h3>
<h4><span>Domain Controller and Critical Asset Backups</span></h4>
<p><span>Organizations should verify that backups for domain controllers and critical assets are available and protected against unauthorized access or modification. Backup processes and procedures should be exercised on a continual basis. Backups should be protected and stored within secured enclaves that include both network and identity segmentation. </span></p>
<p><span>If an organization's Active Directory (AD) were to become corrupted or unavailable due to ransomware or a potentially destructive attack, restoring Active Directory from domain controller backups may be the only viable option to reconstitute domain services. The following domain controller recovery and reconstitution best practices should be proactively reviewed by organizations: </span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Verify that there is a known good backup of domain controllers and </span><code>SYSVOL</code><span> shares (e.g., from a domain controller – backup </span><code>C:\Windows\SYSVOL</code><span>).</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span><span>For domain controllers, a system state backup is preferred.</span> <br><br></span><strong>Note:</strong><span> </span><span>For a system state backup to occur, </span><span>Windows Server Backup</span><span> must be installed as a feature on a domain controller. </span></p>
</li>
<li aria-level="1">
<p role="presentation">The following command can be run from an elevated command prompt to initiate a system state backup of a domain controller.</p>
</li>
</ul>
</li>
</ul></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>wbadmin start systemstatebackup -backuptarget:&lt;targetDrive&gt;:</code></pre>
<p><span>Figure 1: Command to perform a system state backup</span></p></div>
<div class="block-paragraph_advanced"><ul>
<li>
<ul>
<li><span>The following command can be run from an elevated command prompt to perform a </span><code>SYSVOL</code><span> backup. (</span><span>Manage auditing and security log</span><span> permissions must also be configured for the account performing the backup.)</span></li>
</ul>
</li>
</ul></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>robocopy c:\windows\sysvol c:\sysvol-backup /copyall /mir /b /r:0 /xd</code></pre>
<p><span>Figure 2: Command to perform a SYSVOL backup</span></p></div>
<div class="block-paragraph_advanced"><ul>
<li aria-level="1">
<p role="presentation"><span>Proactively identify domain controllers that hold flexible single master operation (FSMO) roles, as these domain controllers will need to be prioritized for recovery in the event that a full domain restoration is required. </span></p>
</li>
</ul></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>netdom query fsmo</code></pre>
<p><span>Figure 3: Command to identify domain controllers that hold FSMO roles</span></p></div>
<div class="block-paragraph_advanced"><ul>
<li aria-level="1">
<p role="presentation"><span>Offline backups: Ensure offline domain controller backups are secured and stored separately from online backups. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Encryption: Backup data should be encrypted both during transit (over the wire) and when at rest or mirrored for offsite storage. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>DSRM Password validation: Ensure that the Directory Services Restore Mode (DSRM) password is set to a known value for each domain controller. This password is required when performing an authoritative or nonauthoritative domain controller restoration. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Configure alerting for backup operations: Backup products and technologies should be configured to detect and provide alerting for operations critical to the availability and integrity of backup data (e.g., deletion of backup data, purging of backup metadata, restoration events, media errors). </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Enforce role-based access control (RBAC): Access to backup media and the applications that govern and manage data backups should use RBAC to restrict the scope of accounts that have access to the stored data and configuration parameters. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Testing and verification: Both authoritative and nonauthoritative domain controller restoration processes should be documented and tested on a regular basis. The same testing and verification processes should be enforced for critical assets and data.</span></p>
</li>
</ul>
<h4><span>Business Continuity Planning</span></h4>
<p><span>Critical asset recovery is dependent upon in-depth planning and preparation, which is often included within an organization's business continuity plan (BCP). Planning and recovery preparation should include the following core competencies:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>A well-defined understanding of crown jewels data and supporting applications that align to backup, failover, and restoration tasks that prioritize mission-critical business operations</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Clearly defined asset prioritization and recovery sequencing</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Thoroughly documented recovery processes for critical systems and data</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Trained personnel to support recovery efforts</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Validation of recovery processes to ensure successful execution</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Clear delineation of responsibility for managing and verifying data and application backups</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Online and offline data backup retention policies, including initiation, frequency, verification, and testing (for both on-premises and cloud-based data)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Established service-level agreements (SLAs) with vendors to prioritize application and infrastructure-focused support</span></p>
</li>
</ul>
<p><span>Continuity and recovery planning can become stale over time, and processes are often not updated to reflect environment and personnel changes. Prioritizing evaluations, continuous training, and recovery validation exercises will enable an organization to be better prepared in the event of a disaster.</span></p>
<h4><span>Detection Opportunities for Backups</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div> </div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Volume Shadow Deletion</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1490/" rel="noopener" target="_blank"><span>T1490 – Inhibit System Recovery</span></a></p>
</td>
<td>
<p><span>Search for instances where a threat actor will delete volume shadow copies to inhibit system recovery. This can be accomplished using the command line, PowerShell, and other utilities.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Unauthorized Access Attempt</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
</td>
<td>
<p><span>Search for unauthorized users attempting to access the media and applications that are used to manage data backups.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Suspicious Usage of the DSRM Password</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
</td>
<td>
<p><span>Monitor security event logs on domain controllers for:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Event ID 4794 - An attempt was made to set the Directory Services Restore Mode administrator password</span></p>
</li>
</ul>
<p><span>Monitoring the following registry key on domain controllers:<br><br></span></p>
<pre class="language-plain"><code>HKLM\System\CurrentControlSet\Control\Lsa\DSRMAdminLogonBehavior</code></pre>
<p><span>Figure 4: DSRM registry key for monitoring</span></p>
<p><span>The possible values for the registry key noted in Figure 4 are:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><code>0</code><span> (default): The DSRM Administrator account can only be used if the domain controller is restarted in Directory Services Restore Mode.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><code>1</code><span>: The DSRM Administrator account can be used for a console-based log on if the local </span><span>Active Directory Domain Services</span><span> service is stopped.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><code>2</code><span>: The DSRM Administrator account can be used for console or network access without needing to reboot a domain controller.</span></p>
</li>
</ul>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div><span>Table <span>4: Detection opportunities for backups</span></span></div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h4><span>IT and OT Segmentation</span></h4>
<p><span>Organizations should ensure that there is both physical and logical segmentation between corporate information technology (IT) domains, identities, networks, and assets and those used in direct support of operational technology (OT) processes and control. By enforcing IT and OT segmentation, organizations can inhibit a threat actor's ability to pivot from corporate environments to mission-critical OT assets using compromised accounts and existing network access paths. </span></p>
<p><span>OT environments should leverage separate identity stores (e.g., dedicated Active Directory domains), which are not trusted or cross-used in support of corporate identity and authentication. </span><strong>The compromise of a corporate identity or asset should not result in a threat actor's ability to directly pivot to accessing an asset that has the ability to influence an OT process.</strong></p>
<p><span>In addition to separate AD forests being leveraged for IT and OT, segmentation should also include technologies that may have a dual use in the IT and OT environments (backup servers, antivirus [AV], endpoint detection and response [EDR], jump servers, storage, virtual network infrastructure). OT segmentation should be designed such that if there is a disruption in the corporate (IT) environment, the OT process can safely function independently, without a direct dependency (account, asset, network pathway) with the corporate infrastructure. For any dependencies that cannot be readily segmented, organizations should identify potential short-term processes or manual controls to ensure that the OT environment can be effectively isolated if evidence of an IT (corporate)-focused incident were detected. </span></p>
<p><span>Segmenting IT and OT environments is a best practice recommended by industry standards such as the National Institute of Standards and Technology (NIST) <em>SP 800-82r3</em></span><span>: <a href="https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-82r3.pdf" rel="noopener" target="_blank">Guide to Operational Technology (OT) Security</a></span><span> and </span><a href="https://www.isa.org/intech-home/2018/september-october/departments/new-standard-specifies-security-capabilities-for-c" rel="noopener" target="_blank"><span>IEC 62443</span></a><span> (formerly ISA99).</span></p>
<p><span>According to these best-practice standards, segmenting IT and OT networks should include the following:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>OT attack surface reduction by restricting the scope of ports, services, and protocols that are directly accessible within the OT network from the corporate (IT) network.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Incoming access from corporate (IT) into OT must terminate within a segmented OT demilitarized zone (DMZ). The OT DMZ must require that a separate level of authentication and access be granted (outside of leveraging an account or endpoint that resides within the corporate IT domain). </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Explicit firewall rules should restrict both incoming traffic from the corporate environment and outgoing traffic from the OT environment.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Firewalls should be configured using the principle of deny by default, with only approved and authorized traffic flows permitted. Egress (internet) traffic flows for all assets that support OT should also follow the deny-by-default model.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Identity (account) segmentation must be enforced between corporate IT and OT. An account or endpoint within either environment should not have any permissions or access rights assigned outside of the respective environment. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Remote access to the OT environment should not leverage similar accounts that have remote access permissions assigned within the corporate IT environment. </span><strong>MFA using separate credentials should be enforced for remotely accessing OT assets and resources.</strong></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Training and verification of manual control processes, including isolation and reliability verification for safety systems.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Secured enclaves for storing backups, programming logic, and logistical diagrams for systems and devices that comprise the OT infrastructure.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>The default usernames and passwords associated with OT devices should always be changed from the default vendor configuration(s). </span></p>
</li>
</ul>
<h4><span>Detection Opportunities for IT and OT Segmented Environments</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Network Service Scanning</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1046/" rel="noopener" target="_blank"><span>T1046 – Network Service Scanning</span></a></p>
</td>
<td>
<p><span>Search for instances where a threat actor is performing internal network discovery to identify open ports and services between segmented environments.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Unauthorized Authentication Attempts Between Segmented Environments</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
</td>
<td>
<p><span>Search for failed logins for accounts limited to one environment attempting to log in within another environment. This can detect threat actors attempting to reuse credentials for lateral movement between networks.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 5: Detection opportunities for IT and OT segmented environments</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Egress Restrictions</span></h4>
<p><span>Servers and assets that are infrequently rebooted are highly targeted by threat actors for establishing backdoors to create persistent beacons to command-and-control (C2) infrastructure. By blocking or severely limiting internet access for these types of assets, an organization can effectively reduce the risk of a threat actor compromising servers, extracting data, or installing backdoors that leverage egress communications for maintaining access.</span></p>
<p><span>Egress restrictions should be enforced so that servers, internal network devices, critical IT assets, OT assets, and field devices cannot attempt to communicate to external sites and addresses (internet resources). The concept of deny by default should apply to all servers, network devices, and critical assets (including both IT and OT), with only allow-listed and authorized egress traffic flows explicitly defined and enforced. Where possible, this should include blocking recursive Domain Name System (DNS) resolutions not included in an allow-list to prevent communication via DNS tunneling.</span></p>
<p><span>If possible, egress traffic should be routed through an inspection layer (such as a proxy) to monitor external connections and block any connections to malicious domains or IP addresses. Connections to uncategorized network locations (e.g., a domain that has been recently registered) should not be permitted. Ideally, DNS requests would be routed through an external service (e.g., Cisco Umbrella, Infoblox DDI) to monitor for lookups to malicious domains. </span></p>
<p><span>Threat actors often attempt to harvest credentials (including New Technology Local Area Network [LAN] Manager [NTLM] hashes) based upon outbound Server Message Block (SMB) or Web-based Distributed Authoring and Versioning (WebDAV) communications. Organizations should review and limit the scope of egress protocols that are permissible from </span><strong>any</strong><span> endpoint within the environment. While Hypertext Transfer Protocol (HTTP) (Transmission Control Protocol (TCP)/80) and HTTP Secure (HTTPS) (TCP/443) egress communications are likely required for many user-based endpoints, the scope of external sites and addresses can potentially be limited based upon web traffic-filtering technologies. Ideally, organizations should only permit egress protocols and communications based upon a predefined allow-list. Common high-risk ports for egress restrictions include:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>File Transfer Protocol (FTP)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Remote Desktop Protocol (RDP)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Secure Shell (SSH)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Server Message Block (SMB)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Trivial File Transfer Protocol (TFTP) </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>WebDAV</span></p>
</li>
</ul>
<h4><span>Detection Opportunities for Suspicious Egress Traffic Flows</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>External Connection Attempt to a Known Malicious IP</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/tactics/TA0011/" rel="noopener" target="_blank"><span>TA0011 – Command and Control</span></a></p>
</td>
<td>
<p><span>Leverage threat feeds to identify attempted connections to known bad IP addresses.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>External Communications from Servers, Critical Assets, and Isolated Network Segments</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/tactics/TA0011/" rel="noopener" target="_blank"><span>TA0011 – Command and Control</span></a></p>
</td>
<td>
<p><span>Search for egress traffic flows from subnets and addresses that correlate to servers, critical assets, OT segments, and field devices.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Outbound Connections Attempted Over SMB</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1212/" rel="noopener" target="_blank"><span>T1212 – Exploitation for Credential Access</span></a></p>
</td>
<td>
<p><span>Search for external connection attempts over SMB, as this may be an attempt to harvest credential hashes.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 6: Detection opportunities for suspicious egress traffic flows</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Virtualization Infrastructure Protections</span><strong> </strong></h4>
<p><span>Threat actors often target virtualization infrastructure (e.g., VMware vSphere, Microsoft Hyper-V) as part of their reconnaissance, lateral movement, data theft, and potential ransomware deployment objectives. Securing virtualization infrastructure requires a Zero Trust network posture as a primary defense. Because management appliances often lack native MFA for local privileged accounts, identity-based security alone can be a high-risk single point of failure. If credentials are compromised, the logical network architecture becomes the final line of defense protecting the virtualization management plane.</span></p>
<p><span>To reduce the attack surface of virtualized infrastructure, a best practice for VMware vSphere vCenter ESXi and Hyper-V appliances and servers is to isolate and restrict access to the management interfaces, essentially enclaving these interfaces within isolated virtual local area networks (VLANs) (network segments) where connectivity is only permissible from dedicated subnets where administrative actions can be initiated.</span></p>
<p><span>To protect the virtualization control plane, organizations must consider a "defense-in-depth" network model. This architecture integrates physical isolation and east-west micro-segmentation to remove all access paths from untrusted networks. The result is a management zone that remains isolated and resilient, even during an active intrusion.</span></p>
<h5><span>VMware vSphere Zero-Trust Network Architecture</span><span> </span></h5>
<p><span>The primary goal is to ensure that even if privileged credentials are compromised, the logical network remains the definitive defensive layer preventing access to virtualization management interfaces.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Immutable VLAN Segmentation</strong><span>: Enforce strict isolation using distinct 802.1Q VLAN IDs for host management, Infrastructure/VCSA, vMotion (non-routable), Storage (non-routable), and production Guest VMs.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Virtual Routing and Forwarding (VRF)</strong><span>: Transition all infrastructure VLANs into a dedicated VRF instance. This ensures that even a total compromise of the "User" or "Guest" zones results in no available route to the management zone(s).</span></p>
</li>
</ul>
<h6><span>Layer 3 and 4 Access Policies</span></h6>
<p><span>The management network must be accessible only from trusted, hardened sources.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>PAW-Exclusive Access:</strong><span> Deconstruct all direct routes from the general corporate LAN to management subnets. Access must originate strictly from a designated Privileged Access Workstation (PAW) subnet.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Ingress Filtering (Management Zone)</strong><span>:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>ALLOW:</strong><span> TCP/443 (UI/API) and TCP/902 (MKS) from the PAW subnet only.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>DENY</strong><span>: Explicitly block SSH (TCP/22) and VAMI (TCP/5480) from all sources </span><span>except</span><span> the PAW subnet.</span></p>
</li>
</ul>
</li>
<li aria-level="1">
<p role="presentation"><strong>Restrictive Egress Policy:</strong><span> Enforce outbound filtering at the hardware gateway (as the VCSA GUI cannot manage egress). To prevent persistence using C2 traffic and data exfiltration, block all internet access except to specific, verified update servers (e.g., VMware Update Manager) and authorized identity providers.</span></p>
</li>
</ul>
<h6><span>Host-Based Firewall Enforcement</span></h6>
<p><span>Complement network firewalls with host-level filtering to eliminate visibility gaps within the same VLAN.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>VCSA (Photon OS)</strong><span>: Transition the default policy to "Default Deny" via the VAMI or, preferably, at the OS level using iptables/nftables for granular source/destination mapping. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>ESXi Hypervisors: </strong><span>Restrict all services (SSH, Web Access, NFC/Storage) to specific management IPs by deselecting "Allow connections from any IP address."</span></p>
</li>
</ul>
<p><span>Additional information related to <a href="https://knowledge.broadcom.com/external/article/377036/how-to-block-all-traffic-on-vcenter-exce.htm" rel="noopener" target="_blank">VMware vSphere VCSA host based firewalls</a>.</span></p>
<p><span>A <a href="https://kb.vmware.com/s/article/1012382" rel="noopener" target="_blank">listing of administrative ports</a> associated with VMWare vCenter (that should be targeted for isolation).</span></p>
<h5><span>Hyper-V Zero-Trust Network Architecture </span></h5>
<p><span>Similar to vSphere, Hyper-V requires strict isolation of its various traffic types to prevent lateral movement from guest workloads to the management plane.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>VLAN Segmentation:</strong><span> Organizations must enforce isolation using distinct VLANs for Host Management, Live Migration, Cluster Heartbeat (CSV), and Production Guest VMs.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Non-Routable Networks:</strong><span> Traffic for Live Migration and Cluster Shared Volumes (CSV) should be placed on non-routable VLANs to ensure these high-bandwidth, sensitive streams cannot be intercepted from other segments.</span></p>
</li>
</ul>
<h6><span>Layer 3 and 4 Access Policies</span></h6>
<p><span>The management network must be accessible only from trusted, hardened sources.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>PAW-Exclusive Access:</strong><span> Deconstruct all direct routes from the general corporate LAN to management subnets. Access must originate strictly from a designated Privileged Access Workstation (PAW) subnet.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Ingress Filtering (Management Zone)</strong><span>:</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><strong>ALLOW</strong><span>: WinRM / PowerShell Remoting (TCP/5985 and TCP/5986), RDP (TCP/3389), and WMI/RPC (TCP/135 and dynamic RPC ports)strictly from the PAW subnet. If using Windows Admin Center, allow HTTPS (TCP/443) to the gateway.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><strong>DENY</strong><span>: Explicitly block SMB (TCP/445), RPC/WMI (TCP/135), and all other management traffic from untrusted sources to prevent credential theft and lateral movement.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><strong>Restrictive Egress Policy: </strong><span>Enforce outbound filtering at the network gateway. To prevent persistence using C2 traffic and data exfiltration, block all internet access from Hyper-V hosts except to specific, verified update servers (e.g., internal WSUS), authorized Active Directory Domain Controllers, and Key Management Servers (KMS).</span></p>
</li>
</ul>
<h6><span>Host-Based Firewall Enforcement</span></h6>
<p><span>Use the Windows Firewall with Advanced Security (WFAS) to achieve a defense-in-depth posture at the host level.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Scope Restriction: </strong><span>For all enabled management rules (e.g., File and Printer Sharing, WMI, PowerShell Remoting), modify the Remote IP Address scope to "These IP addresses" and enter only the PAW and management server subnets.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Management Logging: </strong><span>Enable logging for Dropped Packets in the Windows Firewall profile. This allows the SIEM to ingest "denied" connection attempts, which serve as high-fidelity indicators of internal reconnaissance or unauthorized access attempts.</span></p>
</li>
</ul>
<p><span>Additional information related to <a href="https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/jj721516(v=ws.11)" rel="noopener" target="_blank">Hyper-V host based firewalls</a>.</span></p>
<p><span>Additional information related to <a href="https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/plan/plan-hyper-v-security-in-windows-server" rel="noopener" target="_blank">securing Hyper-V</a>.</span><span> </span></p>
<h5><span>General Virtualization Hardening </span></h5>
<p><span>To protect management interfaces for VMware vSphere the VMKernel network interface card (NIC) should </span><strong>not</strong><span> be bound to the same virtual network assigned to virtual machines running on the host. Additionally, ESXi servers can be configured in lockdown mode, which will only allow console access from the vCenter server(s). Additional information related to <a href="https://kb.vmware.com/s/article/1008077" rel="noopener" target="_blank">lockdown mode</a></span><span>.</span></p>
<p><span>The SSH protocol (TCP/22) provides a common channel for accessing a physical virtualization server or appliance (vCenter) for administration and troubleshooting. Threat actors commonly leverage SSH for direct access to virtualization infrastructure to conduct destructive attacks. In addition to enclaving access to administrative interfaces, SSH access to virtualization infrastructure should be disabled and only enabled for specific use-cases. If SSH is required, network ACLs should be used to limit where connections can originate.</span></p>
<p><span>Identity segmentation should also be configured when accessing administrative interfaces associated with virtualization infrastructure. If Active Directory authentication provides direct integrated access to the physical virtualization stack, a threat actor that has compromised a valid Active Directory account (with permissions to manage the virtualization infrastructure) could potentially use the account to directly access virtualized systems to steal data or perform destructive actions.</span></p>
<p><span>Authentication to virtualized infrastructure should rely upon dedicated and unique accounts that are configured with strong passwords and that are </span><strong>not</strong><span> co-used for additional access within an environment. Additionally, accessing management interfaces associated with virtualization infrastructure should only be initiated from isolated privileged access workstations, which prevent the storing and caching of passwords used for accessing critical infrastructure components.</span></p>
<h5><span>Protecting Hypervisors Against Offline Credential Theft and Exfiltration</span></h5>
<p><span>Organizations should implement a proactive, defense-in-depth technical hardening strategy to systematically address security gaps and mitigate the risk of offline credential theft from the hypervisor layer. The core of this attack is an offline credential theft technique known as a "Disk Swap." Once an adversary has administrative control over the hypervisor (vSphere or Hyper-V), they perform the following steps:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Target Identification:</strong><span> The actor identifies a critical virtualized asset, such as a Domain Controller (DC) </span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Offline Manipulation:</strong><span> The target VM is powered off, and its virtual disk file (e.g., .vmdk for VMware or .vhd/.vhdx for Hyper-V) is detached.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>NTDS.dit Extraction</strong><span>: The disk is attached to a staging or "orphaned" VM under the attacker's control. From this unmonitored machine, they copy the NTDS.dit Active Directory database.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Stealthy Recovery</strong><span>: The disk is re-attached to the original DC, and the VM is powered back on, leaving minimal forensic evidence within the guest operating system.</span></p>
</li>
</ul>
<h6><span>Hardening and Mitigation Guidance</span></h6>
<p><span>To defend against this logic, organizations must implement a defense-in-depth strategy that focuses on cryptographic isolation and strict lifecycle management.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Virtual Machine Encryption</strong><span>: Organizations must encrypt all Tier 0 virtualized assets (e.g., Domain Controllers, PKI, and Backup Servers). Encryption ensures that even if a virtual disk file is stolen or detached, it remains unreadable without access to the specific keys. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Strict Decommissioning Processes</strong><span>: Do not leave powered-off or "orphaned" virtual machines on datastores. These "ghost" VMs are ideal staging environments for attackers. Formally decommission assets by deleting their virtual disks rather than just removing them from the inventory.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Harden Hypervisor Accounts</strong><span>: Disable or restrict default administrative accounts (such as root on ESXi or the local Administrator on Hyper-V hosts). Enforce </span><a href="https://knowledge.broadcom.com/external/article/336894/enabling-or-disabling-lockdown-mode-on-a.html" rel="noopener" target="_blank"><span>Lockdown Mode</span></a><span> (VMware ESXi feature) where possible to prevent direct host-level changes outside of the central management plane.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Remote Audit Logging</strong><span>: Enable and forward all hypervisor-level audit logs (e.g., hostd.log, vpxa.log, or Windows Event Logs for Hyper-V) to a centralized SIEM. </span></p>
</li>
</ul>
<h5><span>Protecting Backups</span></h5>
<p><span>Security measures must encompass both production and backup environments. An attack on the production plane is often coupled with a simultaneous focus on backup integrity, creating a total loss of operational continuity. Virtual disk files (VMDK for VMware and VHD/VHDX for Hyper-V) represent a high-value target for offline data theft and direct manipulation.</span></p>
<h6><span>Hardening and Mitigation Guidance</span></h6>
<p><span>To mitigate the risk of offline theft and backup manipulation, organizations must implement a "Default Encrypted" policy across the entire lifecycle of the virtual disk .</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>At-Rest Encryption for all Tier-0 Assets:</strong><span> Implement vSphere VM Encryption or Hyper-V Shielded VMs for all critical infrastructure (e.g., Domain Controllers, Certificate Authorities). This ensures that the raw VMDK or VHDX files are cryptographically protected, rendering them unreadable if detached or mounted by an unauthorized party.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Encrypted Backup Repositories</strong><span>: Ensure that the backup application is configured to encrypt backup data at rest using a unique key stored in a separate, hardened Key Management System (KMS). This prevents "direct manipulation" of the backup files even if the backup storage itself is compromised. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Network Isolation of Storage &amp; Backups: </strong><span>Isolate the storage management network and the backup infrastructure into dedicated, non-routable VLANs. Access to the backup console and repositories must require phishing-resistant MFA and originate from a designated Privileged Access Workstation (PAW).</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Immutability and Air-Gapping</strong><span>: Use Immutable Backup Repositories to ensure that once a backup is written, it cannot be modified or deleted by any user including a compromised administrator for a set period. This provides a definitive recovery point in the event of a ransomware attack or intentional data sabotage.</span></p>
</li>
</ul>
<h4><span>Detection Opportunities for Monitoring Virtualization Infrastructure</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Unauthorized Access Attempt to Virtualized Infrastructure</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
</td>
<td>
<p><span>Search for attempted logins to virtualized infrastructure by unauthorized accounts.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Unauthorized SSH Connection Attempt</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1021/004/" rel="noopener" target="_blank"><span>T1021.004 – Remote Services: SSH</span></a></p>
</td>
<td>
<p><span>Search for instances where an SSH connection is attempted when SSH has not been enabled for an approved purpose or is not expected from a specific origination asset.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>ESXi Shell/SSH Enablement</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1059/004/" rel="noopener" target="_blank"><span>T1059.004 - Command and Scripting Interpreter</span></a></p>
</td>
<td>
<p><span>Monitor ESXi hostd.log and shell.log for the SSH service being enabled via DCUI, vSphere client, or API calls. Alert on any ESXi SSH enablement event that was not preceded by an approved change request.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Bulk VM Power-Off Events</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1529/" rel="noopener" target="_blank"><span>T1529 - System Shutdown/Reboot</span></a></p>
</td>
<td>
<p><span>Detect sequences where multiple VMs are powered off within a short time window (e.g., &gt;5 VMs in 10 minutes) via vCenter events. </span></p>
<p><span>Correlate with vpxd.log "ReceivedPowerOffVM" events.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>VMDK File Access from Non-Standard Processes</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1486/" rel="noopener" target="_blank"><span>T1486 - Data Encrypted for Impact</span></a></p>
</td>
<td>
<p><span>Monitor for processes accessing .vmdk, .vmx, .vmsd, or .vmsn files outside of normal VMware service processes (hostd, vpxd, fdm). </span></p>
</td>
</tr>
<tr>
<td>
<p><span>execInstalledOnly Disablement</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1562/001/" rel="noopener" target="_blank"><span>T1562.001 - Impair Defenses: Disable or Modify Tools</span></a></p>
</td>
<td>
<p><span>Monitor ESXi shell.log for execution of "esxcli system settings encryption set" with "--require-exec-installed-only=F" or "--require-secure-boot=F". Alert on any cryptographic enforcement disablement event that was not preceded by an approved change request.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>vCenter SSO Identity Modification</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1556/" rel="noopener" target="_blank"><span>T1556 - Modify Authentication Process</span></a></p>
</td>
<td>
<p><span>Monitor vCenter events and vpxd.log for modifications to SSO identity sources, including the addition of new LDAP providers or changes to vshphere.local administrator group membership. Alert on an identity source change not initiated from a designated PAW subnet.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>VM Disk Detach and Reattach to Non-Inventory VM</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1486/" rel="noopener" target="_blank"><span>T1486 - Data Encrypted for Impact</span></a></p>
</td>
<td>
<p><span>Detect sequences where a virtual disk is removed from a Tier-0 asset via "vim.event.VmReconfiguredEvent" and subsequently attached to an orphaned or non-standard inventory VM. </span></p>
<p><span>Correlate with "vim.event.VmRegisteredEvent" events on non-standard datastore paths within the same time window.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>VCSA Shell Command Anomaly</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1059/004/" rel="noopener" target="_blank"><span>T1059.004 - Command and Scripting Interpreter: Unix Shell</span></a></p>
</td>
<td>
<p><span>Monitor VCSA shell audit logs for execution of high-risk commands (e.g., wget, curl, psql, certificate-manager) by any user following an interactive SSH session. Alert on any instance where these commands are executed outside of an approved change window.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Bulk Snapshot Deletion</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1490/" rel="noopener" target="_blank"><span>T1490 - Inhibit System Recovery</span></a></p>
</td>
<td>
<p><span>Detects sequences where snapshots are removed across multiple VMs within a short time window via vCenter events. Correlate with "vim-cmd vmsvc/snapshot.removeall" execution in hostd.log to confirm host-level action.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 7: Detection opportunities for VMware vSphere </span></div></div>
<div class="block-paragraph_advanced"><h4><span>Protecting Against DDoS Attacks</span></h4>
<p><span>A distributed denial-of-service (DDoS) attack is an example of a disruptive attack that could impact the availability of cloud-based resources and services. Modernized DDoS protection must extend beyond the legacy concepts of filtering and rate-limiting, and include cloud-native capabilities that can scale to combat adversarial capabilities.</span></p>
<p><span>In addition to third-party DDoS and web application access protection services, the following table provides an overview of DDoS protection capabilities within common cloud-based infrastructures.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Cloud Provider</strong></p>
</td>
<td>
<p><strong>DDoS Protection Capability </strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Google Cloud</span></p>
</td>
<td>
<p><a href="https://cloud.google.com/security/products/armor"><span>Google Cloud Armor</span></a></p>
</td>
</tr>
<tr>
<td>
<p><span>Amazon Web Services</span></p>
</td>
<td>
<p><a href="https://aws.amazon.com/shield/" rel="noopener" target="_blank"><span>AWS Shield</span></a></p>
</td>
</tr>
<tr>
<td>
<p><span>Microsoft Azure</span></p>
</td>
<td>
<p><a href="https://azure.microsoft.com/en-us/products/ddos-protection" rel="noopener" target="_blank"><span>Azure DDoS Protection</span></a></p>
</td>
</tr>
<tr>
<td>
<p><span>Cloud Platform Agnostic </span></p>
</td>
<td>
<p><a href="https://www.imperva.com/products/web-application-firewall-waf/" rel="noopener" target="_blank"><span>Imperva WAF</span></a></p>
<p><a href="https://www.akamai.com/glossary/what-is-a-waf" rel="noopener" target="_blank"><span>Akamai WAF</span></a></p>
<p><a href="https://www.cloudflare.com/ddos/" rel="noopener" target="_blank"><span>Cloudflare DDoS Protection</span></a></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span>Table 8: Common cloud capabilities to mitigate DDoS attacks</span></p>
</div></div>
<div class="block-paragraph_advanced"><h4><span>Hardening the Cloud Perimeter </span></h4>
<p><span>With the hybrid operating model of modern day infrastructure, cloud consoles and SaaS platforms are high-value targets for credential harvesting and data exfiltration. Minimizing these risks requires a dual-defense strategy: robust identity controls to prevent unauthorized access, and platform-specific guardrails to protect access to resources, data, and to minimize the attack surface. </span></p>
<h5><span>Strong Authentication Enforcement</span></h5>
<p><span>Strong authentication is the foundational requirement for cloud resilience and securing cloud infrastructure. Similar to on-premises environments, a compromise of a privileged credential, token, or session could lead to unintended consequences that result in a high-impact event for an organization. To mitigate these pervasive risks, organizations must unconditionally enforce strong authentication for all external-facing cloud services, administrative portals, and SaaS platforms. </span></p>
<p><span>Organizations should enforce the usage of phishing-resistant authenticators such as FIDO2 (WebAuthn) hardware tokens or passkeys, or certificate based authentication for accounts assigned privileged roles and functions. For non-privileged users, authenticator software (Microsoft Authenticator or Okta Verify) should be configured to utilize device-bound factors such as Windows Hello for Business or TouchID.</span></p>
<p><span>Additionally, organizations should leverage the concept of authenticators (identity + device attestation) as part of the authentication transaction. This includes enforcing a validated-device access policy that restricts privileged access to only originate from managed, compliant, and healthy devices. Trusted network zones should be defined in order to restrict access to cloud resources from the open internet. Untrusted network zones should be defined to restrict authentication from anonymizing services such as VPNs or TOR. Using device-bound session credentials where possible mitigates the risk of session token theft.</span></p>
<h5><span>Identity and Device Segmentation for Privileged Actions</span></h5>
<p><span>The implementation of privileged access workstations (PAWs) is a critical defense against threat actors attempting to compromise administrative sessions. A PAW is a highly hardened, dedicated hardware endpoint used exclusively for sensitive administrative tasks.</span></p>
<p><span>Administrators should leverage a non-privileged account for daily tasks, while privileged actions are restricted to only being permissible from the hardened PAW, or from explicitly defined IP ranges. This "air-gap" between communication and administration prevents an adversary from moving laterally from a compromised non-privileged identity to a privileged context within hybrid environments. </span></p>
<h5><span>Just-in-Time Access and the Principle of Least Privilege</span></h5>
<p><span>Static, standing privileges present a security risk in hybrid environments. Following a zero-trust cloud architecture, administrative privileges should be entirely ephemeral. Implementing Just-In-Time (JIT) and Just-Enough-Access (JEA) mechanisms ensures that administrators are granted only the specific, granular permissions necessary to perform a discrete task, and only for a highly limited duration, after which the permissions are automatically revoked. This architectural model provides organizations with the ability to enforce approvals for privileged actions, enhanced monitoring, and detailed visibility regarding any privileged actions taken within a specific session.</span></p>
<h5><span>Securing Non-Human Identities</span></h5>
<p><span>Organizations should implement identity governance practices that include processes to rotate API keys, certificates, service account secrets, tokens, and sessions on a predefined basis. AI agents or identities correlating to autonomous outcomes should be configured with strictly scoped permissions and associated monitoring. Non-privileged users should be restricted from authorizing third-party application integrations or creating API keys without organizational approval.</span></p>
<p><span>Continuous scanning should be performed to identify and remediate hard-coded secrets and sensitive credentials across all cloud and SaaS environments.</span></p>
<h5><span>Storage Infrastructure Security and Immutable Backups</span></h5>
<p><span>The strategic objective of a destructive cyberattack—whether for extortion or sabotage—is to prolong recovery and reconstitution efforts by ensuring data is irrecoverable. Modern adversaries systematically target the backup plane as part of a destructive event. If backups remain mutable or share an identity plane with the primary environment, attackers can delete or encrypt them, transforming an incident into a prolonged and chaotic recovery exercise.</span></p>
<p><span>While modern-day redundancy for backups should include multiple data copies across diverse media, geographic separation can be a subverted defensive strategy if logical access is unified. To ensure resilience against destructive attacks, the secondary recovery environment should reside within a sovereign cloud tenant or isolated subscription. This environment should be governed by an independent Identity and Access Management (IAM) plane, using distinct credentials and administrative personas that share no commonality with the production environment.</span></p>
<p><span>Backups within an isolated environment must be anchored by immutable storage architectures. By leveraging hardware-verified Write-Once, Read-Many (WORM) technology, the recovery plane ensures that data integrity is mathematically guaranteed. Once committed, data cannot be modified, encrypted, or deleted—even by accounts with root or global administrative privileges, until the retention period expires. This creates a definitive "fail-safe" that ensures a known-good recovery point remains accessible regardless of potential security risks in the primary environment.</span></p>
<p><span>Additional defense-in-depth security architecture controls relevant to common cloud-based infrastructures are included in Table 9.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Cloud Provider</strong></p>
</td>
<td>
<p><strong>Identity Controls</strong></p>
</td>
<td>
<p><strong>Secrets Governance</strong></p>
</td>
<td>
<p><strong>Network Controls</strong></p>
</td>
<td>
<p><strong>Policy Guardrails</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Google Cloud</span></p>
</td>
<td>
<p><a href="https://docs.cloud.google.com/iam/docs/deny-overview"><span>IAM Deny Policies</span></a></p>
</td>
<td>
<p><a href="https://cloud.google.com/security/products/secret-manager"><span>Secret Manager</span></a></p>
</td>
<td>
<p><a href="https://cloud.google.com/security/vpc-service-controls"><span>VPC Service Controls</span></a></p>
</td>
<td>
<p><a href="https://docs.cloud.google.com/resource-manager/docs/organization-policy/overview"><span>Organization Policy Service</span></a></p>
</td>
</tr>
<tr>
<td>
<p><span>Amazon Web Services</span></p>
</td>
<td>
<p><a href="https://aws.amazon.com/iam/identity-center/" rel="noopener" target="_blank"><span>IAM Identity Center</span></a></p>
</td>
<td>
<p><a href="https://aws.amazon.com/secrets-manager/" rel="noopener" target="_blank"><span>Secrets Manager</span></a></p>
</td>
<td>
<p><a href="https://aws.amazon.com/verified-access/" rel="noopener" target="_blank"><span>Verified Access</span></a></p>
</td>
<td>
<p><a href="https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scps.html" rel="noopener" target="_blank"><span>Service Control Policies</span></a></p>
</td>
</tr>
<tr>
<td>
<p><span>Microsoft Azure</span></p>
</td>
<td>
<p><a href="https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-configure" rel="noopener" target="_blank"><span>Entra ID (PIM)</span></a></p>
</td>
<td>
<p><a href="https://azure.microsoft.com/en-us/products/key-vault" rel="noopener" target="_blank"><span>Azure Key Vault</span></a></p>
</td>
<td>
<p><a href="https://azure.microsoft.com/en-us/products/virtual-network/" rel="noopener" target="_blank"><span>Azure Virtual Network</span></a></p>
<p><a href="https://azure.microsoft.com/en-us/products/private-link" rel="noopener" target="_blank"><span>Private Link</span></a></p>
</td>
<td>
<p><a href="https://learn.microsoft.com/en-us/azure/governance/policy/overview" rel="noopener" target="_blank"><span>Azure Policy</span></a></p>
</td>
</tr>
<tr>
<td>
<p><span>Cloud Agnostic Security Solutions</span></p>
</td>
<td>
<p><a href="https://www.okta.com/learn/okta-identity-cloud/" rel="noopener" target="_blank"><span>Okta</span></a></p>
<p><a href="https://www.sailpoint.com/products/identity-security-cloud" rel="noopener" target="_blank"><span>SailPoint</span></a></p>
<p><a href="https://www.pingidentity.com/en/platform/pingone-advanced-identity-cloud.html" rel="noopener" target="_blank"><span>Ping Identity</span></a></p>
</td>
<td>
<p><a href="https://www.hashicorp.com/en/products/vault/use-cases/secrets-management" rel="noopener" target="_blank"><span>Hashicorp Vault</span></a><span> </span><a href="https://docs.cyberark.com/secrets-manager-saas/latest/en/content/get%20started/key_concepts/secrets.html" rel="noopener" target="_blank"><span>CyberArk</span></a></p>
</td>
<td>
<p><a href="https://help.zscaler.com/zpa/understanding-zpa-zia-and-zscaler-client-connector-clouds" rel="noopener" target="_blank"><span>Zscaler</span></a></p>
<p><a href="https://www.netskope.com/products/security-service-edge" rel="noopener" target="_blank"><span>Netskope SSE</span></a></p>
</td>
<td>
<p><a href="https://www.wiz.io/" rel="noopener" target="_blank"><span>Wiz</span></a></p>
<p><a href="https://www.paloaltonetworks.com/prisma/cloud" rel="noopener" target="_blank"><span>Palo Alto Prisma Cloud</span></a></p>
<p><a href="https://orca.security/" rel="noopener" target="_blank"><span>Orca Security</span></a></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span>Table 9: Common cloud capabilities for infrastructure hardening</span></p>
</div></div>
<div class="block-paragraph_advanced"><h4><span>Detection Opportunities for Protecting Cloud Infrastructure and Resources</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Cloud Account Abuse</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1078/004/" rel="noopener" target="_blank"><span>T1078.004 - Valid Accounts: Cloud Accounts</span></a></p>
</td>
<td>
<p><span>Monitor cloud audit logs for authentication from unseen source IPs, anomalous ASNs, or impossible travel patterns. </span></p>
<p><span>Alert on IAM policy modifications, new role assignments, and service account key creation by accounts without prior administrative API activity.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Lateral Movement via Cloud Interfaces</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1021/007/" rel="noopener" target="_blank"><span>T1021.007 - Remote Services: Cloud Services</span></a></p>
</td>
<td>
<p><span>Detect interactive console sign-ins from IPs that previously only performed programmatic API/CLI access. Alert on cloud CLI execution from non-administrative endpoints. </span></p>
<p><span>Monitor for cross-service lateral movement where a single identity authenticates to multiple cloud services in a compressed timeframe outside its historical access pattern.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Modify Cloud Compute Configurations</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1578/005/" rel="noopener" target="_blank"><span>T1578.005 - Modify Cloud Compute Configurations</span></a></p>
</td>
<td>
<p><span>Monitor for unauthorized compute changes including bulk instance creation or deletion deviating from change management baselines. </span></p>
<p><span>Alert on snapshot creation of production volumes by non-backup accounts, disk detach/reattach targeting domain controller or database instances for offline credential theft, and network/firewall modifications exposing internal services to public access.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Cloud Log Enumeration</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1654/" rel="noopener" target="_blank"><span>T1654 - Log Enumeration</span></a></p>
</td>
<td>
<p><span>Monitor for API calls listing or accessing logging configurations from identities without documented operational need. </span></p>
<p><span>Alert on enumeration of SIEM integration settings, log export destinations, and alert rule definitions.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Mass Deletion &amp; Impact</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1490/" rel="noopener" target="_blank"><span>T1490 - Inhibit System Recovery</span></a></p>
</td>
<td>
<p><span>Alert when bulk delete API calls exceed baseline thresholds targeting compute instances, storage, databases, or virtual networks. </span></p>
<p><span>Detect deletion or retention reduction of recovery-critical resources including backup vaults, snapshot schedules, and disaster recovery configurations.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Backup Policy Modification or Deletion</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1490/" rel="noopener" target="_blank"><span>T1490 - Inhibit System Recovery</span></a></p>
</td>
<td>
<p><span>Monitor for unauthorized modifications to backup configurations, including changes to WORM retention policies, backup vault access policies, snapshot deletion, or backup schedule disablement. </span></p>
<p><span>Alert on backup storage account access from identities other than designated backup service accounts.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Conditional Access or Security Policy Modification</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1556/009/" rel="noopener" target="_blank"><span>T1556.009 - Conditional Access Policies</span></a></p>
</td>
<td>
<p><span>Monitor cloud identity provider audit logs for modifications to Conditional Access Policies, MFA enforcement rules, legacy authentication blocking rules, or PIM/JIT role settings. Alert on changes that add location or device exclusions to MFA policies, disable legacy protocol blocks, extend privilege role activation durations, or register new authentication methods on privileged accounts.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 10: Detection opportunities for protecting cloud infrastructure and resources</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Securing Endpoint and Mobile Device Management Platforms</span></h4>
<p><span>Protecting endpoint and Mobile Device Management (MDM) platforms is crucial to ensuring the security and availability of devices used in support of operations. In the context of </span><a href="https://services.google.com/fh/files/misc/apt44-unearthing-sandworm.pdf" rel="noopener" target="_blank"><span>wiper</span></a><span> and destructive-style attacks, these platforms represent the "keys to the kingdom" that threat actors can target to turn an organization’s own infrastructure against itself.</span></p>
<p><strong>Force Multiplier:</strong><span> MDM and endpoint management tools have the inherent ability to push configurations and scripts to enrolled and managed devices. If compromised, a threat actor can use these legitimate administrative platforms to deploy wiper malware or execute remote wipe commands simultaneously across the entire enterprise, achieving destruction in minutes.  </span></p>
<p><span>Unlike ransomware, where data might be recoverable via decryption, wiper attacks aim for the permanent destruction of the Master Boot Record (MBR), GUID Partition Table (GPT), Master File Table (MFT), or overwrite the file system making endpoint devices inaccessible. </span></p>
<h5><span>Proactive Hardening</span></h5>
<p><span>Enforcing strong identity and network controls for securing the management plane can prevent an attacker from gaining access to endpoint and MDM platforms and abusing intended functionality (e.g., deploying wiper scripts or issuing  "Remote Wipe" or "Factory Reset" commands).</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Enforce strong authentication (e.g., phishing-resistant MFA, including FIDO2) for identities assigned privileged roles and functions.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Enforce session lifetimes, idle session timeouts and utilize device-bound session protection to protect against token replay attacks.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Require access policies and </span><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/multi-admin-approval" rel="noopener" target="_blank"><span>multi-admin approval</span></a><span> for authorization of specific actions. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Reduce long-standing administrative permissions and migrate to a Just-in-Time (JIT) or Just-Enough-Access (JEA) access model for privileged roles and actions.  </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>For Microsoft Intune, leverage a combination of </span><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/scope-tags" rel="noopener" target="_blank"><span>role-based access control (RBAC) and scope tags</span></a><span> to reduce the blast radius and minimize the risk of compromised privileged identities being leveraged to impact a large scope of managed devices / endpoints. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Audit admin roles for anything including “Remote tasks/wipe/erase” permissions - and ensure these events are forwarded to a centralized SIEM. Additionally, reduce the scope of administrators that can perform these actions to the minimum required for business operations.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Reduce scope of API token permissions following the principle of least privilege. Remove or expire tokens after a period of inactivity. Rotate tokens on a regular basis.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>For cloud-hosted MDM platforms, utilize access policies to enforce network- and location-based allow listing. For local/on-premises MDM servers, utilize firewalls to restrict access to MDM infrastructure (management plane).</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>If supported, configure wipe protection to prevent against mass device wiping within a specific threshold.  An example of this configuration within the Omnissa Workspace ONE platform is available </span><a href="https://docs.omnissa.com/bundle/WorkspaceONE-UEM-Managing-DevicesV2406/page/WipeProtection.html" rel="noopener" target="_blank"><span>here</span></a><span>.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Review existing scripts and configuration profiles deployed via the MDM platform to identify and remediate any hardcoded plain text passwords, API keys, or other sensitive secrets.</span></p>
</li>
</ul>
<h4><span>Detection Opportunities for Securing Endpoint and Mobile Device Management Platforms</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Remote Wipe or Factory Reset Command Issued</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1485/" rel="noopener" target="_blank"><span>T1485 - Data Destruction</span></a></p>
</td>
<td>
<p><span>Monitor endpoint management platform audit logs for issuance of remote wipe, factory reset, or retire commands. </span></p>
<p><span>Alert on any wipe command targeting more than a threshold number of devices within a defined time window, or wipe commands issued outside approved change windows.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Anomalous MDM/EDR Administrator Authentication</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1078/004/" rel="noopener" target="_blank"><span>T1078.004 - Valid accounts: Cloud accounts</span></a></p>
</td>
<td>
<p><span>Monitor authentication logs for endpoint management platform admin consoles for sign-ins from unrecognized IPs, non-compliant devices, or locations inconsistent with the administrator’s historical access pattern. </span></p>
<p><span>Alert on admin authentication that bypasses Conditional Access or lacks phishing-resistant MFA.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Bulk Script or Configuration Profile Deployment</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1072/" rel="noopener" target="_blank"><span>T1072 - Software Deployment Tools</span></a></p>
</td>
<td>
<p><span>Monitor of mass deployment of new scripts, configuration profiles, or software packages pushed to device groups via the management platform.</span></p>
<p><span> Alert when a deployment targets all devices or broad scope tags rather than specific groups, particularly when initiated by an account that has not previously performed bulk deployments.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Administrative Role or Permission Modification</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1098/" rel="noopener" target="_blank"><span>T1098 - Account Manipulation</span></a></p>
</td>
<td>
<p><span>Monitor platform audit logs for changes to administrative roles, RBAC assignments, or scope tag modifications.</span></p>
<p><span> Alert on elevation of accounts to roles with remote task, wipe, or retire permissions, and on removal of multi-admin approval requirements.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>API Key creation or Anomalous API access</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1098/001/" rel="noopener" target="_blank"><span>T1098.001 - Additional Cloud Credentials</span></a></p>
</td>
<td>
<p><span>Monitor for creation of new API keys, tokens, or service principal credentials for the endpoint management platform. </span></p>
<p><span>Alert on API calls from previously unseen source IPs or user-agents, and on API activity outside business hours. </span></p>
</td>
</tr>
<tr>
<td>
<p><span>Management Platform Audit Log Tampering or Disablement</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1562/008/" rel="noopener" target="_blank"><span>T1562.008 - Impair Defenses: Disable or Modify Cloud Logs</span></a></p>
</td>
<td>
<p><span>Monitor for modifications to the platform’s audit logging configuration, including disablement of change management logging, redirection of syslog export destinations, or deletion of audit log entries. </span></p>
<p><span>Alert on changes to log retention settings or export configurations.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h3><span>3. On-Premises Lateral Movement Protections</span></h3>
<h4><span>Endpoint Hardening</span></h4>
<h5><span>Windows Firewall Configurations</span></h5>
<p><span>Once initial access to on-premises infrastructure is established, threat actors will conduct lateral movement to attempt to further expand the scope of access and persistence. To protect Windows endpoints from being accessed using common lateral movement techniques, a Windows Firewall policy can be configured to restrict the scope of communications permitted between endpoints within an environment. A Windows Firewall policy can be enforced locally or centrally as part of a Group Policy Object (GPO) configuration. At a minimum, the common ports and protocols leveraged for lateral movement that should be blocked between workstation-to-workstation and workstations to non-domain controllers and non-file servers include:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>SMB (TCP/445, TCP/135, TCP/139)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Remote Desktop Protocol (TCP/3389)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Windows Remote Management (WinRM)/Remote PowerShell (TCP/80, TCP/5985, TCP/5986)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Windows Management Instrumentation (WMI) (dynamic port range assigned through Distributed Component Object Model (DCOM))</span></p>
</li>
</ul>
<p><span>Using a GPO (Figure 5), the settings listed in Table 11 can be configured for the Windows Firewall to control </span><strong>inbound</strong><span> communications to endpoints in a managed environment. The referenced settings will effectively block all inbound connections for the </span><span>Private</span><span> and </span><span>Public</span><span> profiles, and for the </span><span>Domain</span><span> profile, only allow connections that do not match a predefined block rule. </span></p></div>
<div class="block-paragraph_advanced"><div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1">
<tbody>
<tr>
<td><span>Computer Configuration &gt; Policies &gt; Windows Settings &gt; Security Settings &gt; Windows Firewall with Advanced Security</span></td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span>Figure 5: GPO path for creating Windows Firewall rules</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col><col><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Profile Setting</strong></p>
</td>
<td>
<p><strong>Firewall State</strong></p>
</td>
<td>
<p><strong>Inbound Connections</strong></p>
</td>
<td>
<p><strong>Log Dropped Packets</strong></p>
</td>
<td>
<p><strong>Log Successful Connections</strong></p>
</td>
<td>
<p><strong>Log File Path</strong></p>
</td>
<td>
<p><strong>Log File Maximum Size (KB)</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Domain</span></p>
</td>
<td>
<p><span>On</span></p>
</td>
<td>
<p><span>Allow</span></p>
</td>
<td>
<p><span>Yes</span></p>
</td>
<td>
<p><span>Yes</span></p>
</td>
<td>
<p><code>%systemroot%\system32\LogFiles\Firewall\pfirewall.log</code></p>
</td>
<td>
<p><span>4,096</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Private</span></p>
</td>
<td>
<p><span>On</span></p>
</td>
<td>
<p><span>Block All Connections</span></p>
</td>
<td>
<p><span>Yes</span></p>
</td>
<td>
<p><span>Yes</span></p>
</td>
<td>
<p><code>%systemroot%\system32\LogFiles\Firewall\pfirewall.log</code></p>
</td>
<td>
<p><span>4,096</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Public</span></p>
</td>
<td>
<p><span>On</span></p>
</td>
<td>
<p><span>Block All Connections</span></p>
</td>
<td>
<p><span>Yes</span></p>
</td>
<td>
<p><span>Yes</span></p>
</td>
<td>
<p><code>%systemroot%\system32\LogFiles\Firewall\pfirewall.log</code></p>
</td>
<td>
<p><span>4,096</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 11: Windows Firewall recommended configuration state</span></div></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--medium
      
      
        h-c-grid__col
        
        h-c-grid__col--4 h-c-grid__col--offset-4
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/destructive-attacks-guidance-fig6.max-1000x1000.png" alt="Windows Firewall Recommendation Configurations">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="2sb2o">Figure 6: Windows Firewall recommendation configurations</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>Additionally, to ensure that only centrally managed firewall rules are enforced (and cannot be overridden by a threat actor), the settings for </span><span>Apply local firewall rules</span><span> and </span><span>Apply local connection security rules</span><span> can be set to </span><span>No</span><span> for all profiles.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--medium
      
      
        h-c-grid__col
        
        h-c-grid__col--4 h-c-grid__col--offset-4
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/destructive-attacks-guidance-fig7.max-1000x1000.png" alt="Windows Firewall Domain Profile Customized Settings">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="2sb2o">Figure 7: Windows Firewall domain profile customized settings</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>To quickly contain and isolate systems, the centralized Windows Firewall setting of </span><span>Block all connections</span><span> (Figure 8) will prevent any inbound connections from being established to a system. This is a setting that can be enforced on workstations and laptops, but will likely impact operations if enforced for servers, although if there is evidence of an active threat actor lateral pivoting within an environment, it may be a necessary step for rapid containment.</span></p>
<p><strong>Note:</strong><span> </span><span>If this control is being used temporarily to facilitate containment as part of an active incident, once the incident has been contained and it has been deemed safe to re-establish connectivity among systems within an environment, the </span><span>Inbound Connections</span><span> setting can be changed back to </span><span>Allow</span><span> using a GPO.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--medium
      
      
        h-c-grid__col
        
        h-c-grid__col--4 h-c-grid__col--offset-4
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/destructive-attacks-guidance-fig8.max-1000x1000.png" alt="Windows Firewall - Block All Connections Settings">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="2sb2o">Figure 8: Windows Firewall - Block All Connections settings</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>If blocking all inbound connectivity for endpoints during a containment event is not practical, or for the </span><span>Domain</span><span> profile configurations, at a minimum, the protocols listed in Table 12 should be enforced using either a GPO or via the commands referenced within the table.</span></p></div>
<div class="block-paragraph_advanced"><div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1">
<tbody>
<tr>
<td>
<p><span>For any specific applications that may require inbound connectivity to end-user endpoints, the local firewall policy should be configured with specific IP address exceptions for origination systems that are authorized to initiate inbound connections to such devices.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Protocol/Port</strong></p>
</td>
<td>
<p><strong>Windows Firewall Rule</strong></p>
</td>
<td>
<p><strong>Command Line Enforcement</strong></p>
</td>
</tr>
<tr>
<td>
<p role="presentation"><span>SMB</span></p>
<p><span>TCP/445, TCP/139, TCP/135</span></p>
</td>
<td>
<p role="presentation"><span>Predefined Rule Name:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>File and Print Sharing</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Remote Desktop</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Windows Management Instrumentation (WMI)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Windows Remote Management</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Windows Remote Management (Compatibility)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>TCP/5986</span></p>
</li>
</ul>
</td>
<td>
<p><code>netsh advfirewall firewall set rule group="File and Printer Sharing" new enable=no</code></p>
</td>
</tr>
<tr>
<td>
<p role="presentation"><span>Remote Desktop Protocol</span></p>
<p><span>TCP/3389</span></p>
</td>
<td>
<p role="presentation"><span>Predefined Rule Name:</span></p>
</td>
<td>
<p><code>netsh advfirewall firewall set rule group="Remote Desktop" new enable=no</code></p>
</td>
</tr>
<tr>
<td>
<p><span>WMI</span></p>
</td>
<td>
<p role="presentation"><span>Predefined Rule Name:</span></p>
</td>
<td>
<p><code>netsh advfirewall firewall set rule group="windows management instrumentation (wmi)" new enable=no</code></p>
</td>
</tr>
<tr>
<td>
<p role="presentation"><span>Windows Remote Management/PowerShell Remoting</span></p>
<p><span>TCP/80, TCP/5985, TCP/5986</span></p>
</td>
<td>
<p role="presentation"><span>Predefined Rule Name:</span></p>
</td>
<td>
<p role="presentation"><code>netsh advfirewall firewall set rule group="Windows Remote Management" new enable=no</code></p>
<p role="presentation"><span>Via PowerShell:</span></p>
<p><code>Disable-PSRemoting -Force</code></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span>Table 12: Windows Firewall suggested block rules</span></p>
</div>
</div></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/destructive-attacks-guidance-fig9.max-1000x1000.png" alt="Windows Firewall Suggested Rule Blocks via Group Policy">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="ibnn4">Figure 9: Windows Firewall suggested rule blocks via Group Policy</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h5><span>NTLM Authentication Configurations</span></h5>
<p><span>Threat actors often attempt to harvest credentials (including Windows NTLMv1 hashes) based upon outbound SMB or WebDAV communications. Organizations should review NTLM settings for Windows-based endpoints, and work to harden, disable, or restrict NTLMv1 authentication requests. </span></p>
<p><span>To fully restrict NTLM authentication to remote servers, the following GPO settings can be leveraged:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Windows Settings &gt; Security Settings &gt; Local Policies &gt; Security Options &gt; Network Security: Restrict NTLM: Outgoing NTLM traffic to remote servers </span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Allow all</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Audit all</span></p>
</li>
<li aria-level="1"><span>Deny all</span></li>
</ul>
</li>
</ul>
<p><strong>Note:</strong><span> </span><span>If "</span><code>Deny all</code><span>" is selected, the client computer cannot authenticate (send credentials) to a remote server using NTLM authentication. Before setting to "</span><code>Deny all,</code><span>" organizations should configure the GPO setting with the "</span><code>Audit all</code><span>" enforcement. With this configuration, audit and block events will be recorded within the Operational event log on endpoints (</span><code>Applications and Services Log\Microsoft\Windows\NTLM</code><span>).</span></p>
<p><span>If any recorded NTLM authentication events are required, organizations can configure the "</span><code>Network security: Restrict NTLM: Add remote server exceptions for NTLM authentication</code><span>" setting to define a listing of remote servers, which are required to use NTLM authentication.</span></p>
<h4><span>Detection Opportunities for SMB, WMI, and NTLM Communications</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>High Volume of SMB Connections</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1021/002/" rel="noopener" target="_blank"><span>T1021.002 – SMB/Windows Admin Shares</span></a></p>
</td>
<td>
<p><span>Search for a sharp increase in SMB connections that fall outside of a normal pattern.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Outbound Connection Attempted Over SMB</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1212/" rel="noopener" target="_blank"><span>T1212 – Exploitation for Credential Access</span></a></p>
</td>
<td>
<p><span>Search for external connection attempts over SMB, as this may be an attempt to harvest credential hashes.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>WMI Being Used to Call a Remote Service</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1047/" rel="noopener" target="_blank"><span>T1047 – Windows Management Instrumentation</span></a></p>
</td>
<td>
<p><span>Search for WMI being used via a command line or PowerShell to call a remote service for execution.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>WMI Being Used for Ingress Tool Transfer</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1105/" rel="noopener" target="_blank"><span>T1105 – Ingress Tool Transfer</span></a></p>
</td>
<td>
<p><span>Search for suspicious usage of WMI to download external resources. </span></p>
</td>
</tr>
<tr>
<td>
<p><span>Forced NTLM Authentication Using SMB or WebDAV</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1187/" rel="noopener" target="_blank"><span>T1187 – Forced Authentication</span></a></p>
</td>
<td>
<p><span>Search for potential NTLM authentication attempts using SMB or WebDAV.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>NTLM Relay via Coercion</span></p>
</td>
<td>
<p><span>T1187 - Forced Authentication</span></p>
</td>
<td>
<p><span>Monitor for NTLM authentication attempts from Domain Controllers or privileged servers to unexpected destinations, particularly to HTTP endpoints (AD CS web enrollment). </span></p>
<p><span>Detect PetitPotam by monitoring for EfsRpcOpenFileRaw calls, DFSCoerce via DFS-related named pipe access, and PrinterBug via SpoolService RPC calls.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 13: Detection opportunities for SMB, WMI, and NTLM communications</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Remote Desktop Protocol Hardening</span></h4>
<p><span>Remote Desktop Protocol (RDP) is a common method used by threat actors to remotely connect to systems, laterally move from the perimeter onto a larger scope of internal systems, and perform malicious activities (such as data theft or ransomware deployment). External-facing systems with RDP open to the internet present an elevated risk. Threat actors may exploit this vector to gain initial access to an organization and then perform lateral movement into the organization to complete their mission objectives.</span></p>
<p><span>Proactively, organizations should scan their public IP address ranges to identify systems with RDP (TCP/3389) and other protocols (SMB – TCP/445) open to the internet. At a minimum, RDP and SMB should not be directly exposed for ingress and egress access to/from the internet. If required for operational purposes, explicit controls should be implemented to restrict the source IP addresses, which can interface with systems using these protocols. The following hardening recommendations should also be implemented.</span></p>
<h5><span>Enforce Multi-Factor Authentication</span></h5>
<p><span>If external-facing RDP must be used for operational purposes, MFA should be enforced when connecting using this method. This can be accomplished either via the integration of a third-party MFA technology or by leveraging a Remote Desktop Gateway and Azure Multifactor Authentication Server using Remote Authentication Dial-In User Service (<a href="https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfaserver-nps-rdg" rel="noopener" target="_blank">RADIUS</a>)</span><span>.</span></p>
<h5><span>Leverage Network-Level Authentication</span></h5>
<p><span>For external-facing RDP servers, Network-Level Authentication (NLA) provides an extra layer of preauthentication before a connection is established. NLA can also be useful for protecting against brute-force attacks, which often target open internet-facing RDP servers.</span></p>
<p><span>NLA can be configured either via the user interface (UI) (Figure 10) or via Group Policy (Figure 11).</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--medium
      
      
        h-c-grid__col
        
        h-c-grid__col--4 h-c-grid__col--offset-4
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/destructive-attacks-guidance-fig10.max-1000x1000.png" alt="Enabling NLA via the UI">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="bx1dm">Figure 10: Enabling NLA via the UI</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>Using a GPO, the setting for NLA can be configured via:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Administrative Templates &gt; Windows Components &gt; Remote Desktop Services &gt; Remote Desktop Session Host &gt; Security &gt; Require user authentication for remote connections by using Network Level Authentication</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Enabled</span></p>
</li>
</ul>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/destructive-attacks-guidance-fig11.max-1000x1000.png" alt="Enabling NLA via Group Policy">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="bx1dm">Figure 11: Enabling NLA via Group Policy</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>Some caveats about leveraging NLA for RDP:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>The Remote Desktop client v7.0 (or greater) must be leveraged.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>NLA uses CredSSP to pass authentication requests on the initiating system. CredSSP stores credentials in Local Security Authority (LSA) memory on the initiating system, and these credentials may remain in memory even after a user logs off the system. This provides a potential exposure risk for credentials in memory on the source system.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>On the RDP server, users permitted for remote access using RDP must be assigned the </span><span>Access this computer from the network</span><span> privilege when NLA is enforced. </span><strong>This privilege is often explicitly denied for user accounts to protect against lateral movement techniques.</strong></p>
</li>
</ul>
<h5><span>Restrict Administrative Accounts from Leveraging RDP on Internet-Facing Systems</span></h5>
<p><span>For external-facing RDP servers, highly privileged domain and local administrative accounts should not be permitted access to authenticate with the external-facing systems using RDP (Figure 12). </span></p>
<p><span>This can be enforced using Group Policy, configurable via the following path: </span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Windows Settings &gt; Security Settings &gt; Local Policies &gt; User Rights Assignment &gt; Deny log on through Terminal Services</span></p>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/destructive-attacks-guidance-fig12.max-1000x1000.png" alt="Group Policy configuration for restricting highly privileged domain and local administrative accounts from leveraging RDP">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="ro2xo">Figure 12: Group Policy configuration for restricting highly privileged domain and local administrative accounts from leveraging RDP</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h4><span>Detection Opportunities for RDP Usage</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>RDP Authentication Integration </span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1110/" rel="noopener" target="_blank"><span>T1110 – Brute Force</span></a></p>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
<p><a href="https://attack.mitre.org/techniques/T1021/001/" rel="noopener" target="_blank"><span>T1021.001 – Remote Desktop Protocol</span></a></p>
</td>
<td>
<p><span>Existing authentication rules should include RDP attempts. This includes use cases for:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Brute Force</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Password Spraying</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>MFA Failures Single User</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>MFA Failures Single Source</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>External Authentication from an Account with Elevated Privileges</span></p>
</li>
</ul>
</td>
</tr>
<tr>
<td>
<p><span>Anomalous Connection Attempts over RDP</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
<p><a href="https://attack.mitre.org/techniques/T1021/001/" rel="noopener" target="_blank"><span>T1021.001 – Remote Desktop Protocol</span></a></p>
</td>
<td>
<p><span>Searching for anomalous RDP connection attempts over known RDP ports such as TCP/3389.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 14: Detection Opportunities for RDP Usage</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Disabling Administrative/Hidden Shares</span></h4>
<p><span>To conduct lateral movement, threat actors may attempt to identify administrative or hidden network shares, including those that are not explicitly mapped to a drive letter and use these for remotely binding to endpoints throughout an environment. As a protective or rapid containment measure, organizations may need to quickly disable default administrative or hidden shares from being accessible on endpoints. This can be accomplished by either modifying the registry, stopping a service, or by using the <a href="https://www.microsoft.com/en-us/download/details.aspx?id=55319" rel="noopener" target="_blank">MSS (Legacy) Group Policy template</a></span><span>.</span></p>
<p><span>Common administrative and hidden shares on endpoints include:</span></p>
<ul>
<li role="presentation"><code>ADMIN$</code></li>
<li role="presentation"><code>C$</code></li>
<li role="presentation"><code>D$</code></li>
<li role="presentation"><code>IPC$</code></li>
</ul></div>
<div class="block-paragraph_advanced"><div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1">
<tbody>
<tr>
<td>
<p><strong>Note:</strong><span> </span><span>Disabling administrative and hidden shares on servers, specifically including domain controllers, may significantly impact the operation and functionality of systems within a domain-based environment.</span></p>
<span>Additionally, if PsExec is used in an environment, disabling the admin (</span><code>ADMIN$</code><span>) share can restrict the capability for this tool to be used to remotely interface with endpoints.</span></td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h5><span>Registry Method</span></h5>
<p><span>Using the registry, administrative and hidden shares can be disabled on endpoints (Figure 13 and Figure 14).</span></p>
<h6><span>Workstations</span></h6></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters
DWORD Name = "AutoShareWks"
Value = "0"</code></pre>
<p><span>Figure 13: Registry value disabling administrative shares on workstations</span></p></div>
<div class="block-paragraph_advanced"><h6><span>Servers</span></h6></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters
DWORD Name = "AutoShareServer"
Value = "0"</code></pre>
<p><span>Figure 14: Registry value disabling administrative shares on servers</span></p></div>
<div class="block-paragraph_advanced"><h5><span>Service Method</span></h5>
<p><span>By stopping the </span><span>Server</span><span> service on an endpoint, the ability to access any shares hosted on the endpoint will be disabled (Figure 15).</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/destructive-attacks-guidance-fig15.max-1000x1000.png" alt="Server service properties">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="7xllt">Figure 15: Server service properties</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h5><span>Group Policy Method</span></h5>
<p><span>Using the MSS (Legacy) Group Policy template, administrative and hidden shares can be disabled on either a server or workstation via a GPO setting (Figure 16).</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Administrative Templates &gt; MSS (Legacy) &gt; MSS (AutoShareServer)</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Disabled</span></p>
</li>
</ul>
</li>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Administrative Templates &gt; MSS (Legacy) &gt; MSS (AutoShareWks)</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Disabled</span></p>
</li>
</ul>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/destructive-attacks-guidance-fig16.max-1000x1000.png" alt="Disabling Administrative And Hidden Shares via the MSS (Legacy) Group Policy Template">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="7xllt">Figure 16: Disabling administrative and hidden shares via the MSS (Legacy) Group Policy template</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h4><span>Detection Opportunities for Accessing Administrative or Hidden Shares</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Network Discovery: Suspicious Usage of the Net Command</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1049/" rel="noopener" target="_blank"><span>T1049 - System Network Connections Discovery</span></a></p>
<p><a href="https://attack.mitre.org/techniques/T1135/" rel="noopener" target="_blank"><span>T1135 - Network Share Discovery</span></a></p>
</td>
<td>
<p><span>Search for suspicious use of the </span><code>net</code><span> command to enumerate systems and file shares within an environment.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 15: Detection opportunities for accessing administrative or hidden shares</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Hardening Windows Remote Management</span></h4>
<p><span>Threat actors may leverage Windows Remote Management (WinRM) to laterally move throughout an environment. </span><strong>WinRM is enabled by default on all Windows Server operating systems (since Windows Server 2012 and above)</strong><span>, but disabled on all client operating systems (Windows 7 and Windows 10) and older server platforms (Windows Server 2008 R2).</span></p>
<p><span>PowerShell remoting (PS remoting) is a native Windows remote command execution feature that is built on top of the WinRM protocol.</span></p>
<p><span>Windows client (nonserver) operating system platforms where WinRM is disabled indicates that there is:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>No WinRM listener configured</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>No Windows firewall exception configured</span></p>
</li>
</ul>
<p><span>By default, WinRM uses TCP/5985 and TCP/5986, which can be either disabled using the Windows Firewall or configured so that a specific subset of IP addresses can be authorized for connecting to endpoints using WinRM.</span></p>
<p><span>WinRM and PowerShell remoting can be explicitly disabled on endpoint using either a PowerShell command (Figure 17) or specific GPO settings.</span></p>
<h5><span>PowerShell</span></h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>Disable-PSRemoting -Force</code></pre>
<p><span>Figure 17: PowerShell command to disable WinRM/PowerShell remoting on an endpoint</span></p></div>
<div class="block-paragraph_advanced"><p><strong>Note:</strong><span> </span><span>Running </span><code>Disable-PSRemoting -Force</code><span> does not prevent local users from creating PowerShell sessions on the local computer or for sessions destined for remote computers.</span></p>
<p><span>After running the command, the message recorded in Figure 18 will be displayed. These steps provide additional hardening, but after running the </span><code>Disable-PSRemoting -Force</code><span> command, PowerShell sessions destined for the target endpoint will not be successful.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/destructive-attacks-guidance-fig18.max-1000x1000.png" alt="Warning message after disabling PSRemoting">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="gwqyc">Figure 18: Warning message after disabling PSRemoting</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>To enforce the additional steps for disabling WinRM via PowerShell (Figure 19 through Figure 22):</span></p>
<ol>
<li><span>Stop and disable the </span><span>WinRM</span><span> service.<br><br></span>
<pre class="language-plain"><code>Stop-Service WinRM -PassThruSet-Service WinRM -StartupType Disabled</code></pre>
<p><span>Figure 19: PowerShell command to stop and disable the WinRM service</span></p>
<span><br></span></li>
<li><span><span>Disable the listener that accepts requests on any IP address.<br><br></span></span>
<pre class="language-plain"><code>dir wsman:\localhost\listener

Remove-Item -Path WSMan:\Localhost\listener\&lt;Listener name&gt;</code></pre>
<p><span>Figure 20: PowerShell commands to delete a WSMan listener</span></p>
<span><span><br></span></span></li>
<li><span><span>Disable the firewall exceptions for WS-Management communications.<br><br></span></span>
<pre class="language-plain"><code>Set-NetFirewallRule -DisplayName 'Windows Remote Management (HTTP-In)' -Enabled False </code></pre>
<p><span>Figure 21: PowerShell command to disable firewall exceptions for WinRM</span></p>
<span><span><br></span></span></li>
<li><span><span><span>Restore the value of </span><code>the LocalAccountTokenFilterPolicy</code><span> to 0, which restricts remote access to members of the Administrators group on the computer.<br><br></span></span></span>
<pre class="language-plain"><code>Set-ItemProperty -Path HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system -Name LocalAccountTokenFilterPolicy -Value 0</code></pre>
<p><span><span><span><span>Figure 22: PowerShell command to configure the registry key for LocalAccountTokenFilterPolicy</span></span></span></span></p>
</li>
</ol></div>
<div class="block-paragraph_advanced"><h5><span>Group Policy</span></h5>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Administrative Templates &gt; Windows Components &gt; Windows Remote Management (WinRM) &gt; WinRM Service &gt; Allow remote server management through WinRM</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Disabled</span></p>
</li>
</ul>
</li>
</ul>
<p><span>If this setting is configured as </span><span>Disabled</span><span>, the WinRM service will not respond to requests from a remote computer, regardless of whether any WinRM listeners are configured.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Administrative Templates &gt; Windows Components &gt; Windows Remote Shell &gt; Allow Remote Shell Access </span></p>
<ul>
<li aria-level="1"><span><span>Disabled</span></span></li>
</ul>
</li>
</ul>
<p><span>This policy setting will manage the configuration of remote access to all supported shells to execute scripts and commands.</span></p>
<h4><span>Detection Opportunities for WinRM Usage</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Unauthorized WinRM Execution Attempt</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1021/006/" rel="noopener" target="_blank"><span>T1021.006 - Remote Services: Windows Remote Management</span></a></p>
</td>
<td>
<p><span>Search for command execution attempts for WinRM on a system where WinRM has been disabled.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Suspicious Process Creation Using WinRM</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1021/006/" rel="noopener" target="_blank"><span>T1021.006 - Remote Services: Windows Remote Management</span></a></p>
</td>
<td>
<p><span>Search for anomalous process creation events using WinRM that deviate from an established baseline.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Suspicious Network Connection Using WinRM</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1021/006/" rel="noopener" target="_blank"><span>T1021.006 - Remote Services: Windows Remote Management</span></a></p>
</td>
<td>
<p><span>Search for network activity over known WinRM ports, such as TCP/5985 and TCP/5986, to identify anomalous connections that deviate from an established baseline.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Remote WMI Connection Using WinRM</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1021/006/" rel="noopener" target="_blank"><span>T1021.006 - Remote Services: Windows Remote Management</span></a></p>
</td>
<td>
<p><span>Search for remote WMI connection attempts using WinRM. </span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 16: Detection opportunities for WinRM use</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Restricting Common Lateral Movement Tools and Methods</span></h4>
<p><span>Table 17 provides a consolidated summary of security configurations that can be leveraged to combat against common remote access tools and methods used for lateral movement within environments.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col></colgroup>
<thead>
<tr>
<th scope="col">
<p><span>Tool/Tactic</span></p>
</th>
<th scope="col">
<p><span>Mitigating Security Configurations (Target Endpoints)</span></p>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p><span>PsExec (using the current logged-on user account, without the </span><code>-u</code><span> switch)</span></p>
<p><span>If the </span><code>-u</code><span> switch is not leveraged, authentication will use Kerberos or NTLM for the current logged-on user of the source endpoint and will register as a Type 3 (network) logon on the destination endpoint.</span></p>
<p><span>PsExec high-level functionality:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Connects to the hidden </span><code>ADMIN$</code><span> share (mapping to the </span><code>C:\Windows</code><span> folder) on a remote endpoint via SMB (TCP/445).</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Uses the Service Control Manager (SCM) to start the </span><code>PSExecsvc</code><span> service and enable a named pipe on a remote endpoint.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Input/output redirection for the console is achieved via the created named pipe.</span></p>
</li>
</ul>
</td>
<td>
<p><strong>Option 1:</strong></p>
<p><span>GPO configuration:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Windows Settings &gt; Security Settings &gt; Local Policies &gt; User Rights Assignment</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Deny access to this computer from the network</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Deny access to this computer from the network</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Deny log on locally</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Deny log on through Terminal Services</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>DCOM:Machine Launch Restrictions in Security Descriptor Definition Language (SDDL) Syntax</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Windows Settings &gt; Local Policies &gt; Security Options</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>DCOM:Machine Access Restrictions in Security Descriptor Definition Language (SDDL) Syntax</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Deny access to this computer from the network</span></p>
</li>
</ul>
<p><strong>Option 2: </strong></p>
<p><span>Windows Firewall rule:<br><br></span></p>
<pre class="language-plain"><code>netsh advfirewall firewall set rule group="File and Printer Sharing" new enable=no</code></pre>
<p><span>Figure 23: PowerShell command to disable inbound file and print sharing (SMB) for an endpoint using a local Windows Firewall rule</span></p>
<p><strong>Option 3:</strong></p>
<p><span>Disable administrative and hidden shares.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>PsExec (with Alternative Credentials, via the </span><code>-u</code><span> switch)</span></p>
<p><span>If the </span><code>-u</code><span> switch is leveraged, authentication will use the alternate supplied credentials and will register as a Type 3 (network) and Type 2 (interactive) logon on the destination endpoint.</span></p>
</td>
<td>
<p><strong>Option 1:</strong></p>
<p><span>GPO configuration:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Windows Settings &gt; Security Settings &gt; Local Policies &gt; User Rights Assignment</span></p>
</li>
</ul>
<p><strong>Option 2:</strong></p>
<p><span>Windows Firewall rule:<br><br></span></p>
<pre class="language-plain"><code>netsh advfirewall firewall set rule group="File and Printer Sharing" new enable=no</code></pre>
<p><span>Figure 24: PowerShell command to disable inbound file and print sharing (SMB) for an endpoint using a local Windows Firewall rule</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Remote Desktop Protocol (RDP)</span></p>
</td>
<td>
<p><strong>Option 1:</strong></p>
<p><span>GPO configuration:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Windows Settings &gt; Security Settings &gt; Local Policies &gt; User Rights Assignment</span></p>
</li>
</ul>
<p><strong>Option 2:</strong></p>
<p><span>Windows Firewall rule:<br><br></span></p>
<pre class="language-plain"><code>netsh advfirewall firewall set rule group="Remote Desktop" new enable=no</code></pre>
<p><span>Figure 25: PowerShell command to disable inbound Remote Desktop (RDP) for an endpoint using a local Windows Firewall rule</span></p>
</td>
</tr>
<tr>
<td>
<p><span>PS remoting and WinRM</span></p>
</td>
<td>
<p><strong>Option 1:</strong></p>
<p><span>PowerShell command:<br><br></span></p>
<pre class="language-plain"><code>Disable-PSRemoting -Force</code></pre>
<p><span>Figure 26: PowerShell command to disable PowerShell remoting for an endpoint</span></p>
<p><strong>Option 2:</strong></p>
<p><span>GPO configuration:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Administrative Templates &gt; Windows Components &gt; Windows Remote Management (WinRM) &gt; WinRM Service &gt; Allow remote server management through WinRM</span></p>
</li>
</ul>
<p><strong>Option 3:</strong></p>
<p><span>Windows Firewall rule:<br><br></span></p>
<pre class="language-plain"><code>netsh advfirewall firewall set rule group="Windows Remote Management" new enable=no</code></pre>
<p><span>Figure 27: PowerShell command to disable inbound WinRM for an endpoint using a local Windows Firewall rule</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Distributed Component Object Model (DCOM)</span></p>
</td>
<td>
<p><strong>Option 1:</strong></p>
<p><span>GPO configuration:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Windows Settings &gt; Local Policies &gt; Security Options</span></p>
</li>
</ul>
<p><span>Both of these settings allow an organization to define additional computer-wide controls that govern access to all DCOM–based applications on an endpoint.</span></p>
<p><span>When users or groups that are provided permissions are specified, the security descriptor field is populated with the SDDL representation of those groups and privileges.</span></p>
<p><span>Users and groups can be given explicit </span><span>Allow</span><span> or </span><span>Deny</span><span> privileges for both local and remote access using DCOM.</span></p>
<p><strong>Option 2:</strong></p>
<p><span>Windows Firewall rules:<br><br></span></p>
<pre class="language-plain"><code>netsh advfirewall firewall set rule group="COM+ Network Access" new enable=no

netsh advfirewall firewall set rule group="COM+ Remote Administration" new enable=no</code></pre>
<p><span>Figure 28: PowerShell commands to disable inbound DCOM for an endpoint using a local Windows Firewall rule</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Third-party remote access applications (e.g., VNC/DameWare/ScreenConnect) that rely upon specific interactive and remote logon permissions being configured on an endpoint.</span></p>
</td>
<td>
<p><span>GPO configuration:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Windows Settings &gt; Security Settings &gt; Local Policies &gt; User Rights Assignment</span></p>
</li>
</ul>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div><span>Table 17: Common lateral movement tools/methods and mitigating security controls</span></div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h4><span>Detection Opportunities for Common Lateral Movement Tools and Methods</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Anomalous PsExec Usage</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1569/002/" rel="noopener" target="_blank"><span>T1569.002 – System Services: Service Execution</span></a></p>
<p><a href="https://attack.mitre.org/techniques/T1021/002/" rel="noopener" target="_blank"><span>T1021.002 – Remote Services: SMB/Windows Admin Shares</span></a></p>
<p><a href="https://attack.mitre.org/techniques/T1570/" rel="noopener" target="_blank"><span>T1570 – Lateral Tool Transfer</span></a></p>
</td>
<td>
<p><span>Search for attempted execution of PsExec on systems where PsExec is disabled or where it deviates from normal activity.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Process Creation Event Involving a COM Object by Different User</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1021/003/" rel="noopener" target="_blank"><span>T1021.003 – Remote Services: Distributed Component Object Model</span></a></p>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
</td>
<td>
<p><span>Search for process creation events including COM objects that are initiated by an account that is not currently the logged-in user for the system.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>High Volume of DCOM-Related Activity</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1021/003/" rel="noopener" target="_blank"><span>T1021.003 – Remote Services: Distributed Component Object Model</span></a></p>
</td>
<td>
<p><span>Search for a sharp increase in volume of DCOM-related activity. </span></p>
</td>
</tr>
<tr>
<td>
<p><span>Third-Party Remote Access Applications</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1219/" rel="noopener" target="_blank"><span>T1219 – Remote Access Software</span></a></p>
</td>
<td>
<p><span>Search for anomalous use of</span><strong> </strong><span>third-party remote access applications. This type of activity could indicate a threat actor is attempting to use third-party remote access applications as an alternate communication channel or for creating remote interactive sessions.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>BYOVD - EDR/AV Tampering via Vulnerable Drivers</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1068/" rel="noopener" target="_blank"><span>T1068 - Exploitation for Privilege Escalation</span></a></p>
<p><a href="https://attack.mitre.org/techniques/T1562/001/" rel="noopener" target="_blank"><span>T1562.001 - Impair Defenses</span></a></p>
</td>
<td>
<p><span>Monitor for kernel driver installations (Sysmon Event ID 6) where the loaded driver hash matches known vulnerable drivers from the LOLDrivers project.</span></p>
<p><span>Alert on new service creation (Event ID 7045) loading .sys files from user-writable paths (e.g., %TEMP%, %APPDATA%). </span></p>
</td>
</tr>
<tr>
<td>
<p><span>RMM Tool Abuse for Lateral Movement</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1219/" rel="noopener" target="_blank"><span>T1219 - Remote Access Tools</span></a></p>
</td>
<td>
<p><span>Monitor for installation or execution of legitimate RMM tools (ScreenConnect/ConnectWise, AnyDesk, Atera, Splashtop, TeamViewer) that are not part of the organization's approved toolset.</span></p>
<p><span>Monitor for new service installations matching known RMM tool signatures.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 18: Detection opportunities for common lateral movement tools and methods</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Additional Endpoint Hardening</span></h4>
<p><span>To help protect against malicious binaries, malware, and encryptors being invoked on endpoints, additional security hardening technologies and controls should be considered. Examples of additional security controls for consideration for Windows-based endpoints are provided as follows.</span></p>
<h5><span>Windows Defender Application Control</span></h5>
<p><span>Windows Defender Application Control is a set of inherent configuration settings within Active Directory that provide lockdown and control mechanisms for controlling which applications and files users can run on endpoints. With this functionality, the following types of rules can be configured within GPOs:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Publisher rules: Can be leveraged to allow or restrict execution of files based upon digital signatures and other attributes</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Path rules: Can be leveraged to allow or restrict file execution or access based upon files residing in specific path</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>File hash rules: Can be leveraged to allow or restrict file execution based on a file's hash</span></p>
</li>
</ul>
<p><span>Additional information related to <a href="https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/applocker/applocker-overview" rel="noopener" target="_blank">Windows Defender Application Control</a></span><span>.</span></p>
<h5><span>Microsoft Defender Attack Surface Reduction</span></h5>
<p><span>Microsoft Defender Attack Surface Reduction (ASR) rules can help protect against various threats, including:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>A threat actor launching executable files and scripts that attempt to download or run files</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>A threat actor running obfuscated or suspicious scripts</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>A threat actor invoking credential theft tools that interface with Local Security Authority Subsystem Service (LSASS)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>A threat actor invoking PsExec or WMI commands</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Normalizing and blocking behaviors that applications do not usually initiate as part of standardized activity</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Blocking executable content from email clients and web mail (phishing)</span></p>
</li>
</ul>
<p><span>ASR requires a Windows E3 license or above. A Windows E5 license provides advanced management capabilities for ASR.</span></p>
<p><span>Additional information related to <a href="https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/attack-surface-reduction" rel="noopener" target="_blank">Microsoft Defender Attack Surface Reduction functionality</a></span><span>.</span></p>
<h5><span>Controlled Folder Access</span></h5>
<p><span>Controlled folder access can help protect data from being encrypted by ransomware. Beginning with Windows 10 version 1709+ and Windows Server 2019+, controlled folder access was introduced within Windows Defender Antivirus (as part of Windows Defender Exploit Guard). </span></p>
<p><span>Once controlled folder access is enabled, applications and executable files are assessed by Windows Defender Antivirus, which then determines if an application is malicious or safe. If an application is determined to be malicious or suspicious, it will be blocked from making changes to any files in a protected folder.</span></p>
<p><span>Once enabled, controlled folder access will apply to a number of system folders and default locations, including:</span></p></div>
<div class="block-paragraph_advanced"><ul>
<li>Documents
<ul>
<li><code>C:\users\&lt;username&gt;\Documents</code></li>
<li><code>C:\users\Public\Documents</code></li>
</ul>
</li>
<li>Pictures
<ul>
<li><code>C:\users\&lt;username&gt;\Pictures</code></li>
<li><code>C:\users\Public\Pictures</code></li>
</ul>
</li>
<li>Videos
<ul>
<li><code>C:\users\&lt;username&gt;\Videos</code></li>
<li><code>C:\users\Public\Videos</code></li>
</ul>
</li>
<li>Music
<ul>
<li><code>C:\users\&lt;username&gt;\Music</code></li>
<li><code>C:\users\Public\Music</code></li>
</ul>
</li>
<li>Desktop
<ul>
<li><code>C:\users\&lt;username&gt;\Desktop</code></li>
<li><code>C:\users\Public\Desktop</code></li>
</ul>
</li>
<li>Favorites
<ul>
<li><code>C:\users\&lt;username&gt;\Favorites</code></li>
</ul>
</li>
</ul></div>
<div class="block-paragraph_advanced"><p><span>Additional folders can be added using the Windows Security application, Group Policy, PowerShell, or mobile device management (MDM) configuration service providers (CSPs). Additionally, applications can be allow-listed for access to protected folders.</span></p>
<p><strong>Note:</strong><span> </span><span>For controlled folder access to fully function, Windows Defender's </span><span>Real Time Protection</span><span> setting must be enabled.</span></p>
<p><span>Additional information related to <a href="https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/enable-controlled-folders" rel="noopener" target="_blank">controlled folder access</a></span><span>.</span></p>
<h5><span>Tamper Protection</span></h5>
<p><span>Threat actors will often attempt to disable security features on endpoints. Tamper protection either in Windows (via Microsoft Defender for Endpoint) or integrated within third-party AV/EDR platforms can help protect security tools from being modified or stopped by a threat actor. Organizations should review the configuration of security technologies that are deployed to endpoints and verify if tamper protection is (or can be) enabled to protect against unauthorized modification. Once implemented, organizations should test and validate that the tamper protection controls behave as expected as different products offer different levels of protection.</span></p>
<p><span>Additional information related to <a href="https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/prevent-changes-to-security-settings-with-tamper-protection" rel="noopener" target="_blank">tamper protection for Windows Defender for Endpoint</a></span><span>.</span></p>
<h4><span>Detection Opportunities for Tamper Protection Events</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Threat Actor Attempting to Disable Security Tooling on an Endpoint</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1562/001/" rel="noopener" target="_blank"><span>T1562.001 - Disable or Modify Tools</span></a></p>
</td>
<td>
<p><span>Monitor for evidence of processes or command-line arguments correlating to security tools/services being stopped.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 19: Detection opportunities for tamper protection events</span></div></div>
<div class="block-paragraph_advanced"><h3><span>4. Credential Exposure and Account Protections</span></h3>
<h4><span>Identification of Privileged Accounts and Groups</span></h4>
<p><span>Threat actors will prioritize identifying privileged accounts as part of reconnaissance efforts. Once identified, threat actors will attempt to obtain credentials for these accounts for lateral movement, persistence, and mission fulfillment.</span></p>
<p><span>Organizations should proactively focus on identifying and reviewing the scope of accounts and groups within Active Directory that have an elevated level of privilege. An elevated level of privilege can be determined by the following criteria:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Accounts or nested groups that are assigned membership into default domain and Exchange-based privileged groups (Figure 29)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Accounts or nested groups that are assigned membership into security groups protected by </span><code>AdminSDHolder</code></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Accounts or groups assigned permissions for organizational units (OUs) housing privileged accounts, groups, or endpoints</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Accounts or groups assigned specific extended right permissions either directly at the root of the domain or for OUs where permissions are inherited by child objects. Examples include:</span></p>
<ul>
<li><code>DS-Replication-Get-Changes-All</code></li>
<li><code>Administer Exchange Information Store</code></li>
<li><code>View Exchange Information Store Status</code></li>
<li><code>Create-Inbound-Forest-Trust</code></li>
<li><code>Migrate-SID-History</code></li>
<li><code>Reanimate-Tombstones</code></li>
<li><code>View Exchange Information Store Status</code></li>
<li><code>User-Force-Change-Password</code></li>
</ul>
</li>
<li aria-level="1">
<p role="presentation"><span>Accounts or groups assigned permissions for modifying or linking GPOs</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Accounts or groups assigned explicit permissions on domain controllers or Tier 0 endpoints</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Accounts or groups assigned directory service replication permissions</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Accounts or groups with local administrative access on all endpoints (or a large scope of critical assets) in a domain</span></p>
</li>
</ul>
<p><span>To identify accounts that are provided membership into default domain-based privileged groups or are protected by </span><code>AdminSDHolder</code><span>, the following PowerShell cmdlets can be run from a domain controller.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>get-ADGroupMember -Identity "Domain Admins" -Recursive | export-csv -path &lt;output directory&gt;\DomainAdmins.csv -NoTypeInformation 

get-ADGroupMember -Identity "Enterprise Admins" -Recursive | export-csv -path &lt;output directory&gt;\EnterpriseAdmins.csv -NoTypeInformation 

get-ADGroupMember -Identity "Schema Admins" -Recursive | export-csv -path &lt;output directory&gt;\SchemaAdmins.csv -NoTypeInformation

get-ADGroupMember -Identity "Administrators" -Recursive | export-csv -path &lt;output directory&gt;\Administrators.csv -NoTypeInformation 

get-ADGroupMember -Identity "Account Operators" -Recursive | export-csv -path &lt;output directory&gt;\AccountOperators.csv -NoTypeInformation 

get-ADGroupMember -Identity "Backup Operators" -Recursive | export-csv -path &lt;output directory&gt;\BackupOperators.csv -NoTypeInformation 

get-ADGroupMember -Identity "Cert Publishers" -Recursive | export-csv -path &lt;output directory&gt;\CertPublishers.csv -NoTypeInformation 

get-ADGroupMember -Identity "Print Operators" -Recursive | export-csv -path &lt;output directory&gt;\PrintOperators.csv -NoTypeInformation 

get-ADGroupMember -Identity "Server Operators" -Recursive | export-csv -path &lt;output directory&gt;\ServerOperators.csv -NoTypeInformation 

get-ADGroupMember -Identity "DNSAdmins" -Recursive | export-csv -path &lt;output directory&gt;\DNSAdmins.csv -NoTypeInformation 

get-ADGroupMember -Identity "Group Policy Creator Owners" -Recursive | export-csv -path &lt;output directory&gt;\Group-Policy-Creator-Owners.csv -NoTypeInformation 

get-ADGroupMember -Identity "Exchange Trusted Subsystem" -Recursive | export-csv -path &lt;output directory&gt;\Exchange-Trusted-Subsystem.csv -NoTypeInformation

get-ADGroupMember -Identity "Exchange Windows Permissions" -Recursive | export-csv -path &lt;output directory&gt;\Exchange-Windows-Permissions.csv -NoTypeInformation 

get-ADGroupMember -Identity "Exchange Recipient Administrators" -Recursive | export-csv -path &lt;output directory&gt;\Exchange-Recipient-Admins.csv -NoTypeInformation 

get-ADUser -Filter {(AdminCount -eq 1) -And (Enabled -eq $True)} | Select-Object Name, DistinguishedName | export-csv -path &lt;output directory&gt;\AdminSDHolder_Enabled.csv</code></pre>
<p><span>Figure 29: Commands to identify domain and exchange-based privileged accounts</span></p></div>
<div class="block-paragraph_advanced"><p><span>Any privileged accounts granted membership into additional security groups can provide a threat actor with a potential path to domain administration-level permissions based upon endpoints where the accounts have permissions to log on or remotely access systems.</span></p>
<p><span>Ideally, only a small scope of accounts should be provided with highly privileged access within a domain. Accounts with highly privileged permissions should </span><strong>not</strong><span> be leveraged for daily use; used for interactive or remote logons to workstations, laptops, or common servers; or used for performing functions on non-domain controller (Tier 0) assets.For additional recommendations for restricting access for privileged accounts, reference the Privileged Account Logon Restrictions</span><span> section of this blog post.</span></p>
<h4><span>Detection Opportunities for Privileged Accounts, Groups, and GPO Modifications</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Interactive or Remote Logon of a Highly Privileged Account to an Unauthorized System</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
</td>
<td>
<p><span>Search for logon attempts correlating to highly privileged accounts authenticating to systems that reside outside of the Tier 0 layer.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Privileged Account and Group Discovery</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1069/" rel="noopener" target="_blank"><span>T1069 – Permission Groups Discovery</span></a></p>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
</td>
<td>
<p><span>Search for command-line events where a user is attempting to enumerate privileged accounts and groups.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Account Added to Highly Privileged Group</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
<p><a href="https://attack.mitre.org/techniques/T1098/" rel="noopener" target="_blank"><span>T1098 – Account Manipulation</span></a></p>
</td>
<td>
<p><span>Identify when accounts are added to highly privileged groups. While this can occur as part of normal activity, it should be infrequent and limited to specific accounts.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Modification of Group Policy Objects</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1484/001/" rel="noopener" target="_blank"><span>T1484.001 – Domain Policy Modification: Group Policy Modification</span></a></p>
</td>
<td>
<p><span>Identify when GPOs are created or modified.</span></p>
<p><span>GPOs can also be exported and reviewed to identify last modification timestamps.<br><br></span></p>
<pre class="language-plain"><code>get-gpo -all | export-csv -path "c:\temp\gpo-listing-all.csv" -NoTypeInformation</code></pre>
<p><span>Figure 30: PowerShell cmdlet to export and review GPO creation and modification timestamps</span></p>
</td>
</tr>
<tr>
<td>
<p><span>DCSync Attack</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1003/006/" rel="noopener" target="_blank"><span>T1003.006 - OS Credential Dumping</span></a></p>
</td>
<td>
<p><span>Monitor for non-domain-controller sources issuing directory replication requests (</span><span>DS-Replication-Get-Changes</span><span> and </span><span>DS-Replication-Get-Changes-All</span><span>). </span></p>
<p><span>Event ID 4662 with properties matching the replication GUIDs (</span><span>1131f6aa-*, 1131f6ad-*</span><span>) from non-domain-controller source addresses is a high-fidelity indicator of DCSync.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 20: Detection opportunities for privileged accounts, groups, and GPO modifications</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Privileged and Service Account Protections</span></h4>
<h5><span>Identify and Review Noncomputer Accounts Configured with an SPN</span></h5>
<p><span>Accounts with service principal names (SPNs) are commonly targeted by threat actors for privilege escalation. Using Kerberos, any domain user can request a Kerberos service ticket (TGS) from a domain controller for any account configured with an SPN. Noncomputer accounts likely are configured with guessable (nonrandom) passwords. Regardless of the domain function level or the host's Windows version, SPNs that are registered under a noncomputer account will use the legacy RC4-HMAC encryption suite rather than Advanced Encryption Standard (AES). The key used for encryption and decryption of the RC4-HMAC encryption type represents an unsalted NTLM hash version of the account's password, which could be derived via cracking the ticket.</span></p>
<p><span>Organizations should review Active Directory to identify noncomputer accounts configured with an SPN. Noncomputer accounts correlated to registered SPNs are likely service accounts and provide a method for a threat actor (without administrative privileges) to potentially derive (crack) the plain-text password for the account (Kerberoasting). To identify noncomputer accounts configured with an SPN, the PowerShell cmdlet referenced in Figure 31 can be run from a domain controller.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>Get-ADUser -Filter {(ServicePrincipalName -like "*")} | Select-Object name,samaccountname,sid,enabled,DistinguishedName</code></pre>
<p><span>Figure 31: PowerShell cmdlet to identify noncomputer accounts configured with an SPN</span></p></div>
<div class="block-paragraph_advanced"><p><span>Where possible, organizations should deregister noncomputer accounts with SPNs configured. Where SPNs are needed, organizations should mitigate the risk associated with Kerberoasting attacks. Accounts with SPNs should be configured with strong, unique passwords (e.g., minimum 25+ characters) with the passwords rotated on a periodic basis for the accounts. Furthermore, privileges should be reviewed and reduced for these accounts to ensure that each account has the minimum required privileges needed for the intended function.</span></p>
<p><span>Accounts with SPNs should be considered in-scope for the proactive hardening measures detailed throughout this blog post.</span></p>
<p><strong>Note:</strong><span> </span><span>SPNs should never be associated with regular interactive user accounts.</span></p>
<h4><span>Detection Opportunities for Noncomputer Accounts Configured with an SPN</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Potential Kerberoasting Attempt Using RC4</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1558/003/" rel="noopener" target="_blank"><span>T1558.003 – Steal or Forge Kerberos Tickets: Kerberoasting</span></a></p>
</td>
<td>
<p><span>Searching for a Kerberos request using downgraded RC4 encryption.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>AS-REP Roasting</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1558/004/" rel="noopener" target="_blank"><span>T1558.004 - Steal or Forge Kerberos Tickets</span></a></p>
</td>
<td>
<p><span>Monitor Event ID 4768 for Kerberos authentication requests using RC4 encryption (0x17) for accounts with the "</span><span>Do not require Kerberos preauthentication</span><span>" flag set. Unlike Kerberoasting (which targets SPNs), AS-REP Roasting targets accounts with disabled preauthentication (which should be reviewed and mitigated).</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 21: Detection opportunities for noncomputer accounts configured with an SPN</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Privileged Account Logon Restrictions</span></h4>
<p><span>Privileged and service account credentials are commonly used for lateral movement and establishing persistence.</span></p>
<p><span>For any accounts that have privileged access throughout an environment, the accounts should not be used on standard workstations and laptops, but rather from designated systems (e.g., privileged access workstations [PAWs]) that reside in restricted and protected VLANs and tiers. Dedicated privileged accounts should be defined for each tier, with controls that enforce that the accounts can only be used within the designated tier. Guardrail enforcement for privileged accounts can be defined within GPOs or by using authentication policy silos (Windows Server 2012 R2 domain-functional level or above).</span></p>
<p><span>The recommendations for restricting the scope of access for privileged accounts are based upon Microsoft's guidance for securing privileged access. For additional information, reference:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><a href="https://docs.microsoft.com/en-us/security/compass/privileged-access-access-model" rel="noopener" target="_blank"><span>https://docs.microsoft.com/en-us/security/compass/privileged-access-access-model</span></a></p>
</li>
<li aria-level="1">
<p role="presentation"><a href="https://docs.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/authentication-policies-and-authentication-policy-silos" rel="noopener" target="_blank"><span>https://docs.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/authentication-policies-and-authentication-policy-silos</span></a></p>
</li>
</ul>
<h5><span>User Rights Assignments</span></h5>
<p><span>As a proactive hardening or quick containment measure, consider blocking any accounts with privileged AD access from being able to log in (remotely or locally) to standard workstations, laptops, and common access servers (e.g., virtualized desktop infrastructure).</span></p>
<p><span>The settings referenced as follows are configurable using user rights assignments defined within GPOs via the path of: </span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Windows Settings &gt; Security Settings &gt; Local Policies &gt; User Rights Assignment</span></p>
</li>
</ul>
<p><span>Accounts delegated with domain-based privileged access should be explicitly denied access to standard workstations and laptop systems within the context of the following settings (which can be configured using GPO settings similar to what are depicted in Figure 32):</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Deny access to this computer from the network (also include</span><strong> </strong><code>S-1-5-114: NT AUTHORITY\Local account and member of Administrators group</code><span>) (</span><code>SeDenyNetworkLogonRight</code><span>)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Deny logon as a batch job (</span><code>SeDenyBatchLogonRight</code><span>)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Deny logon as a service (</span><code>SeDenyServiceLogonRight</code><span>)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Deny logon locally (</span><code>SeDenyInteractiveLogonRight</code><span>)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Deny logon through Terminal Services (</span><code>SeDenyRemoteInteractiveLogonRight</code><span>)</span></p>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/destructive-attacks-guidance-fig32.max-1000x1000.png" alt="Example of Privileged Account Access Restrictions for a Standard Workstation Using GPO Settings">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="l6xux">Figure 32: Example of privileged account access restrictions for a standard workstation using GPO settings</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>Additionally, using GPOs, permissions can be restricted on endpoints to protect against privilege escalation and potential data theft by reducing the scope of accounts that have the following user rights assignments:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Debug programs (</span><code>SeDebugPrivilege</code><span>) </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Back up files and directories (</span><code>SeBackupPrivilege</code><span>) </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Restore files and directories (</span><code>SeRestorePrivilege</code><span>) </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Take ownership of files or other objects (</span><code>SeTakeOwnershipPrivilege</code><span>)</span></p>
</li>
</ul>
<h4><span>Detection Opportunities for Privileged Account Logons</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Attempted Logon of a Privileged Account from a Nonprivileged Access Workstation</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
</td>
<td>
<p><span>Search for logon attempts correlating to highly privileged accounts authenticating to systems that reside outside of the Tier 0 layer.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 22: Detection opportunities for privileged account logons</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Service Account Logon Restrictions</span></h4>
<p><span>Organizations should also consider enhancing the security of domain-based service accounts to restrict the capability for the accounts to be used for interactive, remote desktop, and, where possible, network-based logons. </span></p>
<p><strong><span>Minimum recommended logon hardening for service accounts (on endpoints where the service account is not required for interactive or remote logon purposes):</span></strong></p>
<ul>
<li><span>Computer Configuration &gt; Policies &gt; Windows Settings &gt; Security Settings &gt; Local Policies &gt; User Rights Assignment</span>
<ul>
<li>Deny logon locally (<code>SeDenyInteractiveLogonRight</code>)</li>
<li>Deny logon through Terminal Services (<code>SeDenyRemoteInteractiveLogonRight</code>)</li>
</ul>
</li>
</ul>
<p><strong><span>Additional recommended logon hardening for service accounts (on endpoints where the service accounts is not required for network-based logon purposes):</span></strong></p>
<ul>
<li><span>Computer Configuration &gt; Policies &gt; Windows Settings &gt; Security Settings &gt; Local Policies &gt; User Rights Assignment</span>
<ul>
<li><span>Deny access to this computer from the network (<code>SeDenyNetworkLogonRight</code>)</span></li>
</ul>
</li>
</ul>
<p><span>If a service account is only required to be leveraged on a single endpoint to run a specific service, the service account can be further restricted to only permit the account's usage on a predefined listing of endpoints (Figure 33).</span></p>
<ul>
<li><span>Active Directory Users and Computers &gt; Select the account</span>
<ul>
<li><span>Account tab</span>
<ul>
<li><span>Log On To button &gt; Select the proper scope of computers for access</span></li>
</ul>
</li>
</ul>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--medium
      
      
        h-c-grid__col
        
        h-c-grid__col--4 h-c-grid__col--offset-4
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/destructive-attacks-guidance-fig33.max-1000x1000.png" alt="Option to Restrict an Account to Log onto Specific Endpoints">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="i2oc9">Figure 33: Option to restrict an account to log onto specific endpoints</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h4><span>Detection Opportunities for Service Account Logons</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Anomalous Logon from a Service Account</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
</td>
<td>
<p><span>Search for login attempts for a service account on a new (unexpected) endpoint. This will require baselining service accounts to expected (approved) systems.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 23: Detection opportunities for service account logons</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Managed/Group Managed Service Accounts</span></h4>
<p><span>Organizations with static service accounts should review the feasibility of migrating the service accounts to be managed service accounts (MSAs) or group managed service accounts (gMSAs).</span></p>
<p><span>MSAs were first introduced with the Windows Server 2008 R2 Active Directory schema (domain-functional level) and provide automatic password management (30-day rotation) for dedicated service accounts that are associated with running services on specific endpoints.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Standard MSA: The account is associated with a single endpoint, and the complex password for the account is automatically managed and changed on a predefined frequency (30 days by default). While an MSA can only be associated with a single computer account, multiple services on the same endpoint can leverage the MSA.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Group managed service account (gMSA): First introduced with Windows Server 2012 and are very similar to MSAs, but allow for a single gMSA to be leveraged across </span><span>multiple</span><span> endpoints.</span></p>
</li>
</ul>
<p><span>Common uses for MSAs and gMSAs:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Scheduled Tasks</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Internet Information Services (IIS) application pools</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Structured Query Language (SQL) services (SQL 2012 and later) – Express editions are </span><strong>not</strong><span> supported by MSAs.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Microsoft Exchange services</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Network Load Balancing (clustering) – gMSAs only</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Third-party applications that support MSAs</span></p>
</li>
</ul>
<p><strong>Note:</strong><span> </span><span>Threat actors can potentially discover accounts and groups that have permissions to read/leverage the password for a gMSA for privilege escalation and lateral movement. This can be accomplished by leveraging the </span><code>get-adserviceaccount</code><span> PowerShell cmdlet and enumerating the </span><code>msDS-GroupMSAMembership</code><span> (</span><code>PrincipalsAllowedToRetrieveManagedPassword</code><span>) configuration for a gMSA, which stores the security principals that can access the gMSA password. It is important that when configuring managed service accounts, organizations focus on restricting the scope of accounts and groups that have the ability to obtain and leverage the password for the managed service accounts and enforce structured monitoring of these accounts and groups.</span></p>
<p><span>For additional information related to MSAs and gMSAs, reference:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><a href="https://techcommunity.microsoft.com/t5/ask-the-directory-services-team/managed-service-accounts-understanding-implementing-best/ba-p/397009" rel="noopener" target="_blank"><span>https://techcommunity.microsoft.com/t5/ask-the-directory-services-team/managed-service-accounts-understanding-implementing-best/ba-p/397009</span></a></p>
</li>
<li aria-level="1">
<p role="presentation"><a href="https://docs.microsoft.com/en-us/windows-server/security/group-managed-service-accounts/group-managed-service-accounts-overview" rel="noopener" target="_blank"><span>https://docs.microsoft.com/en-us/windows-server/security/group-managed-service-accounts/group-managed-service-accounts-overview</span></a></p>
</li>
</ul>
<h4><span>Detection Opportunities for Managed/Group Managed Service Accounts</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Group Membership Addition</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1069/" rel="noopener" target="_blank"><span>T1069 – Permission Groups Discovery</span></a></p>
<p><a href="https://attack.mitre.org/techniques/T1098/" rel="noopener" target="_blank"><span>T1098 – Account Manipulation</span></a></p>
</td>
<td>
<p><span>Search for MSAs/gMSAs and the associated </span><code>PrincipalsAllowedToRetrieveManagedPassword</code><span> or </span><code>PrincipalsAllowedToDelegateToAccount</code><span> permissions, which could provide the ability to leverage the MSA/gMSA for malicious purposes.</span></p>
<p><span>Example reconnaissance commands for querying for MSAs/gMSAs and associated attributes:<br><br></span></p>
<pre class="language-plain"><code>get-adserviceaccount

get-adserviceaccount -filter {name -eq 'account-name'} -prop * | select Name, MemberOf, PrincipalsAllowedToDelegateToAccount, PrincipalsAllowedToRetrieveManagedPassword</code></pre>
<p><span>Figure 34: Example reconnaissance commands for querying for MSAs/gMSAs</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div><span>Table 24: Detection opportunities for managed/group managed service accounts</span></div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h4><span>Protected Users Security Group</span></h4>
<p><span>By leveraging the Protected Users security group for privileged accounts, an organization can minimize various exposure factors and common exploitation methods by a threat actor or malware variant obtaining credentials for privileged accounts on disk or in memory from endpoints.</span></p>
<p><span>Beginning with Microsoft Windows 8.1 and Microsoft Windows Server 2012 R2 (and above), the Protected Users security group was introduced to manage credential exposure within an environment. Members of this group automatically have specific protections applied to accounts, including:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>The Kerberos ticket granting ticket (TGT) expires after four hours, rather than the normal 10-hour default setting.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>No NTLM hash for an account is stored in LSASS, since only Kerberos authentication is used (NTLM authentication is disabled for an account).</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Cached credentials are blocked. A domain controller must be available to authenticate the account.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>WDigest authentication is disabled for an account, regardless of an endpoint's applied policy settings.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>DES and RC4 cannot be used for Kerberos preauthentication (Server 2012 R2 or higher); rather, Kerberos with AES encryption will be enforced.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Accounts cannot be used for either constrained or unconstrained delegation (equivalent to enforcing the </span><span>Account is sensitive and cannot be delegated</span><span> setting in Active Directory Users and Computers).</span></p>
</li>
</ul>
<p><span>To provide domain controller-side restrictions for members of the Protected Users security group, the domain functional level must be Windows Server 2012 R2 (or higher). Microsoft Security Advisory </span><a href="https://msrc-blog.microsoft.com/2014/06/05/an-overview-of-kb2871997/" rel="noopener" target="_blank"><span>KB2871997</span></a><span> adds compatibility support for the protections enforced for members of the Protected Users security group for Windows 7, Windows Server 2008 R2, and Windows Server 2012 systems.</span></p>
<p><span>Successful (Event IDs 303, 304) or failed (Event IDs 100, 104) logon events for members of the Protected Users security group can be recorded on domain controllers within the following event logs:</span></p>
<ul>
<li role="presentation">
<pre class="language-plain"><code>%SystemRoot%\System32\Winevt\Logs\Microsoft-Windows-Authentication%4ProtectedUserSuccesses-DomainController.evtx</code></pre>
</li>
<li role="presentation">
<pre class="language-plain"><code>%SystemRoot%\System32\Winevt\Logs\Microsoft-Windows-Authentication%4ProtectedUserFailures-DomainController.evtx</code></pre>
</li>
</ul>
<p><span>The event logs are disabled by default and must be enabled on each domain controller. The PowerShell cmdlets referenced in Figure 35 can be leveraged to enable the event logs for the Protected Users security group on a domain controller.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>$log1 = New-Object System.Diagnostics.Eventing.Reader.EventLogConfiguration Microsoft-Windows-Authentication/ProtectedUserSuccesses-DomainController
$log1.IsEnabled=$true
$log1.SaveChanges()

$log2 = New-Object System.Diagnostics.Eventing.Reader.EventLogConfiguration Microsoft-Windows-Authentication/ProtectedUserFailures-DomainController
$log2.IsEnabled=$true
$log2.SaveChanges()</code></pre>
<p><span>Figure 35: PowerShell cmdlets for enabling event logging for the Protected Users security group on domain controllers</span></p></div>
<div class="block-paragraph_advanced"><p><strong>Note:</strong><span> </span><span>Service accounts (including MSAs) should </span><strong>not</strong><span> be added to the Protected Users security group, as authentication will fail.</span></p></div>
<div class="block-paragraph_advanced"><div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1">
<tbody>
<tr>
<td>
<p><span>If the Protected Users security group cannot be used, at a minimum, privileged accounts should be protected against delegation by configuring the account with the </span><span>Account is Sensitive and Cannot Be Delegated</span><span> flag in Active Directory.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h4><span>Detection Opportunities for the Protected Users Security Group</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Removal of Account from Protected User Group</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1098/" rel="noopener" target="_blank"><span>T1098 – Account Manipulation</span></a></p>
</td>
<td>
<p><span>Search for an account that has been removed from the Protected Users group. </span></p>
</td>
</tr>
<tr>
<td>
<p><span>Attempted Logon of an Account in the Protected User Group from a Nonprivileged Access Workstation</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
</td>
<td>
<p><span>Search for logon attempts from accounts in the Protected Users group authenticating from workstations of nonprivileged users.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 25: Detection opportunities for the Protected Users security group</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Clear-Text Password Protections</span></h4>
<p><span>In addition to restricting access for privileged accounts, controls should be enforced that minimize the exposure of credentials and tokens in memory on endpoints.</span></p>
<p><span>On older Windows versions, clear-text passwords are stored in memory (LSASS) to primarily support WDigest authentication. WDigest should be explicitly disabled on all Windows endpoints where it is not disabled by default.</span></p>
<p><span>By default, WDigest authentication is disabled in Windows 8.1+ and in Windows Server 2012 R2+.</span></p>
<p><span>Beginning with Windows 7 and Windows Server 2008 R2, after installing KB2871997, WDigest authentication can be configured either by modifying the registry or by using the Microsoft Security Guide GPO template from the <a href="https://www.microsoft.com/en-us/download/details.aspx?id=55319" rel="noopener" target="_blank">Microsoft Security Compliance Toolkit</a></span><span>.</span></p>
<h5><span>Registry Method</span></h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest\UseLogonCredential
REG_DWORD = "0"</code></pre>
<p><span>Figure 36: Registry key and value for disabling WDigest authentication</span></p></div>
<div class="block-paragraph_advanced"><p><span>Another registry setting that should be explicitly configured is the </span><code>TokenLeakDetectDelaySecs</code><span> setting (Figure 37), which will clear credentials in memory of logged-off users after 30 seconds, mimicking the behavior of Windows 8.1 and above.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>HKLM\SYSTEM\CurrentControlSet\Control\Lsa\TokenLeakDetectDelaySecs
REG_DWORD = "30"</code></pre>
<p><span>Figure 37: Registry key and value for enforcing the TokenLeakDetectDelaySecs setting</span></p></div>
<div class="block-paragraph_advanced"><h5><span>Group Policy Method</span></h5>
<p><span>Using the Microsoft Security Guide Group Policy template, WDigest authentication can be disabled via a GPO setting (Figure 38).</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Administrative Templates &gt; MS Security Guide &gt; WDigest Authentication</span></p>
<ul>
<li aria-level="1"><span><span>Disabled</span></span></li>
</ul>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/destructive-attacks-guidance-fig38.max-1000x1000.png" alt="Disabling WDigest Authentication via the MS Security Guide Group Policy Template">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="11qec">Figure 38: Disabling WDigest authentication via the MS Security Guide Group Policy Template</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>Additionally, an organization should verify that </span><code>Allow*</code><span> settings are not specified within the registry keys referenced in Figure 39, as this configuration would permit the </span><code>tspkgs</code><span>/CredSSP providers to store clear-text passwords in memory.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Credssp\PolicyDefaults
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CredentialsDelegation</code></pre>
<p><span>Figure 39: Additional registry keys for hardening against clear-text password storage</span></p></div>
<div class="block-paragraph_advanced"><h5><span>Group Policy Reprocessing</span></h5>
<p><span>Threat actors can manually enable WDigest authentication on endpoints by directly modifying the registry (</span><code>UseLogonCredential</code><span> configured to a value of </span><code>1</code><span>). Even on endpoints where WDigest authentication is automatically disabled by default, it is recommended to enforce the GPO settings noted as follows, which will enforce automatic group policy reprocessing for the configured (expected) settings on an automated basis.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Administrative Templates &gt; System &gt; Group Policy &gt; Configure security policy processing</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Enabled - Process even if the Group Policy objects have not changed</span></p>
</li>
</ul>
</li>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Administrative Templates &gt; System &gt; Group Policy &gt; Configure registry policy processing</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Enabled - Process even if the Group Policy objects have not changed</span></p>
</li>
</ul>
</li>
</ul>
<p><strong>Note:</strong><span> </span><span>By default, Group Policy settings are only reprocessed and reapplied if the actual Group Policy was modified prior to the default refresh interval.</span></p>
<p><span>As KB2871997 is not applicable for Windows XP, Windows Server 2003, and Windows Server 2008, to disable WDigest authentication on these platforms, prior to a system reboot, WDigest needs to be removed from the listing of LSA security packages within the registry (Figure 40 and Figure 41).</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>HKLM\System\CurrentControlSet\Control\Lsa\Security Packages</code></pre>
<p><span>Figure 40: Registry key to modify LSA security packages</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/destructive-attacks-guidance-fig41.max-1000x1000.png" alt="LSA security Package Registry Key Before and After Removal of WDigest Authentication from Listing of Providers">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="71ljq">Figure 41: LSA security package registry key before and after removal of WDigest authentication from listing of providers</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h4><span>Detection Opportunities for WDigest Authentication Conditions</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Enable WDigest Authentication</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1112/" rel="noopener" target="_blank"><span>T1112 – Modify Registry</span></a></p>
</td>
<td>
<p><span>Search for evidence of WDigest being enabled in the Windows Registry.<br><br></span></p>
<pre class="language-plain"><code>HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest\UseLogonCredential

REG_DWORD = "1"</code></pre>
<p><span>Figure 42: WDigest Windows Registry modification</span></p>
</td>
</tr>
<tr>
<td>
<p><span>LSASS Memory Access</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1003/001/" rel="noopener" target="_blank"><span>T1003.002 - OS Credential Dumping - LSASS Memory</span></a></p>
</td>
<td>
<p><span>Monitor for processes accessing lsass.exe memory (Sysmon Event ID 10 with GrantedAccess 0x1010 or 0x1FFFFF). Alert on any non-system process opening a handle to LSASS. Deploy LSA Protection (RunAsPPL) and Credential Guard on all supported endpoints.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div><span>Table 26: Detection opportunities for WDigest authentication conditions</span></div>
</div></div>
<div class="block-paragraph_advanced"><h4><span>Credential Protections When Using RDP</span></h4>
<h5><span>Restricted Admin Mode for RDP</span></h5>
<p><span>Restricted Admin mode for RDP can be enabled for all end-user systems assigned to personnel that perform Remote Desktop connections to servers or workstations with administrative credentials. This feature can limit the in-memory exposure of administrative credentials on a destination endpoint when accessed using RDP.</span></p>
<p><span>To leverage Restricted Admin RDP, the command referenced in Figure 43 can be invoked.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>mstsc.exe /RestrictedAdmin</code></pre>
<p><span>Figure 43: Command to invoke restricted admin RDP</span></p></div>
<div class="block-paragraph_advanced"><p><span>When an RDP connection uses the Restricted Admin mode, if the authenticating account is an administrator on the destination endpoint, the credentials for the user account are </span><strong>not</strong><span> stored in memory; rather, the context of the user account appears as the destination machine account (</span><code>domain\destination-computer$</code><span>).</span></p>
<p><span>To leverage Restricted Admin mode for RDP, settings must be enforced on the originating endpoint in addition to the destination endpoint.</span></p>
<h6><span>Originating Endpoint (Client Mode - Windows 7 and Windows Server 2008 R2 and above)</span></h6>
<p><span>A GPO setting must be applied to the originating endpoint initiating the remote desktop session using the </span><span>Restricted Admin</span><span> feature.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Administrative Templates &gt; System &gt; Credential Delegation &gt; Restrict delegation of credentials to remote servers</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Require Restricted Admin</span><span> &gt; set to </span><span>Enabled</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Use the Following Restricted Mode</span><span> &gt; </span><span>Required Restricted Admin</span></p>
</li>
</ul>
</li>
</ul>
</li>
</ul>
<p><span>Configuring this GPO setting will result in the registry keys noted in Figure 44 being configured on an endpoint.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>HKLM\Software\Policies\Microsoft\Windows\CredentialsDelegation\RestrictedRemoteAdministration
0 = Disabled
1 = Enabled

HKLM\Software\Policies\Microsoft\Windows\CredentialsDelegation\RestrictedRemoteAdministrationType
1 = Require Restricted Admin
2 = Require Remote Credential Guard
3 = Restrict Credential Delegation</code></pre>
<p><span>Figure 44: Registry settings for requiring Restricted Admin mode</span></p></div>
<div class="block-paragraph_advanced"><h6><span>Destination Endpoint (Server Mode - Windows 8.1 and Windows Server 2012 R2 and above)</span></h6>
<p><span>A registry setting will need to be configured (Figure 45).</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>HKLM\System\CurrentControlSet\Control\Lsa\DisableRestrictedAdmin
0 = Enabled
1 = Disabled</code></pre>
<p><span>Figure 45: Registry setting for enabling or disabling Restricted Admin RDP</span></p></div>
<div class="block-paragraph_advanced"><p><strong>Recommended:</strong><span> </span><span>Set the registry value to </span><code>0</code><span> to enable Restricted Admin mode.</span></p>
<p><span>With Restricted Admin RDP, another setting that should be configured is the </span><code>DisableRestrictedAdminOutboundCreds</code><span> registry key (Figure 46).</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>HKLM\System\CurrentControlSet\Control\Lsa\DisableRestrictedAdminOutboundCreds
0 = default value (doesn't exist) - Admin Outbound Creds are Enabled
1 = Admin Outbound Creds are Disabled</code></pre>
<p><span>Figure 46: Registry setting for disabling admin outbound credentials</span></p></div>
<div class="block-paragraph_advanced"><p><strong>Recommended:</strong><span> </span><span>Set the registry value to </span><code>1</code><span> to disable admin outbound credentials.</span></p>
<p><strong>Note:</strong><span> </span><span>With this setting set to </span><code>0</code><span>, any outbound authentication requests will appear as the system (</span><code>domain\destination-computer$)</code><span> that a user connected to using Restricted Admin mode. Setting this to </span><code>1</code><span> disables the ability to authenticate to any downstream network resources when attempting to authenticate outbound from a system that a user connected to using Restricted Admin mode for RDP.</span></p>
<p><span>For additional information regarding Restricted Admin mode for RDP, reference:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><a href="https://support.microsoft.com/kb/2973351" rel="noopener" target="_blank"><span>https://support.microsoft.com/kb/2973351</span></a></p>
</li>
<li aria-level="1">
<p role="presentation"><a href="https://blogs.technet.microsoft.com/kfalde/2013/08/14/restricted-admin-mode-for-rdp-in-windows-8-1-2012-r2/" rel="noopener" target="_blank"><span>https://blogs.technet.microsoft.com/kfalde/2013/08/14/restricted-admin-mode-for-rdp-in-windows-8-1-2012-r2/</span></a></p>
</li>
</ul>
<h4><span>Detection Opportunities for Restricted Admin Mode for RDP</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Disable Restricted Admin Mode for RDP</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1112/" rel="noopener" target="_blank"><span>T1112 – Modify Registry</span></a></p>
</td>
<td>
<p><span>Search for an account disabling Restricted Admin mode for RDP in the Windows Registry.<br><br></span></p>
<pre class="language-plain"><code>HKLM\System\CurrentControlSet\Control\Lsa\DisableRestrictedAdmin 

REG_DWORD = "1"</code></pre>
<p><span>Figure 47: Restricted Admin mode for RDP being disabled in the Windows Registry on a destination endpoint</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Disable Require Restricted Admin</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1484/001/" rel="noopener" target="_blank"><span>T1484.001 – Domain Policy Modification: Group Policy Modification</span></a></p>
</td>
<td>
<p><span>Search for the </span><span>Require Restricted Admin</span><span> option being disabled within a GPO configuration. </span></p>
<pre class="language-plain"><code>Computer Configuration &gt; Policies &gt; Administrative Templates &gt; System &gt; Credential Delegation &gt; Restrict delegation of credentials to remote servers

"Require Restricted Admin" &gt; set to Disabled</code></pre>
<p><span>Figure 48: Require Restricted Admin being disabled in a GPO</span></p>
</td>
</tr>
</tbody>
</table></div></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div><span>Table 27: Detection opportunities for Restricted Admin Mode for RDP</span></div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h4><span>Windows Defender Remote Credential Guard</span></h4>
<p><span>For Windows 10 and Windows Server 2016 endpoints, Windows Defender Remote Credential Guard can be leveraged to reduce the exposure of privileged accounts in memory on destination endpoints when Remote Desktop is used for connectivity. With Remote Credential Guard, all credentials remain on the client (origination system) and are not directly exposed to the destination endpoint. Instead, the destination endpoint requests service tickets from the source as needed.</span></p>
<p><span>When a user logs in via RDP to an endpoint that has Remote Credential Guard enabled, none of the SSPs in memory store the account's clear-text password or password hash. Note that Kerberos tickets remain in memory to allow interactive (and single sign-on [SSO]) experiences from the destination server.</span></p>
<p><span>The Remote Desktop client (origination) host:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Must be running at least Windows 10 (v1703) to be able to supply credentials</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Must be running at least Windows 10 (v1607) or Windows Server 2016 to use the user's signed-in credentials (no prompt for credentials)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>User's account must be able to sign into both the client (origination) and the remote (destination) endpoint</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Must be running the Remote Desktop Classic Windows application</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Must use Kerberos authentication to connect to the remote host</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>The Remote Desktop Universal Windows Platform application does not support Windows Defender Remote Credential Guard.</span></p>
</li>
</ul>
<p><strong>Note:</strong><span> If the client cannot connect to a domain controller, then RDP attempts to fall back to NTLM. Windows Defender Remote Credential Guard does not allow NTLM fallback because this would expose credentials to risk.</span></p>
<p><span>The Remote Desktop remote (destination) host:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Must be running at least Windows 10 (v1607) or Windows Server 2016</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Must allow Restricted Admin connections</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Must allow the client's domain user to access Remote Desktop connections</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Must allow delegation of nonexportable credentials</span></p>
</li>
</ul>
<p><span>To enable Remote Credential Guard on the client (origination) host using a GPO configuration:</span></p>
<ul>
<li><em><span>Computer Configuration &gt; Administrative Templates &gt; System &gt; Credentials Delegation &gt; Restrict delegation of credentials to remote servers</span></em>
<ul>
<li><span>To require either Restricted Admin mode or Windows Defender Remote Credential Guard, choose <em>Prefer Windows Defender Remote Credential Guard</em>.</span>
<ul>
<li><span>In this configuration, Remote Credential Guard is preferred, but it will use <em>Restricted Admin mode</em> (if supported) when Remote Credential Guard cannot be used.</span></li>
<li><span>Neither Remote Credential Guard nor Restricted Admin mode for RDP will send credentials in clear text to the Remote Desktop server.</span></li>
</ul>
</li>
<li><span>To require Remote Credential Guard, choose <em>Require Windows Defender Remote Credential Guard</em>.</span>
<ul>
<li><span>In this configuration, a Remote Desktop connection will succeed only if the remote computer meets the requirements for Remote Credential Guard.</span></li>
</ul>
</li>
</ul>
</li>
</ul>
<p><span>To enable Remote Credential Guard on the remote (destination) host, see Figure 49.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>HKLM\System\CurrentControlSet\Control\Lsa
Registry Entry: DisableRestrictedAdmin
Value: 0
reg add HKLM\SYSTEM\CurrentControlSet\Control\Lsa /v DisableRestrictedAdmin /d 0 /t REG_DWORD</code></pre>
<p><span>Figure 49: Registry key and command options to enable Remote Credential Guard on a remote (destination) host</span></p></div>
<div class="block-paragraph_advanced"><p><span>To leverage Remote Credential Guard, use the command referenced in Figure 50.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>mstsc.exe /remoteguard</code></pre>
<p><span>Figure 50: Command to leverage Remote Credential Guard</span></p></div>
<div class="block-paragraph_advanced"><h4><span>Detection Opportunities for Windows Defender Remote Credential Guard</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Disable Remote Credential Guard</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1112/" rel="noopener" target="_blank"><span>T1112 – Modify Registry</span></a></p>
</td>
<td>
<p><span>Search for an account disabling Remote Credential Guard in the Windows Registry.<br><br></span></p>
<pre class="language-plain"><code>HKLM\System\CurrentControlSet\Control\Lsa

Registry Entry: DisableRestrictedAdmin

Value: 1</code></pre>
<p><span>Figure 51: Remote Credential Guard being disabled in the Windows Registry on a destination endpoint</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Disable Require Remote Credential Guard</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1484/001/" rel="noopener" target="_blank"><span>T1484.001 – Domain Policy Modification: Group Policy Modification</span></a></p>
</td>
<td>
<p><span>Search for the </span><span>Require Remote Credential Guard</span><span> option being disabled within a GPO configuration.<br> </span></p>
<pre class="language-plain"><code>Computer Configuration &gt; Administrative Templates &gt; System &gt; Credentials Delegation &gt; Restrict delegation of credentials to remote servers</code></pre>
<p><span>Figure 52: Remote Credential Guard being disabled in a GPO</span></p>
</td>
</tr>
</tbody>
</table></div></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div><span>Table 28: Detection opportunities for Windows Defender Remote Credential Guard</span></div>
</div></div>
<div class="block-paragraph_advanced"><h4><span>Restrict Remote Usage of Local Accounts</span></h4>
<p><span>Local accounts that exist on endpoints are often a common avenue leveraged by threat actors to laterally move throughout an environment. This tactic is especially impactful when the password for the built-in local administrator account is configured to the same value across multiple endpoints.</span></p>
<p><span>To mitigate the impact of local accounts being leveraged for lateral movement, organizations should consider both limiting the ability of local administrator accounts to establish remote connections and creating unique and randomized passwords for local administrator accounts across the environment.</span></p>
<p><a href="https://support.microsoft.com/en-us/help/2871997/microsoft-security-advisory-update-to-improve-credentials-protection-a" rel="noopener" target="_blank"><span>KB2871997</span></a><span> introduced two well-known SIDs that can be leveraged within GPO settings to restrict the use of local accounts for lateral movement.</span></p>
<ul>
<li role="presentation"><code>S-1-5-113: NT AUTHORITY\Local account</code></li>
<li role="presentation"><code>S-1-5-114: NT AUTHORITY\Local account and member of Administrators group</code></li>
</ul>
<p><span>Specifically, the SID </span><code>S-1-5-114: NT AUTHORITY\Local account and member of Administrators group</code><span> is added to an account's access token if the local account is a member of the </span><code>BUILTIN\Administrators</code><span> group. </span><strong>This is the most beneficial SID to leverage to help stop a threat actor (or ransomware variant) that propagates using credentials for any local administrative accounts.</strong></p>
<p><strong>Note:</strong><span> </span><span>For SID </span><code>S-1-5-114: NT AUTHORITY\Local account and member of Administrators group</code><span>, if Failover Clustering is used, this feature should leverage a nonadministrative local account (</span><code>CLIUSR</code><span>) for cluster node management. </span><strong>If this account is a member of the local Administrators group on an endpoint that is part of a cluster, blocking the network logon permissions can cause cluster services to fail.</strong><span> Be cautious and thoroughly test this configuration on servers where Failover Clustering is used.</span></p>
<h4><span>Step 1 – Option 1: S-1-5-114 SID</span></h4>
<p><span>To mitigate the use of local administrative accounts from being used for lateral movement, use the </span><code>SID S-1-5-114: NT AUTHORITY\Local account and member of Administrators group</code><span> within the following settings:</span></p>
<ul>
<li><em><span>Computer Configuration &gt; Policies &gt; Windows Settings &gt; Security Settings &gt; Local Policies &gt; User Rights Assignment</span></em>
<ul>
<li><span>Deny access to this computer from the network (<code>SeDenyNetworkLogonRight</code>)</span></li>
<li><span>Deny logon as a batch job (<code>SeDenyBatchLogonRight</code>)</span></li>
<li><span>Deny logon as a service (<code>SeDenyServiceLogonRight</code>)</span></li>
<li><span>Deny logon through Terminal Services (<code>SeDenyRemoteInteractiveLogonRight</code>)</span></li>
<li><span>Debug programs (<code>SeDebugPrivilege</code>: Permission used for attempted privilege escalation and process injection)</span></li>
</ul>
</li>
</ul>
<h4><span>Step 1 – Option 2: UAC Token-Filtering</span></h4>
<p><span>An additional control that can be enforced via GPO settings pertains to the usage of local accounts for remote administration and connectivity during a network logon. If the full scope of permissions (referenced previously) cannot be implemented in a short timeframe, consider applying the User Account Control (UAC) token-filtering method to local accounts for network-based logons. </span></p>
<p><span>To leverage this configuration via a GPO setting:</span></p>
<ol>
<li aria-level="1">
<p role="presentation"><span>Download the Security Compliance Toolkit (</span><a href="https://www.microsoft.com/en-us/download/details.aspx?id=55319" rel="noopener" target="_blank"><span>https://www.microsoft.com/en-us/download/details.aspx?id=55319</span></a><span>) to use the MS Security Guide </span><code>ADMX</code><span> file. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Once downloaded, the </span><code>SecGuide.admx</code><span> and </span><code>SecGuide.adml</code><span> files must be copied to the </span><code>\Windows\PolicyDefinitions</code><span> and </span><code>\Windows\PolicyDefinitions\en-US directories</code><span> respectively.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>If a centralized GPO store is configured for the domain, copy the </span><code>PolicyDefinitions</code><span> folder to the </span><code>C:\Windows\SYSVOL\sysvol\&lt;domain&gt;\Policies</code><span> folder.</span></p>
</li>
</ol>
<h5><span>GPO Setting</span></h5>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Administrative Templates &gt; MS Security Guide &gt; Apply UAC restrictions to local accounts on network logons</span></p>
<ul>
<li aria-level="1"><span>Enabled</span></li>
</ul>
</li>
</ul>
<p><span>Once enabled, the registry value (Figure 53) will be configured on each endpoint.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\LocalAccountTokenFilterPolicy

REG_DWORD = "0" (Enabled)</code></pre>
<p><span>Figure 53: Registry key and value for enabling UAC restrictions for local accounts</span></p></div>
<div class="block-paragraph_advanced"><p><span>When set to </span><code>0</code><span>, remote connections with high-integrity access tokens are only possible using either the plain-text credential or password hash of the RID 500 local administrator (and only then depending on the setting of </span><code>FilterAdministratorToken</code><span>, which is configurable via the GPO setting of </span><span>User Account Control: Admin Approval Mode for the built-in Administrator account</span><span>).</span></p>
<p><span>The </span><code>FilterAdministratorToken</code><span> option can either enable (1) or disable (0) (default) </span><span>Admin Approval</span><span> mode for the RID 500 local administrator. When enabled, the access token for the RID 500 local administrator account is filtered and therefore UAC is enforced for this account (which can ultimately stop attempts to leverage this account for lateral movement across endpoints).</span></p>
<h5><span>GPO Setting</span></h5>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Windows Settings &gt; Security Settings &gt; Local Policies &gt; Security Options &gt; User Account Control: Admin Approval Mode for the built-in Administrator account</span></p>
</li>
</ul>
<p><span>Once enabled, the registry value (Figure 54) will be configured on each endpoint.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\FilterAdministratorToken

REG_DWORD = "1" (Enabled)</code></pre>
<p><span>Figure 54: Registry key and value for requiring Admin Approval Mode for local administrative accounts</span></p></div>
<div class="block-paragraph_advanced"><p><strong>Note:</strong><span> </span><span>It is also prudent to ensure that the default setting for </span><span>User Account Control: Run all administrators in Admin Approval Mode</span><span> (</span><code>EnableLUA</code><span> option) </span><strong>is not changed</strong><span> from </span><span>Enabled</span><span> (default, as shown in Figure 55) to </span><span>Disabled</span><span>. If this setting is disabled, </span><strong>all UAC policies are also disabled</strong><span>. With this setting disabled, it is possible to perform privileged remote authentication using plain-text credentials or password hashes with any local account that is a member of the local Administrators group.</span></p>
<h5><span>GPO Setting</span></h5>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Administrative Templates &gt; MS Security Guide &gt; User Account Control: Run all administrators in Admin Approval Mode</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Enabled</span></p>
</li>
</ul>
</li>
</ul>
<p><span>Once enabled, the registry value (Figure 55) will be configured on each endpoint. This is the default setting.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA

REG_DWORD = "1" (Enabled)</code></pre>
<p><span>Figure 55: Registry key and value for requiring Admin Approval Mode for all local administrative accounts</span></p></div>
<div class="block-paragraph_advanced"><p><strong>UAC access token filtering will not affect any domain accounts in the local Administrators group on an endpoint.</strong></p>
<h4><span>Step 2: LAPS</span></h4>
<p><span>In addition to blocking the use of local administrator accounts from remote authentication to access endpoints, an organization should align a strategy to enforce password randomization for the built-in local administrator account. For many organizations, the easiest way to accomplish this task is by deploying and leveraging Microsoft's Local Administrator Password Solutions (LAPS).</span></p>
<p><span>Additional information regarding <a href="https://www.microsoft.com/en-us/download/details.aspx?id=46899" rel="noopener" target="_blank">LAPS</a>, and <a href="https://learn.microsoft.com/en-us/entra/identity/devices/howto-manage-local-admin-passwords" target="_blank">here too</a>.</span></p>
<h4><span>Detection Opportunities for Local Accounts</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Attempted Remote Logon of Local Account</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1078/003/" rel="noopener" target="_blank"><span>T1078.003 - Valid Accounts: Local Accounts</span></a></p>
</td>
<td>
<p><span>Search for remote logon attempts for local accounts on an endpoint.</span></p>
</td>
</tr>
</tbody>
</table></div></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 29: Detection opportunities for local accounts</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Active Directory Certificate Services (AD CS) Protections</span></h4>
<p><span>Active Directory Certificate Services (AD CS) is Microsoft's implementation of Public Key Infrastructure (PKI) and integrates directly with Active Directory forests and domains. It can be utilized for a variety of purposes, including digital signatures and user authentication. Certificate Templates are used in AD CS to issue certificates that have been preconfigured for particular tasks. They contain settings and rules that are applied to incoming certificate requests and provide instructions on how a valid certificate request is provided.</span></p>
<p><span>In June of 2021, SpecterOps published a blog post named </span><a href="https://specterops.io/blog/2021/06/17/certified-pre-owned/" rel="noopener" target="_blank"><span>Certified Pre-Owned</span></a><span>, which details their research into possible attacks against AD CS. Since that publication, Mandiant has continued to observe both threat actors and red teamers enhance targeting of AD CS in support of post-compromise objectives. Mandiant's </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/defend-ad-cs-threats/"><span>blog post</span></a> <span>and </span><a href="https://services.google.com/fh/files/misc/active-directory-certificate-services-hardening-wp-en.pdf" rel="noopener" target="_blank"><span>hardening guide</span></a><span> address the continued abuse scenarios and AD CS attack vectors identified through our frontline observations of recent security breaches.</span></p>
<h4><span>Discover Vulnerable Certificate Templates</span></h4>
<p><span>Certificate templates that have been configured and published by AD CS are stored in Active Directory as objects with an object class of </span><code>pKICertificateTemplate</code><span> and can be discovered by blue teams as well as threat actors. Any account that is authenticated to Active Directory can query LDAP directly, with the built-in Windows command </span><code>certutil.exe</code><span>, or with specialized tools such as </span><a href="https://github.com/GhostPack/PSPKIAudit" rel="noopener" target="_blank"><span>PSPKIAudit</span></a><span>, </span><a href="https://github.com/ly4k/Certipy" rel="noopener" target="_blank"><span>Certipy</span></a><span>, and </span><a href="https://github.com/GhostPack/Certify" rel="noopener" target="_blank"><span>Certify</span></a><span>. Mandiant recommends using one of these methods to discover vulnerable certificate templates.</span></p>
<h4><span>Harden Vulnerable Certificate Templates</span></h4>
<p><span>Once discovered, vulnerable certificate templates should be hardened to prevent abuse.</span></p></div>
<div class="block-paragraph_advanced"><ol>
<li aria-level="1">
<p role="presentation"><span>Ensure that all domain controllers and Certificate Authority servers are patched with the latest updates and hotfixes.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>After installing Windows update (</span><a href="https://support.microsoft.com/en-us/topic/kb5014754-certificate-based-authentication-changes-on-windows-domain-controllers-ad2c23b0-15d8-4340-a468-4d4f3b188f16" rel="noopener" target="_blank"><span>KB5014754</span></a><span>) and monitoring/remediating for Event IDs 39 and 41, configure Active Directory to support full enforcement mode to reject authentications based on weaker mappings in certificates.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Using one of the aforementioned methods, regularly review published certificate templates, specifically for any settings related to SAN specifications configured in existing templates.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Review the security permissions assigned to all published certificate templates and validate the scope of enrollment and write permissions are delegated to the correct security principals.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Review published templates configured with the following Enhanced Key Usages (EKUs) that support domain authentication and verify the operational requirement for these configurations.</span></p>
</li>
</ol><ul>
<li aria-level="2">
<p role="presentation"><span>Any Purpose (2.5.29.37.0)</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Subordinate CA (None)</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Client Authentication (1.3.6.1.5.5.7.3.2)</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>PKINIT Client Authentication (1.3.6.1.5.2.3.4)</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Smart Card Logon (1.3.6.1.4.1.311.20.2.2)</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>For templates with sensitive Enhanced Key Usage (EKU), limit enrollment permissions to predefined users or groups, as certificates with EKUs can be used for multiple purposes. Access control lists for templates should be audited to ensure that they align with the principle of least privilege.</span><span>Templates that allow for domain authentication should be carefully reviewed to verify that built-in groups that contain a large scope of accounts are not assigned enrollment permissions. Example: built-in groups that could increase the risk for abuse include:</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>Everyone</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>NT AUTHORITY\Authenticated Users</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Domain Users</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Domain Computers</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>Where possible, enforce "CA Certificate Manager approval" for any templates that include a SAN as an issuance requirement. This will require that any certificate issuance requests be manually reviewed and approved by an identity assigned the "Issue and Manage Certificates" permission on a certificate authority server.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Ensure that Certificate Authorities have not been configured to accept any SAN (irrelevant of the template configuration). This is a non-default configuration and should be avoided wherever possible. This abuse vector is mitigated by KB5014754, but until enforcement of strong mappings is enforced, abuse could still occur based upon historical certificates missing the new OID containing the requester's SID. For additional information, reference the following </span><a href="https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/dn786426(v=ws.11)#controlling-user-added-subject-alternative-names" rel="noopener" target="_blank"><span>Microsoft article</span></a><span>.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Treat both root and subordinate certificate authorities as Tier 0 assets and enforce logon restrictions or authentication policy silos to limit the scope of accounts that have elevated access to the servers where certificate services are installed and configured.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Audit and review the NTAuthCertificates container in AD to validate the referenced CA certificates, as this container references CA certificates that enable authentication within AD. Before authenticating a principal, AD checks the NTAuthCertificates container for the CA specified in the authenticating certificate's Issuer field to validate the authenticity of the CA. If rogue or unauthorized CA certificates are present, this could be indicative of a security event that requires further triage and investigation.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>To avoid the theft of a CA's private keys (e.g., via the DPAPI backup protocol), protect the private keys by leveraging a Hardware Security Module (HSM) on servers where certificate authority services are installed and configured.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Enforce multifactor authentication (MFA) for CA and AD management and operations.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Keep the root CA offline and use subordinate CAs to issue certificates.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Regularly validate and identify potential misconfigurations within existing certificate templates using the built-in Windows command </span><code>certutil.exe</code><span>, or with specialized tools such as </span><a href="https://github.com/GhostPack/PSPKIAudit" rel="noopener" target="_blank"><span>PSPKIAudit</span></a><span>, </span><a href="https://github.com/ly4k/Certipy" rel="noopener" target="_blank"><span>Certipy</span></a><span>, and </span><a href="https://github.com/GhostPack/Certify" rel="noopener" target="_blank"><span>Certify</span></a><span>. Public tools (e.g., PSPKIAudit, Certipy, or Certify) may be flagged by EDR products as they are frequently used by red teams and threat actors.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>To mitigate NTLM Relay attacks in AD CS, enable Extended Protection For Authentication for Certificate Authority Web Enrollment and Certificate Enrollment Web Service. Additionally, require that AD CS accept only HTTPS connections. For additional details, reference the following </span><a href="https://support.microsoft.com/en-gb/topic/kb5005413-mitigating-ntlm-relay-attacks-on-active-directory-certificate-services-ad-cs-3612b773-4043-4aa9-b23d-b87910cd3429" rel="noopener" target="_blank"><span>Microsoft Article</span></a><span>.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Enable audit logging for Certificate Services on CA servers and Kerberos Authentication Service on Domain Controllers by using group policy. Ensure that event IDs 4886 and 4887 from CA servers and 4768 from domain controllers are aggregated in the organization's SIEM solution.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Enable the audit filter on each CA server. This is a bitmask value that represents the seven different audit categories that can be enabled; if all values are enabled, the audit filter will have a value of 127.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Log and monitor events from the CA servers and domain controllers to enhance detections related to AD CS activities (steps 16 and 17 are needed to ensure the appropriate logs are generated).</span></p>
</li>
</div>
<div class="block-paragraph_advanced"><h4><span>Detection Opportunities for AD CS Abuse</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><span>Certificate Request with Mismatched SAN (ESC1)</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1649/" rel="noopener" target="_blank"><span>T1649 - Steal or Forge Authentication Certificates</span></a></p>
</td>
<td>
<p><span>Monitor event IDs 4886 (certificate request received) and 4887 (certificate issued) on CA servers. Alert when the requesting account's identity differs from the Subject Alternative Name (SAN) specified in the certificate.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>NTLM Relay to AD CS Web Enrollment (ESC8)</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1557/001/" rel="noopener" target="_blank"><span>T1557.001 - LLMNR/NBT-NS Poisoning and SMB Relay</span></a></p>
<p><a href="https://attack.mitre.org/techniques/T1649/" rel="noopener" target="_blank"><span>T1649 - Steal or Forge Authentication Certificates</span></a></p>
</td>
<td>
<p><span>Monitor for NTLM authentication to AD CS HTTP enrollment endpoints from domain controllers or privileged servers. Correlate with PetitPotam coercion indicators. This attack chain provides a direct path from any domain user to Domain Admin.</span></p>
</td>
</tr>
</tbody>
</table></div></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 30: Detection opportunities for AD CS abuse</span></div></div>
<div class="block-paragraph_advanced"><h3><span>5. Preventing Destructive Actions in Kubernetes and CI/CD Pipelines</span></h3>
<p><span>Organizations should implement a proactive, defense-in-depth technical hardening strategy to systematically address foundational security gaps and mitigate the risk of destructive actions across their Kubernetes environments and Continuous Integration/Continuous Delivery or Deployment (CI/CD) pipelines. Adversaries increasingly target the CI/CD pipeline and the Kubernetes control plane because they serve as centralized hubs with direct access to application deployments and underlying infrastructure.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Source and Build Compromise:</strong><span> Threat actors target code repositories (e.g., GitHub, GitLab, Azure DevOps) and build environments to steal injected environment variables and secrets. Attackers can then commit malicious workflow files designed to exfiltrate repository data or deploy unauthorized infrastructure.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Container Registry Poisoning: </strong><span>By compromising developer credentials or CI/CD pipeline permissions, attackers overwrite legitimate application images in the container registry. When the Kubernetes cluster pulls the updated image, it unknowingly deploys a poisoned container embedded with backdoors, ransomware, or destructive data-wiping logic.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Cluster-Level Destruction:</strong><span> Once an attacker gains a foothold inside the Kubernetes cluster, they often abuse over-permissive role-based access control (RBAC) configurations. This provides the capability to execute destructive commands using application programming interfaces (APIs) (e.g., kubectl delete deployments), wipe persistent volumes, or delete critical namespaces, effectively causing a loss of availability and application denial of service.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Secrets Extraction and Lateral Movement: </strong><span>Attackers routinely execute Kubernetes-specific attack tools to harvest secrets from compromised Kubernetes pods. These secrets often contain database passwords and cloud identity and access management (IAM) keys, allowing the attacker to pivot out of the cluster and impact cloud-based resources.</span></p>
</li>
</ul>
<p><span>Additional information related to <a href="https://owasp.org/www-project-top-10-ci-cd-security-risks/" rel="noopener" target="_blank">securing CI/CD</a>.</span></p>
<h4><span>Hardening and Mitigation Guidance</span></h4>
<p><span>To defend against CI/CD compromises and destructive actions within Kubernetes, organizations must enforce strict identity boundaries, cryptographic trust, and a least-privilege architecture.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Isolate the Kubernetes Control Plane:</strong><span> Disable unrestricted and public internet access to the Kubernetes API server. For managed services like GKE, EKS, and AKS, ensure the control plane is configured as a private endpoint or heavily restricted via authorized network IP allow-listing. Access to the API should only be permitted from trusted, designated internal management subnets or secure corporate VPNs.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Secure Management Interfaces and CI/CD Pipelines:</strong><span> Enforce mandatory MFA for all access to infrastructure management platforms, including source code repositories such as GitLab/GitHub, and container registries. Utilize hardened container images (e.g., Chainguard containers, Docker Hardened Images) as base images. Implement software supply chain security frameworks (like </span><a href="https://openssf.org/projects/slsa/" rel="noopener" target="_blank"><span>SLSA</span></a><span>) by requiring image signing, provenance generation, and admission controllers (such as Binary Authorization). This ensures that the Kubernetes cluster will definitively reject and block any unverified or poisoned container images from running.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Enforce Strict RBAC and Least Privilege:</strong><span> To limit the "blast radius" of a compromised pod, restrict the use of the cluster-admin role and strictly prohibit wildcard (*) permissions for standard service accounts. Workloads must run under strict security contexts—blocking containers from executing as root, preventing privilege escalation, and restricting access to the underlying worker node (e.g., disabling hostPID and hostNetwork).</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Implement Immutable Cluster Backups: </strong><span>Protect the cluster's state (etcd) and stateful workload data (Persistent Volumes) by utilizing immutable backup repositories. This ensures that even if an attacker gains administrative access to the cluster or CI/CD pipeline and attempts to maliciously delete all resources, the backups cannot be destroyed or altered.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Enable Audit Logging and Threat Detection: </strong><span>Ensure Kubernetes Control Plane audit logs, node-level telemetry, and CI/CD pipeline logs are actively forwarded to a centralized SIEM. Deploy dedicated container threat detection capabilities to immediately alert on malicious exec commands, suspicious Kubernetes enumeration tools, or bulk data deletion attempts within the pods.</span></p>
</li>
</ul>
<p><span>Additional information related to <a href="https://owasp.org/www-project-kubernetes-top-ten/" rel="noopener" target="_blank">securing Kubernetes</a>.</span></p>
<h4><span>Detection Opportunities for Kubernetes and CI/CD</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Bulk Kubernetes Resource Deletion</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1485/" rel="noopener" target="_blank"><span>T1485 - Data Destruction</span></a></p>
</td>
<td>
<p><span>Monitor Kubernetes API audit logs for bulk delete operations targeting Deployments, StatefulSets, Persistent Volume Claims, Namespaces, or ConfigMaps.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Unsigned or Modified Container Image Deployed to Cluster</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1525/" rel="noopener" target="_blank"><span>T1525 - Implant Internal Image</span></a></p>
</td>
<td>
<p><span>Monitor container registries and Kubernetes admission events for deployment of images that fail signature verification, lack provenance attestation, or originate from untrusted registries.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Anomalous Kubernetes Secret Access</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1552/007/" rel="noopener" target="_blank"><span>T1552.007 - Unsecured Credentials: Container API</span></a></p>
</td>
<td>
<p><span>Monitor Kubernetes audit logs for API calls to </span><span>/api/v1/secrets</span><span> or </span><span>/api/v1/namespaces/*/secrets</span><span> from service accounts or users that do not normally access secrets. </span></p>
<p><span>Alert on bulk secret enumeration and on access to secrets in sensitive namespaces.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Unauthorized Modification to CI/CD Pipeline Configuration</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1195/002/" rel="noopener" target="_blank"><span>T1195.002 - Supply Chain Compromise: Compromise Software Supply Chain</span></a></p>
</td>
<td>
<p><span>Monitor source code repositories for modifications to CI/CD pipeline configuration files. </span></p>
<p><span>Alert on changes to pipeline definitions made by accounts that are not members of designated pipeline-owner groups, or changes pushed code outside of an approved pull request/merge request workflow.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Privileged Container or Host Namespace Access</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1611/" rel="noopener" target="_blank"><span>T1611 - Escape to Host</span></a></p>
</td>
<td>
<p><span>Monitor Kubernetes audit logs for pod creation or modification events requesting privileged security contexts, host namespace access, or volume mounts to sensitive host paths. These configurations allow container escape and direct access to the underlying worker node. Alert on any workload requesting these capabilities outside or pre-approved system namespaces.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Kubernetes Audit Logging or Security Agent Tampering</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1562/007/" rel="noopener" target="_blank"><span>T1562.007 - Impair Defenses: Disable or Modify Cloud Firewall</span></a></p>
</td>
<td>
<p><span>Monitor for modifications to Kubernetes API server audit policy configurations, deletion or redirection of log export sinks, and disablement or removal of container runtime security agents. Alert on changes to cluster-level logging configurations in managed services (GKE Cloud Audit Logs, EKS Control Plane Logging, AKS Diagnostic Settings) including disablement of API server, authenticator, or scheduler log streams.</span></p>
</td>
</tr>
</tbody>
</table></div></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 31: Detection opportunities for Kubernetes and CI/CD</span></div></div>
<div class="block-paragraph_advanced"><h3><span>Conclusion</span></h3>
<p><span>Destructive attacks, including ransomware, pose a serious threat to organizations. This blog post provides practical </span><span>guidance on protecting against common techniques used by threat actors for initial access, reconnaissance, privilege escalation, and mission objectives. This blog post should not be considered as a comprehensive defensive guide for every tactic, but it can serve as a valuable resource for organizations to prepare for such attacks. It is based on front-line expertise with helping organizations prepare, contain, eradicate, and recover from potentially destructive threat actors and incidents.</span></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The 25 Best PS5 Games Right Now]]></title>
<description><![CDATA[CNET's gaming experts have deliberated and come up with the top PlayStation 5 games you can play right now, such as Astro Bot, Marathon and Clair Obscur: Expedition 33.]]></description>
<link>https://tsecurity.de/de/3499892/it-nachrichten/the-25-best-ps5-games-right-now/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3499892/it-nachrichten/the-25-best-ps5-games-right-now/</guid>
<pubDate>Fri, 08 May 2026 18:33:18 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[CNET's gaming experts have deliberated and come up with the top PlayStation 5 games you can play right now, such as Astro Bot, Marathon and Clair Obscur: Expedition 33.]]></content:encoded>
</item>
<item>
<title><![CDATA[Nutanix and Palo Alto Networks Integrate for Robust Model Trust]]></title>
<description><![CDATA[Secure your AI models. The Nutanix and Palo Alto Networks Prisma AIRS integration provides advanced AI Model Security and AI Red Teaming for a secure-by-design AI pipeline. The post Nutanix and Palo Alto Networks Integrate for Robust Model Trust appeared…
Read more →
The post Nutanix and Palo Alt...]]></description>
<link>https://tsecurity.de/de/3497020/it-security-nachrichten/nutanix-and-palo-alto-networks-integrate-for-robust-model-trust/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3497020/it-security-nachrichten/nutanix-and-palo-alto-networks-integrate-for-robust-model-trust/</guid>
<pubDate>Thu, 07 May 2026 20:08:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Secure your AI models. The Nutanix and Palo Alto Networks Prisma AIRS integration provides advanced AI Model Security and AI Red Teaming for a secure-by-design AI pipeline. The post Nutanix and Palo Alto Networks Integrate for Robust Model Trust appeared…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/nutanix-and-palo-alto-networks-integrate-for-robust-model-trust/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/nutanix-and-palo-alto-networks-integrate-for-robust-model-trust/">Nutanix and Palo Alto Networks Integrate for Robust Model Trust</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA["SteelSeries finally helped me retire my battered 2015 Astro A50":  This is the multiplatform headset, perfected]]></title>
<description><![CDATA[Finally, after almost a decade, I've replaced my battered Astro A50 headset. The Arctis Nova Pro Omni ticks every single box for multiplatform gamers, in an option far more affordable than its Elite cousin.]]></description>
<link>https://tsecurity.de/de/3496455/windows-tipps/steelseries-finally-helped-me-retire-my-battered-2015-astro-a50-this-is-the-multiplatform-headset-perfected/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3496455/windows-tipps/steelseries-finally-helped-me-retire-my-battered-2015-astro-a50-this-is-the-multiplatform-headset-perfected/</guid>
<pubDate>Thu, 07 May 2026 16:56:12 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Finally, after almost a decade, I've replaced my battered Astro A50 headset. The Arctis Nova Pro Omni ticks every single box for multiplatform gamers, in an option far more affordable than its Elite cousin.]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical Palo Alto Networks software bug hits exposed firewalls]]></title>
<description><![CDATA[Palo Alto Networks is warning customers about a critical buffer overflow vulnerability affecting its PAN-OS user-ID authentication portal that is already being exploited in the wild.



The flaw allows attackers to execute arbitrary code with root privileges on exposed firewalls, the company said...]]></description>
<link>https://tsecurity.de/de/3495724/it-security-nachrichten/critical-palo-alto-networks-software-bug-hits-exposed-firewalls/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3495724/it-security-nachrichten/critical-palo-alto-networks-software-bug-hits-exposed-firewalls/</guid>
<pubDate>Thu, 07 May 2026 13:24:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Palo Alto Networks is warning customers about a critical buffer overflow vulnerability affecting its PAN-OS user-ID authentication portal that is already being exploited in the wild.</p>



<p>The flaw allows attackers to execute arbitrary code with root privileges on exposed firewalls, the company said in a security <a href="https://security.paloaltonetworks.com/CVE-2026-0300" target="_blank" rel="noreferrer noopener">advisory</a>. PAN-OS is the software that runs all Palo Alto Networks next-generation firewalls.</p>



<p>“This issue is applicable only to PA-Series and VM-Series firewalls that are configured to use User-ID Authentication Portal,” the company added. “<a href="https://www.csoonline.com/article/4148974/palo-alto-updates-security-platform-to-discover-ai-agents.html" target="_blank">Prisma</a> Access, Cloud <a href="https://www.csoonline.com/article/4117730/palo-alto-networks-patches-firewalls-after-discovery-of-a-new-denial-of-service-flaw-2.html" target="_blank">NGFW</a>, and Panorama appliances are not impacted by this vulnerability.”</p>



<p>The advisory noted that “limited exploitation” was seen targeting authentication portals exposed to untrusted IP addresses and the public internet. Customers restricting these portals to trusted internal networks are safe.</p>



<p>The issue is awaiting a fix in the upcoming releases of PAN-OS, and users were requested to apply workarounds and mitigations in the meantime.</p>



<h2 class="wp-block-heading"><a></a>Root access through a firewall login portal</h2>



<p>The flaw, tracked as <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0300" target="_blank" rel="noreferrer noopener">CVE-2026-0300</a>, carries a CVSS score of 9.3 in internet-exposed deployments and has been classified as an out-of-bounds write vulnerability, mapped to CWE-787. According to Palo Alto Networks, the issue allows unauthenticated attackers to execute arbitrary code with root privileges on affected devices.</p>



<p>The flaw only impacts PAN-OS deployments where User-ID Authentication Portal is enabled. Affected versions span multiple PAN-OS release branches, including 10.2,11.1, and 12.1 releases prior to patched builds scheduled for rollout in May.</p>



<p>Wiz researcher <a href="https://www.linkedin.com/in/merav-bar-608351232/">Merav Bar</a> said the Google-owned research firm found a total 7% of environments having publicly exposed PAN-OS instances. However, how many of them have the affected portal enabled is not known. “Since this portal utilizes ports 6081 and 6082, the exposure of these specific ports is the primary metric for exploitability,” she added in a <a href="https://www.wiz.io/blog/critical-vulnerability-in-pan-os-exploited-in-the-wild-cve-2026-0300" target="_blank" rel="noreferrer noopener">blog post</a>. “Currently, Shodan identifies 67 exposed PAN-OS servers on port 6081, with none detected on port 6082.”</p>



<p>The vulnerability has also attracted government attention. The US Cybersecurity and Infrastructure Security Agency (CISA) <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-0300" target="_blank" rel="noreferrer noopener">added</a> CVE-2026-0300 to its known Exploited Vulnerabilities (KEV) catalog shortly after the disclosure, while multiple national cybersecurity <a href="https://www.cyber.gc.ca/en/alerts-advisories/palo-alto-networks-security-advisory-av26-425" target="_blank" rel="noreferrer noopener">agencies</a> warned organizations to assume further exploitation is likely.</p>



<h2 class="wp-block-heading"><a></a>Mitigations first, patches shortly after</h2>



<p>While Palo Alto Networks has announced fixes for affected PAN-OS branches, the company is urging customers to immediately reduce exposure rather than wait for patch windows. The vendor said the most important mitigation is restricting access to the User-Id Authentication Portal so it is reachable only from trusted internal IP addresses.</p>



<p>Organizations that do not rely on the Captive Portal feature are being advised to disable it entirely. Palo Alto also recommended disabling Response Pages on interfaces exposed to untrusted traffic while keeping them enabled only on trusted internal interfaces where legitimate users connect.</p>



<p>For customers with Threat Prevention subscriptions, Palo Alto said attacks can additionally be blocked using Threat ID 510019 included in Applications and Threats content version 9097-10022, though decoder support requires PAN-OS 11.1 or later.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-0300 | Palo Alto Cloud NGFW/PAN-OS/Prisma Access out-of-bounds write (EUVD-2026-27879)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in Palo Alto Cloud NGFW, PAN-OS and Prisma Access. This issue affects some unknown processing. Such manipulation leads to out-of-bounds write.

This vulnerability is documented as CVE-2026-0300. The attack can be executed remotely. Ther...]]></description>
<link>https://tsecurity.de/de/3494037/sicherheitsluecken/cve-2026-0300-palo-alto-cloud-ngfwpan-osprisma-access-out-of-bounds-write-euvd-2026-27879/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3494037/sicherheitsluecken/cve-2026-0300-palo-alto-cloud-ngfwpan-osprisma-access-out-of-bounds-write-euvd-2026-27879/</guid>
<pubDate>Wed, 06 May 2026 23:09:57 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/palo_alto:cloud_ngfw">Palo Alto Cloud NGFW, PAN-OS and Prisma Access</a>. This issue affects some unknown processing. Such manipulation leads to out-of-bounds write.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2026-0300">CVE-2026-0300</a>. The attack can be executed remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical Buffer Overflow in Palo Alto Networks PAN-OS User-ID Authentication Portal (CVE-2026-0300)]]></title>
<description><![CDATA[OverviewOn May 6, 2026, Palo Alto Networks published a security advisory for CVE-2026-0300, a critical unauthenticated buffer overflow vulnerability affecting PAN-OS PA-Series and VM-Series firewall appliances. Prisma Access, Cloud NGFW, and Panorama appliances are not affected by this vulnerabil...]]></description>
<link>https://tsecurity.de/de/3492925/it-security-nachrichten/critical-buffer-overflow-in-palo-alto-networks-pan-os-user-id-authentication-portal-cve-2026-0300/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3492925/it-security-nachrichten/critical-buffer-overflow-in-palo-alto-networks-pan-os-user-id-authentication-portal-cve-2026-0300/</guid>
<pubDate>Wed, 06 May 2026 15:54:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2><span><strong>Overview</strong></span></h2><p><span>On May 6, 2026, Palo Alto Networks published a </span><a href="https://security.paloaltonetworks.com/CVE-2026-0300"><span>security advisory</span></a><span> for </span><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0300"><span>CVE-2026-0300</span></a><span>, a critical unauthenticated buffer overflow vulnerability affecting PAN-OS PA-Series and VM-Series firewall appliances. Prisma Access, Cloud NGFW, and Panorama appliances are not affected by this vulnerability. The vulnerability carries a CVSSv4 score of </span><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:A/AU:Y/R:U/V:C/RE:M/U:Red"><span>9.3</span></a><span> and has been confirmed as exploited in the wild by the vendor.</span></p><p></p><p><span>CVE-2026-0300 is a buffer overflow (</span><a href="https://cwe.mitre.org/data/definitions/787"><span>CWE-787</span></a><span>) in the User-ID™ Authentication Portal (also known as Captive Portal), a non-default PAN-OS feature used to map IP addresses to usernames. An unauthenticated remote attacker can exploit this vulnerability by sending specially crafted packets to a device with the Authentication Portal enabled, achieving arbitrary code execution with root privileges on the affected firewall. No authentication or user interaction is required.</span></p><p></p><p><span>Palo Alto Networks has confirmed limited exploitation in the wild targeting Authentication Portals exposed to either untrusted IP addresses or the public internet. No patches are currently available; fixed versions are expected to begin rolling out on May 13, 2026, with additional releases through May 28, 2026.</span></p><p></p><p><span>PAN-OS is among the most widely deployed enterprise firewall operating systems in the world. Shodan </span><a href="https://www.shodan.io/search?query=os%3A%22PAN-OS%22"><span>identifies</span></a><span> approximately 225,000 internet-facing PAN-OS instances, representing a significant attack surface. Rapid7 strongly urges all organizations running affected PAN-OS versions with the User-ID Authentication Portal enabled to </span><span><strong>apply the available workarounds immediately</strong></span><span> and prioritize patching as soon as fixed versions become available.</span></p><h2><span><strong>Mitigation guidance</strong></span></h2><p><span>Organizations running PA-Series and VM-Series firewalls with the User-ID™ Authentication Portal enabled should apply the available workarounds immediately and prioritize patching as soon as fixed versions are released. Check the official </span><a href="https://docs.paloaltonetworks.com/ngfw/administration/user-id/map-ip-addresses-to-users/map-ip-addresses-to-usernames-using-captive-portal/configure-captive-portal"><span>documentation</span></a><span> to establish whether the affected User-ID™ Authentication Portal is currently enabled.</span></p><p></p><p><span>According to the Palo Alto Networks advisory, the following versions are affected by CVE-2026-0300:</span></p><p></p><table><colgroup data-width="1000"><col><col><col><col></colgroup><thead><tr><th><p><span><strong>Product</strong></span></p></th><th><p><span><strong>Affected</strong></span></p></th><th><p><span><strong>Unaffected</strong></span></p></th><th><p><span><strong>Fix ETA</strong></span></p></th></tr></thead><tbody><tr><td><p><span>PAN-OS 12.1</span></p></td><td><p><span>&lt; </span><span>12.1.4-h5</span></p><p><span>&lt; </span><span>12.1.7</span></p></td><td><p><span>&gt;= </span><span>12.1.4-h5</span></p><p><span>&gt;= </span><span>12.1.7</span></p></td><td><p><span>05/13</span></p><p><span>05/28</span></p></td></tr><tr><td><p><span>PAN-OS 11.2</span></p></td><td><p><span>&lt; </span><span>11.2.4-h17</span></p><p><span>&lt; </span><span>11.2.7-h13</span></p><p><span>&lt; </span><span>11.2.10-h6</span></p><p><span>&lt; </span><span>11.2.12</span></p></td><td><p><span>&gt;= </span><span>11.2.4-h17</span></p><p><span>&gt;= </span><span>11.2.7-h13</span></p><p><span>&gt;= </span><span>11.2.10-h6</span></p><p><span>&gt;= </span><span>11.2.12</span></p></td><td><p><span>05/28</span></p><p><span>05/13</span></p><p><span>05/13</span></p><p><span>05/28</span></p></td></tr><tr><td><p><span>PAN-OS 11.1</span></p></td><td><p><span>&lt; </span><span>11.1.4-h33</span></p><p><span>&lt; </span><span>11.1.6-h32</span></p><p><span>&lt; </span><span>11.1.7-h6</span></p><p><span>&lt; </span><span>11.1.10-h25</span></p><p><span>&lt; </span><span>11.1.13-h5</span></p><p><span>&lt; </span><span>11.1.15</span></p></td><td><p><span>&gt;= </span><span>11.1.4-h33</span></p><p><span>&gt;= </span><span>11.1.6-h32</span></p><p><span>&gt;= </span><span>11.1.7-h6</span></p><p><span>&gt;= </span><span>11.1.10-h25</span></p><p><span>&gt;= </span><span>11.1.13-h5</span></p><p><span>&gt;= </span><span>11.1.15</span></p></td><td><p><span>05/13</span></p><p><span>05/13</span></p><p><span>05/28</span></p><p><span>05/13</span></p><p><span>05/13</span></p><p><span>05/28</span></p></td></tr><tr><td><p><span>PAN-OS 10.2</span></p></td><td><p><span>&lt; </span><span>10.2.7-h34</span></p><p><span>&lt; </span><span>10.2.10-h36</span></p><p><span>&lt; </span><span>10.2.13-h21</span></p><p><span>&lt; </span><span>10.2.16-h7</span></p><p><span>&lt; </span><span>10.2.18-h6</span></p></td><td><p><span>&gt;= </span><span>10.2.7-h34</span></p><p><span>&gt;= </span><span>10.2.10-h36</span></p><p><span>&gt;= </span><span>10.2.13-h21</span></p><p><span>&gt;= </span><span>10.2.16-h7</span></p><p><span>&gt;= </span><span>10.2.18-h6</span></p></td><td><p><span>05/28</span></p><p><span>05/13</span></p><p><span>05/28</span></p><p><span>05/28</span></p><p><span>05/13</span></p></td></tr></tbody></table><p></p><p><span>Until patches are available, Palo Alto Networks recommends one of the following workarounds:</span></p><p></p><ul><li><p><span>Restrict User-ID™ Authentication Portal access to only trusted internal zones. Refer to Step 6 of the </span><a href="https://live.paloaltonetworks.com/t5/general-articles/why-it-s-essential-to-secure-your-management-interface/ta-p/1001286"><span>Live Community article</span></a><span> and the </span><a href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000CqbiCAC"><span>Knowledgebase article</span></a><span> for instructions on restricting access.</span></p></li><li><p><span>Disable User-ID™ Authentication Portal entirely if it is not required (Device &gt; User Identification &gt; </span><a href="https://docs.paloaltonetworks.com/ngfw/administration/user-id/map-ip-addresses-to-users/map-ip-addresses-to-usernames-using-captive-portal/configure-captive-portal"><span>Authentication Portal Settings</span></a><span> &gt; uncheck Enable Authentication Portal).</span></p></li></ul><p></p><p><span>Please refer to the vendor </span><a href="https://security.paloaltonetworks.com/CVE-2026-0300"><span>advisory</span></a><span> for the latest guidance.</span></p><h2><span><strong>Rapid7 customers</strong></span></h2><h3><span><strong>Exposure Command, InsightVM, and Nexpose</strong></span></h3><p><span>Exposure Command, InsightVM, and Nexpose customers can assess exposure to CVE-2026-0300 with authenticated vulnerability checks available in the May 6th, 2026 content release.</span></p><h2><span><strong>Updates</strong></span></h2><ul><li><p><span><strong>May 6, 2026</strong></span><span>: Initial publication.</span></p></li></ul><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[PAN-OS Flaw CVE-2026-0300 Exposes Firewalls to Remote Code Execution]]></title>
<description><![CDATA[A newly disclosed cybersecurity issue, tracked as CVE-2026-0300, has drawn urgent attention due to its critical severity and active exploitation. The flaw affects PAN-OS, the operating system used in Palo Alto Networks firewalls, and has been categorized as a buffer overflow vulnerability with se...]]></description>
<link>https://tsecurity.de/de/3492364/it-security-nachrichten/pan-os-flaw-cve-2026-0300-exposes-firewalls-to-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3492364/it-security-nachrichten/pan-os-flaw-cve-2026-0300-exposes-firewalls-to-remote-code-execution/</guid>
<pubDate>Wed, 06 May 2026 12:54:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1244" height="724" src="https://thecyberexpress.com/wp-content/uploads/Buffer-Overflow-Vulnerability.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Buffer Overflow Vulnerability" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Buffer-Overflow-Vulnerability.webp 1244w, https://thecyberexpress.com/wp-content/uploads/Buffer-Overflow-Vulnerability-300x175.webp 300w, https://thecyberexpress.com/wp-content/uploads/Buffer-Overflow-Vulnerability-1024x596.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Buffer-Overflow-Vulnerability-768x447.webp 768w, https://thecyberexpress.com/wp-content/uploads/Buffer-Overflow-Vulnerability-600x349.webp 600w, https://thecyberexpress.com/wp-content/uploads/Buffer-Overflow-Vulnerability-150x87.webp 150w, https://thecyberexpress.com/wp-content/uploads/Buffer-Overflow-Vulnerability-750x436.webp 750w, https://thecyberexpress.com/wp-content/uploads/Buffer-Overflow-Vulnerability-1140x663.webp 1140w, https://thecyberexpress.com/wp-content/uploads/Buffer-Overflow-Vulnerability.webp 1244w, https://thecyberexpress.com/wp-content/uploads/Buffer-Overflow-Vulnerability-300x175.webp 300w, https://thecyberexpress.com/wp-content/uploads/Buffer-Overflow-Vulnerability-1024x596.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Buffer-Overflow-Vulnerability-768x447.webp 768w, https://thecyberexpress.com/wp-content/uploads/Buffer-Overflow-Vulnerability-600x349.webp 600w, https://thecyberexpress.com/wp-content/uploads/Buffer-Overflow-Vulnerability-150x87.webp 150w, https://thecyberexpress.com/wp-content/uploads/Buffer-Overflow-Vulnerability-750x436.webp 750w, https://thecyberexpress.com/wp-content/uploads/Buffer-Overflow-Vulnerability-1140x663.webp 1140w" sizes="(max-width: 1244px) 100vw, 1244px" title="PAN-OS Flaw CVE-2026-0300 Exposes Firewalls to Remote Code Execution 1"></p><span data-contrast="auto">A newly disclosed cybersecurity issue, tracked as CVE-2026-0300, has drawn urgent attention due to its critical severity and active exploitation. The flaw affects PAN-OS, the operating system used in Palo Alto Networks firewalls, and has been categorized as a buffer overflow vulnerability with serious implications for enterprise security environments.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">The CVE-2026-0300 PAN-OS <a class="wpil_keyword_link" href="https://thecyberexpress.com/firewall-daily/vulnerabilities/" title="vulnerability" data-wpil-keyword-link="linked" data-wpil-monitor-id="28136">vulnerability</a> was officially published on May 6, 2026, and updated the same day after being discovered in real-world production environments. It carries a CVSS score of 9.3, placing it firmly in the “critical” category. The issue stems from a buffer overflow vulnerability in the User-ID Authentication Portal, also known as the Captive Portal service, within PAN-OS.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">This flaw allows an unauthenticated attacker to execute arbitrary code with root privileges by sending specially crafted network packets. Because the attack requires no authentication, no user interaction, and can be carried out over the network with low complexity, the exposure <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-risks-in-cybersecurity/" title="risk" data-wpil-keyword-link="linked" data-wpil-monitor-id="28137">risk</a> is considered extremely high.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Technical Details of the Buffer Overflow Vulnerability in PAN-OS</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":299,"335559739":299}'> </span></h3>
<span data-contrast="auto">The root cause of CVE-2026-0300 PAN-OS is classified under CWE-787: Out-of-bounds Write, a common but dangerous type of buffer overflow vulnerability. Attackers can <a class="wpil_keyword_link" href="https://cyble.com/exploit/" target="_blank" rel="noopener" title="exploit" data-wpil-keyword-link="linked" data-wpil-monitor-id="28135">exploit</a> this flaw to overwrite memory and potentially take full control of affected systems.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">The<a href="https://security.paloaltonetworks.com/CVE-2026-0300" target="_blank" rel="nofollow noopener"> vulnerability impacts</a> PA-Series and VM-Series firewalls when the User-ID™ Authentication Portal is enabled. Importantly, Prisma Access, Cloud NGFW, and Panorama appliances are not affected.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Security <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="28134">data</a> associated with the vulnerability highlights the following:</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<ul>
 	<li><b><span data-contrast="auto">Attack Vector:</span></b><span data-contrast="auto"> Network </span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":0,"335559739":0}'> </span></li>
 	<li><b><span data-contrast="auto">Attack Complexity:</span></b><span data-contrast="auto"> Low </span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":0,"335559739":0}'> </span></li>
 	<li><b><span data-contrast="auto">Privileges Required:</span></b><span data-contrast="auto"> None </span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":0,"335559739":0}'> </span></li>
 	<li><b><span data-contrast="auto">User Interaction:</span></b><span data-contrast="auto"> None </span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":0,"335559739":0}'> </span></li>
 	<li><b><span data-contrast="auto">Confidentiality, Integrity, Availability Impact:</span></b><span data-contrast="auto"> High </span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":0,"335559739":0}'> </span></li>
</ul>
<span data-contrast="auto">Additionally, the vulnerability is automatable and has already reached the “ATTACKED” stage in exploit maturity, indicating that <a href="https://thecyberexpress.com/chrome-exploit-cve-2025-10585/" target="_blank" rel="noopener">real-world attacks</a> have been observed.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Active Exploitation and Risk Factors</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":299,"335559739":299}'> </span></h3>
<span data-contrast="auto">Evidence shows limited exploitation of CVE-2026-0300 PAN-OS, particularly targeting systems where the User-ID Authentication Portal is exposed to untrusted networks or the <a href="https://thecyberexpress.com/layer7booter-ip-stresser-on-open-web/" target="_blank" rel="noopener">public internet</a>. Environments that allow external access to this portal face the highest level of risk.</span>

<span data-contrast="auto">The severity is further highlighted by the CVSS vector:</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">This translates to a scenario where attackers can remotely compromise systems without needing credentials or user involvement, leveraging the buffer overflow vulnerability to gain root-level access.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Affected and Unaffected Versions</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":299,"335559739":299}'> </span></h3>
<span data-contrast="auto">Multiple versions of PAN-OS are impacted by CVE-2026-0300, including:</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<ul>
 	<li><span data-contrast="auto">PAN-OS 12.1 versions prior to 12.1.4-h5 and 12.1.7 </span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":0,"335559739":0}'> </span></li>
 	<li><span data-contrast="auto">PAN-OS 11.2 versions prior to 11.2.4-h17, 11.2.7-h13, 11.2.10-h6, and 11.2.12 </span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":0,"335559739":0}'> </span></li>
 	<li><span data-contrast="auto">PAN-OS 11.1 versions prior to 11.1.4-h33, 11.1.6-h32, 11.1.7-h6, 11.1.10-h25, 11.1.13-h5, and 11.1.15 </span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":0,"335559739":0}'> </span></li>
 	<li><span data-contrast="auto">PAN-OS 10.2 versions prior to 10.2.7-h34, 10.2.10-h36, 10.2.13-h21, 10.2.16-h7, and 10.2.18-h6 </span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":0,"335559739":0}'> </span></li>
</ul>
<span data-contrast="auto">Patches are scheduled with estimated availability dates ranging from May 13 to May 28, 2026. Cloud NGFW and Prisma Access deployments remain unaffected.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Mitigation and Workarounds</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":299,"335559739":299}'> </span></h3>
<span data-contrast="auto">While patches are being rolled out, organizations are advised to take immediate steps to reduce exposure to the buffer overflow vulnerability in PAN-OS.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Recommended mitigations include:</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<ul>
 	<li><span data-contrast="auto">Restricting access to the User-ID Authentication Portal to trusted internal <a href="https://thecyberexpress.com/apple-security-updates/" target="_blank" rel="noopener">IP addresses</a> only </span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":0,"335559739":0}'> </span></li>
 	<li><span data-contrast="auto">Preventing any exposure of the portal to the public <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-internet/" title="internet" data-wpil-keyword-link="linked" data-wpil-monitor-id="28138">internet</a> </span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":0,"335559739":0}'> </span></li>
 	<li><span data-contrast="auto">Disabling the User-ID Authentication Portal entirely if it is not required </span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":0,"335559739":0}'> </span></li>
</ul>
<span data-contrast="auto">The risk associated with CVE-2026-0300 PAN-OS drops significantly when these best practices are implemented. Systems that already follow strict network segmentation and access control policies are at a much lower risk.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>]]></content:encoded>
</item>
<item>
<title><![CDATA[“There is simply nothing else like it” becomes even more true now that this premium multi‑system headset is 25 percent cheaper]]></title>
<description><![CDATA[The Logitech Astro A50 X is an extremely expensive item that can connect to multiple platforms and provide immensely satisfying sound quality, and now people have a better chance at owning one with this 25% discount.]]></description>
<link>https://tsecurity.de/de/3490833/windows-tipps/there-is-simply-nothing-else-like-it-becomes-even-more-true-now-that-this-premium-multisystem-headset-is-25-percent-cheaper/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3490833/windows-tipps/there-is-simply-nothing-else-like-it-becomes-even-more-true-now-that-this-premium-multisystem-headset-is-25-percent-cheaper/</guid>
<pubDate>Tue, 05 May 2026 22:56:40 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Logitech Astro A50 X is an extremely expensive item that can connect to multiple platforms and provide immensely satisfying sound quality, and now people have a better chance at owning one with this 25% discount.]]></content:encoded>
</item>
<item>
<title><![CDATA[2026.2.1]]></title>
<description><![CDATA[This patch release addresses a security issue related to Personal Access Token deletion, a regression with stored request payloads that could override collection identifiers, and list truncation beyond 10 items in team workspaces, alongside minor bug fixes.
What's Changed

fix(common): hide horiz...]]></description>
<link>https://tsecurity.de/de/3487795/downloads/202621/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487795/downloads/202621/</guid>
<pubDate>Tue, 05 May 2026 02:17:04 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This patch release addresses a security issue related to Personal Access Token deletion, a regression with stored request payloads that could override collection identifiers, and list truncation beyond 10 items in team workspaces, alongside minor bug fixes.</p>
<h2>What's Changed</h2>
<ul>
<li>fix(common): hide horizontal scrollbar in Firefox for URL input by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Theproudcold/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Theproudcold">@Theproudcold</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3994096430" data-permission-text="Title is private" data-url="https://github.com/hoppscotch/hoppscotch/issues/5906" data-hovercard-type="pull_request" data-hovercard-url="/hoppscotch/hoppscotch/pull/5906/hovercard" href="https://github.com/hoppscotch/hoppscotch/pull/5906">#5906</a></li>
<li>fix(backend): prevent request payload from overriding id and name by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mirarifhasan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mirarifhasan">@mirarifhasan</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4002205187" data-permission-text="Title is private" data-url="https://github.com/hoppscotch/hoppscotch/issues/5913" data-hovercard-type="pull_request" data-hovercard-url="/hoppscotch/hoppscotch/pull/5913/hovercard" href="https://github.com/hoppscotch/hoppscotch/pull/5913">#5913</a></li>
<li>fix(backend): enforce user ownership when deleting PAT by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mirarifhasan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mirarifhasan">@mirarifhasan</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4004500370" data-permission-text="Title is private" data-url="https://github.com/hoppscotch/hoppscotch/issues/5916" data-hovercard-type="pull_request" data-hovercard-url="/hoppscotch/hoppscotch/pull/5916/hovercard" href="https://github.com/hoppscotch/hoppscotch/pull/5916">#5916</a></li>
<li>fix(common): update documentation link for mock server by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sh3xu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sh3xu">@sh3xu</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4015628173" data-permission-text="Title is private" data-url="https://github.com/hoppscotch/hoppscotch/issues/5929" data-hovercard-type="pull_request" data-hovercard-url="/hoppscotch/hoppscotch/pull/5929/hovercard" href="https://github.com/hoppscotch/hoppscotch/pull/5929">#5929</a></li>
<li>fix(backend): bump Prisma packages to <code>7.4.2</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mirarifhasan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mirarifhasan">@mirarifhasan</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4017371087" data-permission-text="Title is private" data-url="https://github.com/hoppscotch/hoppscotch/issues/5932" data-hovercard-type="pull_request" data-hovercard-url="/hoppscotch/hoppscotch/pull/5932/hovercard" href="https://github.com/hoppscotch/hoppscotch/pull/5932">#5932</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Theproudcold/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Theproudcold">@Theproudcold</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3994096430" data-permission-text="Title is private" data-url="https://github.com/hoppscotch/hoppscotch/issues/5906" data-hovercard-type="pull_request" data-hovercard-url="/hoppscotch/hoppscotch/pull/5906/hovercard" href="https://github.com/hoppscotch/hoppscotch/pull/5906">#5906</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sh3xu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sh3xu">@sh3xu</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4015628173" data-permission-text="Title is private" data-url="https://github.com/hoppscotch/hoppscotch/issues/5929" data-hovercard-type="pull_request" data-hovercard-url="/hoppscotch/hoppscotch/pull/5929/hovercard" href="https://github.com/hoppscotch/hoppscotch/pull/5929">#5929</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/hoppscotch/hoppscotch/compare/2026.2.0...2026.2.1"><tt>2026.2.0...2026.2.1</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-7591 | TimBroddin astro-mcp-server up to 1.1.1 MCP Tool Query Construction src/index.ts request.params.arguments sql injection (EUVD-2026-26709)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in TimBroddin astro-mcp-server up to 1.1.1. The impacted element is an unknown function of the file src/index.ts of the component MCP Tool Query Construction. Performing a manipulation of the argument request.params.arguments resul...]]></description>
<link>https://tsecurity.de/de/3481359/sicherheitsluecken/cve-2026-7591-timbroddin-astro-mcp-server-up-to-111-mcp-tool-query-construction-srcindexts-requestparamsarguments-sql-injection-euvd-2026-26709/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3481359/sicherheitsluecken/cve-2026-7591-timbroddin-astro-mcp-server-up-to-111-mcp-tool-query-construction-srcindexts-requestparamsarguments-sql-injection-euvd-2026-26709/</guid>
<pubDate>Sat, 02 May 2026 00:39:17 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, has been found in <a href="https://vuldb.com/product/timbroddin:astro-mcp-server">TimBroddin astro-mcp-server up to 1.1.1</a>. The impacted element is an unknown function of the file <em>src/index.ts</em> of the component <em>MCP Tool Query Construction</em>. Performing a manipulation of the argument <em>request.params.arguments</em> results in sql injection.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-7591">CVE-2026-7591</a>. The attack may be initiated remotely. In addition, an exploit is available.

The project was informed of the problem early through an issue report but has not responded yet.]]></content:encoded>
</item>
<item>
<title><![CDATA[Making AI work for databases]]></title>
<description><![CDATA[In The Sorcerer’s Apprentice, Mickey Mouse uses a magic spell to do his chores. The spell animates a broom that is tasked with carrying water from the well. While the animated broom is managed, it gets the job done; when Mickey falls asleep, the broom carries on its work. When Mickey can’t stop t...]]></description>
<link>https://tsecurity.de/de/3476918/ai-nachrichten/making-ai-work-for-databases/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3476918/ai-nachrichten/making-ai-work-for-databases/</guid>
<pubDate>Thu, 30 Apr 2026 11:02:16 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>In <a href="https://disney.fandom.com/wiki/The_Sorcerer%27s_Apprentice"><em>The Sorcerer’s Apprentice</em></a>, Mickey Mouse uses a magic spell to do his chores. The spell animates a broom that is tasked with carrying water from the well. While the animated broom is managed, it gets the job done; when Mickey falls asleep, the broom carries on its work. When Mickey can’t stop the broom, he chops it to bits with an axe, but all the pieces re-animate and carry on as before. Finally the Sorcerer intervenes to stop the broom and clean up the mess.</p>



<p>Similarly, <a href="https://www.infoworld.com/article/4061121/a-brief-history-of-ai.html">AI promises</a> to lighten the burden of operating databases. For example, using AI to write <a href="https://www.infoworld.com/article/2255395/what-is-sql-the-lingua-franca-of-data-analysis.html">SQL queries</a> or <a href="https://www.infoworld.com/article/4134185/a-checklist-for-enterprise-database-success.html">optimize performance</a> are obvious areas to apply this technology. There is a huge amount of SQL on the internet that can be used to train models around what good queries should look like, and transforming natural language into accurate SQL has a lot of promise.</p>



<p>Further, using AI to handle database management issues should deliver faster performance, more reliable systems, and more efficient use of resources. Customers demand more help around those pain points, and they expect that any supplier can respond to those issues faster with AI. For problems that companies view as “low hanging fruit,” they expect self-service AI to solve those problems on demand rather than waiting.</p>



<h2 class="wp-block-heading">AI promise meets real-world challenge</h2>



<p>Already, we have seen AI get deployed around SQL and database management. BIRD (BIg bench for laRge-scale Database grounded text-to-SQL evaluation) publishes its <a href="https://bird-bench.github.io/">benchmark</a> around how models perform, with the current top AI performing at nearly 82% execution accuracy, based on a Valid Efficiency Score (VES). (See the <a href="https://arxiv.org/pdf/2305.03111">paper on BIRD</a> for details.) How good is a VES of 82%? Currently, human database engineers have a VES of nearly 93%.</p>



<p>The current gap between human and AI performance will shrink over time. But it is currently a great example of the <a href="https://subjectguides.york.ac.uk/study-revision/pareto-principle">Pareto Principle</a> at work — from around 20% of your effort, you can get 80% of your results. To achieve that remaining 20% of results, you have to put in 80% of your effort. With AI, dealing with the simpler issues is where you can achieve the best results, but the harder problems still need a human in the loop to solve the problem or reach the intended goal.</p>



<p>For database management, this is something that we have seen at Percona. Using previous consulting engagements and service delivery projects as a base, we looked at how to automate steps around database management so customers could use AI to solve problems. Once we had the model developed, we tested it internally on database installations. We found that AI did help our team to deliver more efficiently around those simple problems, speeding up how fast they could respond.</p>



<p>At the same time, while these AI systems could make progress on more complex requests, they could not complete the “last mile” by themselves at the start. To overcome this, we looked at how the AI models used data to formulate responses and what sources the model called on most often. This led to more refinement and improvement in the systems alongside a human decision-maker that could understand what the AI was recommending, why it would be suitable, and where it could be improved.</p>



<p>Databases are essential components in the technology stack. As systems of record and sources for data analysis, they have to be reliable, available, and secure. Any decision around databases — from which database you choose for the job through to choices on management or optimization — can have a big impact. Any change has to be managed, or the result can be a broken application.</p>



<h2 class="wp-block-heading">AI and the future of databases</h2>



<p>Database management needs AI. The demand from customers for faster fixes and better performance is not going away, and those customers expect their suppliers to use AI in the same way they might use AI internally. For companies involved in service and support around IT including databases, applying AI to solve problems faster isn’t something that you can avoid. However, the human in the loop model will be essential for these service and support requirements for the foreseeable future. With databases so critical to how applications function and support the business, fully automating service with AI is not yet reliable for 100% of requests. As AI improves, the speed will benefit the majority of potential issues. However, the more complex problems will still require human expertise and control.</p>



<p>The demands of database customers will force teams to use AI. Whether this is internal teams that adopt AI to help them manage database deployment within internal developer platforms, or external service providers that support customers around problems. Customers will move to alternatives if they can’t get the speed of response that they expect. This could be through adopting another service provider for a database like PostgreSQL, or moving to a cloud or managed service provider that can offer better response times. </p>



<p>Mickey used magic to try and solve a problem, but he did not foresee all of the potential consequences. For those who are not database specialists, AI can help them write SQL, manage common tasks, or solve some of the simple problems, but there will always be edge cases where human skills and understanding will be needed. <a href="https://warwick.ac.uk/fac/sci/physics/research/astro/people/stanway/sciencefiction/cosmicstories/clarkes_third_law/">Arthur C. Clarke’s Third Law</a> states that any sufficiently advanced technology is indistinguishable from magic, but the combination of AI and human skill around databases will have the greatest long-term impact without resorting to sorcery.</p>



<p><em>—</em></p>



<p><a href="https://www.infoworld.com/blogs/new-tech-forum"><strong><em>New Tech Forum</em></strong></a><em><strong> provides a venue for technology leaders—including vendors and other outside contributors—to explore and discuss emerging enterprise technology in unprecedented depth and breadth. The selection is subjective, based on our pick of the technologies we believe to be important and of greatest interest to InfoWorld readers. InfoWorld does not accept marketing collateral for publication and reserves the right to edit all contributed content. Send all </strong></em><em><strong>inquiries to </strong></em><a href="mailto:doug_dineley@foundryco.com"><strong><em>doug_dineley@foundryco.com</em></strong></a><em><strong>.</strong></em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The front-end architecture trilemma: Reactivity vs. hypermedia vs. local-first apps]]></title>
<description><![CDATA[While the software development industry has been gorging on large language models (LLMs), the front-end ecosystem has quietly fractured into three competing but interrelated architectural paradigms. Between the dominance of reactive frameworks, the hypermedia-driven simplicity of true REST, and t...]]></description>
<link>https://tsecurity.de/de/3470575/ai-nachrichten/the-front-end-architecture-trilemma-reactivity-vs-hypermedia-vs-local-first-apps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3470575/ai-nachrichten/the-front-end-architecture-trilemma-reactivity-vs-hypermedia-vs-local-first-apps/</guid>
<pubDate>Tue, 28 Apr 2026 11:17:30 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>While the software development industry has been gorging on <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html">large language models</a> (LLMs), the front-end ecosystem has quietly fractured into three competing but interrelated architectural paradigms. Between the dominance of <a href="https://www.infoworld.com/article/2335507/reactive-javascript-the-evolution-of-front-end-architecture.html">reactive frameworks</a>, the <a href="https://www.infoworld.com/article/4150864/htmx-4-0-hypermedia-finds-a-new-gear.html">hypermedia-driven simplicity</a> of true REST, and the decentralized resilience of <a href="https://www.infoworld.com/article/4140734/the-revenge-of-sql-how-a-50-year-old-language-reinvents-itself.html">SQL everywhere</a>, developers are no longer just choosing a library, they are choosing where the data lives: at the server, at the client, or both.</p>



<h2 class="wp-block-heading"><a></a>Three competing architectures, more or less</h2>



<p>Web developers are long familiar with <a href="https://www.infoworld.com/article/3962039/what-you-need-to-know-about-angular-react-vue-and-svelte-popular-javascript-frameworks-compared.html">React</a> and the galaxy of similar reactive frameworks like <a href="https://www.infoworld.com/article/3962039/what-you-need-to-know-about-angular-react-vue-and-svelte-popular-javascript-frameworks-compared.html">Angular, Vue, and Svelte</a>. For nearly a decade, these have dominated the narrative with their competition and co-inspiration. HTMX and hypermedia-driven applications have championed a return to the true RESTful thin client, alongside alternatives like Hotwire and Unpoly.</p>



<p>We could in a sense see reactivity and hypermedia as two opposing camps. Somewhere in between is the local-first SQL movement, which proposes putting SQL directly in the browser. The waters are a bit muddy because local SQL can and does work right alongside React.</p>



<p>It’s still safe to say that a reactive framework paired with a JSON API back end that talks to a datastore (SQL or otherwise) is still the de facto standard. But that monolithic story is starting to fracture in some very interesting ways.</p>



<h2 class="wp-block-heading"><a></a>Where the weight of the data lies</h2>



<p>Data of course is the central mass of web applications. Where it lives and how it moves produce the gravity around which everything else must revolve. Each of these architectures proposes to handle that gravity in its own way, with different benefits and tradeoffs.</p>



<p><strong>Hypermedia (e.g., HTMX):</strong> Keep the data largely off the client. The client is just a visual representation of the server data. The back-end “API” is responsible for producing the data-driven markup. Any kind of datastore can be used by the API server.</p>



<p><strong>React and friends:</strong> A sophisticated, stateful engine runs in the client, and the developer syncs that state with the back end via RESTful JSON API calls. The back-end server tends to be dumb, responsible largely for just invoking other services to provide business logic or data persistence.</p>



<p><strong>Local-first SQL: </strong>The data is distributed to the clients, like with React and friends, but in a much different way. Although the data is automatically synced directly to a datastore (like Postgres), the back-end API server is used only for specialized service calls—not for data persistence.</p>



<p>To summarize:</p>



<ul class="wp-block-list">
<li><strong>HTMX:</strong> Data gravity is at the server.</li>



<li><strong>React:</strong> Data gravity is split between the server and the client.</li>



<li><strong>Local-first:</strong> Data gravity is at the client.</li>
</ul>



<h2 class="wp-block-heading"><a></a>Comparing the approaches</h2>



<p>Besides the technical stats, the developer experience for each of these paradigms is quite different. However, while each paradigm feels different, they intersect in some interesting ways. Let’s take a closer look.</p>



<h3 class="wp-block-heading"><a></a>React and friends</h3>



<p><a href="https://www.infoworld.com/article/2335507/reactive-javascript-the-evolution-of-front-end-architecture.html">Reactivity</a> is the world we have been working in for 15 years. We’ve got a whole universe of frameworks: <a href="https://react.dev/">React</a>, <a href="https://angular.dev/">Angular</a>, <a href="https://vuejs.org/">Vue</a>, <a href="https://svelte.dev/">Svelte</a>, <a href="https://www.solidjs.com/">Solid</a>, and full-stack variants like <a href="https://nextjs.org/">Next.js</a>, <a href="https://nuxt.com/">Nuxt</a>, <a href="https://svelte.dev/docs/kit/introduction">SvelteKit</a>, <a href="https://astro.build/">Astro</a>, etc. The beauty of these is in the <a href="https://www.infoworld.com/article/2335507/reactive-javascript-the-evolution-of-front-end-architecture.html" data-type="link" data-id="https://www.infoworld.com/article/2335507/reactive-javascript-the-evolution-of-front-end-architecture.html">core reactive idea</a>. You have a state that consists of the variables and the UI is updated automatically. The UI is a pure function of state: <code>$UI = f(state)</code>.</p>



<p>The downside is the gradual, almost imperceptible <a href="https://www.infoworld.com/article/4145032/we-mistook-event-handling-for-architecture.html">layering of intense complexity</a> over the top of it all. This complexity seems at first just incidental, but it is in fact a direct outcome of the basic premise: building a state engine on the browser.</p>



<p>The result is you have <em>two </em>states: the browser and the database. The reactive engine becomes a negotiation layer. Add to that the various inherent complexities of managing the browser state, and the result is quite a lot for front-end developers to wrap their heads around.</p>



<p>In the effort to manage such complexity, wring more performance, and improve developer experience, we have wound up with quite a sprawling empire of tools and techniques. Even just for React we have <a href="https://react.dev/reference/rsc/server-components">React Server Components</a>, complex state-management libraries like <a href="https://redux.js.org/">Redux</a> or <a href="https://zustand.docs.pmnd.rs/learn/getting-started/introduction">Zustand</a>, and orchestration layers like <a href="https://tanstack.com/query/latest">TanStack Query</a> for manual cache invalidation.</p>



<p>On the back end, we talk to <a href="https://www.infoworld.com/article/2255837/what-is-json-a-better-format-for-data-exchange.html">JSON APIs</a> (or <a href="https://www.infoworld.com/article/2267992/what-is-graphql-better-apis-by-design.html">GraphQL</a>), which can become unwieldy as a kind of boilerplate layer, but has in its favor an almost universal understanding.</p>



<h3 class="wp-block-heading">HTMX and similar (Hotwired, Unpoly)</h3>



<p><a href="https://www.infoworld.com/article/2334868/htmx-dynamic-html-without-the-javascript.html">HTMX</a> is like using HTML that has superpowers. You can do a huge amount of what you use reactive frameworks for, including all the AJAX and a lot of the partial rendering and effects, with just a few extra attributes sprinkled judiciously.</p>



<p>You spend a lot of time on the server, using a template engine like <a href="https://github.com/pugjs/pug">Pug</a>, <a href="https://www.thymeleaf.org/">Thymeleaf</a>, or <a href="https://github.com/Kotlin/kotlinx.html">Kotlin DSL</a>. These are where you bring together the data from the persistence service and combine it with markup. The markup you generate includes the HTMX attributes.</p>



<p>You tend to decompose the templates, i.e., break them up into dedicated chunks. The idea is you want to have a chunk that can be used within the larger UI to create the whole layout, along with the ability to use that chunk alone when (and if) it is called upon for an AJAX response.</p>



<p>Hypermedia with HTMX is a very powerful model. You are actually using REST, meaning you are transmitting a representational state.</p>



<p><a href="https://hotwired.dev/">Hotwire</a> and <a href="https://unpoly.com/">Unpoly</a> are similar libraries. In the case of Hotwire, you can achieve quite a bit of functionality and performance even without changing your HTML, just by using <a href="https://turbo.hotwired.dev/handbook/frames">Turbo Frames</a> to intercept link clicks and form submissions, automatically turning standard page navigation into partial DOM updates.</p>



<p>The beauty of the hypermedia approaches is that you gain a lot with a little. You are staying as much as possible in HTML, the very poster child of simplicity. On the other hand, you are giving up some of the sheer sophisticated power of reactive frameworks.</p>



<h3 class="wp-block-heading"><a></a>Local-first apps</h3>



<p>Local-first development is the new kid on the block. Like React and friends, local-first keeps the data in two places, but it does so in a radically different way. In its most essential form, it means running a database in the browser that is kept aligned with the remote datastore via a syncing engine. This kind of thing has been done before with <a href="https://www.infoworld.com/article/2260280/what-is-nosql-databases-for-a-cloud-scale-future.html">NoSQL</a> databases like <a href="https://couchdb.apache.org/">CouchDB</a> or with the <a href="https://developer.mozilla.org/en-US/docs/Web/API/IndexedDB_API">IndexedDB API</a>, but the modern browser takes it to another level with a <a href="https://www.infoworld.com/article/2255892/what-is-webassembly-the-next-generation-web-platform-explained.html">Wasm</a>-based database engine, like SQLite.</p>



<p>The user gets a small view of the full data, called a partial replication or a bucket (also called a “shape”). The front-end app interacts directly with that data, and the infrastructure automatically does the work of keeping everything synced. A big benefit here is strong offline support (because the client device is carrying around an actual database).</p>



<p>This is a massive departure from the request-response cycle. In local-first, you don’t fetch data; you subscribe to it. The network becomes a background daemon that reconciles local and remote state using CRDTs (conflict-free replicated data types). CRDTs ensure that if two users edit a task while offline, the merge is seamless rather than messy.</p>



<p>There is also a degree of simplification in using SQL everywhere, though that is offset by a rather unfamiliar and involved architectural setup. A syncing engine like <a href="https://www.powersync.com/">PowerSync</a> or <a href="https://electric-sql.com/">Electric SQL</a> is required, and it has a set of rules that must be maintained. Plus the auth and interaction between the database and the syncing engine must be configured.</p>



<p>Local-first eliminates both the API server and the HTML template server. It pushes the entire data negotiation layer into the automated syncing engine that runs off developer-defined rules.</p>



<p>Interestingly, local-first SQL can be used as a data driver for React (and other reactive engines) or plain vanilla HTML + JS. As such, it is an interesting alternative take on the architecture of the web, which is agnostic about the front end.</p>



<p>Perhaps the strangest arrangement to contemplate is using HTMX and local-first SQL together. This is like a mad scientist architecture, which of course means developers are doing it. In this setup, the back-end HTMX template engine is actually a service worker running the SQL engine. In theory, you get the simplicity of HTMX and the ultra-speed + offline functionality of local SQL. </p>



<h2 class="wp-block-heading"><a></a>Reactivity, hypermedia, or local-first? How to choose</h2>



<p>We remain in the era of the default choice being React plus a JSON API. From there you might experiment with innovative frameworks like <a href="https://www.infoworld.com/article/2265950/hands-on-with-svelte.html">Svelte</a> or <a href="https://www.infoworld.com/article/2271109/hands-on-with-the-solid-javascript-framework.html">Solid</a>. If you are looking for an ingenious way to leverage RESTful simplicity, HTMX or Hotwired are must-tries. Local-first SQL is an exotic animal, fit for the likes of <a href="https://linear.app/now/scaling-the-linear-sync-engine">Linear</a> or <a href="https://www.notion.com/blog/how-we-made-notion-available-offline">Notion</a> right now, but somewhat daring for most of us doing standard production work.</p>



<p>More broadly, the emergence of this trilemma signals the end of the “one true way” for web development. We are moving away from the library wars and into a world of architectural choice.</p>



<p>The choice between reactivity, hypermedia, and local-first isn’t just about code. It’s about where you want to place the data.</p>



<ul class="wp-block-list">
<li>If you want the data to be a server-side document, choose hypermedia.</li>



<li>If you want the data to be a shared memory state, choose reactivity.</li>



<li>If you want the data to be a distributed database, choose local-first.</li>
</ul>



<p>And of course, it is possible to put the approaches together to strive for a blend of the right benefits for your project.</p>



<p>As the JSON-over-the-wire monolith continues to fragment, the best architects won’t be the ones who know the most hooks or the most attributes. They will be the ones who understand the weight of their data and choose the architecture that lets the data move most freely. The framework wars are over, but the battle for the network has just begun. </p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw 2026.4.26]]></title>
<description><![CDATA[2026.4.26
Changes

Channels/QQBot: add full group chat support (history tracking, @-mention gating, activation modes, per-group config, FIFO message queue with deliver debounce), C2C stream_messages streaming with a StreamingController lifecycle manager, unified sendMedia with chunked upload for ...]]></description>
<link>https://tsecurity.de/de/3469725/downloads/openclaw-2026426/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3469725/downloads/openclaw-2026426/</guid>
<pubDate>Tue, 28 Apr 2026 03:16:14 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.4.26</h2>
<h3>Changes</h3>
<ul>
<li>Channels/QQBot: add full group chat support (history tracking, @-mention gating, activation modes, per-group config, FIFO message queue with deliver debounce), C2C <code>stream_messages</code> streaming with a <code>StreamingController</code> lifecycle manager, unified <code>sendMedia</code> with chunked upload for large files, and refactor the engine into pipeline stages, focused outbound submodules, builtin slash-command modules, and explicit DI ports via <code>createEngineAdapters()</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4316471394" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70624" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70624/hovercard" href="https://github.com/openclaw/openclaw/pull/70624">#70624</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cxyhhhhh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cxyhhhhh">@cxyhhhhh</a>.</li>
<li>Channels/Yuanbao: register the Tencent Yuanbao external channel plugin (<code>openclaw-plugin-yuanbao</code>) in the official channel catalog, contract suites, and community plugin docs, with a new <code>docs/channels/yuanbao.md</code> quick-start guide for WebSocket bot DMs and group chats. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335031388" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72756" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72756/hovercard" href="https://github.com/openclaw/openclaw/pull/72756">#72756</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/loongfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/loongfay">@loongfay</a>.</li>
<li>Control UI/Talk: add a generic browser realtime transport contract, Google Live browser Talk sessions with constrained ephemeral tokens, and a Gateway relay for backend-only realtime voice plugins. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/VACInc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/VACInc">@VACInc</a>.</li>
<li>CLI/models: route provider-filtered model listing through an explicit source plan so user config, installed manifest rows, Provider Index previews, and scoped runtime fallbacks keep a stable authority order without adding another catalog cache. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Providers: add Cerebras as a bundled plugin with onboarding, static model catalog, docs, and manifest-owned endpoint metadata.</li>
<li>Memory/OpenAI-compatible: add optional <code>memorySearch.inputType</code>, <code>queryInputType</code>, and <code>documentInputType</code> config for asymmetric embedding endpoints, including direct query embeddings and provider batch indexing. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4226871410" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63313" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63313/hovercard" href="https://github.com/openclaw/openclaw/pull/63313">#63313</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4203912952" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60727" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60727/hovercard" href="https://github.com/openclaw/openclaw/issues/60727">#60727</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HOYALIM/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HOYALIM">@HOYALIM</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/prospect1314521/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/prospect1314521">@prospect1314521</a>.</li>
<li>Ollama/memory: add model-specific retrieval query prefixes for <code>nomic-embed-text</code>, <code>qwen3-embedding</code>, and <code>mxbai-embed-large</code> memory-search queries while leaving document batches unchanged. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4070329121" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45013" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/45013/hovercard" href="https://github.com/openclaw/openclaw/pull/45013">#45013</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/laolin5564/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/laolin5564">@laolin5564</a>.</li>
<li>Plugins/providers: move pre-runtime model-id normalization, endpoint host metadata, OpenAI-compatible request-family hints, model-catalog aliases/suppressions, OpenAI stale Spark suppression, and reusable startup metadata snapshots into plugin manifests so core no longer carries bundled-provider routing tables or repeated manifest rebuilds. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/config: deprecate direct plugin config load/write helpers in favor of passed runtime snapshots plus transactional mutation helpers with explicit restart follow-up policy, scanner guardrails, runtime warnings, and revision-based cache invalidation.</li>
<li>Plugins/install: allow <code>OPENCLAW_PLUGIN_STAGE_DIR</code> to contain layered runtime-dependency roots, resolving read-only preinstalled deps before installing missing deps into the final writable root. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332156784" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72396" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72396/hovercard" href="https://github.com/openclaw/openclaw/issues/72396">#72396</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liorb-mountapps/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liorb-mountapps">@liorb-mountapps</a>.</li>
<li>Control UI: add a raw config pending-changes diff panel that parses JSON5, redacts sensitive values until reveal, and avoids fake raw-edit callbacks when opening the panel. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041206573" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39831" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/39831/hovercard" href="https://github.com/openclaw/openclaw/issues/39831">#39831</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4085689943" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48621" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/48621/hovercard" href="https://github.com/openclaw/openclaw/pull/48621">#48621</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4077071028" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46654" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/46654/hovercard" href="https://github.com/openclaw/openclaw/pull/46654">#46654</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JiajunBernoulli/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JiajunBernoulli">@JiajunBernoulli</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Control UI: polish the quick settings dashboard grid so common cards align across desktop, tablet, and mobile layouts without wasting horizontal space. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Matrix/E2EE: add <code>openclaw matrix encryption setup</code> to enable Matrix encryption, bootstrap recovery, and print verification status from one setup flow. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gumadeiras/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gumadeiras">@gumadeiras</a>.</li>
<li>Agents/compaction: add an opt-in <code>agents.defaults.compaction.maxActiveTranscriptBytes</code> preflight trigger that runs normal local compaction when the active JSONL grows too large, requiring transcript rotation so successful compaction moves future turns onto a smaller successor file instead of raw byte-splitting history. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/migration: add <code>openclaw migrate</code> with plan, dry-run, JSON, pre-migration backup, onboarding detection, archive-only reports, a Claude Code/Desktop importer, and a Hermes importer for configuration, memory/plugin hints, model providers, MCP servers, skills, commands, and supported credentials. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/NousResearch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NousResearch">@NousResearch</a>.</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Agents/LSP: terminate bundled stdio LSP process trees during runtime disposal and Gateway shutdown, so nested children such as <code>tsserver</code> do not survive stop or restart. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331967579" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72357" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72357/hovercard" href="https://github.com/openclaw/openclaw/issues/72357">#72357</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ai-hpc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ai-hpc">@ai-hpc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bittoby/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bittoby">@bittoby</a>.</li>
<li>Gateway/device tokens: stop echoing rotated bearer tokens from shared/admin <code>device.token.rotate</code> responses while preserving the same-device token handoff needed by token-only clients before reconnect. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4264445683" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66773" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66773/hovercard" href="https://github.com/openclaw/openclaw/issues/66773">#66773</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MoerAI/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MoerAI">@MoerAI</a>.</li>
<li>Control UI/Talk: keep Google Live browser sessions on the WebSocket transport instead of falling back to WebRTC, validate browser Google Live WebSocket endpoints, cap Gateway relay sessions per browser connection, and remove stale browser-native voice buttons that did not use the configured Talk/TTS provider. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Gateway/startup: reuse config snapshot plugin manifests for startup auto-enable, config validation, and plugin bootstrap planning, including authored source config and disabled setup-probe handling, so restrictive allowlists avoid duplicate manifest/config passes during boot. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Agents/subagents: enforce <code>subagents.allowAgents</code> for explicit same-agent <code>sessions_spawn(agentId=...)</code> calls instead of auto-allowing requester self-targets. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4336117666" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72827" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72827/hovercard" href="https://github.com/openclaw/openclaw/issues/72827">#72827</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oiGaDio/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oiGaDio">@oiGaDio</a>.</li>
<li>ACP/sessions_spawn: let explicit <code>sessions_spawn(runtime="acp")</code> bootstrap turns run while <code>acp.dispatch.enabled=false</code> still blocks automatic ACP thread dispatch. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4229973496" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63591" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63591/hovercard" href="https://github.com/openclaw/openclaw/issues/63591">#63591</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/moeedahmed/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/moeedahmed">@moeedahmed</a>.</li>
<li>CLI/update: install npm global updates into a verified temporary prefix before swapping the package tree into place, preventing mixed old/new installs and stale packaged files from breaking <code>openclaw update</code> verification. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Gateway: skip CLI startup self-respawn for foreground gateway runs so low-memory Linux/Node 24 hosts start through the same path as direct <code>dist/index.js</code> without hanging before logs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334377532" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72720" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72720/hovercard" href="https://github.com/openclaw/openclaw/issues/72720">#72720</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sign-2025/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sign-2025">@sign-2025</a>.</li>
<li>Google Meet: route local Chrome joins through OpenClaw browser control, grant Meet media permissions, pin local Chrome audio defaults to <code>BlackHole 2ch</code>, and use the configured OpenClaw browser profile so joined agents no longer show <code>Permission needed</code> or use raw/default Chrome state. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oromeis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oromeis">@oromeis</a>.</li>
<li>Plugins/discovery: follow symlinked plugin directories in global and workspace plugin roots while keeping broken links ignored and existing package safety checks in place. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4030788779" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/36754" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/36754/hovercard" href="https://github.com/openclaw/openclaw/issues/36754">#36754</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334070522" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72695" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72695/hovercard" href="https://github.com/openclaw/openclaw/pull/72695">#72695</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4225496480" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63206" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63206/hovercard" href="https://github.com/openclaw/openclaw/pull/63206">#63206</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Quackstro/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Quackstro">@Quackstro</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ming1523/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ming1523">@ming1523</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xsfX20/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xsfX20">@xsfX20</a>.</li>
<li>Plugins/install: skip test files and directories during install security scans while still force-scanning declared runtime entrypoints, so packaged test mocks no longer block plugin installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265051521" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66840" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66840/hovercard" href="https://github.com/openclaw/openclaw/issues/66840">#66840</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4267070478" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67050" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67050/hovercard" href="https://github.com/openclaw/openclaw/pull/67050">#67050</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/saurabhjain1592/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/saurabhjain1592">@saurabhjain1592</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Magicray1217/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Magicray1217">@Magicray1217</a>.</li>
<li>Plugins/install: allow exact package-manager peer links back to the trusted OpenClaw host package during install security scans while continuing to block spoofed or nested escaping <code>node_modules</code> symlinks. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319318874" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70819" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70819/hovercard" href="https://github.com/openclaw/openclaw/pull/70819">#70819</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fgabelmannjr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fgabelmannjr">@fgabelmannjr</a>.</li>
<li>Plugins/install: resolve plugin install destinations from the active profile state dir across CLI, ClawHub, marketplace, local path, and channel setup installs, so <code>openclaw --profile &lt;name&gt; plugins install ...</code> no longer writes into the default profile. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4306498991" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69960" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69960/hovercard" href="https://github.com/openclaw/openclaw/issues/69960">#69960</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4306634637" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69971" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69971/hovercard" href="https://github.com/openclaw/openclaw/pull/69971">#69971</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/FrancisLyman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/FrancisLyman">@FrancisLyman</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sanjays2402/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sanjays2402">@Sanjays2402</a>.</li>
<li>Plugins/registry: suppress duplicate-plugin startup warnings when a tracked npm-installed plugin intentionally overrides the bundled plugin with the same id. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4085889795" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48673" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/48673/hovercard" href="https://github.com/openclaw/openclaw/pull/48673">#48673</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/abdushsk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/abdushsk">@abdushsk</a>.</li>
<li>Plugins/startup: reuse canonical realpath lookups throughout each plugin discovery pass, including package and manifest boundary checks, so Windows npm-global startups no longer repeat expensive path resolution for the same plugin roots. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4251504394" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65733" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65733/hovercard" href="https://github.com/openclaw/openclaw/issues/65733">#65733</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/welfo-beo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/welfo-beo">@welfo-beo</a>.</li>
<li>Gateway/proxy: pass <code>ALL_PROXY</code> / <code>all_proxy</code> into the global Undici env-proxy dispatcher and provider proxy-fetch helper while keeping SSRF trusted-proxy auto-upgrade on <code>HTTP_PROXY</code> / <code>HTTPS_PROXY</code> only, so gateway/provider calls honor all-proxy setups without weakening guarded fetches. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4062862928" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43821" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/43821/hovercard" href="https://github.com/openclaw/openclaw/issues/43821">#43821</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4063492398" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43919" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/43919/hovercard" href="https://github.com/openclaw/openclaw/pull/43919">#43919</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RickyTong1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RickyTong1">@RickyTong1</a>.</li>
<li>Reply/link understanding: keep media and link preprocessing on stable runtime entrypoints and continue with raw message content if optional enrichment fails, so URL-bearing messages are no longer dropped after stale runtime chunk upgrades. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4287281423" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68466" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68466/hovercard" href="https://github.com/openclaw/openclaw/issues/68466">#68466</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/songshikang0111/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/songshikang0111">@songshikang0111</a>.</li>
<li>Discord: persist routed model-picker overrides when the hidden <code>/model</code> dispatch succeeds but the bound thread session store is still stale, including LM Studio suffixed model ids. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4208328194" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61473" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61473/hovercard" href="https://github.com/openclaw/openclaw/pull/61473">#61473</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nanako0129/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nanako0129">@Nanako0129</a>.</li>
<li>Nodes/CLI: add <code>openclaw nodes remove --node &lt;id|name|ip&gt;</code> and <code>node.pair.remove</code> so stale gateway-owned node pairing records can be cleaned without hand-editing state files.</li>
<li>Gateway: include the connecting client and fresh presence version in the initial <code>hello-ok</code> snapshot, so clients no longer need a follow-up event before seeing themselves online.</li>
<li>Docker: install the CA certificate bundle in the slim runtime image so HTTPS calls from containerized gateways no longer fail TLS setup after the <code>bookworm-slim</code> base switch. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335522675" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72787" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72787/hovercard" href="https://github.com/openclaw/openclaw/issues/72787">#72787</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ryuhaneul/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ryuhaneul">@ryuhaneul</a>.</li>
<li>Providers/OpenRouter: remove retired Hunter Alpha and Healer Alpha static catalog rows and disable proxy reasoning injection for stale Hunter Alpha configs, so replies are not hidden when OpenRouter returns answer text in reasoning fields. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4063678295" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43942" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/43942/hovercard" href="https://github.com/openclaw/openclaw/issues/43942">#43942</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/EvanDataForge/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/EvanDataForge">@EvanDataForge</a>.</li>
<li>Providers/reasoning: let Groq and LM Studio declare provider-native reasoning effort values, so Qwen thinking models receive <code>none</code>/<code>default</code> or <code>off</code>/<code>on</code> instead of OpenAI-only <code>low</code>/<code>medium</code> values. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4014930127" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/32638" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/32638/hovercard" href="https://github.com/openclaw/openclaw/issues/32638">#32638</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Aqu1bp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Aqu1bp">@Aqu1bp</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mgoulart/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mgoulart">@mgoulart</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Norpps/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Norpps">@Norpps</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BSTail/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BSTail">@BSTail</a>.</li>
<li>Local models: default custom providers with only <code>baseUrl</code> to the Chat Completions adapter and trust loopback model requests automatically, so local OpenAI-compatible proxies receive <code>/v1/chat/completions</code> without timing out. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041547299" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40024" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40024/hovercard" href="https://github.com/openclaw/openclaw/issues/40024">#40024</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/parachuteshe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/parachuteshe">@parachuteshe</a>.</li>
<li>Channels/message tool: surface Discord, Slack, and Mattermost <code>user:</code>/<code>channel:</code> target syntax in the shared message target schema and Discord ambiguity errors, so DM sends by numeric id stop burning retries before finding <code>user:&lt;id&gt;</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332209830" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72401" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72401/hovercard" href="https://github.com/openclaw/openclaw/issues/72401">#72401</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/garyd9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/garyd9">@garyd9</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/praveen9354/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/praveen9354">@praveen9354</a>.</li>
<li>Agents/tools: scope tool-loop detection history to the active run when available, so scheduled heartbeat cycles no longer inherit stale repeated-call counts from previous runs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041859005" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40144" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40144/hovercard" href="https://github.com/openclaw/openclaw/issues/40144">#40144</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mattbrown319/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mattbrown319">@mattbrown319</a>.</li>
<li>Agents/subagents: preserve requester delivery for completion announces across different channel accounts, keep same-channel thread completions routed to the child thread, and fail closed instead of guessing a child binding when requester conversation signal is missing. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sfuminya/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sfuminya">@sfuminya</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/suyua9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/suyua9">@suyua9</a>.</li>
<li>Agents/status: persist the post-compaction token estimate from auto-compaction when providers omit usage metadata, so <code>/status</code> and session lists keep showing fresh context usage after compaction. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4275752212" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67667" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67667/hovercard" href="https://github.com/openclaw/openclaw/issues/67667">#67667</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4336026319" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72822" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72822/hovercard" href="https://github.com/openclaw/openclaw/pull/72822">#72822</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jimmy-xuzimo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jimmy-xuzimo">@Jimmy-xuzimo</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/skylight-9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/skylight-9">@skylight-9</a>.</li>
<li>Control UI: show loading, reload, and retry states when a lazy dashboard panel cannot load after an upgrade, so the Logs tab no longer appears blank on stale browser bundles. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332419371" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72450" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72450/hovercard" href="https://github.com/openclaw/openclaw/issues/72450">#72450</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sobergou/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sobergou">@sobergou</a>.</li>
<li>Gateway/plugins: start the Gateway in degraded mode when a single plugin entry has invalid schema config, and let <code>openclaw doctor --fix</code> quarantine that plugin config instead of crash-looping every channel. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4222538957" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62976" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62976/hovercard" href="https://github.com/openclaw/openclaw/issues/62976">#62976</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312236696" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70371" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70371/hovercard" href="https://github.com/openclaw/openclaw/issues/70371">#70371</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Doraemon-Claw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Doraemon-Claw">@Doraemon-Claw</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pksidekyk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pksidekyk">@pksidekyk</a>.</li>
<li>Agents/plugins: skip malformed plugin tools with missing schema objects and report plugin diagnostics, so one broken tool no longer crashes Anthropic agent runs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4297771760" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69423" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69423/hovercard" href="https://github.com/openclaw/openclaw/issues/69423">#69423</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jmnickels/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jmnickels">@jmnickels</a>.</li>
<li>Agents/reasoning: recover fully wrapped unclosed <code>&lt;think&gt;</code> replies that would otherwise sanitize to empty text while keeping strict stripping for closed reasoning blocks and unclosed tails after visible text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4033641320" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/37696" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/37696/hovercard" href="https://github.com/openclaw/openclaw/issues/37696">#37696</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4114131932" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51915" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/51915/hovercard" href="https://github.com/openclaw/openclaw/pull/51915">#51915</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/druide67/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/druide67">@druide67</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/okuyam2y/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/okuyam2y">@okuyam2y</a>.</li>
<li>Control UI/Gateway: bind WebChat handshakes to their active socket and reject post-close server registrations, so aborted connects no longer leave zombie clients or misleading duplicate WebSocket connection logs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334957430" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72753" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72753/hovercard" href="https://github.com/openclaw/openclaw/issues/72753">#72753</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LumenFromTheFuture/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LumenFromTheFuture">@LumenFromTheFuture</a>.</li>
<li>Agents/fallback: split ambiguous provider failures into <code>empty_response</code>, <code>no_error_details</code>, and <code>unclassified</code>, and add flat fallback-step fields to structured fallback logs so primary-model failures stay visible when later fallbacks also fail. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329919349" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71922" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71922/hovercard" href="https://github.com/openclaw/openclaw/issues/71922">#71922</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329116597" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71744" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71744/hovercard" href="https://github.com/openclaw/openclaw/issues/71744">#71744</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/andyk-ms/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/andyk-ms">@andyk-ms</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nikolaykazakovvs-ux/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nikolaykazakovvs-ux">@nikolaykazakovvs-ux</a>.</li>
<li>Plugins/Windows: normalize Windows absolute paths before handing bundled plugin modules to Jiti, so Feishu/Lark message sending no longer fails with unsupported <code>c:</code> ESM loader URLs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335348867" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72783" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72783/hovercard" href="https://github.com/openclaw/openclaw/issues/72783">#72783</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jackychen-png/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jackychen-png">@jackychen-png</a>.</li>
<li>CLI/doctor: run bundled plugin runtime-dependency repairs through the async npm installer with spinner/line progress and heartbeat updates, so long <code>openclaw doctor --fix</code> installs no longer look hung in TTY or piped output. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335189382" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72775" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72775/hovercard" href="https://github.com/openclaw/openclaw/issues/72775">#72775</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dfpalhano/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dfpalhano">@dfpalhano</a>.</li>
<li>Feishu/Windows: normalize bundled channel sidecar loads before Jiti evaluates them, so Feishu outbound sends no longer fail with raw <code>C:</code> ESM loader errors on Windows. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335348867" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72783" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72783/hovercard" href="https://github.com/openclaw/openclaw/issues/72783">#72783</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jackychen-png/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jackychen-png">@jackychen-png</a>.</li>
<li>Agents/tools: ignore volatile <code>exec</code> runtime metadata when comparing tool-loop outcomes, so enabled loop detection can stop repeated identical shell-command results instead of resetting on duration, PID, session, or cwd changes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4022477859" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/34574" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/34574/hovercard" href="https://github.com/openclaw/openclaw/issues/34574">#34574</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4048349125" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41502" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/41502/hovercard" href="https://github.com/openclaw/openclaw/pull/41502">#41502</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gucasbrg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gucasbrg">@gucasbrg</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Zcg2021/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Zcg2021">@Zcg2021</a>.</li>
<li>Agents/fallback: classify internal live-session model switch conflicts as unknown fallback failures instead of provider overloads, preventing local vLLM endpoints from receiving misleading overloaded cooldowns. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4225856098" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63229" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63229/hovercard" href="https://github.com/openclaw/openclaw/issues/63229">#63229</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/clawdia-lobster/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/clawdia-lobster">@clawdia-lobster</a>.</li>
<li>Discord: let thread sessions inherit the parent channel's session-level <code>/model</code> override as a model-only fallback without enabling parent transcript inheritance. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335010108" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72755" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72755/hovercard" href="https://github.com/openclaw/openclaw/issues/72755">#72755</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/solavrc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/solavrc">@solavrc</a>.</li>
<li>Gateway/plugins: skip stale configured channels whose matching plugin is no longer discoverable, point cleanup at <code>openclaw doctor --fix</code>, and keep unrelated channel typos fatal so one missing channel plugin no longer crash-loops the Gateway. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4124825809" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53311" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53311/hovercard" href="https://github.com/openclaw/openclaw/issues/53311">#53311</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/futhgar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/futhgar">@futhgar</a>.</li>
<li>Control UI: keep session-specific assistant identity loads authoritative after WebSocket connect, so non-main agent chat sessions do not show the main agent name in the header after bootstrap refreshes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335228084" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72776" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72776/hovercard" href="https://github.com/openclaw/openclaw/issues/72776">#72776</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rockytian-top/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rockytian-top">@rockytian-top</a>.</li>
<li>Agents/Qwen: preserve exact custom <code>modelstudio</code> provider configs with foreign <code>api</code> owners so explicit OpenAI-compatible Model Studio endpoints no longer get normalized into the bundled Qwen plugin path. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4241479558" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64483" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64483/hovercard" href="https://github.com/openclaw/openclaw/issues/64483">#64483</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/FiredMosquito831/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/FiredMosquito831">@FiredMosquito831</a>.</li>
<li>MCP/bundle-mcp: normalize CLI-native <code>type: "http"</code> MCP server entries to OpenClaw <code>transport: "streamable-http"</code> on save, repair existing configs with doctor, and keep embedded Pi from falling back to legacy SSE GET-first startup for those servers. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335050401" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72757" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72757/hovercard" href="https://github.com/openclaw/openclaw/issues/72757">#72757</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Studioscale/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Studioscale">@Studioscale</a>.</li>
<li>OpenCode: expose Anthropic Opus/Sonnet 4.x thinking levels for proxied Claude models, so <code>/think xhigh</code>, <code>/think adaptive</code>, and <code>/think max</code> validate consistently with the direct Anthropic provider. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334548834" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72729" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72729/hovercard" href="https://github.com/openclaw/openclaw/issues/72729">#72729</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/haishmg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/haishmg">@haishmg</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aaajiao/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aaajiao">@aaajiao</a>.</li>
<li>Media-understanding/audio: migrate deprecated <code>{input}</code> placeholders in legacy <code>audio.transcription.command</code> configs to <code>{{MediaPath}}</code>, so custom audio transcribers no longer receive the literal placeholder after doctor repair. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335120301" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72760" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72760/hovercard" href="https://github.com/openclaw/openclaw/issues/72760">#72760</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/krisfanue3-hash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/krisfanue3-hash">@krisfanue3-hash</a>.</li>
<li>Ollama/WSL2: warn when GPU-backed WSL2 installs combine CUDA visibility with an autostarting <code>ollama.service</code> using <code>Restart=always</code>, and document the systemd, <code>.wslconfig</code>, and keep-alive mitigation for crash loops. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4205722264" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61022" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61022/hovercard" href="https://github.com/openclaw/openclaw/pull/61022">#61022</a>; fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4206448739" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61185" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61185/hovercard" href="https://github.com/openclaw/openclaw/issues/61185">#61185</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yhyatt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yhyatt">@yhyatt</a>.</li>
<li>Ollama/onboarding: de-dupe suggested bare local models against installed <code>:latest</code> tags and skip redundant pulls, so setup shows the installed model once and no longer says it is downloading an already available model. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4290796328" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68952" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68952/hovercard" href="https://github.com/openclaw/openclaw/issues/68952">#68952</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tleyden/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tleyden">@tleyden</a>.</li>
<li>Memory-core/doctor: keep <code>doctor.memory.status</code> on the cached path by default and only run live embedding pings for explicit deep probes, preventing slow local embedding backends from blocking Gateway status checks. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328026042" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71568" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71568/hovercard" href="https://github.com/openclaw/openclaw/issues/71568">#71568</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/apex-system/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/apex-system">@apex-system</a>.</li>
<li>Memory/QMD: group same-source collections into one QMD search invocation when the installed QMD supports multiple <code>-c</code> filters, while keeping older QMD builds on the per-collection fallback. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332566839" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72484" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72484/hovercard" href="https://github.com/openclaw/openclaw/issues/72484">#72484</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332567282" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72485" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72485/hovercard" href="https://github.com/openclaw/openclaw/pull/72485">#72485</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4300148574" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69583" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69583/hovercard" href="https://github.com/openclaw/openclaw/pull/69583">#69583</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BsnizND/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BsnizND">@BsnizND</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zeroaltitude/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zeroaltitude">@zeroaltitude</a>.</li>
<li>Memory/QMD: accept QMD status vector-count variants such as <code>Vectors = 42</code>, <code>Vectors:42</code>, and <code>Vectors: 42 embedded</code>, so <code>memory status --deep</code> no longer reports embeddings unavailable for healthy QMD wrappers. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4230927724" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63652" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63652/hovercard" href="https://github.com/openclaw/openclaw/issues/63652">#63652</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4231262054" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63678" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63678/hovercard" href="https://github.com/openclaw/openclaw/pull/63678">#63678</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/apoapostolov/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/apoapostolov">@apoapostolov</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WarrenJones/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WarrenJones">@WarrenJones</a>.</li>
<li>Memory/QMD: skip QMD vector status probes and embedding maintenance in lexical <code>searchMode: "search"</code>, so BM25-only QMD setups on ARM do not trigger llama.cpp/Vulkan builds during status checks or embed cycles. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4189583069" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59234" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59234/hovercard" href="https://github.com/openclaw/openclaw/issues/59234">#59234</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4267984707" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67113" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67113/hovercard" href="https://github.com/openclaw/openclaw/issues/67113">#67113</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PrinceOfEgypt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PrinceOfEgypt">@PrinceOfEgypt</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Vksh07/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Vksh07">@Vksh07</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Snipe76/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Snipe76">@Snipe76</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NomLom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NomLom">@NomLom</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/t4r3e2q1-commits/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/t4r3e2q1-commits">@t4r3e2q1-commits</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dmak/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dmak">@dmak</a>.</li>
<li>Memory/QMD: report the live watcher dirty state in memory status, so changed QMD-backed memory files show as dirty until the queued sync finishes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4200061352" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60244" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60244/hovercard" href="https://github.com/openclaw/openclaw/issues/60244">#60244</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xinzf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xinzf">@xinzf</a>.</li>
<li>Compaction: skip oversized pre-compaction checkpoint snapshots and prune duplicate long user turns from compaction input and rotated successor transcripts, preventing retry storms from being preserved across checkpoint cycles. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335315619" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72780" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72780/hovercard" href="https://github.com/openclaw/openclaw/issues/72780">#72780</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SweetSophia/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SweetSophia">@SweetSophia</a>.</li>
<li>Control UI/Cron: render cron job prompts and run summaries as sanitized markdown in the dashboard, with full-width block content, safer link clicks, and no duplicate error text when a failed run has no summary. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4084972176" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48504" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/48504/hovercard" href="https://github.com/openclaw/openclaw/pull/48504">#48504</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/garethdaine/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/garethdaine">@garethdaine</a>.</li>
<li>Control UI/Gateway: preserve WebChat client version labels across localhost, 127.0.0.1, and IPv6 loopback aliases on the same port, avoiding misleading <code>vcontrol-ui</code> connection logs while investigating duplicate-message reports. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334957430" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72753" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72753/hovercard" href="https://github.com/openclaw/openclaw/issues/72753">#72753</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334796900" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72742" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72742/hovercard" href="https://github.com/openclaw/openclaw/issues/72742">#72742</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LumenFromTheFuture/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LumenFromTheFuture">@LumenFromTheFuture</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/allesgutefy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/allesgutefy">@allesgutefy</a>.</li>
<li>Agents/reasoning: treat orphan closing reasoning tags with following answer text as a privacy boundary across delivery, history, streaming, and Control UI sanitizers so malformed local-model output cannot leak chain-of-thought text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4267622881" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67092" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67092/hovercard" href="https://github.com/openclaw/openclaw/issues/67092">#67092</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AnildoSilva/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AnildoSilva">@AnildoSilva</a>.</li>
<li>Memory-core: run one-shot memory CLI commands through transient builtin and QMD managers so <code>memory index</code>, <code>memory status --index</code>, and <code>memory search</code> no longer start long-lived file watchers that can hit macOS <code>EMFILE</code> limits. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4187752224" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59101" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59101/hovercard" href="https://github.com/openclaw/openclaw/issues/59101">#59101</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4095576345" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49851" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/49851/hovercard" href="https://github.com/openclaw/openclaw/pull/49851">#49851</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mbear469210-coder/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mbear469210-coder">@mbear469210-coder</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/maoyuanxue/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/maoyuanxue">@maoyuanxue</a>.</li>
<li>Agents/ACP: ship the Claude ACP adapter with OpenClaw and require Claude result messages before idle can complete a prompt, preventing parent agents from waking early on long-running <code>sessions_spawn(runtime: "acp", agentId: "claude")</code> children. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330496541" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72080" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72080/hovercard" href="https://github.com/openclaw/openclaw/issues/72080">#72080</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/siavash-saki/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/siavash-saki">@siavash-saki</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iannwu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iannwu">@iannwu</a>.</li>
<li>CLI/tasks: route <code>tasks --json</code>, <code>tasks list --json</code>, and <code>tasks audit --json</code> through a lean JSON path so read-only task inspection no longer loads unrelated plugin/runtime command graphs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4258741985" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66238" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66238/hovercard" href="https://github.com/openclaw/openclaw/issues/66238">#66238</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ChuckChambers/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ChuckChambers">@ChuckChambers</a>.</li>
<li>Memory-core: re-resolve the active runtime config whenever <code>memory_search</code> or <code>memory_get</code> executes, so provider changes made by <code>config.patch</code> stop leaving stale embedding backends behind in existing tool instances. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4206081616" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61098" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61098/hovercard" href="https://github.com/openclaw/openclaw/issues/61098">#61098</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BradGroux/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BradGroux">@BradGroux</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Linux2010/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Linux2010">@Linux2010</a>.</li>
<li>WebChat: keep bare <code>/new</code> and <code>/reset</code> startup instructions out of visible chat history while preserving <code>/reset &lt;note&gt;</code> as user-visible transcript text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332044131" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72369" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72369/hovercard" href="https://github.com/openclaw/openclaw/issues/72369">#72369</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/collynes/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/collynes">@collynes</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/haishmg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/haishmg">@haishmg</a>.</li>
<li>Tasks/memory: checkpoint and truncate SQLite WAL sidecars on a timer and before close for task, Task Flow, proxy capture, and builtin memory databases, bounding long-running gateway <code>*.sqlite-wal</code> growth. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335184021" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72774" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72774/hovercard" href="https://github.com/openclaw/openclaw/issues/72774">#72774</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dfpalhano/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dfpalhano">@dfpalhano</a>.</li>
<li>CLI/doctor: remove dangling channel config, heartbeat targets, and channel model overrides when stale plugin repair removes a missing channel plugin, preventing Gateway boot loops after failed plugin reinstalls. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4247552366" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65293" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65293/hovercard" href="https://github.com/openclaw/openclaw/issues/65293">#65293</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yidecode/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yidecode">@yidecode</a>.</li>
<li>Control UI/Gateway: cache, coalesce, stale-refresh, and invalidate effective tool inventory on channel registry changes while reusing the gateway-bound plugin registry and avoiding model/auth discovery, so chat runs no longer stall Control UI requests on repeated plugin/model setup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331993898" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72365" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72365/hovercard" href="https://github.com/openclaw/openclaw/issues/72365">#72365</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332899080" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72558" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72558/hovercard" href="https://github.com/openclaw/openclaw/pull/72558">#72558</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Gabiii2398/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Gabiii2398">@Gabiii2398</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/1yihui/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/1yihui">@1yihui</a>.</li>
<li>Channels/setup: treat bundled channel plugins as already bundled during <code>channels add</code> and onboarding, enabling them without writing redundant <code>plugins.load.paths</code> entries or path install records. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334766601" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72740" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72740/hovercard" href="https://github.com/openclaw/openclaw/issues/72740">#72740</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iCodePoet/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iCodePoet">@iCodePoet</a>.</li>
<li>WhatsApp: honor gateway <code>HTTPS_PROXY</code> / <code>HTTP_PROXY</code> env vars for QR-login WebSocket connections, while respecting <code>NO_PROXY</code>, so proxied networks no longer fall back to direct <code>mmg.whatsapp.net</code> connections that time out with 408. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332861530" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72547" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72547/hovercard" href="https://github.com/openclaw/openclaw/issues/72547">#72547</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333995671" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72692" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72692/hovercard" href="https://github.com/openclaw/openclaw/pull/72692">#72692</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mebusw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mebusw">@mebusw</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>.</li>
<li>Bonjour: default mDNS advertisements to the system hostname when it is DNS-safe, avoiding <code>openclaw.local</code> probing conflicts and Gateway restart loops on hosts such as <code>Lobster</code> or <code>ubuntu</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331958353" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72355" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72355/hovercard" href="https://github.com/openclaw/openclaw/issues/72355">#72355</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333934083" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72689" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72689/hovercard" href="https://github.com/openclaw/openclaw/issues/72689">#72689</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334059157" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72694" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72694/hovercard" href="https://github.com/openclaw/openclaw/pull/72694">#72694</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mscheuerlein-bot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mscheuerlein-bot">@mscheuerlein-bot</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gcusms/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gcusms">@gcusms</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/moyuwuhen601/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/moyuwuhen601">@moyuwuhen601</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pavan987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pavan987">@pavan987</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zml-0912/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zml-0912">@zml-0912</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hhq365/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hhq365">@hhq365</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>.</li>
<li>Agents/OpenAI-compatible: retry replay-safe empty <code>stop</code> turns once for <code>openai-completions</code> endpoints, so transient empty local backend responses no longer surface as “Agent couldn't generate a response” when a continuation succeeds, and restore <code>openclaw agent --model</code> for one-shot CLI runs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334894224" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72751" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72751/hovercard" href="https://github.com/openclaw/openclaw/issues/72751">#72751</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/moooV252/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/moooV252">@moooV252</a>.</li>
<li>Git hooks: skip ignored staged paths when formatting and restaging pre-commit files, so merge commits no longer abort when <code>.gitignore</code> newly ignores staged merged content. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334805845" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72744" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72744/hovercard" href="https://github.com/openclaw/openclaw/issues/72744">#72744</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>Memory-core/dreaming: add a supported <code>dreaming.model</code> knob for Dream Diary narrative subagents, wired through phase config and the existing plugin subagent model-override trust gate. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4255215946" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65963" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65963/hovercard" href="https://github.com/openclaw/openclaw/issues/65963">#65963</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/esqandil/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/esqandil">@esqandil</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mjamiv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mjamiv">@mjamiv</a>.</li>
<li>Agents/Anthropic: remove trailing assistant prefill payloads when extended thinking is enabled, so Opus 4.7/Sonnet 4.6 requests do not fail Anthropic's user-final-turn validation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334735494" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72739" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72739/hovercard" href="https://github.com/openclaw/openclaw/issues/72739">#72739</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/superandylin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/superandylin">@superandylin</a>.</li>
<li>Agents/vLLM/Qwen: add plugin-owned Qwen thinking controls for vLLM chat-template kwargs and DashScope-style top-level <code>enable_thinking</code> flags, including preserved thinking for agent loops. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331705792" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72329" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72329/hovercard" href="https://github.com/openclaw/openclaw/issues/72329">#72329</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stavrostzagadouris/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stavrostzagadouris">@stavrostzagadouris</a>.</li>
<li>Memory-core/dreaming: treat request-scoped narrative fallback as expected, skip session cleanup when no subagent run was created, and remove duplicate phase-level cleanup so fallback no longer emits warning noise. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4268571406" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67152" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67152/hovercard" href="https://github.com/openclaw/openclaw/issues/67152">#67152</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jsompis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jsompis">@jsompis</a>.</li>
<li>Agents/exec: apply configured <code>tools.exec.timeoutSec</code> to background, <code>yieldMs</code>, and node <code>system.run</code> commands when no per-call timeout is set, preventing auto-backgrounded and remote node commands from running indefinitely. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4274573328" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67600" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67600/hovercard" href="https://github.com/openclaw/openclaw/issues/67600">#67600</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4274648073" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67603" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67603/hovercard" href="https://github.com/openclaw/openclaw/pull/67603">#67603</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dlmpx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dlmpx">@dlmpx</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kagura-agent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kagura-agent">@kagura-agent</a>.</li>
<li>Config/doctor: stop masking unknown-key validation diagnostics such as <code>agents.defaults.llm</code>, and have <code>openclaw doctor --fix</code> remove the retired <code>agents.defaults.llm</code> timeout block. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aidiffuser/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aidiffuser">@aidiffuser</a>.</li>
<li>CLI/startup: keep the built pre-dispatch CLI graph free of package-level imports and extend packaged CLI smoke coverage to onboard and doctor help paths, preventing missing runtime dependencies such as tslog from killing onboarding before repair code can run. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4223102766" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63024" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63024/hovercard" href="https://github.com/openclaw/openclaw/issues/63024">#63024</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hu19940121/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hu19940121">@hu19940121</a>.</li>
<li>CLI/plugins: preserve unversioned ClawHub install specs so <code>plugins update</code> can follow newer ClawHub releases instead of pinning to the initially resolved version. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4222950605" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63010" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63010/hovercard" href="https://github.com/openclaw/openclaw/issues/63010">#63010</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4179937057" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58426" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/58426/hovercard" href="https://github.com/openclaw/openclaw/pull/58426">#58426</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kangsen1234/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kangsen1234">@kangsen1234</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/robinspt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/robinspt">@robinspt</a>.</li>
<li>Memory-core/subagents: tag plugin-created subagent sessions with their plugin owner so dreaming narrative cleanup can delete its own ephemeral sessions without granting broad admin session deletion. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334282794" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72712" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72712/hovercard" href="https://github.com/openclaw/openclaw/issues/72712">#72712</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BSG2000/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BSG2000">@BSG2000</a>.</li>
<li>Gateway/models: move local-provider pricing opt-outs, OpenRouter/LiteLLM aliases, and proxy passthrough pricing lookup into plugin manifest metadata so core no longer carries extension-specific pricing tables.</li>
<li>CLI/update: honor <code>OPENCLAW_NO_AUTO_UPDATE=1</code> as a gateway startup kill-switch for configured background package auto-updates, so operators can hold a deliberate downgrade during incident recovery without editing config first. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334350067" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72715" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72715/hovercard" href="https://github.com/openclaw/openclaw/issues/72715">#72715</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Xivi08/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Xivi08">@Xivi08</a>.</li>
<li>Agents/Claude CLI: force live-session launches to include <code>--output-format stream-json</code> whenever OpenClaw adds <code>--input-format stream-json</code>, so new Claude CLI sessions no longer fail immediately while reusable sessions keep working. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331058930" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72206" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72206/hovercard" href="https://github.com/openclaw/openclaw/issues/72206">#72206</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kwangwonkoh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kwangwonkoh">@kwangwonkoh</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Xivi08/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Xivi08">@Xivi08</a>.</li>
<li>CLI/plugins: accept ClawHub plugin API wildcard ranges such as <code>*</code> without rejecting compatible plugin installs, while still requiring a valid runtime API version. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4160287580" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56446" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56446/hovercard" href="https://github.com/openclaw/openclaw/issues/56446">#56446</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4160379824" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56466" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/56466/hovercard" href="https://github.com/openclaw/openclaw/pull/56466">#56466</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/darconada/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/darconada">@darconada</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/claygeo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/claygeo">@claygeo</a>.</li>
<li>CLI/plugins: add an explicit <code>npm:&lt;package&gt;</code> install prefix that skips ClawHub lookup for known npm packages while keeping bare package specs ClawHub-first. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4152647207" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55805" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/55805/hovercard" href="https://github.com/openclaw/openclaw/issues/55805">#55805</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4133768218" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54377" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54377/hovercard" href="https://github.com/openclaw/openclaw/pull/54377">#54377</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Zeoy2020/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Zeoy2020">@Zeoy2020</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vagusX/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vagusX">@vagusX</a>.</li>
<li>CLI/plugins: let config-gated bundled plugins install without persisting invalid placeholder config entries, so install/uninstall sweeps can cover plugins such as memory-lancedb before the user configures credentials. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/plugins: reject malformed ClawHub plugin specs with trailing <code>@</code> before registry lookup, so empty-version typos report as invalid specs instead of package-not-found errors. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4161404128" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56579" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56579/hovercard" href="https://github.com/openclaw/openclaw/issues/56579">#56579</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4161414890" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56582" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/56582/hovercard" href="https://github.com/openclaw/openclaw/pull/56582">#56582</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kansodata/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kansodata">@Kansodata</a>.</li>
<li>Agents/sessions: acquire the session write lock only after cold bootstrap, plugin, and tool setup so fallback runs are not blocked by stalled pre-model startup work.</li>
<li>Browser/plugins: auto-start the bundled browser plugin when root <code>browser</code> config is present, including restrictive plugin allowlists, and ignore stale persisted plugin registries whose package paths no longer exist.</li>
<li>Browser: circuit-break repeated managed Chrome launch failures per profile so browser requests stop spawning Chromium indefinitely when CDP cannot start. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4238688678" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64271" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64271/hovercard" href="https://github.com/openclaw/openclaw/issues/64271">#64271</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TheophilusChinomona/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TheophilusChinomona">@TheophilusChinomona</a>.</li>
<li>Gateway/models: skip external OpenRouter and LiteLLM pricing refreshes for local/self-hosted model endpoints so startup does not wait on remote pricing catalogs for local-only Ollama, vLLM, and compatible providers.</li>
<li>CLI/plugins: stop security-blocked plugin installs from retrying as hook packs, so normal plugin packages report the scanner failure without a misleading "not a valid hook pack" follow-up. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4206381395" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61175" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61175/hovercard" href="https://github.com/openclaw/openclaw/issues/61175">#61175</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4236769831" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64102" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64102/hovercard" href="https://github.com/openclaw/openclaw/pull/64102">#64102</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/KonsultDigital/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/KonsultDigital">@KonsultDigital</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ziyincody/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ziyincody">@ziyincody</a>.</li>
<li>Agents/Anthropic: strip stale trailing assistant prefill turns from outbound replay so context-engine short circuits cannot send unsupported assistant-prefill payloads to provider APIs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332888910" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72556" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72556/hovercard" href="https://github.com/openclaw/openclaw/issues/72556">#72556</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Veda-openclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Veda-openclaw">@Veda-openclaw</a>.</li>
<li>Agents/Google: strip stale trailing assistant/model prefill turns from Gemini outbound replay so Google Generative AI requests end with a user turn or function response. Follow-up to <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332888910" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72556" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72556/hovercard" href="https://github.com/openclaw/openclaw/issues/72556">#72556</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Veda-openclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Veda-openclaw">@Veda-openclaw</a>.</li>
<li>Control UI/Dreaming: require explicit confirmation before applying restart-impacting Dreaming mode changes, with restart warning copy and loading feedback. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4233221234" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63804" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63804/hovercard" href="https://github.com/openclaw/openclaw/issues/63804">#63804</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4233286540" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63807" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63807/hovercard" href="https://github.com/openclaw/openclaw/pull/63807">#63807</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bbddbb1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bbddbb1">@bbddbb1</a>.</li>
<li>CLI/agent: mark Gateway-to-embedded fallback runs with <code>meta.transport: "embedded"</code> and <code>meta.fallbackFrom: "gateway"</code> in JSON output, and make the terminal diagnostic explicit so scripts and operators can distinguish fallback runs from Gateway runs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327249504" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71416" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71416/hovercard" href="https://github.com/openclaw/openclaw/issues/71416">#71416</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Agents/tools: normalize <code>null</code> or missing tool-call arguments to <code>{}</code> for parameterless object schemas before Pi validation, so empty-argument tools run instead of failing argument validation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333066551" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72587" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72587/hovercard" href="https://github.com/openclaw/openclaw/issues/72587">#72587</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Agents/subagents: clear active embedded-run state before terminal lifecycle events so post-completion cleanup no longer treats finished child runs as still active and skips archive or announcement bookkeeping. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4309345615" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70187" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70187/hovercard" href="https://github.com/openclaw/openclaw/pull/70187">#70187</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>CLI/update: keep the automatic post-update completion refresh on the core-command tree so it no longer stages bundled plugin runtime deps before the Gateway restart path, avoiding <code>.24</code> update hangs and 1006 disconnect cascades. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333693515" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72665" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72665/hovercard" href="https://github.com/openclaw/openclaw/issues/72665">#72665</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sakalaboator/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sakalaboator">@sakalaboator</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/He-Pin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/He-Pin">@He-Pin</a>.</li>
<li>Control UI: make explicit Reload Config actions discard stale local config edits while passive refreshes and failed-save recovery keep pending drafts intact. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4042433661" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40352" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40352/hovercard" href="https://github.com/openclaw/openclaw/issues/40352">#40352</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4042843645" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40443" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/40443/hovercard" href="https://github.com/openclaw/openclaw/pull/40443">#40443</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/realmikechong-dotcom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/realmikechong-dotcom">@realmikechong-dotcom</a>.</li>
<li>Agents/Bedrock: stop heartbeat runs from persisting blank user transcript turns and repair existing blank user text messages before replay, preventing AWS Bedrock <code>ContentBlock</code> blank-text validation failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333504705" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72640" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72640/hovercard" href="https://github.com/openclaw/openclaw/issues/72640">#72640</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333358856" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72622" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72622/hovercard" href="https://github.com/openclaw/openclaw/issues/72622">#72622</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/goldzulu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/goldzulu">@goldzulu</a>.</li>
<li>Agents/LM Studio: promote standalone bracketed local-model tool requests into registered tool calls and hide unsupported bracket blocks from visible replies, so MemPalace MCP lookups do not print raw <code>[tool]</code> JSON scaffolding in chat. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4258167996" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66178" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66178/hovercard" href="https://github.com/openclaw/openclaw/issues/66178">#66178</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/detroit357/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/detroit357">@detroit357</a>.</li>
<li>Local models: warn when an assistant reply looks like a tool call but the provider emitted plain text instead of a structured tool invocation, making fake/non-executed tool calls visible in logs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4110625662" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51332" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51332/hovercard" href="https://github.com/openclaw/openclaw/issues/51332">#51332</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/emilclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/emilclaw">@emilclaw</a>.</li>
<li>Local models: accept persisted non-secret local auth markers for private-LAN custom OpenAI-compatible providers, so LAN Ollama configs no longer fail with missing auth when <code>ollama-local</code> is saved as the key. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4094215279" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49736" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49736/hovercard" href="https://github.com/openclaw/openclaw/issues/49736">#49736</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/charles-zh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/charles-zh">@charles-zh</a>.</li>
<li>TUI/local models: treat visible gateway client labels such as <code>openclaw-tui</code> as the current requester session for session-aware tools, so Ollama tool calls no longer fail by resolving the UI label as a session id. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4260076318" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66391" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66391/hovercard" href="https://github.com/openclaw/openclaw/issues/66391">#66391</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kickingzebra/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kickingzebra">@kickingzebra</a>.</li>
<li>Local models: route self-hosted OpenAI-compatible model discovery through the guarded fetch path pinned to the configured host, covering vLLM and SGLang setup without reopening local/LAN SSRF probes. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4076198483" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46359" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/46359/hovercard" href="https://github.com/openclaw/openclaw/pull/46359">#46359</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cdxiaodong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cdxiaodong">@cdxiaodong</a>.</li>
<li>Local models: classify terminated, reset, closed, timeout, and aborted model-call failures and attach a process memory snapshot to the diagnostic event, making LM Studio/Ollama RAM-pressure failures easier to prove from stability bundles. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4249906273" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65551" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65551/hovercard" href="https://github.com/openclaw/openclaw/issues/65551">#65551</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BigWiLLi111/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BigWiLLi111">@BigWiLLi111</a>.</li>
<li>Local models: pass configured provider request timeouts through OpenAI SDK transports and the model idle watchdog so long-running local or custom OpenAI-compatible streams use one timeout knob instead of hitting the SDK's 10-minute default or the 120s idle default. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4231111693" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63663" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63663/hovercard" href="https://github.com/openclaw/openclaw/issues/63663">#63663</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aidiffuser/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aidiffuser">@aidiffuser</a>.</li>
<li>LM Studio: trust configured LM Studio loopback, LAN, and tailnet endpoints for guarded model requests by default, preserving explicit private-network opt-outs. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4205504518" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60994" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60994/hovercard" href="https://github.com/openclaw/openclaw/issues/60994">#60994</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tnowakow/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tnowakow">@tnowakow</a>.</li>
<li>Docker/setup: route Docker onboarding defaults for host-side LM Studio and Ollama through <code>host.docker.internal</code> and add the Linux host-gateway mapping to the bundled Compose file, so containerized gateways can reach local providers without using container loopback. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289073782" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68684" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68684/hovercard" href="https://github.com/openclaw/openclaw/issues/68684">#68684</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289314253" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68702" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68702/hovercard" href="https://github.com/openclaw/openclaw/pull/68702">#68702</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/safrano9999/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/safrano9999">@safrano9999</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/skolez/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/skolez">@skolez</a>.</li>
<li>Agents/LM Studio: strip prior-turn Gemma 4 reasoning from OpenAI-compatible replay while preserving active tool-call continuation reasoning. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289319395" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68704" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68704/hovercard" href="https://github.com/openclaw/openclaw/issues/68704">#68704</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chip-snomo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chip-snomo">@chip-snomo</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kailigithub/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kailigithub">@Kailigithub</a>.</li>
<li>LM Studio: allow interactive onboarding to leave the API key blank for unauthenticated local servers, using local synthetic auth while clearing stale LM Studio auth profiles. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265841731" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66937" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66937/hovercard" href="https://github.com/openclaw/openclaw/issues/66937">#66937</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/olamedia/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/olamedia">@olamedia</a>.</li>
<li>Plugins/startup/registry: reuse a Gateway <code>PluginLookUpTable</code> and one manifest registry pass across startup plugin IDs, plugin loading, deferred channel reloads, model pricing, read-only channel defaults, capability/provider/media resolution, manifest contracts, extractors, web fallback discovery, owner maps, and cold provider-discovery caches, with new startup-trace timing/count metrics for installed-index, manifest, startup-plan, and owner-map work. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mcaxtr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mcaxtr">@mcaxtr</a>.</li>
<li>Mattermost: keep direct-message replies top-level by suppressing reply roots for DM delivery while preserving channel and group thread roots, and derive inbound chat kind from the trusted channel lookup instead of the websocket event channel type. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4198774864" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60115" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60115/hovercard" href="https://github.com/openclaw/openclaw/pull/60115">#60115</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4144047176" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55186" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/55186/hovercard" href="https://github.com/openclaw/openclaw/pull/55186">#55186</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331558573" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72305" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72305/hovercard" href="https://github.com/openclaw/openclaw/pull/72305">#72305</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333662921" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72659" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72659/hovercard" href="https://github.com/openclaw/openclaw/pull/72659">#72659</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4195267865" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59758" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59758/hovercard" href="https://github.com/openclaw/openclaw/issues/59758">#59758</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4197726401" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59981" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59981/hovercard" href="https://github.com/openclaw/openclaw/issues/59981">#59981</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4195702082" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59791" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/59791/hovercard" href="https://github.com/openclaw/openclaw/pull/59791">#59791</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4168354725" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57565" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/57565/hovercard" href="https://github.com/openclaw/openclaw/pull/57565">#57565</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jwchmodx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jwchmodx">@jwchmodx</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hnykda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hnykda">@hnykda</a>.</li>
<li>Docker: pre-create <code>/home/node/.openclaw</code> with node ownership and private permissions so first-run Docker Compose named volumes no longer fail startup with EACCES. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4081165640" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48072" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/48072/hovercard" href="https://github.com/openclaw/openclaw/pull/48072">#48072</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4235354201" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63959" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63959/hovercard" href="https://github.com/openclaw/openclaw/pull/63959">#63959</a>; fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4207166215" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61279" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61279/hovercard" href="https://github.com/openclaw/openclaw/issues/61279">#61279</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/timoxue/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/timoxue">@timoxue</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jeanibarz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jeanibarz">@jeanibarz</a>.</li>
<li>CLI/Gateway: treat local restart probe policy closes for connect, exact <code>device required</code>, pairing, and auth failures as Gateway reachability proof without accepting empty, broad standalone token/password/scope/role, or pair-substring 1008 close reasons. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4086431078" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48771" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48771/hovercard" href="https://github.com/openclaw/openclaw/issues/48771">#48771</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4086615069" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48801" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/48801/hovercard" href="https://github.com/openclaw/openclaw/pull/48801">#48801</a>; related <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4228912213" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63491" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63491/hovercard" href="https://github.com/openclaw/openclaw/issues/63491">#63491</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MarsDoge/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MarsDoge">@MarsDoge</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/genoooool/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/genoooool">@genoooool</a>.</li>
<li>Feishu: send outgoing interactive reply payloads as native cards with clickable buttons while preserving text, media, and document-comment fallbacks. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3919571266" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/13175" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/13175/hovercard" href="https://github.com/openclaw/openclaw/issues/13175">#13175</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4177896611" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58298" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58298/hovercard" href="https://github.com/openclaw/openclaw/issues/58298">#58298</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4080155978" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47891" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/47891/hovercard" href="https://github.com/openclaw/openclaw/pull/47891">#47891</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Horacehxw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Horacehxw">@Horacehxw</a>.</li>
<li>Process/Windows: decode command stdout and stderr from raw bytes with console-codepage awareness, while preserving valid UTF-8 output and multibyte characters split across chunks. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4102777975" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50519" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/50519/hovercard" href="https://github.com/openclaw/openclaw/issues/50519">#50519</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iready/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iready">@iready</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kevinten10/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kevinten10">@kevinten10</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhangyongjie1997/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhangyongjie1997">@zhangyongjie1997</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/knightplat-blip/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/knightplat-blip">@knightplat-blip</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/heiqishi666/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/heiqishi666">@heiqishi666</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/slepybear/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slepybear">@slepybear</a>.</li>
<li>Bonjour/Windows: hide the bundled mDNS advertiser's Windows ARP shell probe so Gateway startup no longer flashes command-prompt windows. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4310157936" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70238" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70238/hovercard" href="https://github.com/openclaw/openclaw/issues/70238">#70238</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alexandre-leng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alexandre-leng">@alexandre-leng</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PratikRai0101/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PratikRai0101">@PratikRai0101</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/infinitypacific/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/infinitypacific">@infinitypacific</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tomerpeled/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tomerpeled">@tomerpeled</a>.</li>
<li>Agents/bootstrap: dedupe hook-injected bootstrap context files by workspace-relative path and store normalized resolved paths so duplicate relative and absolute hook paths no longer depend on the process cwd. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4190963394" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59344" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/59344/hovercard" href="https://github.com/openclaw/openclaw/pull/59344">#59344</a>; fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4190804191" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59319" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59319/hovercard" href="https://github.com/openclaw/openclaw/issues/59319">#59319</a>; related <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4162233538" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56721" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/56721/hovercard" href="https://github.com/openclaw/openclaw/pull/56721">#56721</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4162249580" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56725" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/56725/hovercard" href="https://github.com/openclaw/openclaw/pull/56725">#56725</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4168683400" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57587" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/57587/hovercard" href="https://github.com/openclaw/openclaw/pull/57587">#57587</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/koen666/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/koen666">@koen666</a>.</li>
<li>Agents/bootstrap: refresh cached workspace bootstrap snapshots on long-lived main-session turns when <code>AGENTS.md</code>, <code>SOUL.md</code>, <code>MEMORY.md</code>, or <code>TOOLS.md</code> change on disk, while preserving unchanged snapshot identity through the workspace file cache. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4245012829" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64871" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64871/hovercard" href="https://github.com/openclaw/openclaw/pull/64871">#64871</a>; related <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4063325217" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43901" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/43901/hovercard" href="https://github.com/openclaw/openclaw/pull/43901">#43901</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3989354959" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/26497" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/26497/hovercard" href="https://github.com/openclaw/openclaw/issues/26497">#26497</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4000351209" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/28594" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/28594/hovercard" href="https://github.com/openclaw/openclaw/issues/28594">#28594</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4008006931" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/30896" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/30896/hovercard" href="https://github.com/openclaw/openclaw/issues/30896">#30896</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aimqwest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aimqwest">@aimqwest</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mikejuyoon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mikejuyoon">@mikejuyoon</a>.</li>
<li>macOS Gateway: detect installed-but-unloaded LaunchAgent split-brain states during status, doctor, and restart, and re-bootstrap launchd supervision before falling back to unmanaged listener restarts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4270911583" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67335" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67335/hovercard" href="https://github.com/openclaw/openclaw/issues/67335">#67335</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4125657224" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53475" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53475/hovercard" href="https://github.com/openclaw/openclaw/issues/53475">#53475</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4322280015" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71060" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71060/hovercard" href="https://github.com/openclaw/openclaw/issues/71060">#71060</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4185336537" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58890" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58890/hovercard" href="https://github.com/openclaw/openclaw/issues/58890">#58890</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4204966968" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60885" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60885/hovercard" href="https://github.com/openclaw/openclaw/issues/60885">#60885</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319157550" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70801" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70801/hovercard" href="https://github.com/openclaw/openclaw/issues/70801">#70801</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ze1tgeist88/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ze1tgeist88">@ze1tgeist88</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dafacto/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dafacto">@dafacto</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vishutdhar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vishutdhar">@vishutdhar</a>.</li>
<li>Plugins/install: treat mirrored core logger dependencies as staged bundled runtime deps so packaged Gateway starts do not crash when the external plugin-runtime-deps root is missing <code>tslog</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331181809" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72228" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72228/hovercard" href="https://github.com/openclaw/openclaw/issues/72228">#72228</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332620459" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72493" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72493/hovercard" href="https://github.com/openclaw/openclaw/pull/72493">#72493</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/deepujain/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/deepujain">@deepujain</a>.</li>
<li>Build/plugins: preserve active bundled runtime-dependency staging temp directories owned by live build processes so overlapping postbuild runs no longer delete each other's staged deps mid-prune. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331140342" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72220" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72220/hovercard" href="https://github.com/openclaw/openclaw/pull/72220">#72220</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/VACInc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/VACInc">@VACInc</a>.</li>
<li>Plugins/install: hide bundled runtime-dependency npm child windows on Windows across Gateway startup, postinstall, and packaged staging paths so Telegram/Anthropic dependency repair no longer flashes shell windows. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331615103" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72315" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72315/hovercard" href="https://github.com/openclaw/openclaw/issues/72315">#72315</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/athuljayaram/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/athuljayaram">@athuljayaram</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshfeng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshfeng">@joshfeng</a>.</li>
<li>Agents/Windows: normalize lazy agent runtime imports before Node ESM loading so Windows drive-letter <code>subagent-registry</code> runtime paths no longer fail every agent task with <code>ERR_UNSUPPORTED_ESM_URL_SCHEME</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333477433" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72636" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72636/hovercard" href="https://github.com/openclaw/openclaw/issues/72636">#72636</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334354906" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72716" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72716/hovercard" href="https://github.com/openclaw/openclaw/pull/72716">#72716</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Andyz-CData/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Andyz-CData">@Andyz-CData</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xialonglee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xialonglee">@xialonglee</a>.</li>
<li>Plugins/Windows: normalize lazy plugin service override imports before Node ESM loading so drive-letter browser-control module paths no longer fail with <code>ERR_UNSUPPORTED_ESM_URL_SCHEME</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332955345" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72573" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72573/hovercard" href="https://github.com/openclaw/openclaw/issues/72573">#72573</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333188067" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72599" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72599/hovercard" href="https://github.com/openclaw/openclaw/pull/72599">#72599</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333023955" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72582" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72582/hovercard" href="https://github.com/openclaw/openclaw/pull/72582">#72582</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/llzzww316/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/llzzww316">@llzzww316</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/feineryonah-byte/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/feineryonah-byte">@feineryonah-byte</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WuKongAI-CMU/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WuKongAI-CMU">@WuKongAI-CMU</a>.</li>
<li>Browser/plugins: load <code>playwright-core</code> through the browser runtime shim so packaged installs can run Playwright actions from staged plugin runtime deps after doctor/startup repair. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330902734" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72168" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72168/hovercard" href="https://github.com/openclaw/openclaw/issues/72168">#72168</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331230145" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72238" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72238/hovercard" href="https://github.com/openclaw/openclaw/pull/72238">#72238</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zdg1110/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zdg1110">@zdg1110</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yetval/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yetval">@yetval</a>.</li>
<li>Plugins/install: stage bundled plugin runtime dependencies before Gateway startup, drain update restarts, and materialize plugin-owned root chunks in external mirrors so staged deps resolve under native ESM. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330416924" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72058" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72058/hovercard" href="https://github.com/openclaw/openclaw/issues/72058">#72058</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330508233" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72084" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72084/hovercard" href="https://github.com/openclaw/openclaw/pull/72084">#72084</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amnesia106/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amnesia106">@amnesia106</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/drvoss/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/drvoss">@drvoss</a>.</li>
<li>TTS/SecretRef: resolve <code>messages.tts.providers.*.apiKey</code> from the active runtime snapshot so SecretRef-backed MiniMax and other TTS provider keys work in runtime reply/audio paths. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289130983" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68690" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68690/hovercard" href="https://github.com/openclaw/openclaw/issues/68690">#68690</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Gateway/install: surface systemd user-bus recovery hints during Linux service activation and retry via the target user scope when <code>systemctl --user</code> reports no-medium bus failures, without letting stale <code>SUDO_USER</code> override <code>sudo -u</code> installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4040941886" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39673" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/39673/hovercard" href="https://github.com/openclaw/openclaw/issues/39673">#39673</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4067677546" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44417" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44417/hovercard" href="https://github.com/openclaw/openclaw/issues/44417">#44417</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4229610817" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63561" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63561/hovercard" href="https://github.com/openclaw/openclaw/issues/63561">#63561</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Arbor4/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Arbor4">@Arbor4</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/myrsu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/myrsu">@myrsu</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mssteuer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mssteuer">@mssteuer</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/boyuaner/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/boyuaner">@boyuaner</a>.</li>
<li>CLI/nodes: make unfiltered <code>openclaw nodes list</code> prefer the effective paired-node view used by <code>nodes status</code> while preserving pending rows, pairing-scope fallback, terminal-safe table rendering, and paired JSON metadata. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4077580136" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46871" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/46871/hovercard" href="https://github.com/openclaw/openclaw/issues/46871">#46871</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4252092457" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65772" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65772/hovercard" href="https://github.com/openclaw/openclaw/pull/65772">#65772</a> through the ProjectClownfish <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333343041" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72619" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72619/hovercard" href="https://github.com/openclaw/openclaw/pull/72619">#72619</a> repair. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/skainguyen1412/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/skainguyen1412">@skainguyen1412</a>.</li>
<li>CLI/startup: read generated startup metadata from the bundled <code>dist</code> layout before falling back to live help rendering, so root/browser help and channel-option bootstrap stay on the fast path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Feishu/Lark: stop treating broadcast-only <code>@all</code>/<code>@_all</code> messages as bot mentions while preserving direct bot mentions, including messages that also include <code>@all</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4033693984" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/37706" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/37706/hovercard" href="https://github.com/openclaw/openclaw/issues/37706">#37706</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JosepLee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JosepLee">@JosepLee</a>.</li>
<li>CLI/help: treat positional <code>help</code> invocations like <code>openclaw channels help</code> as help paths for startup gating, avoiding model/auth warmup while preserving positional arguments such as <code>openclaw docs help</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gumadeiras/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gumadeiras">@gumadeiras</a>.</li>
<li>Web search: route plugin-scoped web_search SecretRefs through the active runtime config snapshot so provider execution receives resolved credentials across app/runtime paths, including <code>plugins.entries.brave.config.webSearch.apiKey</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289130983" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68690" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68690/hovercard" href="https://github.com/openclaw/openclaw/issues/68690">#68690</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/VACInc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/VACInc">@VACInc</a>.</li>
<li>Voice Call: allow SecretRef-backed Twilio auth tokens and call-specific OpenAI/ElevenLabs TTS API keys through the plugin config surface. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289130983" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68690" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68690/hovercard" href="https://github.com/openclaw/openclaw/issues/68690">#68690</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Google Meet/Voice Call: clean stale chrome-node realtime bridges before rejoining, expose bridge inspection, tolerate transient node input pull failures, default Chrome command-pair audio to 24 kHz PCM16 while preserving legacy 8 kHz G.711 mu-law pairs, handle Gemini Live interruptions/VAD and function-response names correctly, route stateful <code>google_meet</code> tools through the gateway runtime, support <code>realtime.agentId</code>, and send non-blocking consult continuations before long tool-backed answers finish. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332050444" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72371" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72371/hovercard" href="https://github.com/openclaw/openclaw/issues/72371">#72371</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332743811" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72525" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72525/hovercard" href="https://github.com/openclaw/openclaw/issues/72525">#72525</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332742867" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72523" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72523/hovercard" href="https://github.com/openclaw/openclaw/issues/72523">#72523</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332383464" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72440" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72440/hovercard" href="https://github.com/openclaw/openclaw/issues/72440">#72440</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332290261" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72425" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72425/hovercard" href="https://github.com/openclaw/openclaw/issues/72425">#72425</a>; (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332050745" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72372" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72372/hovercard" href="https://github.com/openclaw/openclaw/pull/72372">#72372</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332743254" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72524" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72524/hovercard" href="https://github.com/openclaw/openclaw/pull/72524">#72524</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332097646" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72381" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72381/hovercard" href="https://github.com/openclaw/openclaw/pull/72381">#72381</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332388165" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72441" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72441/hovercard" href="https://github.com/openclaw/openclaw/pull/72441">#72441</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330987894" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72189" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72189/hovercard" href="https://github.com/openclaw/openclaw/pull/72189">#72189</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332290401" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72426" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72426/hovercard" href="https://github.com/openclaw/openclaw/pull/72426">#72426</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BsnizND/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BsnizND">@BsnizND</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/VACInc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/VACInc">@VACInc</a>.</li>
<li>Discord/media: keep incidental Markdown image badges in final replies as text unless a channel opts into Markdown-image media extraction, while preserving Telegram Markdown-image media replies and explicit <code>MEDIA:</code> attachments. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333512243" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72642" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72642/hovercard" href="https://github.com/openclaw/openclaw/issues/72642">#72642</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/solavrc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/solavrc">@solavrc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bartok9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bartok9">@Bartok9</a>.</li>
<li>Matrix/E2EE: stabilize recovery and broken-device QA flows while avoiding Matrix device-cleanup sync races that could leave shutdown-time crypto work running. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gumadeiras/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gumadeiras">@gumadeiras</a>.</li>
<li>Cron: apply <code>cron.maxConcurrentRuns</code> to the nested isolated-agent lane, start isolated execution timeouts only after the runner enters that lane, keep legacy flat <code>jobs.json</code> rows loadable, invalidate stale pending runtime slots after schedule edits, and preserve due slots for formatting-only rewrites. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334195587" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72707" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72707/hovercard" href="https://github.com/openclaw/openclaw/issues/72707">#72707</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3998171451" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/27996" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/27996/hovercard" href="https://github.com/openclaw/openclaw/issues/27996">#27996</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328262576" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71607" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71607/hovercard" href="https://github.com/openclaw/openclaw/issues/71607">#71607</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4049490726" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41783" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/41783/hovercard" href="https://github.com/openclaw/openclaw/issues/41783">#41783</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328629024" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71651" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71651/hovercard" href="https://github.com/openclaw/openclaw/pull/71651">#71651</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kagura-agent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kagura-agent">@kagura-agent</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xialonglee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xialonglee">@xialonglee</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fagnersouza666/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fagnersouza666">@fagnersouza666</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ayanesakura/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ayanesakura">@ayanesakura</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Hurray0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Hurray0">@Hurray0</a>.</li>
<li>Cron/delivery: classify isolated successes, quiet <code>NO_REPLY</code> turns, model/provider failures, execution denials, <code>--no-deliver</code> traces, skipped-job alerts, and verified delivery outcomes correctly so cron history, retries, and failure counters reflect what actually happened. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334620088" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72732" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72732/hovercard" href="https://github.com/openclaw/openclaw/issues/72732">#72732</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4099027844" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50170" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/50170/hovercard" href="https://github.com/openclaw/openclaw/issues/50170">#50170</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4061722670" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43604" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/43604/hovercard" href="https://github.com/openclaw/openclaw/issues/43604">#43604</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4287182300" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68452" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68452/hovercard" href="https://github.com/openclaw/openclaw/issues/68452">#68452</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4204696109" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60846" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60846/hovercard" href="https://github.com/openclaw/openclaw/issues/60846">#60846</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331088054" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72210" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72210/hovercard" href="https://github.com/openclaw/openclaw/issues/72210">#72210</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4268858101" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67172" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67172/hovercard" href="https://github.com/openclaw/openclaw/issues/67172">#67172</a>; follow-up to <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4132019195" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54188" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54188/hovercard" href="https://github.com/openclaw/openclaw/issues/54188">#54188</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4061845058" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43631" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/43631/hovercard" href="https://github.com/openclaw/openclaw/pull/43631">#43631</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4287182726" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68453" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68453/hovercard" href="https://github.com/openclaw/openclaw/pull/68453">#68453</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331130608" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72219" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72219/hovercard" href="https://github.com/openclaw/openclaw/pull/72219">#72219</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4269089318" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67186" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67186/hovercard" href="https://github.com/openclaw/openclaw/pull/67186">#67186</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zNatix/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zNatix">@zNatix</a>, @pixeldyn, @ChickenEggRoll, @SPFAdvisors, @anyech, @slideshow-dingo, @hatemclawbot-collab, @xydigit-sj, @oc-gh-dr, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/1yihui/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/1yihui">@1yihui</a>.</li>
<li>Cron/routing: preserve direct Telegram thread/account IDs, explicit Discord <code>user:</code>/<code>channel:</code> delivery targets, and <code>session:&lt;id&gt;</code> failure-destination routing so reminders, cron announcements, and failure alerts keep the intended recipient kind across direct and group chats. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4066185841" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44270" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44270/hovercard" href="https://github.com/openclaw/openclaw/issues/44270">#44270</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4221312754" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62777" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62777/hovercard" href="https://github.com/openclaw/openclaw/issues/62777">#62777</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4066608008" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44325" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/44325/hovercard" href="https://github.com/openclaw/openclaw/pull/44325">#44325</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4066877751" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44351" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/44351/hovercard" href="https://github.com/openclaw/openclaw/pull/44351">#44351</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4067595953" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44412" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/44412/hovercard" href="https://github.com/openclaw/openclaw/pull/44412">#44412</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333658933" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72657" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72657/hovercard" href="https://github.com/openclaw/openclaw/pull/72657">#72657</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4287884114" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68535" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68535/hovercard" href="https://github.com/openclaw/openclaw/pull/68535">#68535</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4221461201" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62798" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62798/hovercard" href="https://github.com/openclaw/openclaw/pull/62798">#62798</a>. Thanks @RunMintOn, @arkyu2077, @0xsline, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>, @slideshow-dingo, @likewen-tech, and @neeravmakwana.</li>
<li>Subagents: keep the delegated task only in the subagent system prompt and send a short initial kickoff message, avoiding duplicate task tokens while preserving multiline task formatting. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330266987" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72019" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72019/hovercard" href="https://github.com/openclaw/openclaw/issues/72019">#72019</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330403858" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72053" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72053/hovercard" href="https://github.com/openclaw/openclaw/pull/72053">#72053</a>. Thanks @Wizongod and @ly85206559.</li>
<li>Onboarding/GitHub Copilot: add manifest-owned <code>--github-copilot-token</code> support for non-interactive setup, including env fallback, tokenRef storage in ref mode, saved-profile reuse, and current Copilot default-model wiring. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4097444746" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50002" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/50002/hovercard" href="https://github.com/openclaw/openclaw/issues/50002">#50002</a> and supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4097445479" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50003" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/50003/hovercard" href="https://github.com/openclaw/openclaw/pull/50003">#50003</a>. Thanks @scottgl9.</li>
<li>Gateway/install: add a validated <code>--wrapper</code>/<code>OPENCLAW_WRAPPER</code> service install path that persists executable LaunchAgent/systemd wrappers across forced reinstalls, updates, and doctor repairs instead of falling back to raw node/bun <code>ProgramArguments</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4297397474" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69400" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69400/hovercard" href="https://github.com/openclaw/openclaw/issues/69400">#69400</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332409419" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72445" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72445/hovercard" href="https://github.com/openclaw/openclaw/pull/72445">#72445</a>) Thanks @willtmc.</li>
<li>Plugins: fail plugin registration when loader-owned acceptance gates reject missing hook names or memory-only capability registration from non-memory plugins, surfacing the issue through plugin status and doctor instead of silently dropping the registration. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332435276" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72459" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72459/hovercard" href="https://github.com/openclaw/openclaw/issues/72459">#72459</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>macOS Gateway: write launchd services with a state-dir <code>WorkingDirectory</code>, use a durable state-dir temp path instead of freezing macOS session <code>TMPDIR</code>, create that temp directory before bootstrap, and label abort-shaped launchd exits as <code>SIGABRT/abort</code> in status output. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4127640305" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53679" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53679/hovercard" href="https://github.com/openclaw/openclaw/issues/53679">#53679</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4309815603" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70223" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70223/hovercard" href="https://github.com/openclaw/openclaw/issues/70223">#70223</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329643796" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71848" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71848/hovercard" href="https://github.com/openclaw/openclaw/issues/71848">#71848</a>. Thanks @dlturock, @stammi922, and @palladius.</li>
<li>Control UI/update: make <code>Update now</code> require a real gateway process replacement, report skipped/error update outcomes with stable reasons, and verify the running gateway version after restart so global installs cannot silently keep old code in memory. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4217678354" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62492" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62492/hovercard" href="https://github.com/openclaw/openclaw/issues/62492">#62492</a>; addresses <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4245063393" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64892" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64892/hovercard" href="https://github.com/openclaw/openclaw/issues/64892">#64892</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4229612858" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63562" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63562/hovercard" href="https://github.com/openclaw/openclaw/issues/63562">#63562</a>. Thanks @IAMSamuelRodda.</li>
<li>Exec approvals: accept runtime-owned <code>source: "allow-always"</code> and <code>commandText</code> allowlist metadata in gateway and node approval-set payloads so Control UI round-trips no longer fail with <code>unexpected property 'source'</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4197832508" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60000" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60000/hovercard" href="https://github.com/openclaw/openclaw/issues/60000">#60000</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4198205333" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60064" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60064/hovercard" href="https://github.com/openclaw/openclaw/pull/60064">#60064</a>. Thanks @sd1471123, @sharkqwy, and @luoyanglang.</li>
<li>Exec/node: skip approval-plan preparation for full-trust <code>host=node</code> runs so interpreter and script commands no longer fail with <code>SYSTEM_RUN_DENIED: approval cannot safely bind</code> when effective policy is <code>security=full</code> and <code>ask=off</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4084375630" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48457" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48457/hovercard" href="https://github.com/openclaw/openclaw/issues/48457">#48457</a> and duplicate <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4293866252" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69251" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69251/hovercard" href="https://github.com/openclaw/openclaw/issues/69251">#69251</a>. Thanks @ajtran303, @jaserNo1, @Blakeshannon, @lesliefag, and @AvIsBeastMC.</li>
<li>Exec/node: synthesize a local approval plan when a paired node advertises <code>system.run</code> without <code>system.run.prepare</code>, unblocking approval-required <code>host=node</code> exec on current macOS companion nodes while preserving remote prepare for node hosts that support it. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4033313008" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/37591" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/37591/hovercard" href="https://github.com/openclaw/openclaw/issues/37591">#37591</a> and duplicate <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265048569" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66839" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66839/hovercard" href="https://github.com/openclaw/openclaw/issues/66839">#66839</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4303037278" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69725" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69725/hovercard" href="https://github.com/openclaw/openclaw/pull/69725">#69725</a>. Thanks @soloclz.</li>
<li>Memory/QMD: prefer QMD's <code>--mask</code> collection pattern flag so root memory indexing stays scoped to <code>MEMORY.md</code> instead of widening to every markdown file in the workspace. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4249056416" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65480" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65480/hovercard" href="https://github.com/openclaw/openclaw/issues/65480">#65480</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4249056746" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65481" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65481/hovercard" href="https://github.com/openclaw/openclaw/pull/65481">#65481</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4258914603" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66259" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66259/hovercard" href="https://github.com/openclaw/openclaw/pull/66259">#66259</a>. Thanks @ccage-simp, @Bortlesboat, @seank-com, and @crazyscience.</li>
<li>Memory/doctor: treat the specific <code>gateway timeout after ...</code> gateway memory probe result as inconclusive instead of reporting embeddings not ready, while preserving warnings for explicit failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4067725204" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44426" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44426/hovercard" href="https://github.com/openclaw/openclaw/issues/44426">#44426</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4076741219" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46576" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/46576/hovercard" href="https://github.com/openclaw/openclaw/pull/46576">#46576</a> with the Greptile review feedback applied. Thanks Cengiz (@ghost).</li>
<li>Gateway/startup: defer QMD, core request handlers, setup wizard, CLI outbound senders, plugin HTTP routes, chat/session projection, node session runtime validation, embedded-run activity reads, MCP loopback server imports, channel runtime helpers, HTTP/canvas/plugin auth helpers, isolated cron imports, and hook dispatch parsing until their request or shutdown paths, while making plain <code>gateway status</code> use a parse-only config snapshot so no-plugin boots and status reads avoid broad runtime fanout. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Lobster/Gateway: memoize repeated Ajv schema compilation before loading the embedded Lobster runtime so scheduled workflows and <code>llm.invoke</code> loops stop growing gateway heap on content-identical schemas. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4323825705" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71148" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71148/hovercard" href="https://github.com/openclaw/openclaw/issues/71148">#71148</a>. Thanks @cmi525, @vsolaz, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Codex harness: normalize cached input tokens before session/context accounting so prompt cache reads are not double-counted in <code>/status</code>, <code>session_status</code>, or persisted <code>sessionEntry.totalTokens</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4294939319" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69298" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69298/hovercard" href="https://github.com/openclaw/openclaw/issues/69298">#69298</a>. Thanks @richardmqq.</li>
<li>Hooks/session-memory: use the host local timezone for memory filenames, fallback timestamp slugs, and markdown headers instead of UTC dates. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4077284827" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46703" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/46703/hovercard" href="https://github.com/openclaw/openclaw/issues/46703">#46703</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4077318445" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46721" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/46721/hovercard" href="https://github.com/openclaw/openclaw/pull/46721">#46721</a>) Thanks @Astro-Han.</li>
<li>Gateway health: preserve live runtime-backed channel/account state in <code>gateway.health</code> snapshots and cached refreshes while keeping raw probe payloads on sensitive/admin paths only. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041371133" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39921" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/39921/hovercard" href="https://github.com/openclaw/openclaw/pull/39921">#39921</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4054923925" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42586" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/42586/hovercard" href="https://github.com/openclaw/openclaw/pull/42586">#42586</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4076534390" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46527" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/46527/hovercard" href="https://github.com/openclaw/openclaw/pull/46527">#46527</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4119683274" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52770" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/52770/hovercard" href="https://github.com/openclaw/openclaw/pull/52770">#52770</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4054579227" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42543" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/42543/hovercard" href="https://github.com/openclaw/openclaw/pull/42543">#42543</a>) Thanks @FAL1989, @rstar327, @0xble, and @ajayr.</li>
<li>Feishu: extract quoted/replied interactive-card text across schema 1.0, schema 2.0, i18n, template-variable, and post-format fallback shapes without carrying broad generated/config churn from related parser experiments. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4038206905" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/38776" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/38776/hovercard" href="https://github.com/openclaw/openclaw/pull/38776">#38776</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4201051829" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60383" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60383/hovercard" href="https://github.com/openclaw/openclaw/pull/60383">#60383</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4052134122" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42218" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/42218/hovercard" href="https://github.com/openclaw/openclaw/pull/42218">#42218</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4075296473" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45936" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/45936/hovercard" href="https://github.com/openclaw/openclaw/pull/45936">#45936</a>) Thanks @lishuaigit, @lskun, @just2gooo, and @Br1an67.</li>
<li>Telegram/agents: hide raw failed write/edit warning messages in Telegram when the assistant already explicitly acknowledges the failed action, while keeping warnings when the reply claims success or omits the failure; <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4040278873" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39406" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/39406/hovercard" href="https://github.com/openclaw/openclaw/issues/39406">#39406</a> remains the broader configurable delivery-policy follow-up. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4107998150" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51065" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51065/hovercard" href="https://github.com/openclaw/openclaw/issues/51065">#51065</a>; covers <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4040841536" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39631" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/39631/hovercard" href="https://github.com/openclaw/openclaw/issues/39631">#39631</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bartok9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bartok9">@Bartok9</a> and @Bortlesboat.</li>
<li>Exec approvals: accept a symlinked <code>OPENCLAW_HOME</code> as the trusted approvals root while still rejecting symlinked <code>.openclaw</code> path components below it. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4243267118" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64663" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64663/hovercard" href="https://github.com/openclaw/openclaw/pull/64663">#64663</a>) Thanks @FunJim.</li>
<li>Logging: add top-level <code>hostname</code>, flattened <code>message</code>, and available <code>agent_id</code>, <code>session_id</code>, and <code>channel</code> fields to file-log JSONL records for multi-agent filtering without removing existing structured log arguments. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4108127045" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51075" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51075/hovercard" href="https://github.com/openclaw/openclaw/issues/51075">#51075</a>. Thanks @stevengonsalvez.</li>
<li>ACP: route server logs to stderr before Gateway config/bootstrap work so ACP stdout remains JSON-RPC only for IDE integrations. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4088925593" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49060" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49060/hovercard" href="https://github.com/openclaw/openclaw/issues/49060">#49060</a>. Thanks @Hollychou924.</li>
<li>Logging: propagate internal request trace scopes through Gateway HTTP requests and WebSocket frames so file logs, diagnostic events, agent run traces, model-call traces, OTEL spans, and trusted provider <code>traceparent</code> headers share a correlatable <code>traceId</code> without logging raw request or model content. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4042435480" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40353" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40353/hovercard" href="https://github.com/openclaw/openclaw/issues/40353">#40353</a>. Thanks @liangruochong44-ui.</li>
<li>Diagnostics/OTEL: capture privacy-safe model-call request payload bytes, streamed response bytes, first-response latency, and total duration in diagnostic events, plugin hooks, stability snapshots, and OTEL model-call spans/metrics without logging raw model content. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4019760959" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/33832" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/33832/hovercard" href="https://github.com/openclaw/openclaw/issues/33832">#33832</a>. Thanks @wwh830.</li>
<li>Logging: write validated diagnostic trace context as top-level <code>traceId</code>, <code>spanId</code>, <code>parentSpanId</code>, and <code>traceFlags</code> fields in file-log JSONL records so traced requests and model calls are easier to correlate in log processors. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4042435480" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40353" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40353/hovercard" href="https://github.com/openclaw/openclaw/issues/40353">#40353</a>. Thanks @liangruochong44-ui.</li>
<li>Logging/sessions: apply configured redaction patterns to persisted session transcript text and accept escaped character classes in safe custom redaction regexes, so transcript JSONL no longer keeps matching sensitive text in the clear. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4056740716" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42982" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42982/hovercard" href="https://github.com/openclaw/openclaw/issues/42982">#42982</a>. Thanks @panpan0000.</li>
<li>Agents/sessions: let <code>sessions_spawn runtime="subagent"</code> ignore ACP-only <code>streamTo</code> and <code>resumeSessionId</code> fields while keeping ACP passthrough and documenting <code>streamTo</code> as ACP-only. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4061499254" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43556" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/43556/hovercard" href="https://github.com/openclaw/openclaw/issues/43556">#43556</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4224020997" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63120" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63120/hovercard" href="https://github.com/openclaw/openclaw/issues/63120">#63120</a>; covers <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4159060112" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56326" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56326/hovercard" href="https://github.com/openclaw/openclaw/issues/56326">#56326</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4210049383" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61724" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61724/hovercard" href="https://github.com/openclaw/openclaw/issues/61724">#61724</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4243766641" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64714" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64714/hovercard" href="https://github.com/openclaw/openclaw/issues/64714">#64714</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4269747849" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67248" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67248/hovercard" href="https://github.com/openclaw/openclaw/issues/67248">#67248</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4286646321" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68397" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68397/hovercard" href="https://github.com/openclaw/openclaw/pull/68397">#68397</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4247437331" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65282" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65282/hovercard" href="https://github.com/openclaw/openclaw/pull/65282">#65282</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4183666554" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58686" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/58686/hovercard" href="https://github.com/openclaw/openclaw/pull/58686">#58686</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4159218513" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56342" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/56342/hovercard" href="https://github.com/openclaw/openclaw/pull/56342">#56342</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041738951" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40102" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/40102/hovercard" href="https://github.com/openclaw/openclaw/pull/40102">#40102</a>. Thanks @skernelx, @damselem, @Br1an67, @Mintalix, @IsaacAPerez, @vvitovec, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sanjays2402/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sanjays2402">@Sanjays2402</a>, @shenkq97, and @1034378361.</li>
<li>Providers/Ollama: honor <code>/api/show</code> capabilities, custom Modelfile <code>PARAMETER num_ctx</code>, configured provider/model context defaults, whitelisted native params such as <code>temperature</code>, <code>top_p</code>, and <code>think</code>, and native thinking effort levels so local models get accurate tools, context, and thinking behavior without forcing full-context VRAM use. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4243652449" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64710" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64710/hovercard" href="https://github.com/openclaw/openclaw/issues/64710">#64710</a>, duplicate <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4247974485" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65343" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65343/hovercard" href="https://github.com/openclaw/openclaw/issues/65343">#65343</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4286116014" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68344" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68344/hovercard" href="https://github.com/openclaw/openclaw/issues/68344">#68344</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4068385205" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44550" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44550/hovercard" href="https://github.com/openclaw/openclaw/issues/44550">#44550</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4115724405" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52206" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52206/hovercard" href="https://github.com/openclaw/openclaw/issues/52206">#52206</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4093765160" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49684" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49684/hovercard" href="https://github.com/openclaw/openclaw/issues/49684">#49684</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4288813407" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68662" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68662/hovercard" href="https://github.com/openclaw/openclaw/issues/68662">#68662</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4080851654" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48010" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48010/hovercard" href="https://github.com/openclaw/openclaw/issues/48010">#48010</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328145755" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71584" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71584/hovercard" href="https://github.com/openclaw/openclaw/issues/71584">#71584</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4069340291" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44786" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44786/hovercard" href="https://github.com/openclaw/openclaw/issues/44786">#44786</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4298714503" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69464" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69464/hovercard" href="https://github.com/openclaw/openclaw/pull/69464">#69464</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4070089946" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44955" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/44955/hovercard" href="https://github.com/openclaw/openclaw/pull/44955">#44955</a>. Thanks @yuan-b, @netherby, @xilopaint, @Diyforfun2026, @neeravmakwana, @taitruong, @armi0024, @LokiCode404, @zhouZcong, @dshenster-byte, @tangzhi, @pandego, @maweibin, @Adam-Researchh, @EmpireCreator, @g0st1n, and @voltwake.</li>
<li>Image tool/media: honor <code>tools.media.image.timeoutSeconds</code> and matching per-model image timeouts in explicit image analysis, including the MiniMax VLM fallback path, so slow local vision models are not capped by hardcoded 30s/60s aborts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4279519640" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67889" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67889/hovercard" href="https://github.com/openclaw/openclaw/issues/67889">#67889</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4279773642" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67929" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67929/hovercard" href="https://github.com/openclaw/openclaw/pull/67929">#67929</a>. Thanks @AllenT22 and @alchip.</li>
<li>Providers/Ollama: strip custom provider prefixes before native chat/embedding requests, skip ambient localhost discovery unless config/auth opts in, handle custom remote <code>api: "ollama"</code> providers, accept OpenAI SDK-style <code>baseURL</code>, scope synthetic local auth and embedding bearer headers to declared host boundaries, resolve custom-named local providers for subagents, add provider-scoped model request timeouts, preserve explicit input modalities, and document <code>params.keep_alive</code> plus local/LAN/cloud/multi-host/web-search/embedding/thinking setup recipes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331946087" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72353" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72353/hovercard" href="https://github.com/openclaw/openclaw/issues/72353">#72353</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4163674492" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56939" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56939/hovercard" href="https://github.com/openclaw/openclaw/issues/56939">#56939</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4218171224" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62533" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62533/hovercard" href="https://github.com/openclaw/openclaw/issues/62533">#62533</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4063699337" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43945" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/43945/hovercard" href="https://github.com/openclaw/openclaw/issues/43945">#43945</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4242267309" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64541" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64541/hovercard" href="https://github.com/openclaw/openclaw/issues/64541">#64541</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289810240" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68796" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68796/hovercard" href="https://github.com/openclaw/openclaw/issues/68796">#68796</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4040967916" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39690" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/39690/hovercard" href="https://github.com/openclaw/openclaw/issues/39690">#39690</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4164708025" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57116" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/57116/hovercard" href="https://github.com/openclaw/openclaw/pull/57116">#57116</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4218493302" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62549" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62549/hovercard" href="https://github.com/openclaw/openclaw/pull/62549">#62549</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4294028827" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69261" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69261/hovercard" href="https://github.com/openclaw/openclaw/pull/69261">#69261</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4305660897" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69857" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69857/hovercard" href="https://github.com/openclaw/openclaw/pull/69857">#69857</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4246414524" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65143" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65143/hovercard" href="https://github.com/openclaw/openclaw/pull/65143">#65143</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4261643783" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66511" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66511/hovercard" href="https://github.com/openclaw/openclaw/pull/66511">#66511</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4063699337" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43945" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/43945/hovercard" href="https://github.com/openclaw/openclaw/issues/43945">#43945</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4058318799" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43224" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/43224/hovercard" href="https://github.com/openclaw/openclaw/pull/43224">#43224</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041140398" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39785" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/39785/hovercard" href="https://github.com/openclaw/openclaw/pull/39785">#39785</a>. Thanks @maximus-dss, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>, @IanxDev, @tsukhani, @issacthekaylon, @Julien-BKK, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Linux2010/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Linux2010">@Linux2010</a>, @hyspacex, @maxramsay, @Meli73, @LittleJakub, @Juankcba, @uninhibite-scholar, @yfge, @Skrblik, and @Mriris.</li>
<li>Providers/Ollama: move memory embeddings to <code>/api/embed</code> with batched <code>input</code>, route local web search through Ollama's signed daemon proxy while keeping cloud auth scoped, treat Ollama memory embeddings as key-optional in doctor, and keep model usage visible by estimating native transcript usage when <code>/api/chat</code> omits counters. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041488866" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39983" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/39983/hovercard" href="https://github.com/openclaw/openclaw/issues/39983">#39983</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4292504181" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69132" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69132/hovercard" href="https://github.com/openclaw/openclaw/issues/69132">#69132</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4076765556" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46584" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/46584/hovercard" href="https://github.com/openclaw/openclaw/issues/46584">#46584</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4039238525" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39112" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/39112/hovercard" href="https://github.com/openclaw/openclaw/pull/39112">#39112</a>. Thanks @sskkcc, @LiudengZhang, @yoon1012, @hyspacex, @fengly78, and @TylonHH.</li>
<li>Agents/Ollama: parse stringified native tool-call arguments, retry native empty/thinking-only turns, accept already-prefixed LLM task model overrides, apply provider-owned replay normalization for Cloud models, validate explicit <code>--thinking max</code>, show resolved thinking defaults in Control UI, and include configured provider models in <code>models list --provider</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4303167754" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69735" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69735/hovercard" href="https://github.com/openclaw/openclaw/issues/69735">#69735</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4098081207" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50052" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/50052/hovercard" href="https://github.com/openclaw/openclaw/issues/50052">#50052</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328894010" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71697" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71697/hovercard" href="https://github.com/openclaw/openclaw/issues/71697">#71697</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328145755" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71584" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71584/hovercard" href="https://github.com/openclaw/openclaw/issues/71584">#71584</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332228603" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72407" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72407/hovercard" href="https://github.com/openclaw/openclaw/issues/72407">#72407</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4246874368" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65207" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65207/hovercard" href="https://github.com/openclaw/openclaw/issues/65207">#65207</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4306117215" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69910" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69910/hovercard" href="https://github.com/openclaw/openclaw/pull/69910">#69910</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4262256583" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66552" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66552/hovercard" href="https://github.com/openclaw/openclaw/pull/66552">#66552</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4206791675" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61223" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61223/hovercard" href="https://github.com/openclaw/openclaw/issues/61223">#61223</a>. Thanks @rongshuzhao, @yfge, @L3G, @ralphy-maplebots, @Hollychou924, @ismael-81, @g0st1n, @NotecAG, and @drzeast-png.</li>
<li>Providers/PDF/Ollama: add bounded network timeouts for Ollama model pulls and native Anthropic/Gemini PDF analysis requests so unresponsive provider endpoints no longer hang sessions indefinitely. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4131775554" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54142" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54142/hovercard" href="https://github.com/openclaw/openclaw/issues/54142">#54142</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4131780831" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54144" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54144/hovercard" href="https://github.com/openclaw/openclaw/pull/54144">#54144</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4131781144" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54145" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54145/hovercard" href="https://github.com/openclaw/openclaw/pull/54145">#54145</a>. Thanks @jinduwang1001-max and @arkyu2077.</li>
<li>Docker/QA: add observability coverage to the normal Docker aggregate so QA-lab OTEL and Prometheus diagnostics run inside Docker. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Auto-reply: poison inbound message dedupe after replay-unsafe provider/runtime failures so retries stay safe before visible progress but cannot duplicate messages after block output, tool side effects, or session progress. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4295112826" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69303" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69303/hovercard" href="https://github.com/openclaw/openclaw/issues/69303">#69303</a>; keeps <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4181977803" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58549" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58549/hovercard" href="https://github.com/openclaw/openclaw/issues/58549">#58549</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4242766269" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64606" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64606/hovercard" href="https://github.com/openclaw/openclaw/issues/64606">#64606</a> as duplicate validation. Thanks @martingarramon, @NikolaFC, and @zeroth-blip.</li>
<li>Agents/model fallback: keep auto-persisted fallback model overrides selected across turns until <code>/new</code> or reset clears them, avoiding repeated probes of a known-bad primary while <code>/status</code> shows the selected and active models. Thanks @kibedu.</li>
<li>Agents/model fallback: jump directly to a known later live-session model redirect instead of walking unrelated fallback candidates, while preserving the already-landed live-session/fallback loop guard. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4167179452" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57471" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/57471/hovercard" href="https://github.com/openclaw/openclaw/issues/57471">#57471</a>; related loop family already closed via <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4181008782" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58496" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58496/hovercard" href="https://github.com/openclaw/openclaw/issues/58496">#58496</a>. Thanks @yuxiaoyang2007-prog.</li>
<li>Gateway/Bonjour: keep @homebridge/ciao cancellation handlers registered across advertiser restarts so late probing cancellations cannot crash Linux and other mDNS-churned gateways.</li>
<li>Plugins/startup: load the default <code>memory-core</code> slot during Gateway startup when permitted so active-memory recall can call <code>memory_search</code> and <code>memory_get</code> without requiring an explicit <code>plugins.slots.memory</code> entry, while preserving <code>plugins.slots.memory: "none"</code>.</li>
<li>Plugins/CLI: prefer native require for compiled bundled plugin JavaScript before jiti so read-only config, status, device, and node commands avoid unnecessary transform overhead on slow hosts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4221630999" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62842" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62842/hovercard" href="https://github.com/openclaw/openclaw/issues/62842">#62842</a>. Thanks @Effet.</li>
<li>Plugins/compat/CLI: inventory doctor-side deprecation migrations separately from runtime plugin compatibility, add dated records for legacy extension-api, memory registration, provider hook/type aliases, runtime aliases, channel SDK helpers, and approval/test utility shims, refresh the persisted registry after managed plugin removals, make plugin install/uninstall writes conflict-aware, clear stale denylists, and fail tracked plugin/hook updates or unloadable package installs instead of leaving stale state. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>WebChat/Control UI: support non-video file attachments in chat uploads while preserving the existing image attachment path and MIME-sniff fallback for generic image uploads. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320611972" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70947" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70947/hovercard" href="https://github.com/openclaw/openclaw/pull/70947">#70947</a>) Thanks @IAMSamuelRodda.</li>
<li>Skills/memory: restore Chokidar v5 hot reloads by watching concrete skill and memory roots with filters, including SKILL.md removals and deleted skill folders without broad workspace recursion. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3994509566" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/27404" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/27404/hovercard" href="https://github.com/openclaw/openclaw/issues/27404">#27404</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4019092319" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/33585" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/33585/hovercard" href="https://github.com/openclaw/openclaw/issues/33585">#33585</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4048900568" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41606" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/41606/hovercard" href="https://github.com/openclaw/openclaw/issues/41606">#41606</a>. Thanks @shelvenzhou, @08820048, and @rocke2020.</li>
<li>Gateway/chat: keep duplicate attachment-backed <code>chat.send</code> retries with the same idempotency key on the documented in-flight path so aborts still target the real active run. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4308621432" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70139" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70139/hovercard" href="https://github.com/openclaw/openclaw/issues/70139">#70139</a>. Thanks @Feelw00.</li>
<li>Gateway/session rows: report the same config-resolved thinking default that runtime sessions use, including global and per-agent defaults, so Control UI and TUI default labels stay aligned. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329269914" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71779" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71779/hovercard" href="https://github.com/openclaw/openclaw/pull/71779">#71779</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4321156135" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70981" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70981/hovercard" href="https://github.com/openclaw/openclaw/pull/70981">#70981</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4321797296" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71033" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71033/hovercard" href="https://github.com/openclaw/openclaw/pull/71033">#71033</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4311083134" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70302" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70302/hovercard" href="https://github.com/openclaw/openclaw/pull/70302">#70302</a>) Thanks @chen-zhang-cs-code, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>, and @cholaolu-boop.</li>
<li>Plugins: share package entrypoint resolution between install and discovery, reject mismatched <code>runtimeExtensions</code>, and cache bundled runtime-dependency manifest reads during scans.</li>
<li>WhatsApp/Web: keep quiet but healthy linked-device sessions connected by basing the watchdog on WhatsApp Web transport activity, while retaining a longer app-silence cap so frame activity cannot mask a stuck session forever. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317373252" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70678" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70678/hovercard" href="https://github.com/openclaw/openclaw/issues/70678">#70678</a>; carries forward the focused <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327494555" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71466" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71466/hovercard" href="https://github.com/openclaw/openclaw/pull/71466">#71466</a> approach and keeps <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4235211931" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63939" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63939/hovercard" href="https://github.com/openclaw/openclaw/pull/63939">#63939</a> as related configurable-timeout follow-up. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oromeis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oromeis">@oromeis</a>.</li>
<li>Discord/gateway: count failed health-monitor restart attempts toward cooldown and hourly caps, and evict stale account lifecycle state during channel reloads so repeated Discord gateway recovery cannot loop on old status. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4037442367" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/38596" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/38596/hovercard" href="https://github.com/openclaw/openclaw/issues/38596">#38596</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4042713721" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40413" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/40413/hovercard" href="https://github.com/openclaw/openclaw/pull/40413">#40413</a>) Thanks @jellyAI-dev and @vashquez.</li>
<li>Cron/context engine: run isolated cron jobs under run-scoped context-engine session keys so prior runs of the same job are not inherited unless the job is explicitly session-bound. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331505048" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72292" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72292/hovercard" href="https://github.com/openclaw/openclaw/pull/72292">#72292</a>) Thanks @jalehman.</li>
<li>Control UI: localize command palette labels, categories, skill shortcuts, footer hints, and connect-command copy labels while preserving localized command palette search matching. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4206202649" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61130" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61130/hovercard" href="https://github.com/openclaw/openclaw/pull/61130">#61130</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4206163055" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61119" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61119/hovercard" href="https://github.com/openclaw/openclaw/pull/61119">#61119</a>) Thanks @rubensfox20.</li>
<li>Plugins/memory-lancedb: request float embedding responses from OpenAI-compatible servers so local providers that default SDK requests to base64 no longer return dimension-mismatched LanceDB vectors while preserving configured dimensions. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4075425486" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45982" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/45982/hovercard" href="https://github.com/openclaw/openclaw/issues/45982">#45982</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4187115245" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59048" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/59048/hovercard" href="https://github.com/openclaw/openclaw/pull/59048">#59048</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4075652492" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46069" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/46069/hovercard" href="https://github.com/openclaw/openclaw/pull/46069">#46069</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4075431997" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45986" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/45986/hovercard" href="https://github.com/openclaw/openclaw/pull/45986">#45986</a>) Thanks @deep-introspection, @xiaokhkh, @caicongyang, and @thiswind.</li>
<li>Plugins/memory-lancedb: advance auto-capture cursors per session only after messages are processed or intentionally skipped, retry failed messages, survive compacted histories, and clear cursor state on session end. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326654147" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71349" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71349/hovercard" href="https://github.com/openclaw/openclaw/issues/71349">#71349</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4051142895" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42083" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/42083/hovercard" href="https://github.com/openclaw/openclaw/pull/42083">#42083</a>. Thanks @as775116191.</li>
<li>Plugins/memory-core: respect configured memory-search embedding concurrency during non-batch indexing so local Ollama embedding backends can serialize indexing instead of flooding the server. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4264947077" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66822" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66822/hovercard" href="https://github.com/openclaw/openclaw/issues/66822">#66822</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265769455" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66931" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66931/hovercard" href="https://github.com/openclaw/openclaw/pull/66931">#66931</a>) Thanks @oliviareid-svg and @LyraInTheFlesh.</li>
<li>Docker/update smoke: keep the package-derived update-channel fixture on package-shipped files and make its UI build stub create the asset the updater verifies. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/models: repair legacy <code>models.providers.*.api = "openai"</code> config values to <code>openai-completions</code>, and skip providers with future stale API enum values during startup instead of bricking the gateway. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332548488" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72477" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72477/hovercard" href="https://github.com/openclaw/openclaw/issues/72477">#72477</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332844009" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72542" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72542/hovercard" href="https://github.com/openclaw/openclaw/pull/72542">#72542</a>) Thanks @JooyoungChoi14 and @obviyus.</li>
<li>Gateway/skills: redact <code>apiKey</code> and secret-named <code>env</code> values from the <code>skills.update</code> RPC response to prevent leaking credentials into WebSocket traffic, client logs, or session transcripts. Config is still written to disk in full; only the response payload is redacted. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4306962807" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69998" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69998/hovercard" href="https://github.com/openclaw/openclaw/pull/69998">#69998</a>) Thanks @Ziy1-Tan.</li>
<li>Plugins/CLI: let flag-driven <code>openclaw channels add</code> install the selected channel plugin from its default source without opening an interactive prompt, fixing published npm Telegram setup in stdin-closed automation.</li>
<li>Onboarding/setup: keep first-run config reads, plugin compatibility notices, OpenAI Codex auth, post-auth default-model policy lookup, skip-auth, provider-scoped model pickers, and post-model sanity checks on cold manifest/setup metadata unless the user chooses to browse all models, avoiding full plugin/provider runtime loads between prompts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Gateway/Bonjour: suppress known @homebridge/ciao cancellation and network assertion failures through scoped process handlers so malformed mDNS packets or restricted VPS networking disable/restart Bonjour instead of crashing the gateway. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4274075946" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67578" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67578/hovercard" href="https://github.com/openclaw/openclaw/issues/67578">#67578</a>. Thanks @zenassist26-create.</li>
<li>Discord: keep late clicks on already-resolved exec approval buttons quiet when elevated mode auto-resolved the request, while still surfacing real approval submission failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265667453" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66906" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66906/hovercard" href="https://github.com/openclaw/openclaw/issues/66906">#66906</a>. Thanks @rlerikse.</li>
<li>Telegram: send a fresh final message for long-lived preview-streamed replies so the visible Telegram timestamp reflects completion time instead of the preview creation time. Thanks @rubencu.</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-41322 | withastro up to 10.0.4 _astro web browser cache containing sensitive information (GHSA-c57f-mm3j-27q9 / EUVD-2026-25580)]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in withastro astro up to 10.0.4. Affected by this issue is the function _astro. This manipulation causes use of web browser cache containing sensitive information.

This vulnerability appears as CVE-2026-41322. The attack may be initiated re...]]></description>
<link>https://tsecurity.de/de/3463665/sicherheitsluecken/cve-2026-41322-withastro-up-to-1004-astro-web-browser-cache-containing-sensitive-information-ghsa-c57f-mm3j-27q9-euvd-2026-25580/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3463665/sicherheitsluecken/cve-2026-41322-withastro-up-to-1004-astro-web-browser-cache-containing-sensitive-information-ghsa-c57f-mm3j-27q9-euvd-2026-25580/</guid>
<pubDate>Sat, 25 Apr 2026 10:50:37 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">problematic</a> has been reported in <a href="https://vuldb.com/product/withastro:astro">withastro astro up to 10.0.4</a>. Affected by this issue is the function <code>_astro</code>. This manipulation causes use of web browser cache containing sensitive information.

This vulnerability appears as <a href="https://vuldb.com/cve/CVE-2026-41322">CVE-2026-41322</a>. The attack may be initiated remotely. There is no available exploit.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Palo Alto Networks and Google Cloud]]></title>
<description><![CDATA[Palo Alto Networks and Google Cloud Secure the AI Enterprise. See 4 new integrations, including Prisma AIRS, announced at Cloud Next ’26. The post Palo Alto Networks and Google Cloud appeared first on Palo Alto Networks Blog. This article has…
Read more →
The post Palo Alto Networks and Google Cl...]]></description>
<link>https://tsecurity.de/de/3455523/it-security-nachrichten/palo-alto-networks-and-google-cloud/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3455523/it-security-nachrichten/palo-alto-networks-and-google-cloud/</guid>
<pubDate>Wed, 22 Apr 2026 18:22:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Palo Alto Networks and Google Cloud Secure the AI Enterprise. See 4 new integrations, including Prisma AIRS, announced at Cloud Next ’26. The post Palo Alto Networks and Google Cloud appeared first on Palo Alto Networks Blog. This article has…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/palo-alto-networks-and-google-cloud/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/palo-alto-networks-and-google-cloud/">Palo Alto Networks and Google Cloud</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Browser statt Firewall: Palo Alto zielt auf KMU]]></title>
<description><![CDATA[Mit Prisma Browser for Business bringt Palo Alto Networks seinen Unternehmensbrowser in den Mittelstand. Nicht mehr Netzwerk oder Endpoint sollen die Arbeit sichern, sondern der Browser selbst.]]></description>
<link>https://tsecurity.de/de/3437800/it-security-nachrichten/browser-statt-firewall-palo-alto-zielt-auf-kmu/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3437800/it-security-nachrichten/browser-statt-firewall-palo-alto-zielt-auf-kmu/</guid>
<pubDate>Thu, 16 Apr 2026 09:39:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Mit Prisma Browser for Business bringt Palo Alto Networks seinen Unternehmensbrowser in den Mittelstand. Nicht mehr Netzwerk oder Endpoint sollen die Arbeit sichern, sondern der Browser selbst.]]></content:encoded>
</item>
<item>
<title><![CDATA[Announcing ADEM Universal Agent]]></title>
<description><![CDATA[The ADEM Universal Agent for Prisma Access unifies network data across branch sites to fuel agentic autonomous operations. Get full-stack visibility. The post Announcing ADEM Universal Agent appeared first on Palo Alto Networks Blog. This article has been indexed from…
Read more →
The post Announ...]]></description>
<link>https://tsecurity.de/de/3423797/it-security-nachrichten/announcing-adem-universal-agent/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3423797/it-security-nachrichten/announcing-adem-universal-agent/</guid>
<pubDate>Fri, 10 Apr 2026 15:37:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The ADEM Universal Agent for Prisma Access unifies network data across branch sites to fuel agentic autonomous operations. Get full-stack visibility. The post Announcing ADEM Universal Agent appeared first on Palo Alto Networks Blog. This article has been indexed from…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/announcing-adem-universal-agent/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/announcing-adem-universal-agent/">Announcing ADEM Universal Agent</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[3sat Wissenschaftsdoku im Stream - Mediatheken - Prisma]]></title>
<description><![CDATA[Obwohl Experten seit Jahrzehnten versuchen, unsere IT-Systeme zu sichern, verursachen Cyberangriffe mittlerweile dreimal mehr Schäden als ...]]></description>
<link>https://tsecurity.de/de/3419546/it-security-nachrichten/3sat-wissenschaftsdoku-im-stream-mediatheken-prisma/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3419546/it-security-nachrichten/3sat-wissenschaftsdoku-im-stream-mediatheken-prisma/</guid>
<pubDate>Thu, 09 Apr 2026 09:36:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Obwohl Experten seit Jahrzehnten versuchen, unsere IT-Systeme zu sichern, verursachen Cyberangriffe mittlerweile dreimal mehr Schäden als ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Palo Alto Networks at Nutanix .NEXT 2026]]></title>
<description><![CDATA[Discover how Palo Alto Networks and Nutanix are Securing the AI-Powered Hybrid Multicloud with zero trust and Prisma AIRS. The post Palo Alto Networks at Nutanix .NEXT 2026 appeared first on Palo Alto Networks Blog. This article has been indexed…
Read more →
The post Palo Alto Networks at Nutanix...]]></description>
<link>https://tsecurity.de/de/3417489/it-security-nachrichten/palo-alto-networks-at-nutanix-next-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3417489/it-security-nachrichten/palo-alto-networks-at-nutanix-next-2026/</guid>
<pubDate>Wed, 08 Apr 2026 15:36:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Discover how Palo Alto Networks and Nutanix are Securing the AI-Powered Hybrid Multicloud with zero trust and Prisma AIRS. The post Palo Alto Networks at Nutanix .NEXT 2026 appeared first on Palo Alto Networks Blog. This article has been indexed…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/palo-alto-networks-at-nutanix-next-2026/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/palo-alto-networks-at-nutanix-next-2026/">Palo Alto Networks at Nutanix .NEXT 2026</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Prisma Browser for Business: Sicherheit im Browser für KMU - IP-Insider]]></title>
<description><![CDATA[Er soll vor Phishing, Malware und betrügerischen Webseiten schützen. Zusätzlich gibt es Funktionen zur Verhinderung von Datenabfluss (Data Loss ...]]></description>
<link>https://tsecurity.de/de/3412896/it-security-nachrichten/prisma-browser-for-business-sicherheit-im-browser-fuer-kmu-ip-insider/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3412896/it-security-nachrichten/prisma-browser-for-business-sicherheit-im-browser-fuer-kmu-ip-insider/</guid>
<pubDate>Tue, 07 Apr 2026 08:06:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Er soll vor Phishing, Malware und betrügerischen Webseiten schützen. Zusätzlich gibt es Funktionen zur Verhinderung von Datenabfluss (<b>Data</b> Loss ...]]></content:encoded>
</item>
<item>
<title><![CDATA[La evolución del sector asegurador español ante la era de la IA: estrategia, gobernanza y el imperativo del riesgo prudencial]]></title>
<description><![CDATA[El sector asegurador —en general, y en España en particular— se encuentra a las puertas de una fase de transformación que va más allá de la mera digitalización para adentrarse en una potencial reconfiguración estructural impulsada por la inteligencia artificial (IA). Este fenómeno, lejos de ser u...]]></description>
<link>https://tsecurity.de/de/3411349/it-nachrichten/la-evolucin-del-sector-asegurador-espaol-ante-la-era-de-la-ia-estrategia-gobernanza-y-el-imperativo-del-riesgo-prudencial/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3411349/it-nachrichten/la-evolucin-del-sector-asegurador-espaol-ante-la-era-de-la-ia-estrategia-gobernanza-y-el-imperativo-del-riesgo-prudencial/</guid>
<pubDate>Mon, 06 Apr 2026 16:32:09 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>El <strong>sector asegurador</strong> —en general, y en España en particular— se encuentra a las puertas de una fase de transformación que va más allá de la mera digitalización para adentrarse en una potencial <strong>reconfiguración estructural impulsada por la inteligencia artificial (IA)</strong>. Este fenómeno, lejos de ser una tendencia coyuntural, apunta a consolidarse progresivamente como uno de los ejes centrales de las estrategias corporativas para los próximos años en el sector, proyectándose como un horizonte de cambio inminente.</p>



<p>Sin embargo, la implantación actual de estas tecnologías se manifiesta todavía con cautela en un sector prudente en el riesgo y fuertemente regulado, con diferencias también según el ramo de actividad. La Autoridad Europea de Seguros y Pensiones de Jubilación (EIOPA) publicó el pasado 2 de febrero un <a href="https://www.eiopa.europa.eu/eiopa-survey-generative-ai-shows-swift-cautious-adoption-among-europes-insurers-2026-02-02_en?prefLang=es" target="_blank" rel="nofollow">informe sobre el uso de la inteligencia artificial generativa (<em>GenAI</em>) en el sector asegurador europeo.</a> El informe, basado en las respuestas de 347 empresas de 25 países, destaca una adopción en rápido aumento de la <em>GenAI </em>entre las aseguradoras europeas, con casi dos tercios que ya han comenzado a usar la tecnología (si bien la mayoría se encuentran todavía en fase de prueba de concepto), lo que indica una implantación prudente y controlada, así como un importante potencial de crecimiento futuro. La mayoría de los casos de uso comunicados (64%) se centran en herramientas de productividad tipo <em>back-end</em> (extracción de datos de facturas, grabaciones de audio o informes médicos, generación de contenido para correos electrónicos, contratos o materiales de marketing, etc.). El uso mayoritario restante corresponde a desarrollo de aplicaciones de IA de última generación orientadas al cliente, como los <em>chatbots</em>. Por ramos, Vida presenta una penetración algo más moderada que en seguros de No Vida, reflejando la cautela inherente a productos con horizontes temporales de larga duración y una carga regulatoria más pesada. Aunque EIOPA no muestra datos específicos del mercado español, parece que aquí el grado de adopción sería algo superior a nuestros vecinos, tal y como muestran otros estudios previos de Minsait. No obstante, estos datos reflejan el uso de IA general (<em>GenAI </em>+ clásica), no específicamente generativa.</p>



<p>En este escenario, para un director de Estrategia y Gobierno de la IA (<em>Chief AI Officer</em> o CAIO) en el entorno asegurador español, se plantea una dualidad compleja: la necesidad de capitalizar las eficiencias disruptivas mientras se navega en un ecosistema de riesgo prudencial donde la transparencia y la explicabilidad no son opciones, sino mandatos regulatorios estrictos. A esta complejidad se suma un factor clave: la inversión necesaria dista mucho de ser trivial. No sólo implica integrar modelos avanzados en infraestructuras heredadas, sino también incorporar talento especializado capaz de gestionar nuevas arquitecturas tecnológicas y perfiles adicionales en ámbitos como la planificación, la regulación o el ‘delivery’ de soluciones.</p>



<h2 class="wp-block-heading">La arquitectura de la disrupción: IA generativa y el auge de los sistemas agente</h2>



<p>La distinción entre la IA tradicional y las nuevas fronteras de la IA generativa y agentiva resulta clave para comprender el cambio de paradigma que podría materializarse en los próximos años. Mientras que la IA convencional se ha venido centrando históricamente en el análisis predictivo y la clasificación de datos estructurados, la IA generativa permite introducir la capacidad de interactuar con grandes volúmenes de datos no estructurados, como contratos, informes periciales o comunicaciones con clientes. No obstante, la verdadera revolución —que ya se vislumbra— es la transición hacia los agentes autónomos. Estos sistemas no sólo generan contenido, sino que poseen la capacidad de descomponer problemas complejos, razonar sobre objetivos y ejecutar flujos de trabajo de manera proactiva con una mínima intervención humana.</p>



<h2 class="wp-block-heading">El impacto real de la IA en la cadena de valor</h2>



<p>La IA generativa y los agentes autónomos van a redefinir cada eslabón de la cadena de valor aseguradora, permitiendo una transición desde modelos reactivos hacia una gestión proactiva del riesgo. En el ámbito de la suscripción y la evaluación de riesgos, la IA va a permitir procesar rápidamente grandes volúmenes de datos externos e internos para tomar decisiones más precisas y personalizadas. Esta capacidad de análisis predictivo es esencial para ofrecer cotizaciones instantáneas y coberturas dinámicas que se ajusten al perfil del cliente en tiempo real.</p>



<h3 class="wp-block-heading">La revolución en la gestión de siniestros y detección de fraude</h3>



<p>Pero, con toda seguridad, es en la gestión de siniestros donde el beneficio económico directo va a ser más evidente. La integración de IA permitirá una automatización que reduce drásticamente los tiempos de respuesta. Según un estudio de Shift Technology (empresa puntera del sector ‘InsurTech’), casos de uso avanzados demuestran que la IA puede alcanzar una precisión del 95% en la automatización de siniestros de baja complejidad. Mediante el uso de agentes autónomos, el tiempo de tramitación de un siniestro puede reducirse de semanas a horas, mejorando la satisfacción del cliente de manera exponencial.</p>



<p>La detección del fraude es otro pilar crítico. Según el mismo estudio, los sistemas de IA ya analizan patrones y anomalías en los datos para identificar situaciones sospechosas con una precisión documentada del 93%. En el contexto español, donde el fraude supone una carga significativa para la mutualidad de asegurados, el uso de <em>GenAI </em>(combinada con otros modelos de aprendizaje no supervisado) para analizar inconsistencias entre documentos y detalles de la pérdida puede convertirse en una herramienta fundamental para proteger la rentabilidad de las carteras.</p>



<h3 class="wp-block-heading">Atención al cliente e “hiperpersonalización” de pólizas</h3>



<p>Por otro lado, y en línea con el estudio de EIOPA, uno de los ámbitos donde ya se observa una mayor madurez y grado de adopción es en la utilización de <em>chatbots </em>inteligentes y asistentes virtuales potenciados por IA (incluyendo modelos de lenguaje naturales, principalmente generativos), para atender consultas de clientes de forma inmediata. Además, mediante análisis de datos de clientes, la IA ayuda a identificar preferencias y ofrecer productos o coberturas personalizadas a cada perfil. Esto se traduce en respuestas más rápidas y pólizas más ajustadas a las necesidades de cada cliente, incrementando la satisfacción y fidelización de los asegurados.</p>



<h2 class="wp-block-heading">El marco regulatorio: AI Act, DORA y Solvencia II</h2>



<p>La innovación con IA en el seguro español navega en un mar de normativas cada vez más denso. El Reglamento de IA de la Unión Europea (<a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R1689" target="_blank" rel="nofollow">AI Act</a>), de implantación secuencial desde agosto de 2024, establece una clasificación de riesgos que impacta directamente en las operaciones aseguradoras. El primer hito, ya cumplido, fue descartar los Sistemas de “Riesgo Prohibido” (febrero de 2025). Sin embargo, el uso de la IA para la evaluación de riesgos y la fijación de precios en seguros de vida y salud ha sido recogido en el Anexo III del AI ACT dentro de la categoría de “Servicios Esenciales” y por tanto etiquetado como de “Alto Riesgo”, entendiendo que dicha finalidad puede tener impacto en los derechos fundamentales de las personas físicas. Estos Sistemas conllevan obligaciones estrictas en materia de gobernanza de datos, documentación técnica y supervisión humana, entre otras. Y para añadir más complejidad —si cabe—, la definición de “Sistema IA” que hace el Reglamento puede alcanzar a modelos tradicionales, tales como el cálculo actuarial o los modelos lineales generalizados (GLM), que llevan siendo utilizados durante más de 70 años en el sector. Es imperativo resolver esta ambigüedad regulatoria, ya que puede suponer un notable freno a la innovación y generar una duplicidad de cargas sobre procesos ‘core’ del sector, más que consolidados y auditados.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/04/image_ff2d2f.png" alt="" class="wp-image-4154498" srcset="https://b2b-contenthub.com/wp-content/uploads/2026/04/image_ff2d2f.png?quality=50&amp;strip=all 602w, https://b2b-contenthub.com/wp-content/uploads/2026/04/image_ff2d2f.png?resize=300%2C158&amp;quality=50&amp;strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2026/04/image_ff2d2f.png?resize=150%2C79&amp;quality=50&amp;strip=all 150w, https://b2b-contenthub.com/wp-content/uploads/2026/04/image_ff2d2f.png?resize=444%2C235&amp;quality=50&amp;strip=all 444w" width="602" height="318" sizes="auto, (max-width: 602px) 100vw, 602px"></figure></div>



<p>A este marco se suma el Reglamento de Resiliencia Operativa Digital (<a href="https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32022R2554&amp;from=FR" target="_blank" rel="nofollow">DORA</a>), que obliga a las entidades financieras, incluidas las aseguradoras, a garantizar que sus infraestructuras digitales —incluidas aquellas que soportan IA— sean resistentes ante incidentes y ciberamenazas. La interdependencia entre la IA y la ciberseguridad es bidireccional: mientras la IA mejora la capacidad de detección de amenazas, también se convierte en un vector de ataque que requiere protecciones específicas y una monitorización constante de las vulnerabilidades.</p>



<h3 class="wp-block-heading">Enfoque de riesgo prudencial y el desafío de la “caja negra”</h3>



<p>A pesar de los beneficios evidentes, la adopción de la IA en el sector asegurador español se rige por un principio de prudencia extrema. El paraguas de Solvencia II, bajo la supervisión de la Dirección General de Seguros y Fondos de Pensiones (DGSFP), exige que cualquier innovación sea compatible con la estabilidad financiera y la protección del consumidor. El concepto de “riesgo prudencial” adquiere aquí una relevancia máxima: las aseguradoras deben mantener un perfil de riesgo conservador y asegurar que el uso de tecnologías emergentes no comprometa su adecuación de capital ni su liquidez.</p>



<p>En este sentido, otro de los grandes desafíos que conlleva la aplicación de la IA en el ámbito asegurador es el carácter de “caja negra” de muchos modelos avanzados, especialmente los basados en aprendizaje profundo (<em>deep learning</em>) e IA generativa. En un sector donde las decisiones sobre primas, coberturas y denegaciones de siniestros deben ser justificables ante cliente y regulador, la opacidad algorítmica es inasumible. EIOPA ha enfatizado que la transparencia y la explicabilidad son principios innegociables para una IA fiable. Estos aspectos son, además, un requerimiento regulatorio por parte del AI Act en los Sistemas de Alto Riesgo.</p>



<h2 class="wp-block-heading">Gobernanza de datos: el cimiento de una IA responsable</h2>



<p>Para que la IA despliegue su potencial bajo un prisma prudencial, la gobernanza de datos se convierte en la prioridad número uno. EIOPA ha establecido principios claros: los datos utilizados para entrenar modelos de IA deben ser completos, representativos y estar libres de sesgos discriminatorios. En el contexto de la Directiva de Distribución de Seguros (IDD), las aseguradoras españolas tienen la obligación de actuar con honestidad y profesionalidad, lo que implica que el uso de la IA debe priorizar el interés del cliente y evitar cualquier forma de exclusión financiera injustificada.</p>



<p>El CAIO debe liderar la implementación de políticas de gobernanza de datos que aseguren que la información sea “apropiada” para su propósito. Esto incluye no solo la calidad técnica del dato, sino también su dimensión ética. La trazabilidad de los datos, desde su origen hasta su procesamiento por el algoritmo, es un requisito esencial para cumplir con las expectativas de supervisión de la DGSFP y para garantizar la soberanía del conocimiento dentro de la organización.</p>



<h2 class="wp-block-heading">Tendencias emergentes: computación cuántica e IoT</h2>



<p>Mirando hacia un futuro un paso más allá, hay que considerar el potencial que va a aportar a la IA otras tecnologías disruptivas. La computación cuántica se perfila como un acelerador masivo de los algoritmos de aprendizaje automático, permitiendo el procesamiento de conjuntos de datos masivos de manera mucho más eficiente para la tarificación de riesgos complejos. Aunque todavía en fase de investigación, se espera que en un horizonte de unos cinco años la computación cuántica empiece a utilizarse en servicios habituales de gestión de riesgos catastróficos y optimización de carteras.</p>



<p>Por otro lado, la integración de la IA con el Internet de las Cosas (IoT) —en hogares conectados, vehículos telemáticos, dispositivos de salud… y siempre respetando los derechos fundamentales de las personas físicas, según establece el AI Act—, permitirá a las aseguradoras pasar de ser pagadores de siniestros a ser gestores de prevención. Los agentes autónomos podrán interactuar con estos datos en tiempo real para sugerir cambios de comportamiento que reduzcan la probabilidad de un siniestro, alineando los intereses de la aseguradora con la seguridad y bienestar del cliente.</p>



<h2 class="wp-block-heading">Conclusiones: la ruta hacia un seguro más inteligente y prudente</h2>



<p>La transformación del sector asegurador español —y global— mediante la IA es un proceso de cambio estructural, una evolución significativa que ha de recorrerse para aprovechar el pleno potencial de las nuevas tecnologías, marcado por la necesidad de eficiencia y la exigencia de responsabilidad. El impacto real, aún incipiente, ya comienza a vislumbrarse en la reducción de tiempos de tramitación, la precisión en la detección del fraude y una personalización del servicio sin precedentes. Sin embargo, el éxito sostenible de esta transición dependerá de la capacidad de las entidades para integrar la innovación dentro de un marco de riesgo prudencial sólido.</p>



<p>Para el CAIO, los imperativos son claros:</p>



<ul class="wp-block-list">
<li><strong>Priorizar la gobernanza:</strong> la IA es tan buena como los datos que la alimentan y la estructura que la supervisa. Establecer roles y responsabilidades claros entre las funciones de tecnología, riesgos, cumplimiento y protección de datos es esencial.</li>



<li><strong>Fomentar la transparencia:</strong> ante el riesgo de “caja negra”, las aseguradoras deben invertir en tecnologías de explicabilidad y mantener siempre una supervisión humana efectiva en las decisiones de alto impacto.</li>



<li><strong>Gestionar la escala:</strong> pasar de la experimentación a la orquestación masiva de agentes autónomos requiere una infraestructura resiliente y alineada con normativas como DORA.</li>



<li><strong>Preservar el conocimiento:</strong> la soberanía tecnológica será el factor diferencial de las aseguradoras líderes, preservando que el corazón de la inteligencia de negocio permanezca como un activo estratégico propio.</li>
</ul>



<p>En última instancia, la IA no sustituye la prudencia del asegurador, sino que la potencia. Al dotar a las entidades de herramientas para comprender mejor el riesgo y servir con mayor agilidad al cliente, la tecnología refuerza la misión fundamental del sector: actuar como la red de seguridad de la sociedad en un entorno cada vez más complejo y digital. Sólo si la innovación audaz y la prudencia regulatoria coexisten y se retroalimentan se podrá crear valor real y duradero.</p>



&gt;<figure class="wp-block-media-text__media"><img decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/04/image.jpeg?quality=50&amp;strip=all" alt="Jesús Gil Jaime, responsable de Riesgos de la Oficina Corporativa de Estrategia en Inteligencia Artificial de Ibercaja." class="wp-image-4154497 size-full" loading="lazy" width="400px"></figure><div class="wp-block-media-text__content">
<p><a href="https://www.linkedin.com/in/jes%C3%BAs-gil-jaime-a10ba9286/" target="_blank" rel="nofollow">Jesús Gil Jaime</a> es responsable de Riesgos de la Oficina Corporativa de Estrategia en Inteligencia Artificial de Ibercaja. Formado en Estadística, Matemáticas, <em>Big Data</em> e IA, actualmente es doctorando por la Universidad de Zaragoza en Métodos de Inteligencia Artificial aplicados al análisis y predicción de Series Temporales en Economía.</p>
</div></div>



<p></p>
</div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[astrojs/vercel < = 10.0.0 - Unauthenticated x-astro-path Header Path Override]]></title>
<description><![CDATA[Topic: astrojs/vercel < = 10.0.0 - Unauthenticated x-astro-path Header Path Override Risk: Medium Text:#!/usr/bin/env python3  # Exploit Title:        @astrojs/vercel < = 10.0.0 - Unauthenticated x-astro-path Header Path Override  ...]]></description>
<link>https://tsecurity.de/de/3406393/sicherheitsluecken/astrojsvercel-1000-unauthenticated-x-astro-path-header-path-override/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3406393/sicherheitsluecken/astrojsvercel-1000-unauthenticated-x-astro-path-header-path-override/</guid>
<pubDate>Fri, 03 Apr 2026 22:37:37 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: astrojs/vercel &lt; = 10.0.0 - Unauthenticated x-astro-path Header Path Override Risk: Medium Text:#!/usr/bin/env python3  # Exploit Title:        @astrojs/vercel &lt; = 10.0.0 - Unauthenticated x-astro-path Header Path Override  ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloudflare’s new CMS is not a WordPress killer, it’s a WordPress alternative]]></title>
<description><![CDATA[Cloudflare on Wednesday rolled out EmDash, which it described as “the spiritual successor to WordPress.” The security vendor positioned EmDash as a far more secure site building tool that avoids the extensive cybersecurity problems with WordPress plugins. 



But the Cloudflare claims go far beyo...]]></description>
<link>https://tsecurity.de/de/3404289/it-security-nachrichten/cloudflares-new-cms-is-not-a-wordpress-killer-its-a-wordpress-alternative/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3404289/it-security-nachrichten/cloudflares-new-cms-is-not-a-wordpress-killer-its-a-wordpress-alternative/</guid>
<pubDate>Fri, 03 Apr 2026 03:21:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Cloudflare on Wednesday rolled out EmDash, which it described as “the spiritual successor to WordPress.” The security vendor positioned EmDash as a far more secure site building tool that avoids the <a href="https://www.csoonline.com/article/3497490/critical-plugin-flaw-opens-over-a-million-wordpress-sites-to-rce-attacks.html" target="_blank">extensive cybersecurity problems with WordPress plugins</a>. </p>



<p>But the Cloudflare claims go far beyond cybersecurity issues. The vendor is arguing that the very nature of websites in 2026 is sharply different to the kind of website that WordPress was designed to handle. </p>



<p>“WordPress powers over 40% of the internet. It is a massive success that has enabled anyone to be a publisher, and created a global community of WordPress developers. But the WordPress open source project will be 24 years old this year,” the <a href="https://blog.cloudflare.com/emdash-wordpress/" target="_blank" rel="noreferrer noopener">Cloudflare announcement</a> said. “Hosting a website has changed dramatically during that time. When WordPress was born, AWS EC2 didn’t exist. In the intervening years, that task has gone from renting virtual private servers, to uploading a JavaScript bundle to a globally distributed network at virtually no cost. It’s time to upgrade the most popular CMS on the internet to take advantage of this change.”</p>



<h2 class="wp-block-heading">More flexible licensing</h2>



<p>Cloudflare’s statement also suggested that it is delivering open source in a way that is potentially more open and flexible than the WordPress approach. </p>



<p>“EmDash is fully open source, MIT licensed, and available on GitHub. While EmDash aims to be compatible with WordPress functionality, no WordPress code was used to create EmDash. That allows us to license the open source project under the more permissive MIT license. We hope that allows more developers to adapt, extend, and participate in EmDash’s development,” the company said. “EmDash is committed to building on what WordPress created: an open source publishing stack that anyone can install and use at little cost, while fixing the core problems that WordPress cannot solve.”</p>



<h2 class="wp-block-heading">The next wave of web development</h2>



<p>In an interview with Computerworld, Cloudflare senior product manager <a href="https://www.linkedin.com/in/mattietk/" target="_blank" rel="noreferrer noopener">Matt Taylor</a> said his team sees the project as the next wave of web development platforms.</p>



<p>“There is a whole new generation of developers, and WordPress is old news to them. If you are starting today, there is no way you are picking WordPress,” Taylor said, adding that AI agents are also not going to opt for WordPress platforms when creating new sites. </p>



<p>Even when adding Cloudflare in front of a WordPress site to enhance security, he noted, “you have to hack the system to work with the modern internet.”</p>



<p>WordPress was unable to provide its feedback on the announcement by deadline.</p>



<h2 class="wp-block-heading">WordPress not for new users</h2>



<p><a href="https://moorinsightsstrategy.com/team/melody-brue/" target="_blank" rel="noreferrer noopener">Melody Brue</a>, principal analyst for Moor Insights &amp; Strategy, said she has not seen many developers who are not already experienced with WordPress choosing it to build sites, and that she is also seeing that AI agents never opt for WordPress unless they were given explicit instructions to do so. Given how rampant autonomous AI agents are today, the ability to be more hospitable to agentic systems may prove a massive advantage.</p>



<p>“For somebody new, you have this opportunity to skip all of these legacy CMS assumptions and have true least privilege by design, a first class experience for agents. At least, that is what [Cloudflare] is trying to deliver,” Brue said. “They are baking in agent skills.”</p>



<h2 class="wp-block-heading">Enterprise concerns</h2>



<p>When it comes to enterprise web development strategies, however, things get a little more complex, Brue said. Given how deeply they are already invested in WordPress code and plugins and the support environment, existing WordPress enterprise users are not likely to easily move. </p>



<p>But the <a href="https://www.cio.com/article/3545272/things-get-nasty-in-lawsuit-between-wordpress-org-and-wp-engine.html" target="_blank">extensive legal outbursts</a> from <a href="https://www.cio.com/article/3596491/as-the-wordpress-saga-continues-cios-need-to-figure-out-what-it-might-mean-for-all-open-source.html" target="_blank">last year</a> involving Automattic CEO Matt Mullenweg, and the lawsuit with WP Engine, made some enterprise IT executives nervous, once they realized how much control one person had over WordPress platforms.</p>



<p>Brue said, “I can understand the concerns,” but added that the WordPress squabbles seem to have become more subdued lately: “There is now less of the tantrum throwing happening.”</p>



<p><a href="https://www.infotech.com/profiles/thomas-randall" target="_blank" rel="noreferrer noopener">Thomas Randall</a>, a research director at Info-Tech Research Group, agreed with Brue that enterprise environments are unlikely to abandon WordPress any time soon.</p>



<p>“Is EmDash the spiritual successor to WordPress? Not from what Cloudflare has shown so far. The problem Cloudflare highlights, security vulnerabilities in WordPress plugins, is real. But the rest of the announcement deserves skepticism,” Randall said. “For instance, enterprise IT teams with complex WordPress environments will encounter nontrivial barriers for migration. EmDash uses Portable Text rather than WordPress’s HTML content model, which would significantly complicate automated migration. Existing PHP themes and plugins would not carry over directly and would likely require substantial redevelopment.”</p>



<p>But that would still open the door to newcomers who have not already invested in the WordPress environment.</p>



<h2 class="wp-block-heading">Competing in a different layer</h2>



<p><a href="https://www.linkedin.com/in/noah-m-kenney-27499a166/" target="_blank" rel="noreferrer noopener">Noah Kenney</a>, principal consultant for Digital 520, said the future is likely to look much more inviting for an EmDash-like approach than for legacy WordPress.</p>



<p>“Cloudflare’s EmDash is less about replacing WordPress outright and more about setting a new security baseline, which is that CMS platforms should have isolated execution environments, least-privilege access, and verifiable permission models,” Kenney said. “That has implications for both content management and how enterprises evaluate third-party extensibility risk more broadly.”</p>



<p>However, he noted, “viability is an ecosystem question just as much as it is a technical one. EmDash, even if superior from an architectural perspective, is effectively starting from zero. Enterprise adoption will depend heavily on migration tooling, developer adoption, and whether Cloudflare can build a credible plugin and integration ecosystem.”</p>



<p>Kenney added that he sees EmDash as “very likely to influence the next phase of CMS architecture, particularly in security-sensitive and enterprise environments where plugin risk is already a prevalent issue.”</p>



<p><a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research, saw the EmDash move in a much broader context, potentially signaling the near-term future of website strategies. </p>



<p>“EmDash is competing in a different layer altogether,” Gogia said. “It sits closer to composable and headless CMS platforms like Contentful and Strapi, and even closer to developer frameworks like Astro. It is collapsing what used to be separate concerns; content management, execution runtime, and security enforcement are being fused into one programmable environment.”</p>



<p>This, he observed, “is where the real friction emerges. Traditional CMS buyers are not necessarily developers first. They prioritize usability, ecosystem depth, and speed of execution for business teams. EmDash is clearly optimized for developers and architects. So the competition is not just product versus product. It is operating model versus operating model. And in that contest, incumbents have inertia on their side, while EmDash has architectural purity. History shows those two rarely move at the same speed.”</p>



<p><em>This article originally appeared on <a href="https://www.computerworld.com/article/4154105/cloudflares-new-cms-is-not-a-wordpress-killer-its-a-wordpress-alternative.html" target="_blank">Computerworld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloudflare’s new CMS is not a WordPress killer, it’s a WordPress alternative]]></title>
<description><![CDATA[Cloudflare on Wednesday rolled out EmDash, which it described as “the spiritual successor to WordPress.” The security vendor positioned EmDash as a far more secure site building tool that avoids the extensive cybersecurity problems with WordPress plugins. 



But the Cloudflare claims go far beyo...]]></description>
<link>https://tsecurity.de/de/3404286/it-nachrichten/cloudflares-new-cms-is-not-a-wordpress-killer-its-a-wordpress-alternative/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3404286/it-nachrichten/cloudflares-new-cms-is-not-a-wordpress-killer-its-a-wordpress-alternative/</guid>
<pubDate>Fri, 03 Apr 2026 03:16:36 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Cloudflare on Wednesday rolled out EmDash, which it described as “the spiritual successor to WordPress.” The security vendor positioned EmDash as a far more secure site building tool that avoids the <a href="https://www.csoonline.com/article/3497490/critical-plugin-flaw-opens-over-a-million-wordpress-sites-to-rce-attacks.html" target="_blank">extensive cybersecurity problems with WordPress plugins</a>. </p>



<p>But the Cloudflare claims go far beyond cybersecurity issues. The vendor is arguing that the very nature of websites in 2026 is sharply different to the kind of website that WordPress was designed to handle. </p>



<p>“WordPress powers over 40% of the internet. It is a massive success that has enabled anyone to be a publisher, and created a global community of WordPress developers. But the WordPress open source project will be 24 years old this year,” the <a href="https://blog.cloudflare.com/emdash-wordpress/" target="_blank" rel="noreferrer noopener">Cloudflare announcement</a> said. “Hosting a website has changed dramatically during that time. When WordPress was born, AWS EC2 didn’t exist. In the intervening years, that task has gone from renting virtual private servers, to uploading a JavaScript bundle to a globally distributed network at virtually no cost. It’s time to upgrade the most popular CMS on the internet to take advantage of this change.”</p>



<h2 class="wp-block-heading">More flexible licensing</h2>



<p>Cloudflare’s statement also suggested that it is delivering open source in a way that is potentially more open and flexible than the WordPress approach. </p>



<p>“EmDash is fully open source, MIT licensed, and available on GitHub. While EmDash aims to be compatible with WordPress functionality, no WordPress code was used to create EmDash. That allows us to license the open source project under the more permissive MIT license. We hope that allows more developers to adapt, extend, and participate in EmDash’s development,” the company said. “EmDash is committed to building on what WordPress created: an open source publishing stack that anyone can install and use at little cost, while fixing the core problems that WordPress cannot solve.”</p>



<h2 class="wp-block-heading">The next wave of web development</h2>



<p>In an interview with Computerworld, Cloudflare senior product manager <a href="https://www.linkedin.com/in/mattietk/" target="_blank" rel="noreferrer noopener">Matt Taylor</a> said his team sees the project as the next wave of web development platforms.</p>



<p>“There is a whole new generation of developers, and WordPress is old news to them. If you are starting today, there is no way you are picking WordPress,” Taylor said, adding that AI agents are also not going to opt for WordPress platforms when creating new sites. </p>



<p>Even when adding Cloudflare in front of a WordPress site to enhance security, he noted, “you have to hack the system to work with the modern internet.”</p>



<p>WordPress was unable to provide its feedback on the announcement by deadline.</p>



<h2 class="wp-block-heading">WordPress not for new users</h2>



<p><a href="https://moorinsightsstrategy.com/team/melody-brue/" target="_blank" rel="noreferrer noopener">Melody Brue</a>, principal analyst for Moor Insights &amp; Strategy, said she has not seen many developers who are not already experienced with WordPress choosing it to build sites, and that she is also seeing that AI agents never opt for WordPress unless they were given explicit instructions to do so. Given how rampant autonomous AI agents are today, the ability to be more hospitable to agentic systems may prove a massive advantage.</p>



<p>“For somebody new, you have this opportunity to skip all of these legacy CMS assumptions and have true least privilege by design, a first class experience for agents. At least, that is what [Cloudflare] is trying to deliver,” Brue said. “They are baking in agent skills.”</p>



<h2 class="wp-block-heading">Enterprise concerns</h2>



<p>When it comes to enterprise web development strategies, however, things get a little more complex, Brue said. Given how deeply they are already invested in WordPress code and plugins and the support environment, existing WordPress enterprise users are not likely to easily move. </p>



<p>But the <a href="https://www.cio.com/article/3545272/things-get-nasty-in-lawsuit-between-wordpress-org-and-wp-engine.html" target="_blank">extensive legal outbursts</a> from <a href="https://www.cio.com/article/3596491/as-the-wordpress-saga-continues-cios-need-to-figure-out-what-it-might-mean-for-all-open-source.html" target="_blank">last year</a> involving Automattic CEO Matt Mullenweg, and the lawsuit with WP Engine, made some enterprise IT executives nervous, once they realized how much control one person had over WordPress platforms.</p>



<p>Brue said, “I can understand the concerns,” but added that the WordPress squabbles seem to have become more subdued lately: “There is now less of the tantrum throwing happening.”</p>



<p><a href="https://www.infotech.com/profiles/thomas-randall" target="_blank" rel="noreferrer noopener">Thomas Randall</a>, a research director at Info-Tech Research Group, agreed with Brue that enterprise environments are unlikely to abandon WordPress any time soon.</p>



<p>“Is EmDash the spiritual successor to WordPress? Not from what Cloudflare has shown so far. The problem Cloudflare highlights, security vulnerabilities in WordPress plugins, is real. But the rest of the announcement deserves skepticism,” Randall said. “For instance, enterprise IT teams with complex WordPress environments will encounter nontrivial barriers for migration. EmDash uses Portable Text rather than WordPress’s HTML content model, which would significantly complicate automated migration. Existing PHP themes and plugins would not carry over directly and would likely require substantial redevelopment.”</p>



<p>But that would still open the door to newcomers who have not already invested in the WordPress environment.</p>



<h2 class="wp-block-heading">Competing in a different layer</h2>



<p><a href="https://www.linkedin.com/in/noah-m-kenney-27499a166/" target="_blank" rel="noreferrer noopener">Noah Kenney</a>, principal consultant for Digital 520, said the future is likely to look much more inviting for an EmDash-like approach than for legacy WordPress.</p>



<p>“Cloudflare’s EmDash is less about replacing WordPress outright and more about setting a new security baseline, which is that CMS platforms should have isolated execution environments, least-privilege access, and verifiable permission models,” Kenney said. “That has implications for both content management and how enterprises evaluate third-party extensibility risk more broadly.”</p>



<p>However, he noted, “viability is an ecosystem question just as much as it is a technical one. EmDash, even if superior from an architectural perspective, is effectively starting from zero. Enterprise adoption will depend heavily on migration tooling, developer adoption, and whether Cloudflare can build a credible plugin and integration ecosystem.”</p>



<p>Kenney added that he sees EmDash as “very likely to influence the next phase of CMS architecture, particularly in security-sensitive and enterprise environments where plugin risk is already a prevalent issue.”</p>



<p><a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research, saw the EmDash move in a much broader context, potentially signaling the near-term future of website strategies. </p>



<p>“EmDash is competing in a different layer altogether,” Gogia said. “It sits closer to composable and headless CMS platforms like Contentful and Strapi, and even closer to developer frameworks like Astro. It is collapsing what used to be separate concerns; content management, execution runtime, and security enforcement are being fused into one programmable environment.”</p>



<p>This, he observed, “is where the real friction emerges. Traditional CMS buyers are not necessarily developers first. They prioritize usability, ecosystem depth, and speed of execution for business teams. EmDash is clearly optimized for developers and architects. So the competition is not just product versus product. It is operating model versus operating model. And in that contest, incumbents have inertia on their side, while EmDash has architectural purity. History shows those two rarely move at the same speed.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Open-Source-CMS von Cloudflare: EmDash fordert WordPress heraus]]></title>
<description><![CDATA[EmDash ist ein neues Content-Management-System mit TypeScript- und Astro-Basis. Plug-ins sollen dort sicher innerhalb einer Sandbox laufen.]]></description>
<link>https://tsecurity.de/de/3402902/it-nachrichten/open-source-cms-von-cloudflare-emdash-fordert-wordpress-heraus/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3402902/it-nachrichten/open-source-cms-von-cloudflare-emdash-fordert-wordpress-heraus/</guid>
<pubDate>Thu, 02 Apr 2026 16:01:55 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[EmDash ist ein neues Content-Management-System mit TypeScript- und Astro-Basis. Plug-ins sollen dort sicher innerhalb einer Sandbox laufen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Tools, um MCP-Server abzusichern]]></title>
<description><![CDATA[srcset="https://b2b-contenthub.com/wp-content/uploads/2025/11/Gorodenkoff_shutterstock_2324952347_16z9.jpg?quality=50&strip=all 7200w, https://b2b-contenthub.com/wp-content/uploads/2025/11/Gorodenkoff_shutterstock_2324952347_16z9.jpg?resize=300%2C168&quality=50&strip=all 300w, https://b2b-content...]]></description>
<link>https://tsecurity.de/de/3401344/it-security-nachrichten/tools-um-mcp-server-abzusichern/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3401344/it-security-nachrichten/tools-um-mcp-server-abzusichern/</guid>
<pubDate>Thu, 02 Apr 2026 06:06:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> srcset="https://b2b-contenthub.com/wp-content/uploads/2025/11/Gorodenkoff_shutterstock_2324952347_16z9.jpg?quality=50&amp;strip=all 7200w, https://b2b-contenthub.com/wp-content/uploads/2025/11/Gorodenkoff_shutterstock_2324952347_16z9.jpg?resize=300%2C168&amp;quality=50&amp;strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2025/11/Gorodenkoff_shutterstock_2324952347_16z9.jpg?resize=768%2C432&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2025/11/Gorodenkoff_shutterstock_2324952347_16z9.jpg?resize=1024%2C576&amp;quality=50&amp;strip=all 1024w, https://b2b-contenthub.com/wp-content/uploads/2025/11/Gorodenkoff_shutterstock_2324952347_16z9.jpg?resize=1536%2C864&amp;quality=50&amp;strip=all 1536w, https://b2b-contenthub.com/wp-content/uploads/2025/11/Gorodenkoff_shutterstock_2324952347_16z9.jpg?resize=2048%2C1152&amp;quality=50&amp;strip=all 2048w, https://b2b-contenthub.com/wp-content/uploads/2025/11/Gorodenkoff_shutterstock_2324952347_16z9.jpg?resize=1240%2C697&amp;quality=50&amp;strip=all 1240w, https://b2b-contenthub.com/wp-content/uploads/2025/11/Gorodenkoff_shutterstock_2324952347_16z9.jpg?resize=150%2C84&amp;quality=50&amp;strip=all 150w, https://b2b-contenthub.com/wp-content/uploads/2025/11/Gorodenkoff_shutterstock_2324952347_16z9.jpg?resize=854%2C480&amp;quality=50&amp;strip=all 854w, https://b2b-contenthub.com/wp-content/uploads/2025/11/Gorodenkoff_shutterstock_2324952347_16z9.jpg?resize=640%2C360&amp;quality=50&amp;strip=all 640w, https://b2b-contenthub.com/wp-content/uploads/2025/11/Gorodenkoff_shutterstock_2324952347_16z9.jpg?resize=444%2C250&amp;quality=50&amp;strip=all 444w" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption">Unabhängig davon, welche MCP-Server Unternehmen wofür einsetzen – “Unsicherheiten” sollten dabei außenvorbleiben.</figcaption></figure><p class="imageCredit">Gorodenkoff | shutterstock.com</p></div>



<p>Model Context Protocol (<a href="https://www.computerwoche.de/article/4031227/was-ist-model-context-protocol.html" target="_blank">MCP</a>) verbindet KI-Agenten mit Datenquellen und erfreut sich im Unternehmensumfeld wachsender Beliebtheit. Allerdings ist auch MCP <a href="https://www.csoonline.com/article/4032065/wie-model-context-protocol-gehackt-wird.html" target="_blank">nicht frei von Sicherheitslücken</a>, wie entsprechende Entdeckungen, etwa beim SaaS-Anbieter <a href="https://www.upguard.com/blog/asana-discloses-data-exposure-bug-in-mcp-server" target="_blank" rel="noreferrer noopener">Asana</a> oder dem IT-Riesen <a href="https://www.catonetworks.com/blog/cato-ctrl-poc-attack-targeting-atlassians-mcp/" target="_blank" rel="noreferrer noopener">Atlassian</a> gezeigt haben. Inzwischen hat sich jedoch einiges in Sachen MCP-Sicherheit getan. Einerseits wurden mit Blick auf das Kernprotokoll etliche Fortschritte erzielt. Beispielsweise in Form von Support für OAuth sowie für Authentifizierungs-Server von Drittanbietern und Identity-Management-Systeme. Darüber hinaus wurde inzwischen auch eine <a href="https://modelcontextprotocol.info/tools/registry/" target="_blank" rel="noreferrer noopener">offizielle MCP Registry</a> geschaffen, die einen Überblick über sichere, öffentlich verfügbare MCP-Server bietet.</p>



<p>Dennoch bestehen weiterhin Sicherheitslücken, die sich für diverse Cyberschandtaten ausnutzen lassen – <a href="https://www.computerwoche.de/article/4044551/wenn-der-ki-agent-im-fakeshop-kauft.html" target="_blank">Prompt Injection</a>, Tool Poisoning, Token-Diebstahl, Server-übergreifende Attacken oder manipulierte Messages sind nur einige von vielen Beispielen. Mit anderen Worten: Unternehmen, die sich beim <a href="https://www.computerwoche.de/article/4049237/3-tipps-um-agentic-ai-systeme-in-der-cloud-zu-entwickeln.html" target="_blank">Aufbau von Agentic-AI-Systemen</a> einen Wettbewerbsvorteil verschaffen wollen, müssen erhebliche Anstrengungen unternehmen, um zu gewährleisten, dass sensible Daten nicht nach außen dringen. Glücklicherweise gibt es diverse Tools, die dabei Unterstützung versprechen.</p>



<p>In diesem Artikel lesen Sie:</p>



<ul class="wp-block-list">
<li>was Security-Tools für MCP leisten sollten, und</li>



<li>welche Angebote in diesem Bereich interessant sind.</li>
</ul>



<h2 class="wp-block-heading">Das sollten MCP-Sicherheitslösungen können</h2>



<p>Die Gefahr von Datenlecks, Prompt Injections und weiteren Sicherheitsbedrohungen besteht unabhängig davon, ob Unternehmen:</p>



<ul class="wp-block-list">
<li>ihre eigenen KI-Agenten mit MCP-Servern von Drittanbietern,</li>



<li>ihre eigenen MCP-Server mit Drittanbieter-Agenten, oder</li>



<li>ihre eigenen Server mit den eigenen Agenten verbinden.</li>
</ul>



<p>Soll heißen: Unternehmen müssen in jedem Fall Autorisierungen und Berechtigungen überprüfen, detaillierte Zugriffskontrollen implementieren und alles protokollieren. Daraus ergeben sich auch die Anforderungen für MCP-Sicherheitslösungen. Diese sollten bieten:</p>



<ul class="wp-block-list">
<li><strong>MCP-Servererkennung.</strong> Für Mitarbeiter eines Unternehmens ist es einfach, MCP-Server herunterzuladen und zu nutzen. Mit Scan-Services für MCP-Server können Unternehmen sämtliche Instanzen von Schatten-MCP-Servern in ihrer Umgebung finden.</li>



<li><strong>Laufzeitschutz.</strong> KI-Agenten kommunizieren mit MCP-Servern in natürlicher Sprache. MCP-Sicherheits-Tools sollten deshalb in der Lage sein, diese Kommunikation auf Sicherheitsprobleme wie Prompt Injections hin zu überwachen.</li>



<li><strong>Authentifizierungs- und Zugriffskontrollen.</strong> Das MCP-Protokoll unterstützt inzwischen OAuth, aber das ist nur ein erster Schritt. Für zusätzliche Sicherheit empfehlen sich Tools mit integrierten Kontroll-Frameworks für Zero Trust und Least Privilege.</li>



<li><strong>Logging und Observability.</strong> Tools und Plattformen sollten zudem die Möglichkeit bieten, MCP-Protokolle zu sammeln, Sicherheitsteams über Richtlinienverstöße zu informieren, Compliance-Daten zu erfassen oder Protokolle in die bestehende Sicherheitsinfrastruktur einzuspeisen.</li>
</ul>



<h2 class="wp-block-heading">MCP-Security-Angebote</h2>



<p>Im Folgenden haben wir die Anbieter von MCP-Security-Tools in drei Kategorien aufgeteilt. Diese Aufstellung erhebt keinen Anspruch auf Vollständigkeit.</p>



<p><strong>Hyperscaler</strong></p>



<p>Für Unternehmen, die sich vollständig auf eine bestimmte Cloud-Plattform verlassen, bieten die MCP-Tools des jeweiligen <a href="https://www.csoonline.com/article/3492887/aws-google-und-azure-im-vergleich-welcher-hyperscaler-ist-der-sicherste.html" target="_blank">Hyperscalers</a> einen einfachen Einstieg.</p>



<ul class="wp-block-list">
<li><strong>Amazon Web Services (AWS)</strong> hat Mitte 2025 seine eigene agentenbasierte KI-Plattform eingeführt. <a href="https://aws.amazon.com/de/bedrock/agentcore/" target="_blank" rel="noreferrer noopener">Amazon Bedrock AgentCore</a> umfasst ein Gateway, das mehrere Protokolle unterstützt (darunter auch MCP), ein Identity-Management-System sowie Observability.</li>



<li><strong>Microsoft</strong> bietet einen grundlegenden <a href="https://learn.microsoft.com/de-de/azure/developer/azure-mcp-server/overview" target="_blank" rel="noreferrer noopener">Azure-MCP-Server</a> an, inklusive Support für Azure Key Vault. Darüber hinaus unterstützen auch Azure AI Foundry Agent Service und Azure API Management das Model Context Protocol. Zudem bietet Microsoft mit dem <a href="https://learn.microsoft.com/de-de/agent-framework/overview/agent-framework-overview" target="_blank" rel="noreferrer noopener">Agent Framework</a> auch ein Open-Source-Entwicklungskit, das sowohl MCP als auch Agent2Agent unterstützt und beispielsweise Schutz vor Prompt Injections verspricht.</li>



<li><strong>Google Cloud</strong> kündigte Anfang 2025 seine <a href="https://cloud.google.com/blog/products/ai-machine-learning/mcp-toolbox-for-databases-now-supports-model-context-protocol?hl=en" target="_blank" rel="noreferrer noopener">MCP Toolbox für Datenbanken</a> an – inklusive integrierter Authentifizierung und Observability. Außerdem hat der Hyperscaler auch <a href="https://cloud.google.com/blog/products/identity-security/how-to-secure-your-remote-mcp-server-on-google-cloud?hl=en" target="_blank" rel="noreferrer noopener">eine Referenzarchitektur</a> veröffentlicht, um MCP-Server auf seiner Cloud-Plattform abzusichern.</li>
</ul>



<p><strong>Große Plattformanbieter</strong></p>



<ul class="wp-block-list">
<li>Der IT-Dienstleister <strong>Cloudflare</strong> hat mit <a href="https://blog.cloudflare.com/zero-trust-mcp-server-portals/" target="_blank" rel="noreferrer noopener">MCP Server Portals</a> ein Tool veröffentlicht, mit dem Unternehmen MCP-Verbindungen zentralisiert absichern und überwachen können. Die Funktion ist Bestandteil der Cloudflare-One-Plattform.</li>



<li><strong>Palo Alto Networks</strong> hat mit Blick auf MCP-Sicherheit mehrere Eisen im Feuer. Mit <a href="https://www.paloaltonetworks.com/blog/2025/06/securing-ai-agent-innovation-prisma-airs-mcp-server/" target="_blank" rel="noreferrer noopener">Prisma AIRS</a> hat das Unternehmen einen eigenen, intermediären MCP-Server veröffentlicht. Dieser sitzt zwischen den KI-Agenten und dem eigentlichen MCP-Server und erkennt schadhafte Inhalte und Daten. Das Tool <a href="https://www.paloaltonetworks.com/blog/2025/06/cloud-security-model-context-protocol-mcp-security/" target="_blank" rel="noreferrer noopener">MCP Security</a> ist hingegen Bestandteil von Cortex Cloud WAAS und überprüft die MCP-Kommunikation an der Netzwerkgrenze auf bösartige Aktivitäten.</li>



<li><strong>SentinelOne</strong> gewährt mit seiner <a href="https://www.sentinelone.com/blog/avoiding-mcp-mania-how-to-secure-the-next-frontier-of-ai/" target="_blank" rel="noreferrer noopener">Singularity Platform</a> ebenfalls Einblick in die MCP-Interaktionskette und bietet zum Beispiel Warnmeldungen und automatisierte Incident Response für MCP-Server auf lokaler oder Remote-Ebene.</li>



<li>Daneben hat auch <strong>Broadcom</strong> MCP-Sicherheitsfunktionen für VMware Cloud Foundation <a href="https://www.broadcom.com/company/news/product-releases/63401" target="_blank" rel="noreferrer noopener">angekündigt</a>, die künftig mehr Sicherheit für agentenbasierte Workflows gewährleisten sollen.</li>
</ul>



<p><strong>Startups</strong></p>



<ul class="wp-block-list">
<li>Die <a href="https://acuvity.ai/" target="_blank" rel="noreferrer noopener">Plattform</a> von <strong>Acuvity</strong> (seit Februar 2026 Teil von Proofpoint) verspricht, MCP-Server umfassend abzusichern. Dafür sorgt laut dem Anbieter eine Kombination aus Least-Privilege-Execution, unveränderlichen Laufzeiten, kontinuierlichen Schwachstellenscans, Authentifizierung und Bedrohungserkennung.</li>



<li>Das API-Security-Startup <strong>Akto</strong> hat eine <a href="https://www.akto.io/mcp-security" target="_blank" rel="noreferrer noopener">MCP-Security-Plattform</a> im Angebot. Sie umfasst ein Discovery Tool, um MCP-Server in Unternehmensumgebungen zu identifizieren, Security-Testing-Werkzeuge sowie Monitoring- und Threat-Detection-Funktionen.</li>



<li><strong>Invariant Labs</strong> bietet mit <a href="https://github.com/invariantlabs-ai/mcp-scan" target="_blank" rel="noreferrer noopener">MCP-Scan</a> ein quelloffenes Tool, das die statische Analyse und Echtzeitüberwachung von MCP-Servern ermöglicht. Mit <a href="https://invariantlabs.ai/blog/guardrails" target="_blank" rel="noreferrer noopener">Guardrails</a> hat das Startup auch ein kommerzielles Produkt im Angebot. Dabei handelt es sich um einen Proxy. Der zwischen KI-Agenten und MCP-Servern sitzt und vor Security-Risiken schützen soll. Das Tool befähigt Anwender außerdem dazu, Richtlinien aufzusetzen.</li>



<li><strong>Highflame </strong>(vormals Javelin) <a href="https://highflame.com/mcpsecurity" target="_blank" rel="noreferrer noopener">addressiert</a> ebenfalls das Thema MCP-Sicherheit. Etwa mit Funktionen wie MCP-Server auf Risiken zu scannen oder Datenanfragen zu überprüfen.  </li>



<li><strong>Lasso Security</strong> stellt ein Open-Source-<a href="https://github.com/lasso-security/mcp-gateway" target="_blank" rel="noreferrer noopener">MCP-Gateway</a> zur Verfügung, das die Konfiguration und das Lebenszyklusmanagement von MCP-Servern ermöglicht und Messages um sensible Informationen bereinigt.</li>
</ul>



<p>(fm)</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloudflare Announces EmDash As Open-Source 'Spiritual Successor' To WordPress]]></title>
<description><![CDATA[In classic Cloudflare fashion, the CDN provider used April Fool's Day to unveil an actual, "not a joke" product. Today, the company announced EmDash -- an open-source "spiritual successor" to WordPress that aims to solve plugin security. Phoronix reports: With the help of AI coding agents, Cloudf...]]></description>
<link>https://tsecurity.de/de/3400656/it-security-nachrichten/cloudflare-announces-emdash-as-open-source-spiritual-successor-to-wordpress/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3400656/it-security-nachrichten/cloudflare-announces-emdash-as-open-source-spiritual-successor-to-wordpress/</guid>
<pubDate>Wed, 01 Apr 2026 22:22:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[In classic Cloudflare fashion, the CDN provider used April Fool's Day to unveil an actual, "not a joke" product. Today, the company announced EmDash -- an open-source "spiritual successor" to WordPress that aims to solve plugin security. Phoronix reports: With the help of AI coding agents, Cloudflare engineers have been rebuilding the WordPress open-source project "from the ground up." EmDash is written entirely in TypeScript and is a server-less design. Making plug-ins more secure than the WordPress architecture, EmDash plug-ins are sandboxed and run in their own isolate. EmDash builds upon the Astro web framework. EmDash doesn't rely on any WordPress code but is designed to be compatible with WordPress functionality. EmDash is open-source now under the MIT license. The EmDash code is available on GitHub.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Cloudflare+Announces+EmDash+As+Open-Source+'Spiritual+Successor'+To+WordPress%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F04%2F01%2F1935240%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F04%2F01%2F1935240%2Fcloudflare-announces-emdash-as-open-source-spiritual-successor-to-wordpress%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/26/04/01/1935240/cloudflare-announces-emdash-as-open-source-spiritual-successor-to-wordpress?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-4615 | Palo Alto Cloud NGFW/PAN-OS/Prisma Access Management Web Interface cross site scripting (WID-SEC-2025-2237)]]></title>
<description><![CDATA[A vulnerability was found in Palo Alto Cloud NGFW, PAN-OS and Prisma Access. It has been declared as problematic. Affected is an unknown function of the component Management Web Interface. Such manipulation leads to improper neutralization of script in attributes in a web page.

This vulnerabilit...]]></description>
<link>https://tsecurity.de/de/3397879/sicherheitsluecken/cve-2025-4615-palo-alto-cloud-ngfwpan-osprisma-access-management-web-interface-cross-site-scripting-wid-sec-2025-2237/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3397879/sicherheitsluecken/cve-2025-4615-palo-alto-cloud-ngfwpan-osprisma-access-management-web-interface-cross-site-scripting-wid-sec-2025-2237/</guid>
<pubDate>Wed, 01 Apr 2026 04:07:39 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/palo_alto:cloud_ngfw">Palo Alto Cloud NGFW, PAN-OS and Prisma Access</a>. It has been declared as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected is an unknown function of the component <em>Management Web Interface</em>. Such manipulation leads to improper neutralization of script in attributes in a web page.

This vulnerability is listed as <a href="https://vuldb.com/source_cve/327789">CVE-2025-4615</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CrowdStrike, Cisco and Palo Alto Networks all shipped agentic SOC tools at RSAC 2026 — the agent behavioral baseline gap survived all three]]></title>
<description><![CDATA[CrowdStrike CEO George Kurtz highlighted in his RSA Conference 2026 keynote that the fastest recorded adversary breakout time has dropped to 27 seconds. The average is now 29 minutes, down from 48 minutes in 2024. That is how much time defenders have before a threat spreads. Now CrowdStrike senso...]]></description>
<link>https://tsecurity.de/de/3397558/it-nachrichten/crowdstrike-cisco-and-palo-alto-networks-all-shipped-agentic-soc-tools-at-rsac-2026-the-agent-behavioral-baseline-gap-survived-all-three/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3397558/it-nachrichten/crowdstrike-cisco-and-palo-alto-networks-all-shipped-agentic-soc-tools-at-rsac-2026-the-agent-behavioral-baseline-gap-survived-all-three/</guid>
<pubDate>Tue, 31 Mar 2026 23:46:44 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>CrowdStrike CEO George Kurtz highlighted in his <a href="https://www.rsaconference.com/usa">RSA Conference 2026</a> keynote that the <a href="https://www.youtube.com/watch?v=6SYgMYZdkK4">fastest recorded adversary breakout time has dropped</a> to 27 seconds. The average is now 29 minutes, down from 48 minutes in 2024. That is how much time defenders have before a threat spreads. Now <a href="https://www.crowdstrike.com/en-us/press-releases/crowdstrike-establishes-the-endpoint-as-the-epicenter-for-ai-security/">CrowdStrike sensors detect</a> more than 1,800 distinct AI applications running on enterprise endpoints, representing nearly 160 million unique application instances. Every one generates detection events, identity events, and data access logs flowing into SIEM systems architected for human-speed workflows.</p><p>Cisco found that 85% of surveyed enterprise customers <a href="https://blogs.cisco.com/news/reimagining-security-for-the-agentic-workforce">have AI agent pilots underway</a>. Only 5% moved agents into production, according to Cisco President and Chief Product Officer Jeetu Patel in his <a href="https://blogs.cisco.com/news/reimagining-security-for-the-agentic-workforce">RSAC blog post</a>. That 80-point gap exists because security teams cannot answer the basic questions agents force. Which agents are running, what are they authorized to do, and who is accountable when one goes wrong.</p><p>“The number one threat is security complexity. But we’re running towards that direction in AI as well,” Etay Maor, VP of Threat Intelligence at Cato Networks, told VentureBeat at RSAC 2026. Maor has attended the conference for 16 consecutive years. “We’re going with multiple point solutions for AI. And now you’re creating the next wave of security complexity.”</p><h2>Agents look identical to humans in your logs </h2><p>In most default logging configurations, agent-initiated activity looks identical to human-initiated activity in security logs. “It looks indistinguishable if an agent runs Louis’s web browser versus if Louis runs his browser,” Elia Zaitsev, CTO of CrowdStrike, told VentureBeat in an exclusive interview at RSAC 2026. Distinguishing the two requires walking the process tree. “I can actually walk up that process tree and say, this Chrome process was launched by Louis from the desktop. This Chrome process was launched from Louis’s cloud Cowork or ChatGPT application. Thus, it’s agentically controlled.”</p><p>Without that depth of endpoint visibility, a compromised agent executing a sanctioned API call with valid credentials fires zero alerts. The exploit surface is already being tested. During his keynote, Kurtz described ClawHavoc, the first major supply chain attack on an AI agent ecosystem, targeting ClawHub, OpenClaw's public skills registry. Koi Security's February audit found 341 malicious skills out of 2,857; a follow-up analysis by Antiy CERT identified <a href="https://www.antiy.net/p/clawhavoc-analysis-of-large-scale-poisoning-campaign-targeting-the-openclaw-skill-market-for-ai-agents/">1,184 compromised packages historically across the platform</a>. Kurtz noted ClawHub now hosts 13,000 skills in its registry. The infected skills contained backdoors, reverse shells, and credential harvesters; Kurtz said in his keynote that some erased their own memory after installation and could remain latent before activating. "The frontier AI creators will not secure itself," Kurtz said. "The frontier labs are following the same playbook. They're building it. They're not securing it."</p><h2>Two agentic SOC architectures, one shared blind spot</h2><p><b>Approach A: AI agents inside the SIEM.</b> <a href="https://newsroom.cisco.com/c/r/newsroom/en/us/a/y2026/m03/cisco-reimagines-security-for-the-agentic-workforce.html">Cisco and Splunk announced</a> six specialized AI agents for Splunk Enterprise Security: Detection Builder, Triage, Guided Response, Standard Operating Procedures (SOP), Malware Threat Reversing, and Automation Builder. Malware Threat Reversing is currently available in Splunk Attack Analyzer and Detection Studio is generally available as a unified workspace; the remaining five agents are in alpha or prerelease through June 2026. Exposure Analytics and Federated Search follow the same timeline. Upstream of the SOC, Cisco's DefenseClaw framework scans OpenClaw skills and MCP servers before deployment, while new Duo IAM capabilities extend zero trust to agents with verified identities and time-bound permissions.</p><p>“The biggest impediment to scaled adoption in enterprises for business-critical tasks is establishing a sufficient amount of trust,” Patel told VentureBeat. “Delegating and trusted delegating, the difference between those two, one leads to bankruptcy. The other leads to market dominance.”</p><p><b>Approach B: Upstream pipeline detection.</b> CrowdStrike pushed analytics into the data ingestion pipeline itself, <a href="https://www.crowdstrike.com/en-us/press-releases/crowdstrike-unveils-falcon-next-gen-siem-support-for-microsoft-defender-for-endpoint/">integrating its Onum acquisition</a> natively into Falcon’s ingestion system for real-time analytics, detection, and enrichment before events reach the analyst’s queue. Falcon Next-Gen SIEM now ingests Microsoft Defender for Endpoint telemetry natively, so Defender shops do not need additional sensors. CrowdStrike also introduced federated search across third-party data stores and a Query Translation Agent that converts legacy Splunk queries to accelerate SIEM migration.</p><p>Falcon Data Security for the Agentic Enterprise applies cross-domain data loss prevention to data agents' access at runtime. CrowdStrike’s adversary-informed cloud risk prioritization connects agent activity in cloud workloads to the same detection pipeline. Agentic MDR through Falcon Complete adds machine-speed managed detection for teams that cannot build the capability internally.</p><p>“The agentic SOC is all about, how do we keep up?” Zaitsev said. “There’s almost no conceivable way they can do it if they don’t have their own agentic assistance.”</p><p>CrowdStrike opened its platform to external AI providers through Charlotte AI AgentWorks, announced at RSAC 2026, letting customers build custom security agents on Falcon using frontier AI models. Launch partners include Accenture, Anthropic, AWS, Deloitte, Kroll, NVIDIA, OpenAI, Salesforce, and Telefónica Tech. IBM validated buyer demand through a collaboration integrating Charlotte AI with its Autonomous Threat Operations Machine for coordinated, machine-speed investigation and containment.</p><p><b>The ecosystem contenders.</b> Palo Alto Networks, in an exclusive pre-RSAC briefing with VentureBeat, outlined Prisma AIRS 3.0, extending its AI security platform to agents with artifact scanning, agent red teaming, and a runtime that catches memory poisoning and excessive permissions. The company introduced an agentic identity provider for agent discovery and credential validation. Once Palo Alto Networks closes its proposed acquisition of Koi, the company adds agentic endpoint security. Cortex delivers agentic security orchestration across its customer base.</p><p>Intel announced that CrowdStrike’s Falcon platform is being optimized for Intel-powered AI PCs, leveraging neural processing units and silicon-level telemetry to detect agent behavior on the device. Kurtz framed AIDR, AI Detection and Response, as the next category beyond EDR, tracking agent-speed activity across endpoints, SaaS, cloud, and AI pipelines. He said that “humans are going to have 90 agents that work for them on average” as adoption scales but did not specify a timeline.</p><h2>The gap no vendor closed</h2><table><tbody><tr><td><p><b>What security leaders</b> <b>need</b></p></td><td><p><b>Approach A: agents inside the SIEM (Cisco/Splunk)</b></p></td><td><p><b>Approach B: upstream pipeline detection (CrowdStrike)</b></p></td><td><p><b>Gap neither closes</b></p></td></tr><tr><td><p><b>Triage at agent volume</b></p></td><td><p>Six AI agents handle triage, detection, and response inside Splunk ES</p></td><td><p>Onum-powered pipeline detects and enriches threats before the analyst sees them</p></td><td><p>Neither baselines normal agent behavior before flagging anomalies</p></td></tr><tr><td><p><b>Agent vs. human differentiation</b></p></td><td><p>Duo IAM tracks agent identities but does not differentiate agent from human activity in SOC telemetry</p></td><td><p>Process tree lineage distinguishes at runtime. AIDR extends to agent-specific detection</p></td><td><p>No vendor’s announced capabilities include an out-of-the-box agent behavioral baseline</p></td></tr><tr><td><p><b>27-second response window</b></p></td><td><p>Guided Response Agent executes containment at machine speed</p></td><td><p>In-pipeline detection reduces queue volume. Agentic MDR adds managed response</p></td><td><p>Human-in-the-loop governance has not been reconciled with machine-speed response in either approach</p></td></tr><tr><td><p><b>Legacy SIEM portability</b></p></td><td><p>Native Splunk integration preserves existing workflows</p></td><td><p>Query Translation Agent converts Splunk queries. Native Defender ingestion lets Microsoft shops migrate</p></td><td><p>Neither addresses teams running multiple SIEMs during migration</p></td></tr><tr><td><p><b>Agent supply chain</b></p></td><td><p>DefenseClaw scans skills and MCP servers pre-deployment. Explorer Edition red-teams agents</p></td><td><p>EDR AI Runtime Protection catches compromised skills post-deployment. Charlotte AI AgentWorks enables custom agents</p></td><td><p>Neither covers the full lifecycle. Pre-deployment scanning misses runtime exploits and vice versa</p></td></tr></tbody></table><p>The matrix makes one thing visible that the keynotes did not. No vendor shipped an agent behavioral baseline. Both approaches automate triage and accelerate detection. Based on VentureBeat's review of announced capabilities, neither defines what normal agent behavior looks like in a given enterprise environment.</p><p>Teams running Microsoft Sentinel and Copilot for Security represent a third architecture not formally announced as a competing approach at RSAC this week, but CISOs in Microsoft-heavy environments need to test whether Sentinel's native agent telemetry ingestion and Copilot's automated triage close the same gaps identified above.</p><p>Maor cautioned that the vendor response recycles a pattern he has tracked for 16 years. “I hope we don’t have to go through this whole cycle,” he told VentureBeat. “I hope we learned from the past. It doesn’t really look like it.”</p><p>Zaitsev’s advice was blunt. “You already know what to do. You’ve known what to do for five, ten, fifteen years. It’s time to finally go do it.”</p><h2>Five things to do Monday morning </h2><p>These steps apply regardless of your SOC platform. None requires ripping and replacing current tools. Start with visibility, then layer in controls as agent volume grows. </p><ol><li><p><b>Inventory every agent on your endpoints.</b> CrowdStrike detects 1,800 AI applications across enterprise devices. Cisco’s Duo Identity Intelligence discovers agentic identities. Palo Alto Networks’ agentic IDP catalogs agents and maps them to human owners. If you run a different platform, start with an EDR query for known agent directories and binaries. You cannot set policy for agents you do not know exist.</p></li><li><p><b>Determine whether your SOC stack can differentiate agent from human activity.</b> CrowdStrike’s Falcon sensor and AIDR do this through process tree lineage. Palo Alto Networks’ agent runtime catches memory poisoning at execution. If your tools cannot make this distinction, your triage rules are applying the wrong behavioral models.</p></li><li><p><b>Match the architectural approach to your current SIEM.</b> Splunk shops gain agent capabilities through Approach A. Teams evaluating migration get pipeline detection with Splunk query translation and native Defender ingestion through Approach B. Palo Alto Networks’ Cortex delivers a third option. Teams on Microsoft Sentinel, Google Chronicle, Elastic, or other platforms should evaluate whether their SIEM can ingest agent-specific telemetry at this volume.</p></li><li><p><b>Build an agent behavioral baseline before your next board meeting.</b> No vendor ships one. Define what your agents are authorized to do: which APIs, which data stores, which actions, at which times. Create detection rules for anything outside that scope.</p></li><li><p><b>Pressure-test your agent supply chain.</b> Cisco’s DefenseClaw and Explorer Edition scan and red-team agents before deployment. CrowdStrike’s runtime detection catches compromised agents post-deployment. Both layers are necessary. Kurtz said in his keynote that ClawHavoc compromised over a thousand ClawHub skills with malware that erased its own memory after installation. If your playbook does not account for an authorized agent executing unauthorized actions at machine speed, rewrite it.</p></li></ol><p>The SOC was built to protect humans using machines. It now protects machines using machines. The response window shrank from 48 minutes to 27 seconds. Any agent generating an alert is now a suspect, not just a sensor. The decisions security leaders make in the next 90 days will determine whether their SOC operates in this new reality or gets buried under it.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw has 500,000 instances and no enterprise kill switch]]></title>
<description><![CDATA[“Your AI? It’s my AI now.” The line came from Etay Maor, VP of Threat Intelligence at Cato Networks, in an exclusive interview with VentureBeat at RSAC 2026 — and it describes exactly what happened to a U.K. CEO whose OpenClaw instance ended up for sale on BreachForums. Maor's argument is that th...]]></description>
<link>https://tsecurity.de/de/3397100/it-nachrichten/openclaw-has-500000-instances-and-no-enterprise-kill-switch/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3397100/it-nachrichten/openclaw-has-500000-instances-and-no-enterprise-kill-switch/</guid>
<pubDate>Tue, 31 Mar 2026 20:01:41 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>“Your AI? It’s my AI now.” The line came from Etay Maor, VP of Threat Intelligence at <a href="https://www.catonetworks.com/">Cato Networks</a>, in an exclusive interview with VentureBeat at <a href="https://www.rsaconference.com/usa">RSAC 2026</a> — and it describes exactly what happened to a U.K. CEO whose <a href="https://venturebeat.com/security/openclaw-can-bypass-your-edr-dlp-and-iam-without-triggering-a-single-alert">OpenClaw</a> instance ended up for sale on BreachForums. Maor's argument is that the industry handed AI agents the kind of autonomy it would never extend to a human employee, discarding zero trust, least privilege, and assume-breach in the process.</p><p>The proof arrived on <a href="https://www.catonetworks.com/blog/cato-ctrl-when-openclaw-ai-personal-assistant-becomes-backdoor/">BreachForums</a> three weeks before Maor’s interview. On February 22, a threat actor using the handle “fluffyduck” posted a listing advertising root shell access to the CEO’s computer for $25,000 in Monero or Litecoin. The shell was not the selling point. The CEO’s OpenClaw AI personal assistant was. The buyer would get every conversation the CEO had with the AI, the company’s full production database, Telegram bot tokens, Trading 212 API keys, and personal details the CEO disclosed to the assistant about family and finances. The threat actor noted the CEO was actively interacting with OpenClaw in real time, making the listing a live intelligence feed rather than a static data dump.</p><p><a href="https://www.catonetworks.com/blog/cato-ctrl-when-openclaw-ai-personal-assistant-becomes-backdoor/">Cato CTRL senior security researcher Vitaly Simonovich documented the listing</a> on February 25. The CEO’s OpenClaw instance stored everything in plain-text Markdown files under ~/.openclaw/workspace/ with no encryption at rest. The threat actor didn't need to exfiltrate anything; the CEO had already assembled it. When the security team discovered the breach, there was no native enterprise kill switch, no management console, and no way to inventory how many other instances were running across the organization.</p><p>OpenClaw runs locally with direct access to the host machine’s file system, network connections, browser sessions, and installed applications. The coverage to date has tracked its velocity, but what it hasn't mapped is the threat surface. The four vendors who used RSAC 2026 to ship responses still haven't produced the one control enterprises need most: a native kill switch.</p><h2>The threat surface by the numbers</h2><table><tbody><tr><td><p><b>Metric</b></p></td><td><p><b>Numbers</b></p></td><td><p><b>Source</b></p></td></tr><tr><td><p>Internet-facing instances</p></td><td><p>~500,000 (March 24 live check)</p></td><td><p>Etay Maor, Cato Networks (exclusive RSAC 2026 interview)</p></td></tr><tr><td><p>Exposed instances with security risks</p></td><td><p>30,000+ observed during scan window</p></td><td><p><a href="https://www.bitsight.com/blog/openclaw-ai-security-risks-exposed-instances">Bitsight</a></p></td></tr><tr><td><p>Exploitable via known RCE</p></td><td><p>15,200 instances</p></td><td><p><a href="https://securityscorecard.com/blog/beyond-the-hype-moltbots-real-risk-is-exposed-infrastructure-not-ai-superintelligence/">SecurityScorecard</a></p></td></tr><tr><td><p>High-severity CVEs</p></td><td><p>3 (highest CVSS: 8.8)</p></td><td><p>NVD (<a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24763">24763</a>, <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25157">25157</a>, <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25253">25253</a>)</p></td></tr><tr><td><p>Malicious skills on ClawHub</p></td><td><p>341 in Koi audit (335 from ClawHavoc); 824 by mid-Feb</p></td><td><p><a href="https://www.koi.ai/blog/clawhavoc-341-malicious-clawedbot-skills-found-by-the-bot-they-were-targeting">Koi</a></p></td></tr><tr><td><p>ClawHub skills with critical flaws</p></td><td><p>13.4% of 3,984 analyzed</p></td><td><p><a href="https://snyk.io/blog/toxicskills-malicious-ai-agent-skills-clawhub/">Snyk</a></p></td></tr><tr><td><p>API tokens exposed (Moltbook)</p></td><td><p>1.5 million</p></td><td><p><a href="https://www.wiz.io/blog/exposed-moltbook-database-reveals-millions-of-api-keys">Wiz</a></p></td></tr></tbody></table><p>Maor ran a live Censys check during an exclusive VentureBeat interview at RSAC 2026. “The first week it came out, there were about 6,300 instances. Last week, I checked: 230,000 instances. Let’s check now… almost half a million. Almost doubled in one week,” Maor said. Three high-severity CVEs define the attack surface: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24763">CVE-2026-24763</a> (CVSS 8.8, command injection via Docker PATH handling), <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25157">CVE-2026-25157</a> (CVSS 7.7, OS command injection), and <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25253">CVE-2026-25253</a> (CVSS 8.8, token exfiltration to full gateway compromise). All three CVEs have been patched, but OpenClaw has no enterprise management plane, no centralized patching mechanism, and no fleet-wide kill switch. Individual administrators must update each instance manually, and most have not.</p><p>The defender-side telemetry is just as alarming. CrowdStrike's Falcon sensors <a href="https://ir.crowdstrike.com/news-releases/news-release-details/crowdstrike-establishes-endpoint-epicenter-ai-security/">already detect more than 1,800 distinct AI applications</a> across its customer fleet — from ChatGPT to Copilot to OpenClaw — generating around 160 million unique instances on enterprise endpoints. ClawHavoc, a malicious skill distributed through the ClawHub marketplace, became the primary case study in the OWASP Agentic Skills Top 10. CrowdStrike CEO George Kurtz flagged it in his RSAC 2026 keynote as the first major supply chain attack on an AI agent ecosystem.</p><h2>AI agents got root access. Security got nothing.</h2><p>Maor framed the visibility failure through the OODA loop (observe, orient, decide, act) during the RSAC 2026 interview. Most organizations are failing at the first step: security teams can't see which AI tools are running on their networks, which means the productivity tools employees bring in quietly become shadow AI that attackers exploit. The BreachForums listing proved the end state. The CEO’s OpenClaw instance became a centralized intelligence hub with SSO sessions, credential stores, and communication history aggregated into one location. “The CEO’s assistant can be your assistant if you buy access to this computer,” Maor told VentureBeat. “It’s an assistant for the attacker.”</p><p>Ghost agents amplify the exposure. Organizations adopt AI tools, run a pilot, lose interest, and move on — leaving agents running with credentials intact. “We need an HR view of agents. Onboarding, monitoring, offboarding. If there’s no business justification? Removal,” Maor told VentureBeat. “We’re not left with any ghost agents on our network, because that’s already happening.”</p><h2>Cisco moved toward an OpenClaw kill switch</h2><p>Cisco President and Chief Product Officer Jeetu Patel framed the stakes during an exclusive VentureBeat interview at RSAC 2026. “I think of them more like teenagers. They’re supremely intelligent, but they have no fear of consequence,” Patel said of AI agents. “The difference between delegating and trusted delegating of tasks to an agent … one of them leads to bankruptcy. The other one leads to market dominance.” </p><p>Cisco launched three free, open-source security tools for OpenClaw at RSAC 2026. <a href="https://blogs.cisco.com/ai/cisco-announces-defenseclaw">DefenseClaw</a> packages Skills Scanner, MCP Scanner, AI BoM, and CodeGuard into a single open-source framework running inside NVIDIA’s OpenShell runtime, which NVIDIA launched at GTC the week before RSAC. “Every single time you actually activate an agent in an Open Shell container, you can now automatically instantiate all the security services that we have built through Defense Claw,” Patel told VentureBeat. <a href="https://newsroom.cisco.com/c/r/newsroom/en/us/a/y2026/m03/cisco-reimagines-security-for-the-agentic-workforce.html">AI Defense Explorer Edition</a> is a free, self-serve version of Cisco’s algorithmic red-teaming engine, testing any AI model or agent for prompt injection and jailbreaks across more than 200 risk subcategories. The <a href="https://leaderboard.aidefense.cisco.com/rankings">LLM Security Leaderboard</a> ranks foundation models by adversarial resilience rather than performance benchmarks. Cisco also shipped <a href="https://duo.com/blog/introducing-duo-agentic-identity">Duo Agentic Identity</a> to register agents as identity objects with time-bound permissions, Identity Intelligence to discover shadow agents through network monitoring, and the Agent Runtime SDK to embed policy enforcement at build time.</p><h2>Palo Alto made agentic endpoints a security category of their own</h2><p>Palo Alto Networks CEO Nikesh Arora characterized OpenClaw-class tools as creating a new supply chain running through unregulated, unsecured marketplaces during an exclusive March 18 pre-RSA briefing with VentureBeat. <a href="https://www.koi.ai/blog/clawhavoc-341-malicious-clawedbot-skills-found-by-the-bot-they-were-targeting">Koi found 341 malicious skills</a> on ClawHub in its initial audit, with the total growing to 824 as the registry expanded. <a href="https://snyk.io/blog/toxicskills-malicious-ai-agent-skills-clawhub/">Snyk found 13.4% of analyzed skills</a> contained critical security flaws. Palo Alto Networks built Prisma AIRS 3.0 around a new agentic registry that requires every agent to be logged before operating, with credential validation, MCP gateway traffic control, agent red-teaming, and runtime monitoring for memory poisoning. The pending Koi acquisition adds supply chain visibility specifically for agentic endpoints.</p><h2>Cato CTRL delivered the adversarial proof</h2><p>Cato Networks’ threat intelligence arm Cato CTRL presented two sessions at RSAC 2026. The <a href="https://www.catonetworks.com/resources/2026-cato-ctrl-threat-report/">2026 Cato CTRL Threat Report</a>, published separately, includes a proof-of-concept “Living Off AI” attack targeting Atlassian’s MCP and Jira Service Management. Maor’s research provides the independent adversarial validation that vendor product announcements cannot deliver on their own. The platform vendors are building governance for sanctioned agents. Cato CTRL documented what happens when the unsanctioned agent on the CEO’s laptop gets sold on the dark web.</p><h2>Monday morning action list</h2><p>Regardless of vendor stack, four controls apply immediately: bind OpenClaw to localhost only and block external port exposure, enforce application allowlisting through MDM to prevent unauthorized installations, rotate every credential on machines where OpenClaw has been running, and apply least-privilege access to any account an AI agent has touched.</p><ol><li><p><b>Discover the install base. </b>CrowdStrike’s Falcon sensor, Cato’s SASE platform, and Cisco Identity Intelligence all detect shadow AI. For teams without premium tooling, query endpoints for the ~/.openclaw/ directory using native EDR or MDM file-search policies. If the enterprise has no endpoint visibility at all, run Shodan and Censys queries against corporate IP ranges.</p></li><li><p><b>Patch or isolate. </b>Check every discovered instance against CVE-2026-24763, CVE-2026-25157, and CVE-2026-25253. Instances that cannot be patched should be network-isolated. There is no fleet-wide patching mechanism.</p></li><li><p><b>Audit skill installations. </b>Review installed skills against Cisco’s Skills Scanner or the <a href="https://snyk.io/blog/toxicskills-malicious-ai-agent-skills-clawhub/">Snyk</a> and <a href="https://www.koi.ai/blog/clawhavoc-341-malicious-clawedbot-skills-found-by-the-bot-they-were-targeting">Koi</a> research. Any skill from an unverified source should be removed immediately.</p></li><li><p><b>Enforce DLP and ZTNA controls. </b>Cato’s ZTNA controls restrict unapproved AI applications. Cisco Secure Access SSE enforces policy on MCP tool calls. Palo Alto’s Prisma Access Browser controls data flow at the browser layer.</p></li><li><p><b>Kill ghost agents. </b>Build a registry of every AI agent running. Document business justification, human owner, credentials held, and systems accessed. Revoke credentials for agents with no justification. Repeat weekly.</p></li><li><p><b>Deploy DefenseClaw for sanctioned use. </b>Run OpenClaw inside NVIDIA’s OpenShell runtime with Cisco’s <a href="https://blogs.cisco.com/ai/cisco-announces-defenseclaw">DefenseClaw</a> to scan skills, verify MCP servers, and instrument runtime behavior automatically.</p></li><li><p><b>Red-team before deploying. </b>Use <a href="https://newsroom.cisco.com/c/r/newsroom/en/us/a/y2026/m03/cisco-reimagines-security-for-the-agentic-workforce.html">Cisco AI Defense Explorer Edition</a> (free) or Palo Alto Networks’ agent red-teaming in Prisma AIRS 3.0. Test the workflow, not just the model.</p></li></ol><p>The <a href="https://owasp.org/www-project-agentic-skills-top-10/">OWASP Agentic Skills Top 10</a>, published using ClawHavoc as its primary case study, provides a standards-grade framework for evaluating these risks. Four vendors shipped responses at RSAC 2026. None of them is a native enterprise kill switch for unsanctioned OpenClaw deployments. <!-- -->Until one exists, the Monday morning action list above is the closest thing to one.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Five Browser and AI Security Questions Keeping CxOs up at Night]]></title>
<description><![CDATA[Prisma Browser secures the last mile of work, data, and AI interactions by addressing CxO concerns: shadow AI, unmanaged devices, agentic AI and data leakage. The post Five Browser and AI Security Questions Keeping CxOs up at Night appeared first…
Read more →
The post Five Browser and AI Security...]]></description>
<link>https://tsecurity.de/de/3396299/it-security-nachrichten/five-browser-and-ai-security-questions-keeping-cxos-up-at-night/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3396299/it-security-nachrichten/five-browser-and-ai-security-questions-keeping-cxos-up-at-night/</guid>
<pubDate>Tue, 31 Mar 2026 15:36:40 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Prisma Browser secures the last mile of work, data, and AI interactions by addressing CxO concerns: shadow AI, unmanaged devices, agentic AI and data leakage. The post Five Browser and AI Security Questions Keeping CxOs up at Night appeared first…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/five-browser-and-ai-security-questions-keeping-cxos-up-at-night/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/five-browser-and-ai-security-questions-keeping-cxos-up-at-night/">Five Browser and AI Security Questions Keeping CxOs up at Night</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ZDF Mediathek: Wahre Verbrechen – Suche nach Gerechtigkeit im Stream - Prisma]]></title>
<description><![CDATA[Wahre Verbrechen – Suche nach Gerechtigkeit - Cybercrime im Ex-NATO-Bunker ... Sa., 23.08. ... 17 Min. ... Es geht um Drogen, Waffen, Kinderpornografie - ...]]></description>
<link>https://tsecurity.de/de/3395107/it-security-nachrichten/zdf-mediathek-wahre-verbrechen-suche-nach-gerechtigkeit-im-stream-prisma/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3395107/it-security-nachrichten/zdf-mediathek-wahre-verbrechen-suche-nach-gerechtigkeit-im-stream-prisma/</guid>
<pubDate>Tue, 31 Mar 2026 08:34:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wahre Verbrechen – Suche nach Gerechtigkeit - <b>Cybercrime</b> im Ex-NATO-Bunker ... Sa., 23.08. ... 17 Min. ... Es geht um Drogen, Waffen, Kinderpornografie - ...]]></content:encoded>
</item>
<item>
<title><![CDATA[RSAC 2026 shipped five agent identity frameworks and left three critical gaps open]]></title>
<description><![CDATA[“You can deceive, manipulate, and lie. That’s an inherent property of language. It’s a feature, not a flaw,” CrowdStrike CTO Elia Zaitsev told VentureBeat in an exclusive interview at RSA Conference 2026. If deception is baked into language itself, every vendor trying to secure AI agents by analy...]]></description>
<link>https://tsecurity.de/de/3394200/it-nachrichten/rsac-2026-shipped-five-agent-identity-frameworks-and-left-three-critical-gaps-open/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3394200/it-nachrichten/rsac-2026-shipped-five-agent-identity-frameworks-and-left-three-critical-gaps-open/</guid>
<pubDate>Mon, 30 Mar 2026 21:31:48 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>“You can deceive, manipulate, and lie. That’s an inherent property of language. It’s a feature, not a flaw,” <a href="https://www.crowdstrike.com/en-us/press-releases/crowdstrike-establishes-the-endpoint-as-the-epicenter-for-ai-security/">CrowdStrike</a> CTO Elia Zaitsev told VentureBeat in an exclusive interview at RSA Conference 2026. If deception is baked into language itself, every vendor trying to secure AI agents by analyzing their intent is chasing a problem that cannot be conclusively solved. Zaitsev is betting on context instead. CrowdStrike’s Falcon sensor walks the process tree on an endpoint and tracks what agents did, not what agents appeared to intend. “Observing actual kinetic actions is a structured, solvable problem,” Zaitsev told VentureBeat. “Intent is not.”</p><p>That argument landed 24 hours after CrowdStrike CEO George Kurtz disclosed two production incidents at Fortune 50 companies. In the first, a CEO's AI agent rewrote the company's own security policy — not because it was compromised, but because it wanted to fix a problem, lacked the permissions to do so, and removed the restriction itself. Every identity check passed; the company caught the modification by accident. The second incident involved a 100-agent Slack swarm that delegated a code fix between agents with no human approval. Agent 12 made the commit. The team discovered it after the fact.</p><p>Two incidents at two Fortune 50 companies. Caught by accident both times. Every identity framework that shipped at RSAC this week missed them. The vendors verified who the agent was. None of them tracked what the agent did.</p><p>The urgency behind every framework launch reflects a broader market shift. "The difficulty of securing agentic AI is likely to push customers toward trusted platform vendors that can offer broader coverage across the expanding attack surface," according to William Blair's RSA Conference 2026 equity research report by analyst Jonathan Ho. Five vendors answered that call at RSAC this week. None of them answered it completely.</p><h2>Attackers are already inside enterprise pilots</h2><p>The scale of the exposure is already visible in production data. <a href="https://www.crowdstrike.com/en-us/blog/new-crowdstrike-innovations-secure-ai-agents-govern-shadow-ai/">CrowdStrike's Falcon sensors</a> detect more than 1,800 distinct AI applications across the company's customer fleet, generating 160 million unique instances on enterprise endpoints. Cisco found that <a href="https://newsroom.cisco.com/c/r/newsroom/en/us/a/y2026/m03/cisco-reimagines-security-for-the-agentic-workforce.html">85% of its enterprise customers surveyed have pilot agent programs</a>; only 5% have moved to production, meaning the vast majority of these agents are running without the governance structures production deployments typically require. "The biggest impediment to scaled adoption in enterprises for business-critical tasks is establishing a sufficient amount of trust," Cisco President and Chief Product Officer Jeetu Patel told VentureBeat in an exclusive interview at RSA Conference 2026. "Delegating versus trusted delegating of tasks to agents. The difference between those two, one leads to bankruptcy and the other leads to market dominance."</p><p>Etay Maor, VP of Threat Intelligence at <a href="https://www.catonetworks.com/blog/cato-ctrl-when-openclaw-ai-personal-assistant-becomes-backdoor/">Cato Networks</a>, ran a live Censys scan during an exclusive VentureBeat interview at RSA Conference 2026 and counted nearly 500,000 internet-facing OpenClaw instances. The week before: 230,000. Cato CTRL senior researcher Vitaly Simonovich documented a BreachForums listing from February 22, 2026, published on the <a href="https://www.catonetworks.com/blog/cato-ctrl-when-openclaw-ai-personal-assistant-becomes-backdoor/">Cato CTRL blog on February 25</a>, where a threat actor advertised root shell access to a UK CEO’s computer for $25,000 in cryptocurrency. The selling point was the CEO’s OpenClaw AI personal assistant, which had accumulated the company’s production database, Telegram bot tokens, and Trading 212 API keys in plain-text Markdown with no encryption at rest. “Your AI? It’s my AI now. It’s an assistant for the attacker,” Maor told VentureBeat.</p><p>The exposure data from multiple independent researchers tells the same story. Bitsight found more than 30,000 OpenClaw instances exposed to the public internet between January 27 and February 8, 2026. <a href="https://securityscorecard.com/blog/beyond-the-hype-moltbots-real-risk-is-exposed-infrastructure-not-ai-superintelligence/">SecurityScorecard</a> identified 15,200 of those instances as vulnerable to remote code execution through three high-severity CVEs, the worst rated CVSS 8.8. <a href="https://www.koi.ai/blog/clawhavoc-341-malicious-clawedbot-skills-found-by-the-bot-they-were-targeting">Koi Security found 824 malicious skills on ClawHub</a> — 335 of them tied to ClawHavoc, which Kurtz flagged in his keynote as the first major supply chain attack on an AI agent ecosystem.</p><h2>Five vendors, three gaps none of them closed</h2><p><a href="https://newsroom.cisco.com/c/r/newsroom/en/us/a/y2026/m03/cisco-reimagines-security-for-the-agentic-workforce.html">Cisco</a> went deepest on identity governance. <a href="https://newsroom.cisco.com/c/r/newsroom/en/us/a/y2026/m03/cisco-reimagines-security-for-the-agentic-workforce.html">Duo Agentic Identity</a> registers agents as distinct identity objects mapped to human owners, and every tool call routes through an MCP gateway in Secure Access SSE. Cisco Identity Intelligence catches shadow agents by monitoring network traffic rather than authentication logs. Patel told VentureBeat that today’s agents behave “more like teenagers — supremely intelligent, but with no fear of consequence, easily sidetracked or influenced.” <a href="https://www.crowdstrike.com/en-us/press-releases/crowdstrike-establishes-the-endpoint-as-the-epicenter-for-ai-security/">CrowdStrike</a> made the biggest philosophical bet, treating agents as endpoint telemetry and tracking the kinetic layer through Falcon’s process-tree lineage. CrowdStrike expanded <a href="https://www.crowdstrike.com/en-us/blog/new-crowdstrike-innovations-secure-ai-agents-govern-shadow-ai/">AIDR</a> to cover Microsoft Copilot Studio agents and shipped Shadow SaaS and AI Agent Discovery across Copilot, Salesforce Agentforce, ChatGPT Enterprise, and OpenAI Enterprise GPT.</p><p><a href="https://www.paloaltonetworks.com/company/press/2026/palo-alto-networks-secures-agentic-ai-with-prisma-airs-3-0">Palo Alto Networks</a> built <a href="https://www.paloaltonetworks.com/blog/2026/03/prisma-airs-3-0-autonomous-ai/">Prisma AIRS 3.0</a> with an agentic registry, an agentic IDP, and an MCP gateway for runtime traffic control. Palo Alto Networks’ pending Koi acquisition adds supply chain and runtime visibility. <a href="https://www.microsoft.com/en-us/security/blog/2026/03/20/secure-agentic-ai-end-to-end/">Microsoft</a> spread governance across Entra, Purview, Sentinel, and Defender, with <a href="https://techcommunity.microsoft.com/blog/microsoftsentinelblog/what%E2%80%99s-new-in-microsoft-sentinel-rsac-2026/4503971">Microsoft Sentinel</a> embedding MCP natively and a Claude MCP connector in public preview April 1. Cato CTRL delivered the adversarial proof that the identity gaps the other four vendors are trying to close are already being exploited. Maor told VentureBeat that enterprises abandoned basic security principles when deploying agents. “We just gave these AI tools complete autonomy,” Maor said.</p><h2>Gap 1: Agents can rewrite the rules governing their own behavior</h2><p>The Kurtz incident illustrates the gap exactly. Every credential check passed — the action was authorized. Zaitsev argues that the only reliable detection happens at the kinetic layer: which file was modified, by what process, initiated by what agent, compared against a behavioral baseline. Intent-based controls evaluate whether the call looks malicious. This one did not. Palo Alto Networks offers <a href="https://www.paloaltonetworks.com/blog/2026/03/prisma-airs-3-0-autonomous-ai/">pre-deployment red teaming in Prisma AIRS 3.0</a>, but red teaming runs before deployment, not during runtime when self-modification happens. No vendor ships behavioral anomaly detection for policy-modifying actions as a production capability.</p><p>Patel framed the stakes in the VentureBeat interview: “The agent takes the wrong action and worse yet, some of those actions might be critical actions that are not reversible.” Board question: An authorized agent modifies the policy governing the agent’s future actions. What fires?</p><h2>Gap 2: Agent-to-agent handoffs have no trust verification</h2><p>The 100-agent swarm is the proof point. Agent A found a defect and posted to Slack. Agent 12 executed the fix. No human approved the delegation. Zaitsev’s approach: collapse agent identities back to the human. An agent acting on your behalf should never have more privileges than you do. But no product follows the delegation chain between agents. IAM was built for human-to-system. Agent-to-agent delegation needs a trust primitive that does not exist in OAuth, SAML, or MCP.</p><h2>Gap 3: Ghost agents hold live credentials with no offboarding</h2><p>Organizations adopt AI tools, run a pilot, lose interest, and move on. The agents keep running. The credentials stay active. Maor calls these abandoned instances ghost agents. Zaitsev connected ghost agents to a broader failure: agents expose where enterprises delayed action on basic identity hygiene. Standing privileged accounts, long-lived credentials, and missing offboarding procedures. These problems existed for humans. Agents running at machine speed make the consequences catastrophic.</p><p>Maor demonstrated a <a href="https://www.catonetworks.com/resources/living-off-the-ai-targeting-ai-agents/">Living Off the AI</a> attack at the RSA Conference 2026, chaining Atlassian’s MCP and Jira Service Management to show that attackers do not separate trusted tools, services, and models. Attackers chain all three. “We need an HR view of agents,” Maor told VentureBeat. “Onboarding, monitoring, offboarding. If there’s no business justification? Removal.”</p><h2>Why these three gaps resist a product fix</h2><p>Human IAM assumes the identity holder will not rewrite permissions, spawn new identities, or leave. Agents violate all three. OAuth handles user-to-service. SAML handles federated human identity. MCP handles model-to-tool. None includes agent-to-agent verification.</p><h2>Five vendors against three gaps</h2><table><tbody><tr><td><p></p></td><td><p><b>Cisco</b></p></td><td><p><b>CrowdStrike</b></p></td><td><p><b>Microsoft</b></p></td><td><p><b>Palo Alto Networks</b></p></td><td><p><b>Unsolved</b></p></td></tr><tr><td><p><b>Registration. Can the vendor discover and inventory agents?</b></p></td><td><p>Duo Agentic Identity. Agents registered as identity objects with human owners. Shadow agent detection via network traffic.</p></td><td><p>Falcon sensor auto-discovery. 1,800+ agent apps, ~160M instances across customer fleet.</p></td><td><p>Security Dashboard for AI + Entra shadow AI detection at the network layer.</p></td><td><p>Agentic registry in Prisma AIRS 3.0. Agents inventoried before operating.</p></td><td><p>All four register agents. No cross-vendor identity standard exists.</p></td></tr><tr><td><p><b>Self-modification. Can the vendor detect when an agent changes its own policies?</b></p></td><td><p>MCP gateway catches anomalous tool-call patterns in real time, but does not monitor for direct policy file modifications on the endpoint.</p></td><td><p>Process-tree lineage tracks file modifications at the action layer. Could detect a policy file change, but no dedicated self-modification rule ships.</p></td><td><p>Defender predictive shielding adjusts access policies reactively during active attacks. Not proactive self-modification detection.</p></td><td><p>AI Red Teaming tests for this before deployment. No runtime detection after the agent is live.</p></td><td><p>OPEN. No vendor detects an agent rewriting the policy governing the agent’s own behavior as a shipping capability.</p></td></tr><tr><td><p><b>Delegation. Can the vendor track when one agent hands work to another?</b></p></td><td><p>Maps each agent to a human owner. Does not track agent-to-agent handoffs.</p></td><td><p>Collapses the agent identity to the human operator. Does not correlate the delegation chains between agents.</p></td><td><p>Entra governs individual non-human identities. No multi-agent chain tracking.</p></td><td><p>AI Agent Gateway governs individual agents. No delegation primitive between agents.</p></td><td><p>OPEN. No trust primitive for agent-to-agent delegation exists in OAuth, SAML, or MCP.</p></td></tr><tr><td><p><b>Decommission. Can the vendor confirm a killed agent holds zero credentials?</b></p></td><td><p>Identity Intelligence runs a continuous inventory of active agents.</p></td><td><p>Shadow SaaS + AI Agent Discovery finds running agents across SaaS and endpoints.</p></td><td><p>Entra's shadow AI detection surfaces unmanaged AI applications.</p></td><td><p>Koi acquisition (pending) adds endpoint visibility for agent applications.</p></td><td><p>OPEN. All four discover running agents. None verifies zero residual credentials after decommission.</p></td></tr><tr><td><p><b>Runtime / Kinetic. Can the vendor monitor what agents do in real time?</b></p></td><td><p>MCP gateway enforces policy per tool call at the network layer. Contextual anomaly detection on call patterns.</p></td><td><p>Falcon EDR tracks commands, scripts, file activity, and network connections at the process level.</p></td><td><p>Defender endpoint + cloud monitoring. Predictive shielding during active incidents.</p></td><td><p>Prisma AIRS AI Agent Gateway for runtime traffic control.</p></td><td><p>CrowdStrike is the only vendor framing endpoint runtime as the primary safety net for agentic behavior.</p></td></tr></tbody></table><h2>Five things to do Monday morning before your board asks</h2><ol><li><p><b>Audit self-modification risk.</b> Pull every agent with write access to security policies, IAM configs, firewall rules, or ACLs. Flag any agent that can modify controls governing the agent’s own behavior. No vendor automates this.</p></li><li><p><b>Map delegation paths.</b> Document every agent-to-agent invocation. Flag delegation without human approval. Human-in-the-loop on every delegation event until a trust primitive ships.</p></li><li><p><b>Kill ghost agents.</b> Build a registry. For each agent: business justification, human owner, credentials held, systems accessed. No justification? Manual revoke. Weekly.</p></li><li><p><b>Stress test the MCP gateway enforcement.</b> <a href="https://newsroom.cisco.com/c/r/newsroom/en/us/a/y2026/m03/cisco-reimagines-security-for-the-agentic-workforce.html">Cisco</a>, <a href="https://www.paloaltonetworks.com/company/press/2026/palo-alto-networks-secures-agentic-ai-with-prisma-airs-3-0">Palo Alto Networks</a>, and <a href="https://techcommunity.microsoft.com/blog/microsoftsentinelblog/what%E2%80%99s-new-in-microsoft-sentinel-rsac-2026/4503971">Microsoft</a> all announced MCP gateways this week. Verify that agent tool traffic actually routes through the gateway. A misconfigured gateway creates false confidence while agents call tools directly.</p></li><li><p><b>Baseline agent behavioral norms.</b> Before any agent reaches production, establish what normal looks like: typical API calls, data access patterns, systems touched, and hours of activity. Without a behavioral baseline, the kinetic-layer anomaly detection Zaitsev describes has nothing to compare against.</p></li></ol><p>Zaitsev’s advice was blunt: you already know what to do. Agents just made the cost of not doing it catastrophic. Every vendor at RSAC verified who the agent was. None of them tracked what the agent did.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[heise+ | OM System OM-3 Astro im Test: Was leistet die spiegellose Astrokamera?]]></title>
<description><![CDATA[Die OM-3 Astro ist die einzige spiegellose Astrokamera ab Werk. Wir haben getestet, wie sich der MFT-Sensor und fünf Objektive am Sternenhimmel schlagen.]]></description>
<link>https://tsecurity.de/de/3393168/it-nachrichten/heise-om-system-om-3-astro-im-test-was-leistet-die-spiegellose-astrokamera/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3393168/it-nachrichten/heise-om-system-om-3-astro-im-test-was-leistet-die-spiegellose-astrokamera/</guid>
<pubDate>Mon, 30 Mar 2026 15:17:14 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die OM-3 Astro ist die einzige spiegellose Astrokamera ab Werk. Wir haben getestet, wie sich der MFT-Sensor und fünf Objektive am Sternenhimmel schlagen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Data Security Posture Management: Die besten DSPM-Tools]]></title>
<description><![CDATA[Data Security Posture Management erfordert nicht nur die richtigen Tools, sondern auch eine entsprechende Vorbereitung. Foto: Rawpixel.com | shutterstock.comCloud Computing ist von Natur aus dynamisch und flüchtig: Daten können schnell und einfach erstellt, gelöscht oder verschoben werden. Das so...]]></description>
<link>https://tsecurity.de/de/3391656/it-security-nachrichten/data-security-posture-management-die-besten-dspm-tools/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3391656/it-security-nachrichten/data-security-posture-management-die-besten-dspm-tools/</guid>
<pubDate>Mon, 30 Mar 2026 02:43:25 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img decoding="async" alt="Data Security Posture Management erfordert nicht nur die richtigen Tools, sondern auch eine entsprechende Vorbereitung." title="Data Security Posture Management erfordert nicht nur die richtigen Tools, sondern auch eine entsprechende Vorbereitung." src="https://images.computerwoche.de/bdb/3376718/1200x.jpg" width="1200" loading="lazy"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Data Security Posture Management erfordert nicht nur die richtigen Tools, sondern auch eine entsprechende Vorbereitung.</p></figcaption></figure><p class="imageCredit"> Foto: Rawpixel.com | shutterstock.com</p></div><p>Cloud Computing ist von Natur aus dynamisch und flüchtig: Daten können schnell und einfach erstellt, gelöscht oder verschoben werden. Das sorgt dafür, dass auch die Cloud-Angriffsfläche sehr dynamisch ist – was <a href="https://www.csoonline.com/article/3495736/cloud-security-strategie-in-die-cloud-aber-mit-sicherheit.html" title="Schutzmaßnahmen erschwert" target="_blank">Schutzmaßnahmen erschwert</a>. Ein lästiges Problem stellt dabei insbesondere dar, sensible Daten innerhalb von Cloud-Umgebungen aufzuspüren. An dieser Stelle kommt Data Security Posture Management – kurz DSPM – ins Spiel.</p>



<h2 class="wp-block-heading">Was ist Data Security Posture Management?</h2>



<p>Im Bereich DSPM wurden in den vergangenen Jahren diverse Tools entwickelt, die dabei unterstützen, sowohl bekannte als auch unbekannte Daten zu erkennen, zu strukturieren und mit Blick auf Security und <a href="https://www.csoonline.com/article/3494359/der-grose-ki-risiko-guide.html" title="Datenschutzrisiken" target="_blank">Datenschutzrisiken</a> zu managen. Data Security Posture Management Tools können Sicherheitsentscheidern und ihren Teams dabei einen umfassenden Blick auf den Datenbestand des Unternehmens ermöglichen.</p>



<p>Das könnte Ihnen eventuell bekannt vorkommen – dennoch handelt es sich bei DSPM nicht um einen Abkömmling von <a href="https://www.computerwoche.de/article/2797438/was-sie-ueber-dlp-wissen-muessen.html" title="Data Loss Prevention" target="_blank">Data Loss Prevention</a> (DLP). Der wesentliche Unterschied besteht darin, dass DSPM-Tools nicht darauf “warten”, dass Daten gestohlen oder exfiltriert werden. DSPM-Produkte sind darauf ausgerichtet, Daten zu finden – unabhängig davon, wo sie sich befinden und ob diese Speicherorte gut dokumentiert oder unstrukturiert sind. Dabei zielen Data Security Posture Management Tools insbesondere darauf ab, sogenannte “Schattendaten” aufzuspüren. Dabei handelt es sich zum Beispiel um Datenelemente, die von Entwicklern oder Backup-Prozessen erstellt wurden oder veraltete <a href="https://www.csoonline.com/article/3492659/datenlecks-finden-so-verhindern-sie-repository-leaks.html" title="Repositories" target="_blank">Repositories</a>, die in längst vergessenen, nicht mehr aktualisierten Cloud-Containern schlummern. DSPM-Tools übernehmen dabei eine “Locator”-Funktion. Gefundene Probleme zu beheben, fällt eigentlich in den Bereich traditionellerer Toolsets – beispielsweise <a href="https://www.csoonline.com/article/3494258/threat-intelligence-datenbanken-in-einem-soar-die-richtigen-spielzuge-gegen-hacker.html" title="SOAR" target="_blank">SOAR</a>, <a href="https://www.csoonline.com/article/3492608/was-ist-siem.html" title="SIEM" target="_blank">SIEM</a> oder <a href="https://www.trendmicro.com/de_de/what-is/cloud-native/cnapp.html" title="CNAPP" target="_blank" rel="noopener">CNAPP</a>. Inzwischen werden solche “Fix it”-Tools jedoch zunehmend von den Anbietern im Bereich Data Security Posture Management integriert.</p>



<p>Daten aufzuspüren, ist allerdings nur der erste Schritt des DSPM-Prozesses: Sobald diese gefunden sind, müssen sie katalogisiert, ausgewertet und in verschiedenen Dashboards zusammengefasst werden. Das kann schwierig sein, wenn keine strikten Sicherheitskontrollen vorhanden sind. Deshalb werben die meisten DSPM-Anbieter auch damit, dass Kundendaten immer in der Umgebung des Kunden bleiben – was in der Regel bedeutet, dass nicht die eigentlichen Daten, sondern Metadaten gesammelt werden. Das heißt bei den Anbietern “agentenloser” oder API-Zugriff und hat den Vorteil, dass große Datenmengen schnell gescannt werden können, um die Art ihrer Nutzung und <a title="potenzielle Risikofaktoren" href="https://www.csoonline.com/article/3495397/gehackte-konten-verlorene-datendie-15-dicksten-datenschutzverletzungen-unseres-jahrhunderts.html" target="_blank">potenzielle Risikofaktoren</a> zu verstehen. </p>



<p>Sobald die Daten entdeckt und die Metadaten gesammelt sind, besteht der nächste Schritt darin, regelmäßige Scans durchzuführen, um festzustellen, welche Änderungen vorgenommen werden. Die Betonung liegt dabei auf “regelmäßig”. Ergänzend hinzu kommt schließlich auch noch das Thema <a title="Data Governance" href="https://www.computerwoche.de/article/2803961/was-ist-data-governance.html" target="_blank">Data Governance</a>: DSPM-Tools klassifizieren nach Risiken und können im Zusammenspiel mit anderen Security-Tools Richtlinien durchsetzen und Probleme beheben.</p>



<p>Grundsätzlich bestehen DSPM-Tools aus mehreren Komponenten, darunter:</p>



<ul class="wp-block-list">
<li><p>Agenten und “agentless Collectors” (nützlich, um On-Premises-Daten zu tracken),</p></li>



<li><p>ein zentralisiertes Management-Dashboard,</p></li>



<li><p>Scanner, die Datensammlungen erkennen und priorisieren,</p></li>



<li><p>Data-Lineage- und Usage-Karten sowie</p></li>



<li><p>Compliance Assessments.</p></li>
</ul>



<p>Das übergeordnete Ziel von DSPM-Produkten besteht darin, umfassendere <a href="https://www.csoonline.com/article/3495818/cloud-risiken-verwalten-so-wahlen-sie-das-passende-cspm-tool-aus.html" title="Cloud Security Posture Management" target="_blank">Cloud Security Posture Management</a> (CSPM)-Tools zu ergänzen. Dabei fokussieren die DSPM-Werkzeuge jedoch nicht auf Cloud-Infrastrukturen selbst, sondern ausschließlich auf Daten sowie darauf, wie diese durch die verschiedenen Services genutzt werden. In vielen Fällen haben DSPM-Anbieter deswegen auch CSPM-Offerings im Portfolio.</p>



<h2 class="wp-block-heading">DSPM-Produkte evaluieren</h2>



<p>Tools im Bereich Data Security Posture Management zu evaluieren, erfordert erheblichen Personalaufwand, da viele verschiedene Aspekte der IT-Infrastruktur eines Unternehmens davon betroffen sind. Das ist allerdings auch gut so, schließlich wollen Sie ja auch alle relevanten Daten identifizieren. Hilfreich ist zu diesem Zweck insbesondere ein Plan, der die wichtigsten Daten nach Priorität ordnet. Ein weiterer Tipp: Dokumentieren Sie, wie die einzelnen DSPM-Tools ihre Data Map erstellen und wie diese – und die darauf basierenden Dashboards – zu interpretieren sind. Schließlich ist es bei der Entscheidung über ein DSPM-Tool essenziell zu wissen, welche spezifischen Cloud Services abgedeckt sind und welche (noch) nicht.</p>



<p>Was die Preisgestaltung von DSPM-Tools angeht, ist diese im Regelfall flexibel gestaltet und hängt von diversen Faktoren ab. Das Gros der Anbieter setzt auf entsprechende Abo-Modelle. Sicher ist, dass das teuer wird: Sie dürfen pro Jahr mit einer sechsstelligen Summe rechnen. Eine weitere Vorwarnung: Es wird Sie einiges an Zeit und Mühe kosten, den Umfang, das Integrationsniveau und die enthaltenen Schutzfunktionen der einzelnen DSPM-Angebote bis ins letzte Detail zu durchdringen.</p>



<h2 class="wp-block-heading">Die besten DSPM-Tools</h2>



<p>Im Folgenden haben wir die aktuell wichtigsten DSPM-Anbieter und ihre Offerings für Sie zusammengestellt. </p>



<ul class="wp-block-list">
<li><strong><a href="https://concentric.ai/product-overview/" target="_blank" rel="noreferrer noopener">Concentric Semantic Intelligence</a></strong></li>



<li><strong><a href="https://www.cyera.io/platform" target="_blank" rel="noreferrer noopener">Cyera Data Security Platform</a></strong></li>



<li><strong><a href="https://www.ibm.com/guardium" target="_blank" rel="noreferrer noopener">IBM Guardium</a></strong></li>



<li><strong><a href="https://www.onetrust.com/platform/data-discovery-and-security/" target="_blank" rel="noreferrer noopener">Onetrust Data Use Governance</a></strong></li>



<li><strong><a href="https://www.prismacloud.io/prisma/cloud/cloud-data-security" target="_blank" rel="noreferrer noopener">Palo Alto Networks Prisma Cloud DSPM</a></strong></li>



<li><a href="https://www.proofpoint.com/de/products/data-security-posture-management" target="_blank" rel="noreferrer noopener">Proofpoint DSPM</a></li>



<li><strong><a href="https://securiti.ai/" target="_blank" rel="noreferrer noopener">Securiti Data Command Center DSPM</a></strong></li>



<li><strong><a href="https://www.sentra.io/product" target="_blank" rel="noreferrer noopener">Sentra Cloud-Native Data Security Platform</a></strong></li>



<li><strong><a href="https://www.symmetry-systems.com/dataguard-dspm/" target="_blank" rel="noreferrer noopener">Symmetry Modern Data Security Platform</a></strong></li>



<li><a href="https://www.tenable.com/cloud-security/solutions/dspm" target="_blank" rel="noreferrer noopener">Tenable DSPM</a></li>



<li><strong><a href="https://www.varonis.com/products/data-security-platform" target="_blank" rel="noreferrer noopener">Varonis Data Security Platform</a></strong></li>



<li><strong><a href="https://www.wiz.io/solutions/dspm" target="_blank" rel="noreferrer noopener">Wiz DSPM</a></strong></li>
</ul>



<p>(fm)</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-33769 | withastro up to 5.18.0 Image Optimization Endpoint information disclosure (GHSA-g735-7g2w-hh3f / EUVD-2026-14984)]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in withastro astro up to 5.18.0. This vulnerability affects unknown code of the component Image Optimization Endpoint. Performing a manipulation results in information disclosure.

This vulnerability is cataloged as CVE-2026-33769. It is pos...]]></description>
<link>https://tsecurity.de/de/3390434/sicherheitsluecken/cve-2026-33769-withastro-up-to-5180-image-optimization-endpoint-information-disclosure-ghsa-g735-7g2w-hh3f-euvd-2026-14984/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3390434/sicherheitsluecken/cve-2026-33769-withastro-up-to-5180-image-optimization-endpoint-information-disclosure-ghsa-g735-7g2w-hh3f-euvd-2026-14984/</guid>
<pubDate>Sun, 29 Mar 2026 09:53:38 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">problematic</a> has been reported in <a href="https://vuldb.com/product/withastro:astro">withastro astro up to 5.18.0</a>. This vulnerability affects unknown code of the component <em>Image Optimization Endpoint</em>. Performing a manipulation results in information disclosure.

This vulnerability is cataloged as <a href="https://vuldb.com/source_cve/352840">CVE-2026-33769</a>. It is possible to initiate the attack remotely. There is no exploit available.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-33768 | withastro up to 10.0.1 Query Parameter x_astro_path confused deputy (GHSA-mr6q-rp88-fx84 / EUVD-2026-14982)]]></title>
<description><![CDATA[A vulnerability classified as critical was found in withastro astro up to 10.0.1. The affected element is an unknown function of the component Query Parameter Handler. The manipulation of the argument x_astro_path results in unintended intermediary.

This vulnerability is reported as CVE-2026-337...]]></description>
<link>https://tsecurity.de/de/3390431/sicherheitsluecken/cve-2026-33768-withastro-up-to-1001-query-parameter-xastropath-confused-deputy-ghsa-mr6q-rp88-fx84-euvd-2026-14982/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3390431/sicherheitsluecken/cve-2026-33768-withastro-up-to-1001-query-parameter-xastropath-confused-deputy-ghsa-mr6q-rp88-fx84-euvd-2026-14982/</guid>
<pubDate>Sun, 29 Mar 2026 09:53:05 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> was found in <a href="https://vuldb.com/product/withastro:astro">withastro astro up to 10.0.1</a>. The affected element is an unknown function of the component <em>Query Parameter Handler</em>. The manipulation of the argument <em>x_astro_path</em> results in unintended intermediary.

This vulnerability is reported as <a href="https://vuldb.com/source_cve/352843">CVE-2026-33768</a>. The attack can be launched remotely. No exploit exists.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-29772 | withastro up to 9.x POST /_server-islands/ JSON.parse allocation of resources (GHSA-3rmj-9m5h-8fpv / EUVD-2026-14962)]]></title>
<description><![CDATA[A vulnerability was found in withastro astro up to 9.x. It has been classified as problematic. This vulnerability affects the function JSON.parse of the file /_server-islands/ of the component POST Handler. This manipulation causes allocation of resources.

This vulnerability is handled as CVE-20...]]></description>
<link>https://tsecurity.de/de/3390274/sicherheitsluecken/cve-2026-29772-withastro-up-to-9x-post-server-islands-jsonparse-allocation-of-resources-ghsa-3rmj-9m5h-8fpv-euvd-2026-14962/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3390274/sicherheitsluecken/cve-2026-29772-withastro-up-to-9x-post-server-islands-jsonparse-allocation-of-resources-ghsa-3rmj-9m5h-8fpv-euvd-2026-14962/</guid>
<pubDate>Sun, 29 Mar 2026 07:56:33 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/withastro:astro">withastro astro up to 9.x</a>. It has been classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This vulnerability affects the function <code>JSON.parse</code> of the file <em>/_server-islands/</em> of the component <em>POST Handler</em>. This manipulation causes allocation of resources.

This vulnerability is handled as <a href="https://vuldb.com/source_cve/352862">CVE-2026-29772</a>. The attack can be initiated remotely. There is not any exploit available.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[Equinix launches AI platform to simplify control of distributed AI resources]]></title>
<description><![CDATA[An age-old problem for enterprise IT managers has always been data sprawl. However, in the era of AI, where data is needed from every potential source available, scale in data sprawl become unmanageable. Existing architectures weren’t designed for distributing processing, which is part and parcel...]]></description>
<link>https://tsecurity.de/de/3387583/it-security-nachrichten/equinix-launches-ai-platform-to-simplify-control-of-distributed-ai-resources/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3387583/it-security-nachrichten/equinix-launches-ai-platform-to-simplify-control-of-distributed-ai-resources/</guid>
<pubDate>Fri, 27 Mar 2026 20:36:39 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>An age-old problem for enterprise IT managers has always been data <a href="https://www.networkworld.com/article/4067370/tool-sprawl-hampers-enterprise-observability-efforts.html">sprawl</a>. However, in the era of AI, where data is needed from every potential source available, scale in <a href="https://www.networkworld.com/article/4062258/balancing-ais-opportunities-and-challenges-to-serve-enterprises.html">data sprawl become unmanageabl</a>e. Existing architectures weren’t designed for distributing processing, which is part and parcel of AI training.</p>



<p>Data center provider Equinix says it has the solution:  The Distributed AI Hub powered by Equinix Fabric Intelligence. The <a href="https://simplywall.st/stocks/us/real-estate/nasdaq-eqix/equinix/news/should-equinixs-eqix-new-distributed-ai-hub-reshape-how-inve/amp">platform</a> offers a unified framework offering connectivity across locations to bring together data center, edge, or clouds and  AI models or resources. </p>



<p>“Every enterprise has come to the realization that AI is not centralized,” said Arun Dev, vice president and global head of Digital Interconnection at Equinix. “What’s becoming more important is inference at the edge, agentic, and this is where the conversations with our customers led us to really look at this distributed AI framework, where they were struggling with a few things.”</p>



<p>For starters, customers tell Equinix that they’ve got data in multiple public clouds, Equinix colocation data centers, on prem locations and neo-clouds and other data platforms. In this scenario, there’s concerns around how customers get visibility across all of these different sources of data that are in different locations, according to Dev.</p>



<p>There are about 3,000 cloud and IT service providers available through Equinix, Dev said. That includes major hyperscale cloud providers, tier two and smaller clouds, all of them have a presence. The framework builds connections between all of the service providers as well as colocation and on-premises systems.</p>



<p>The AI Hub includes a new AI-ready backbone to support distributed AI deployments, a global AI Solutions Lab to test new solutions, and Fabric Intelligence to better support next-generation workloads for enterprises.</p>



<p>Fabric Intelligence is a software layer that enhances Equinix Fabric, the company’s on-demand global interconnection service, with real-time awareness and automation for AI and multicloud workloads. It is integrated with AI orchestration tools to automate connectivity decisions, taps into live telemetry for deep observability, and dynamically adjusts routing and segmentation to optimize performance and simplify network operations.</p>



<p>To support customers with their AI migration, Equinix is launching a global AI Solutions Lab across 20 locations in 10 countries to give enterprises an environment to collaborate with leading AI partners. Dev said the lab has several customers that are “dipping their toes” when it comes to AI and Equinix helps them validate AI architectures and AI technologies.</p>



<p>“The solution validation center is where [pilot programs] become real, and it gives customers the confidence to be able to deploy play in this environment before they move off and actually implement it,” he said.</p>



<p>The AI Hub basically provides the orchestration layer for Equinix’s Distributed AI infrastructure <a href="https://www.networkworld.com/article/4063434/equinix-unveils-distributed-ai-infrastructure-targeting-inferencing-cloud-connectivity.html">announced last fall</a> that provides the physical network for the platform.</p>



<p>Dev said the hub is a reference framework, so if customers want to run virtual instances at Equinix, or if customers want to deploy this in their own colocation environment, they’re free to do either. Or customers can take the framework and modify it to their own specific needs.</p>



<p>Equinix announced too that the AI Hub would integrate security support from <a href="https://blog.equinix.com/blog/2026/03/11/equinix-and-palo-alto-networks-partner-to-enable-ai-you-can-trust/">Palo Alto Networks</a> and its <a href="https://www.networkworld.com/article/4084195/palo-alto-networks-readies-security-for-ai-first-world.html">Prisma AIRS real-time AI</a> security and centralized policy enforcement package.   The idea is to bring real-time AI security and centralized policy enforcement across any location.  The Prisma AIRS package will be available on Equinix Network Edge, letting organizations centrally manage AI-driven security services at the digital edge, closer to users, clouds and critical workloads, according to Equinix.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[heise+ | Fotografieren am Klöntalersee in der Schweiz: Farben, Nebel und tolle Fotospots]]></title>
<description><![CDATA[Spiegelungen, Nebel und Sternenhimmel: So nutzen Sie den See für beeindruckende Astro- und Landschaftsfotografie.]]></description>
<link>https://tsecurity.de/de/3387224/it-nachrichten/heise-fotografieren-am-kloentalersee-in-der-schweiz-farben-nebel-und-tolle-fotospots/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3387224/it-nachrichten/heise-fotografieren-am-kloentalersee-in-der-schweiz-farben-nebel-und-tolle-fotospots/</guid>
<pubDate>Fri, 27 Mar 2026 18:01:58 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Spiegelungen, Nebel und Sternenhimmel: So nutzen Sie den See für beeindruckende Astro- und Landschaftsfotografie.]]></content:encoded>
</item>
<item>
<title><![CDATA[Vom Desktop ins Web – der neue Atlas der Schweiz (fossgis2026)]]></title>
<description><![CDATA[Der Atlas der Schweiz ist der offizielle Nationalatlas und wird seit 1961 von der ETH Zürich herausgegeben. Die Desktop-Version (gestartet in 2016) basiert auf einem interaktiven 3D-Globus mit über 400 thematischen Karten. Dank neuer Webtechnologien – vom Rendering, über UI bis zu Geodatenformate...]]></description>
<link>https://tsecurity.de/de/3384221/it-security-video/vom-desktop-ins-web-der-neue-atlas-der-schweiz-fossgis2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3384221/it-security-video/vom-desktop-ins-web-der-neue-atlas-der-schweiz-fossgis2026/</guid>
<pubDate>Thu, 26 Mar 2026 18:20:56 +0100</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Der Atlas der Schweiz ist der offizielle Nationalatlas und wird seit 1961 von der ETH Zürich herausgegeben. Die Desktop-Version (gestartet in 2016) basiert auf einem interaktiven 3D-Globus mit über 400 thematischen Karten. Dank neuer Webtechnologien – vom Rendering, über UI bis zu Geodatenformaten – konnte der Atlas ins Web migriert und einer grösseren Nutzerschaft zugänglich gemacht werden. Der Vortrag zeigt Konzeption, UX-Design, Architektur und den Einsatz offener Webtechnologien.

Ziel des Vortrags ist es, die Migration eines umfassenden digitalen Atlas in moderne Webtechnologien aufzuzeigen und dabei einen möglichst ganzheitlichen Einblick in das Vorgehen und die technischen Entscheidungen zu geben.
Zu Beginn werden die Ausgangslage und die Zielsetzung erläutert: Der Atlas der Schweiz, bisher als Desktop-Applikation mit Online-Backend verfügbar, soll einer breiteren Öffentlichkeit über den Browser zugänglich gemacht werden. Dabei galt es, eine Lösung zu finden, die hohe kartografische Qualität, Performance, Sicherheit und langfristige Wartbarkeit vereint.
Im Anschluss wird der konzeptionelle Teil des Vorgehens beschrieben – von der Ideen- und Konzeptphase über das User-Experience-Design bis hin zum User-Testing, das in Zusammenarbeit mit einer spezialisierten Agentur durchgeführt wurde.
Darauf folgt der technische Teil des Vortrags: die Wahl des geeigneten Karten-Rendering-Frameworks (Kombination von MapLibre und Deck.gl), die Software-Architektur des neuen Systems sowie die Entscheidung für moderne Frontend-Technologien wie Astro (Static Site Generation), Vue.js und Tailwind CSS.
Ein weiteres Kapitel widmet sich der Migration der bestehenden Inhalte und Datenstrukturen in das neue System, gefolgt von einer kurzen Demo der aktuellen Public Beta-Version des Atlas der Schweiz.
Zum Abschluss wird ein Ausblick auf die geplante Weiterentwicklung des Projekts gegeben – darunter neue Themen, Performance-Optimierungen und die Integration zusätzlicher 3D-Funktionen.

Der Vortrag richtet sich an Personen mit Interesse an Webentwicklung, Webkarten und der Anwendung moderner Open-Source-Technologien in der Kartografie.

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://pretalx.com/fossgis2026/talk/YWJM3W/]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-33769 | withastro up to 5.18.0 Image Optimization Endpoint information disclosure (GHSA-g735-7g2w-hh3f / EUVD-2026-14984)]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in withastro astro up to 5.18.0. This vulnerability affects unknown code of the component Image Optimization Endpoint. Performing a manipulation results in information disclosure.

This vulnerability is cataloged as CVE-2026-33769. It is pos...]]></description>
<link>https://tsecurity.de/de/3378112/sicherheitsluecken/cve-2026-33769-withastro-up-to-5180-image-optimization-endpoint-information-disclosure-ghsa-g735-7g2w-hh3f-euvd-2026-14984/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3378112/sicherheitsluecken/cve-2026-33769-withastro-up-to-5180-image-optimization-endpoint-information-disclosure-ghsa-g735-7g2w-hh3f-euvd-2026-14984/</guid>
<pubDate>Tue, 24 Mar 2026 21:51:41 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/?kb.risk">problematic</a> has been reported in <a href="https://vuldb.com/?product.withastro:astro">withastro astro up to 5.18.0</a>. This vulnerability affects unknown code of the component <em>Image Optimization Endpoint</em>. Performing a manipulation results in information disclosure.

This vulnerability is cataloged as <a href="https://vuldb.com/?source_cve.352840">CVE-2026-33769</a>. It is possible to initiate the attack remotely. There is no exploit available.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-33768 | withastro up to 10.0.1 Query Parameter x_astro_path confused deputy (GHSA-mr6q-rp88-fx84 / EUVD-2026-14982)]]></title>
<description><![CDATA[A vulnerability classified as critical was found in withastro astro up to 10.0.1. The affected element is an unknown function of the component Query Parameter Handler. The manipulation of the argument x_astro_path results in unintended intermediary.

This vulnerability is reported as CVE-2026-337...]]></description>
<link>https://tsecurity.de/de/3378111/sicherheitsluecken/cve-2026-33768-withastro-up-to-1001-query-parameter-xastropath-confused-deputy-ghsa-mr6q-rp88-fx84-euvd-2026-14982/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3378111/sicherheitsluecken/cve-2026-33768-withastro-up-to-1001-query-parameter-xastropath-confused-deputy-ghsa-mr6q-rp88-fx84-euvd-2026-14982/</guid>
<pubDate>Tue, 24 Mar 2026 21:51:40 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/?kb.risk">critical</a> was found in <a href="https://vuldb.com/?product.withastro:astro">withastro astro up to 10.0.1</a>. The affected element is an unknown function of the component <em>Query Parameter Handler</em>. The manipulation of the argument <em>x_astro_path</em> results in unintended intermediary.

This vulnerability is reported as <a href="https://vuldb.com/?source_cve.352843">CVE-2026-33768</a>. The attack can be launched remotely. No exploit exists.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-29772 | withastro up to 9.x POST /_server-islands/ JSON.parse allocation of resources (GHSA-3rmj-9m5h-8fpv / EUVD-2026-14962)]]></title>
<description><![CDATA[A vulnerability was found in withastro astro up to 9.x. It has been classified as problematic. This vulnerability affects the function JSON.parse of the file /_server-islands/ of the component POST Handler. This manipulation causes allocation of resources.

This vulnerability is handled as CVE-20...]]></description>
<link>https://tsecurity.de/de/3378108/sicherheitsluecken/cve-2026-29772-withastro-up-to-9x-post-server-islands-jsonparse-allocation-of-resources-ghsa-3rmj-9m5h-8fpv-euvd-2026-14962/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3378108/sicherheitsluecken/cve-2026-29772-withastro-up-to-9x-post-server-islands-jsonparse-allocation-of-resources-ghsa-3rmj-9m5h-8fpv-euvd-2026-14962/</guid>
<pubDate>Tue, 24 Mar 2026 21:51:36 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.withastro:astro">withastro astro up to 9.x</a>. It has been classified as <a href="https://vuldb.com/?kb.risk">problematic</a>. This vulnerability affects the function <code>JSON.parse</code> of the file <em>/_server-islands/</em> of the component <em>POST Handler</em>. This manipulation causes allocation of resources.

This vulnerability is handled as <a href="https://vuldb.com/?source_cve.352862">CVE-2026-29772</a>. The attack can be initiated remotely. There is not any exploit available.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[Palo Alto Networks’ Prisma AIRS 3.0 closes visibility gaps in autonomous AI systems]]></title>
<description><![CDATA[Palo Alto Networks has advanced its AI security platform with Prisma AIRS 3.0, securing the agentic AI lifecycle and enabling enterprises to move from observation to safe autonomous execution. The shift toward an AI-powered enterprise introduces systemic security challenges, ranging from unmanage...]]></description>
<link>https://tsecurity.de/de/3375731/it-security-nachrichten/palo-alto-networks-prisma-airs-30-closes-visibility-gaps-in-autonomous-ai-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3375731/it-security-nachrichten/palo-alto-networks-prisma-airs-30-closes-visibility-gaps-in-autonomous-ai-systems/</guid>
<pubDate>Tue, 24 Mar 2026 09:36:41 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Palo Alto Networks has advanced its AI security platform with Prisma AIRS 3.0, securing the agentic AI lifecycle and enabling enterprises to move from observation to safe autonomous execution. The shift toward an AI-powered enterprise introduces systemic security challenges, ranging from unmanaged shadow AI to the critical new frontiers of agentic identity, runtime security, and automated governance. While many enterprises monitor what AI says, they remain blind to what AI does. Prisma AIRS 3.0 closes … <a href="https://www.helpnetsecurity.com/2026/03/24/palo-alto-networks-prisma-airs-3-0-closes-visibility-gaps-in-autonomous-ai-systems/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/03/24/palo-alto-networks-prisma-airs-3-0-closes-visibility-gaps-in-autonomous-ai-systems/">Palo Alto Networks’ Prisma AIRS 3.0 closes visibility gaps in autonomous AI systems</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Palo Alto Networks’ Prisma AIRS 3.0 closes visibility gaps in autonomous AI systems]]></title>
<description><![CDATA[Palo Alto Networks has advanced its AI security platform with Prisma AIRS 3.0, securing the agentic AI lifecycle and enabling enterprises to move from observation to safe autonomous execution. The shift toward an AI-powered enterprise introduces systemic security challenges, ranging…
Read more →
...]]></description>
<link>https://tsecurity.de/de/3375727/it-security-nachrichten/palo-alto-networks-prisma-airs-30-closes-visibility-gaps-in-autonomous-ai-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3375727/it-security-nachrichten/palo-alto-networks-prisma-airs-30-closes-visibility-gaps-in-autonomous-ai-systems/</guid>
<pubDate>Tue, 24 Mar 2026 09:36:35 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Palo Alto Networks has advanced its AI security platform with Prisma AIRS 3.0, securing the agentic AI lifecycle and enabling enterprises to move from observation to safe autonomous execution. The shift toward an AI-powered enterprise introduces systemic security challenges, ranging…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/palo-alto-networks-prisma-airs-3-0-closes-visibility-gaps-in-autonomous-ai-systems/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/palo-alto-networks-prisma-airs-3-0-closes-visibility-gaps-in-autonomous-ai-systems/">Palo Alto Networks’ Prisma AIRS 3.0 closes visibility gaps in autonomous AI systems</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Palo Alto updates security platform to discover AI agents]]></title>
<description><![CDATA[As CISOs worry about AI agent sprawl, Palo Alto Networks has announced an update to its Prisma AIRS security platform and enterprise browser to include the ability to discover AI agents, models, and connections across the entire IT environment, to scan agents for vulnerabilities, and to allow adm...]]></description>
<link>https://tsecurity.de/de/3375092/it-security-nachrichten/palo-alto-updates-security-platform-to-discover-ai-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3375092/it-security-nachrichten/palo-alto-updates-security-platform-to-discover-ai-agents/</guid>
<pubDate>Tue, 24 Mar 2026 01:36:46 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>As CISOs worry about AI agent sprawl, Palo Alto Networks has announced an update to its Prisma AIRS security platform and enterprise browser to include the ability to discover AI agents, models, and connections across the entire IT environment, to scan agents for vulnerabilities, and to allow admins to simulate red team tests for agents.</p>



<p>Assuming the completion of Palo Alto Networks’ <a href="https://www.paloaltonetworks.com/company/press/2026/palo-alto-networks-announces-intent-to-acquire-koi-to-secure-the-agentic-endpoint" target="_blank" rel="noreferrer noopener">planned acquisition of Koi Security</a>, it said, Prisma AIRS 3.0 will soon also offer an AI Agent Gateway providing a central control plane to enforce agent runtime and identity security.</p>



<p><a href="https://www.gartner.com/en/newsroom/press-releases/2025-08-26-gartner-predicts-40-percent-of-enterprise-apps-will-feature-task-specific-ai-agents-by-2026-up-from-less-than-5-percent-in-2025" target="_blank" rel="noreferrer noopener">According to Gartner</a>, 40% of enterprise applications will be integrated with task-specific AI agents by the end of this year, up from less than 5% today. As organizations accelerate their digital transformation, agentic AI in enterprise applications will move beyond individual productivity, Gartner says, setting new standards for teamwork and workflow through smarter human-agent interactions.</p>



<p>To meet that challenge, Prisma AIRS is adding new ways to use AI to detect AI application security issues. In a prerelease briefing for reporters, Nikesh Arora, CEO of Palo Alto Networks, predicted, “in next five years, our customers are going to go through the most significant overhaul of their enterprise networks they’ve ever seen” because of AI.</p>



<p>“Every CIO wants AI implemented yesterday,” he said. “Every company wants to see how they can leverage AI as quickly as possible,” wants to understand if the shift to AI is real, and if so, how CIOs need to prepare.</p>



<p>“Can we use AI to deliver better cybersecurity outcomes? Yes, we can,” he said. But it won’t happen overnight. In fact, he said, the pace at which large language models (LLMs) are moving is significantly expanding the attack surface.</p>



<p>Recently, he said, there have been news reports that AI agents created by firms caused hacks within their own companies. He didn’t cite specific examples, but <a href="https://www.msn.com/en-us/news/other/rogue-ai-triggers-major-meta-data-breach/gm-GM7C517F59" target="_blank" rel="noreferrer noopener">last week Meta said</a> there had been a severe internal security breach after an autonomous AI agent exposed sensitive company and user data to unauthorized employees for two hours.</p>



<p>In the future, if agents in the enterprise are more than a fad, Arora said, “there will be millions of agents traversing enterprise architectures, trying to execute on their behalf — both agents delegated by people like you and me, and autonomously. I can’t imagine meeting a CEO in the last three months who does not have some aspiration to start having agents effectively doing tasks within the enterprise. It’s slow going, but the intention is there. And I can see many system integrators and consultants out there advocating and helping customers with that migration.”</p>



<p>But, he added, there are risks. To meet them, Prisma AIRS 3.0 will allow admins to safely deploy AI applications, he said. To increase visibility, the platform will identify agents running in cloud environments, on SaaS platforms and locally on endpoints. A capability called Agent Artifact Security maps out an agent’s architecture and scans for vulnerabilities, and another capability called AI Red Teaming for Agents simulates context-aware agentic attacks, discovers AI-related vulnerabilities, and recommends runtime security policies.</p>



<h2 class="wp-block-heading">Prisma Browser</h2>



<p>To also improve AI security, Palo Alto Networks released a new version of Prisma Browser for enterprise end users, with expanded capabilities allowing employees to use any LLM they choose. The new version of the browser is able to discover user-generated AI activity and enforce content-aware boundaries to keep agents within their intended scope. The browser also prevents sensitive data from leaking to unmanaged or public AI tools during automated tasks, identifies and blocks prompt injection attacks, including malicious instructions designed to hijack AI agents hidden within websites. </p>



<p>Palo Alto Networks said the browser also provides real-time distinction between human actions and automated AI tasks. By assessing the intentions of both human and non-human identities, Prisma Browser enables total accountability and compliance with evolving global AI regulations</p>



<h2 class="wp-block-heading">Next Generation Trust Security</h2>



<p>Separately, Palo Alto Networks also announced a new digital certificate lifecycle management platform, following the closing last month of its <a href="https://www.csoonline.com/article/4131325/palo-alto-closes-privileged-access-gap-with-25b-cyberark-acquisition.html" target="_blank">acquisition of CyberArk</a>.</p>



<p>By integrating CyberArk’s machine identity intelligence into the network, NGTS closes the gap between the teams managing certificates and the teams responsible for uptime, Palo Alto Networks said in a press release.</p>



<p>The company said that Next Generation Trust Security (NGTS) will help organizations deal with the fact that the maximum lifespan of digital certificates<a href="https://www.csoonline.com/article/4097721/how-cisos-can-prepare-for-the-new-era-of-short-lived-tls-certificates.html" target="_blank"> has just been cut to 200 days</a> from 398 days, and by 2029 will fall to just 47 days. Until now, many companies have been keeping track of certificates through spreadsheets, says Palo Alto Networks; NGTS discovers and manages the lifecycle of certificates across the network for them.</p>



<p>The company said that NGTS also eliminates unapproved certificates and blind spots that lead to security gaps, protects the business from certificate-related outages and trust failures by automatically identifying and refreshing credentials before they expire and disrupt customer transactions or internal services, and accelerates the transition to a post-quantum future by handling faster renewal cycles and evolving encryption standards through automation.</p>



<p>Palo Alto Networks has not announced pricing for NGTS.</p>



<p><em>This article originally appeared on <a href="https://www.csoonline.com/article/4148974/palo-alto-updates-security-platform-to-discover-ai-agents.html" target="_blank">CSOonline</a>.</em></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Palo Alto updates security platform to discover AI agents]]></title>
<description><![CDATA[As CISOs worry about AI agent sprawl, Palo Alto Networks has announced an update to its Prisma AIRS security platform and enterprise browser to include the ability to discover AI agents, models, and connections across the entire IT environment, to scan agents for vulnerabilities, and to allow adm...]]></description>
<link>https://tsecurity.de/de/3375083/it-security-nachrichten/palo-alto-updates-security-platform-to-discover-ai-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3375083/it-security-nachrichten/palo-alto-updates-security-platform-to-discover-ai-agents/</guid>
<pubDate>Tue, 24 Mar 2026 01:21:22 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>As CISOs worry about AI agent sprawl, Palo Alto Networks has announced an update to its Prisma AIRS security platform and enterprise browser to include the ability to discover AI agents, models, and connections across the entire IT environment, to scan agents for vulnerabilities, and to allow admins to simulate red team tests for agents.</p>



<p>Assuming the completion of Palo Alto Networks’ <a href="https://www.paloaltonetworks.com/company/press/2026/palo-alto-networks-announces-intent-to-acquire-koi-to-secure-the-agentic-endpoint" target="_blank" rel="noreferrer noopener">planned acquisition of Koi Security</a>, it said, Prisma AIRS 3.0 will soon also offer an AI Agent Gateway providing a central control plane to enforce agent runtime and identity security.</p>



<p><a href="https://www.gartner.com/en/newsroom/press-releases/2025-08-26-gartner-predicts-40-percent-of-enterprise-apps-will-feature-task-specific-ai-agents-by-2026-up-from-less-than-5-percent-in-2025" target="_blank" rel="noreferrer noopener">According to Gartner</a>, 40% of enterprise applications will be integrated with task-specific AI agents by the end of this year, up from less than 5% today. As organizations accelerate their digital transformation, agentic AI in enterprise applications will move beyond individual productivity, Gartner says, setting new standards for teamwork and workflow through smarter human-agent interactions.</p>



<p>To meet that challenge, Prisma AIRS is adding new ways to use AI to detect AI application security issues. In a prerelease briefing for reporters, Nikesh Arora, CEO of Palo Alto Networks, predicted, “in next five years, our customers are going to go through the most significant overhaul of their enterprise networks they’ve ever seen” because of AI.</p>



<p>“Every CIO wants AI implemented yesterday,” he said. “Every company wants to see how they can leverage AI as quickly as possible,” wants to understand if the shift to AI is real, and if so, how CIOs need to prepare.</p>



<p>“Can we use AI to deliver better cybersecurity outcomes? Yes, we can,” he said. But it won’t happen overnight. In fact, he said, the pace at which large language models (LLMs) are moving is significantly expanding the attack surface.</p>



<p>Recently, he said, there have been news reports that AI agents created by firms caused hacks within their own companies. He didn’t cite specific examples, but <a href="https://www.msn.com/en-us/news/other/rogue-ai-triggers-major-meta-data-breach/gm-GM7C517F59" target="_blank" rel="noreferrer noopener">last week Meta said</a> there had been a severe internal security breach after an autonomous AI agent exposed sensitive company and user data to unauthorized employees for two hours.</p>



<p>In the future, if agents in the enterprise are more than a fad, Arora said, “there will be millions of agents traversing enterprise architectures, trying to execute on their behalf — both agents delegated by people like you and me, and autonomously. I can’t imagine meeting a CEO in the last three months who does not have some aspiration to start having agents effectively doing tasks within the enterprise. It’s slow going, but the intention is there. And I can see many system integrators and consultants out there advocating and helping customers with that migration.”</p>



<p>But, he added, there are risks. To meet them, Prisma AIRS 3.0 will allow admins to safely deploy AI applications, he said. To increase visibility, the platform will identify agents running in cloud environments, on SaaS platforms and locally on endpoints. A capability called Agent Artifact Security maps out an agent’s architecture and scans for vulnerabilities, and another capability called AI Red Teaming for Agents simulates context-aware agentic attacks, discovers AI-related vulnerabilities, and recommends runtime security policies.</p>



<h2 class="wp-block-heading">Prisma Browser</h2>



<p>To also improve AI security, Palo Alto Networks released a new version of Prisma Browser for enterprise end users, with expanded capabilities allowing employees to use any LLM they choose. The new version of the browser is able to discover user-generated AI activity and enforce content-aware boundaries to keep agents within their intended scope. The browser also prevents sensitive data from leaking to unmanaged or public AI tools during automated tasks, identifies and blocks prompt injection attacks, including malicious instructions designed to hijack AI agents hidden within websites. </p>



<p>Palo Alto Networks said the browser also provides real-time distinction between human actions and automated AI tasks. By assessing the intentions of both human and non-human identities, Prisma Browser enables total accountability and compliance with evolving global AI regulations</p>



<h2 class="wp-block-heading">Next Generation Trust Security</h2>



<p>Separately, Palo Alto Networks also announced a new digital certificate lifecycle management platform, following the closing last month of its <a href="https://www.csoonline.com/article/4131325/palo-alto-closes-privileged-access-gap-with-25b-cyberark-acquisition.html" target="_blank">acquisition of CyberArk</a>.</p>



<p>By integrating CyberArk’s machine identity intelligence into the network, NGTS closes the gap between the teams managing certificates and the teams responsible for uptime, Palo Alto Networks said in a press release.</p>



<p>The company said that Next Generation Trust Security (NGTS) will help organizations deal with the fact that the maximum lifespan of digital certificates<a href="https://www.csoonline.com/article/4097721/how-cisos-can-prepare-for-the-new-era-of-short-lived-tls-certificates.html" target="_blank"> has just been cut to 200 days</a> from 398 days, and by 2029 will fall to just 47 days. Until now, many companies have been keeping track of certificates through spreadsheets, says Palo Alto Networks; NGTS discovers and manages the lifecycle of certificates across the network for them.</p>



<p>The company said that NGTS also eliminates unapproved certificates and blind spots that lead to security gaps, protects the business from certificate-related outages and trust failures by automatically identifying and refreshing credentials before they expire and disrupt customer transactions or internal services, and accelerates the transition to a post-quantum future by handling faster renewal cycles and evolving encryption standards through automation.</p>



<p>Palo Alto Networks has not announced pricing for NGTS.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Securing the Enterprise AI Ecosystem with ServiceNow and Prisma AIRS]]></title>
<description><![CDATA[Prisma AIRS integrates with ServiceNow AI Control Tower for unified AI governance and real-time security. Accelerate your enterprise AI adoption securely. The post Securing the Enterprise AI Ecosystem with ServiceNow and Prisma AIRS appeared first on Palo Alto Networks Blog.…
Read more →
The post...]]></description>
<link>https://tsecurity.de/de/3368134/it-security-nachrichten/securing-the-enterprise-ai-ecosystem-with-servicenow-and-prisma-airs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3368134/it-security-nachrichten/securing-the-enterprise-ai-ecosystem-with-servicenow-and-prisma-airs/</guid>
<pubDate>Sat, 21 Mar 2026 00:20:42 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Prisma AIRS integrates with ServiceNow AI Control Tower for unified AI governance and real-time security. Accelerate your enterprise AI adoption securely. The post Securing the Enterprise AI Ecosystem with ServiceNow and Prisma AIRS appeared first on Palo Alto Networks Blog.…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/securing-the-enterprise-ai-ecosystem-with-servicenow-and-prisma-airs/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/securing-the-enterprise-ai-ecosystem-with-servicenow-and-prisma-airs/">Securing the Enterprise AI Ecosystem with ServiceNow and Prisma AIRS</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Astro Oblivion, FreePBX, GitHub, OWASP, Promptlock, Claude Aaran Leyland - SWN #507]]></title>
<description><![CDATA[Porn bombing the celestial zoom room and Astro Oblivion, FreePBX, GitHub, OWASP, Promptlock, Claude Aaran Leyland, and More, on this edition of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-507]]></description>
<link>https://tsecurity.de/de/3356180/it-security-nachrichten/astro-oblivion-freepbx-github-owasp-promptlock-claude-aaran-leyland-swn-507/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3356180/it-security-nachrichten/astro-oblivion-freepbx-github-owasp-promptlock-claude-aaran-leyland-swn-507/</guid>
<pubDate>Tue, 17 Mar 2026 17:55:39 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Porn bombing the celestial zoom room and Astro Oblivion, FreePBX, GitHub, OWASP, Promptlock, Claude Aaran Leyland, and More, on this edition of the Security Weekly News.</p> <p>Visit <a rel="noopener" target="_blank" href="https://www.securityweekly.com/swn">https://www.securityweekly.com/swn</a> for all the latest episodes!</p> <p>Show Notes: <a rel="noopener" target="_blank" href="https://securityweekly.com/swn-507">https://securityweekly.com/swn-507</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Who’s in the data-center space race?]]></title>
<description><![CDATA[Tired of paying high-sky electric bills to power your server racks? Tired of paying even more to cool them down? Tired of vibrations and high temperatures messing up your superconducting quantum computers? Tired of your unreliable connections? Get ready for data centers… in SPAAAAAAAACE.



It’s ...]]></description>
<link>https://tsecurity.de/de/3353007/it-security-nachrichten/whos-in-the-data-center-space-race/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3353007/it-security-nachrichten/whos-in-the-data-center-space-race/</guid>
<pubDate>Mon, 16 Mar 2026 15:35:49 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Tired of paying high-sky electric bills to power your server racks? Tired of paying even more to cool them down? Tired of vibrations and high temperatures messing up your superconducting quantum computers? Tired of your unreliable connections? Get ready for data centers… in SPAAAAAAAACE.</p>



<p>It’s easy to imagine the pitch for space-based data centers. But clearly there are obstacles to overcome, starting with <a href="https://techcrunch.com/2026/02/11/why-the-economics-of-orbital-ai-are-so-brutal/">how much money</a> it takes to send anything up there. Plus, if you need to do any kind of maintenance or upgrade, how are you going to get to it? Not to mention the fact that your racks can barely survive a strong kick, much less being strapped to a rocket that literally moves by setting off a bunch of controlled explosions. And then there’s all the space radiation.</p>



<p>But wait. It’s not as crazy as it sounds. For one, think of the environmental benefits.</p>



<p>“Data centers on Earth consume massive amounts of energy,” says <a href="https://www.linkedin.com/in/frederic-grandmont-a4910819/">Frederic Grandmont</a>, technology and business development manager for space and defense systems at engineering company ABB Canada. “In a world where carbon footprints are under scrutiny, a self-cooling, solar-powered server farm seems to be an ideal end-state,” he adds.</p>



<p>In fact, we already have a ton of computing power up there already. There are computers on the International Space Station, in every ship we send up, and in pretty much every satellite whizzing around the Earth. We’ve already figured out the biggest problems—how to keep them working, how to power them, and how to cool them down.</p>



<p>And laser-based communications in space are point-to-point since there’s no atmosphere or much of anything to get in the way, and they happen at the speed of light. In fact, even Earth-to-satellite communications are now getting pretty reliable and delivering low latency, atmosphere and all.</p>



<p>“Data volumes and latency impediments are on the verge of being solved,” says Grandmont.</p>



<p>“Mega-constellations of satellites with direct optical downlinks to Earth are essentially a fiber-optic connection without the cable,” he says. The data is routed at high speeds within nodes of the constellations and then sent to receiving systems with direct views to cloud-free ground stations on Earth.</p>



<p>The next challenges are to scale up, to get the launch costs down, and to figure out the whole maintenance-in-space problem.</p>



<h2 class="wp-block-heading">Who’s in the race?</h2>



<p>All the big players have thrown their hats in the ring.</p>



<p>In January, <a href="https://www.fcc.gov/document/sb-accepts-filing-spacexs-application-orbital-data-centers">SpaceX filed a proposal</a> with the FCC for an orbital data center constellation with up to one million satellites in low Earth orbit. SpaceX, which already has about 10,000 Starlink satellites in orbit, merged with xAI in February and said its new constellation will use solar to power space-based AI data centers. To fully protect its frequencies from interference, SpaceX will also have to file with ITU, the International Telecommunication Union.</p>



<p>SpaceX did not explain when exactly its 1 million satellites will be going up. But it’s not the only company in the race.</p>



<p>In November, Google announced <a href="https://research.google/blog/exploring-a-space-based-scalable-ai-infrastructure-system-design/">Project Suncatcher</a>, a plan to put Google’s TPUs—their answer to Nvidia GPUs—in solar-powered satellite constellations with free-space optical links, so that they can run AI workloads in space.</p>



<p>According to Google, a solar panel in orbit is eight times more productive than one on Earth and produces power continuously, reducing the need for batteries. “This approach would have tremendous potential for scale, and also minimizes impact on terrestrial resources,” wrote <a href="https://www.linkedin.com/in/travisbeals/">Travis Beals</a>, the company’s senior director for paradigms of intelligence.</p>



<p>Google has already tested and validated communications, figured out how to keep all the parts of the data center orbiting in formation, tested the hardiness of their chips against radiation—they passed—and figured out when launch costs would be low enough to make the whole project economically feasible. According to their calculations, they’ll need launch costs to be less than $200 per kilogram, and they expect that milestone to be reached in the mid-2030s. Their next step is to launch two prototype satellites by early 2027. </p>



<p>In mid-November, Nvidia teamed up with satellite company Starcloud to <a href="https://blogs.nvidia.com/blog/starcloud/">launch an Nvidia H100 GPU into space</a> for the first time. The sixty-kilogram satellite is about the size of a small refrigerator, Nvidia said, and will have more than a hundred times more GPU compute than any previous space operation.</p>



<p>According to Nvidia, space-based data centers will eventually cost ten times less than traditional ones, including the launch costs.</p>



<p>One company that’s been in the headlines recently for promising that this cost reduction will come sooner rather than later is SpaceX. “My estimate is that within 2 to 3 years, the lowest cost way to generate AI compute will be in space,” SpaceX CEO Elon Musk said in a <a href="https://www.spacex.com/updates#xai-joins-spacex">press release</a> in February.</p>



<p>In 2025, about 3,000 tons of payload was launched into space, most of it being Starlink satellites carried by SpaceX’s Falcon rocket. But this year, the company’s newest vehicle, Starship, will come online, he said. Starship’s 12th launch is scheduled for April. Starship is designed for full reusability and can carry significantly more cargo than the Falcon, reducing costs. So far, it’s had six successful fights and five explosions.</p>



<p>There are also a number of space startups in the game. Lonestar is a data storage and edge processing services startup that plans to serve data centers on Earth, in space, and even on the moon. In August, it <a href="https://www.lonestarlunar.com/press-release/successful-test-of-solar-system-internet-on-lonestar-mission">launched a data center mission to the moon</a> and did a successful test of their edge processing capabilities.</p>



<p>In Europe, a consortium that includes Ariane Group, Airbus, Thales Alenia Space, and HPE <a href="https://ascend-horizon.eu/">plans to put a data center in space by 2030</a>.</p>



<p>In September, another startup, Axiom Space announced that it will put a <a href="https://www.axiomspace.com/release/axiom-space-spacebilt-announce-orbital-data-center-node">data center on the ISS</a>, with the first nodes to launch soon by the end of this year. The goal is to have three interconnected data center nodes in space by 2027 and to provide computing services to any satellites and spacecraft with compatible optical communication terminals.</p>



<p>Aetherflux, another space infrastructure startup, plans to put its first <a href="https://aetherflux.medium.com/aetherflux-announces-orbital-data-center-targets-q1-2027-dc813d3e2387">orbital data center satellite</a> in orbit by the first quarter of 2027.</p>



<p>In other space infrastructure news, there’s a startup called Star Catcher that is building a space-based power grid. It has signed deals with Loft Orbital, Astro Digital, Starcloud, Satlyt, Mission Space, and other space computing players.</p>



<p>In November, <a href="https://www.star-catcher.com/news/record-breaking-optical-power-beaming-proves-path-to-scalable-power-grid-for-space">Star Catcher ran a ground-based test</a>, setting a new world record for wireless optical power transmission, and plans to have its first in-orbit demonstration next year. The idea is that Star Catcher collects solar power, concentrates it, and beams it to satellites that can’t collect enough on their own for all the on-board stuff they want to do.</p>



<p>The satellites collect that power using the solar panels they already have in place—no modifications required.</p>



<p>Meanwhile, some of the biggest space data projects are already underway, in China. The Aurora 1000 space computer from Comospace <a href="https://global.chinadaily.com.cn/a/202512/05/WS69323706a310d6866eb2d03e.html">has already logged more than 1,000 days of operation</a> on a Jilin-1 satellite, and the next-gen Aurora 5000, which will have a GPU, is scheduled for trials in 2026. </p>



<p>Then there’s the Three Body 12-satellite computing constellation carrying an 8-billion parameter AI model, which was launched last May. In February, <a href="http://english.scio.gov.cn/m/chinavoices/2026-02/14/content_118334369.html">China announced</a> that, after nine months of in-orbit testing, the constellation successfully demonstrated key capabilities in space networking, computing, and model deployment. Called the <a href="https://www.sohu.com/a/980884832_211762">Star Computing project</a>, it will consist of 400 AI training satellites and 2,400 inference computing satellites, capable of tens of thousands of petabytes of inference and millions of petabytes of training power by 2030. By 2035, the network is expected to have enough computing power to support hundreds of millions of AI agents.</p>



<h2 class="wp-block-heading">Extreme edge computing</h2>



<p>We seem to be on the cusp of a major shift in how we use space for our computing needs.</p>



<p>Jeff Bezos <a href="https://www.reuters.com/business/energy/data-centres-space-jeff-bezos-thinks-its-possible-2025-10-03/">predicted last fall</a> that gigawatt-scale data centers will be built in space within the next 10 to 20 years and would outperform those based on Earth.</p>



<p>“The lowest cost place for data centers is space,” <a href="https://x.com/Benioff/status/1991179419285651927">echoed Marc Benioff</a> at a conference in November.</p>



<p>According to <a href="https://www.linkedin.com/in/onikquddus/">Onik Quddus</a>, vice president with Booz Allen’s national security business, the break-even point will come sometime between 2030 and 2035. “At that point, the cost per kilogram will be low enough that deploying hardware in orbit becomes comparable to deploying a terrestrial data center,” he says.</p>



<p>But if you don’t want to wait years for the ability to send your processing to space, there are already companies renting edge-compute capabilities to run AI models in orbit.</p>



<p>“For most technology managers, the first practical use cases won’t be shipping entire cloud workloads to orbit,” says Quddus. “It will be the emergence of edge processing on satellites.”</p>



<p>Satellites can run compact AI models, including small language models, he says. “Which means we can interpret imagery, detect anomalies, compress insights, and respond autonomously.” And do that all in space, without waiting for data to be sent back to Earth, he adds.</p>



<p>Take, for example, Loft Orbital, which <a href="https://loftorbital.com/yam-9-benchmarking-the-future-of-ai-enabled-space-infrastructure/">sent its YAM-9 commercial satellite into orbit</a> and successfully deployed it in November. It has four nodes and can handle multiple AI applications running simultaneously.</p>



<p>Why bother when it’s so much cheaper to run AI models here at home? Loft’s system includes access to sensors and data streams from the other Loft satellites already up in low Earth orbit.</p>



<p>And, this year, Loft is partnering with Helsing, a European defense technology and AI company, to launch an AI-powered <a href="https://loftorbital.com/helsing-and-loft-orbital-join-forces-to-deploy-europes-first-ai-powered-multi-sensor-satellite-constellation-for-governmental-defense-and-security-applications/">multi-sensor satellite constellation</a> into orbit, designed for border surveillance, troop movement tracking, and infrastructure protection.</p>



<p>“I believe we will see the early implementation of data center communication, storage, and processing in space—low Earth orbit or lunar—within the next three years,” says <a href="https://www.linkedin.com/in/thomas-coughlin-41a65/">Tom Coughlin</a>, IEEE fellow and president of Coughlin Associates, a consulting firm. And he predicts significant growth in this area, as well as general outer space commercialization, within the next 10 years.</p>



<p>And these data centers won’t just be for serving Earth-based customers, he says, especially as human activities in space increase. “The need for local data center capabilities will also rise,” he says, “To mitigate latency issues associated with long-range communication.”</p>



<p>But not everyone is that optimistic. <a href="https://www.gartner.com/en/documents/7493153">According to Gartner</a>, space-based data centers won’t be useful for decades, so companies should focus on expanding capacity down here on Earth.</p>



<p>“I honestly think the idea with the current landscape of putting data centers in space is ridiculous,” OpenAI CEO Sam Altman <a href="https://www.youtube.com/watch?v=M0TNC0RtLis">told The Indian Express</a> in February.</p>



<p>Current satellite computing can’t easily scale to data centers, agrees <a href="https://www.linkedin.com/in/holgermueller/">Holger Mueller</a>, an analyst at Constellation Research. “Weight is still the restriction,” he says. “It’s the equivalent of you buying a tablet or small laptop to travel across Latin America versus putting in a data center in the Amazon. Different power requirements, investment, totally different setup.”</p>



<p>Then there are issues like damaged solar panels from meteorite storms and satellite debris, he adds. “You would have to pay for operational redundancy, which is further investment.”</p>



<p>“Data centers will be built where they are affordable,” he says. “I don’t see space happening soon. Remember the Microsoft submerged one? Crickets…”</p>



<p>But he agrees that solar power is nice, though the sun is only visible from one side of the planet at any given time. And space is cold, he says.</p>



<h2 class="wp-block-heading">Cooling down in outer space</h2>



<p>In fact, space is very cold. Close to absolute zero cold. But vacuum is also a great insulator, and there’s no air to move the heat around.</p>



<p>“You can’t convect heat away,” says <a href="https://www.linkedin.com/in/richbonnerphd/">Richard Bonner</a>, CTO at Accelsius, a liquid cooling company. Bonner has worked on NASA research projects about the challenge of cooling in space and is very familiar with the problem.</p>



<p>A small proportion of the heat might be turned back into useful electricity, but that’s not really a solution, he says, because computer chips don’t get quite that hot.</p>



<p>Instead, heat is radiated. When an object warms up, it generates electromagnetic radiation. This is how we’re able to see warm bodies at night with infrared glasses.</p>



<p>“So, the only way to let that heat go is by radiation,” Bonnor says. “And it requires surface area, so you need these big panels to radiate the heat.” For data centers, these could be football-field-sized panels, he says.</p>



<p>It might seem that the backs of the solar panels would be a good place to radiate excess heat, but solar panels generate their own heat that needs to be radiated away.</p>



<p>The technology is there, Bonner says, and is already in use, though on a much smaller scale than what a full-sized data center would need. “Solar panels, radiator panels—not only do they exist, but they’ve existed for many, many decades,” he says.</p>



<p>Another kind of computing that benefits greatly from being surrounded by the coldness of space is quantum computing. Space could be uniquely beneficial here, Bonner says. “Quantum computers don’t have to dissipate a lot of heat, but they do require very, very cold temperatures. The other nice thing about space is that there’s no vibration.”</p>



<p>But that doesn’t mean that quantum computers are going to be launched into space tomorrow. “Given how sensitive these instruments are, there’s a lot that has to happen to allow them to survive launch,” he says.</p>



<p>Unless they’re built up in space to start with. But that’s a subject for a different article, maybe a decade from now.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Contagious Interview: Evolution of VS Code and Cursor Tasks Infection Chains Part 2]]></title>
<description><![CDATA[2026-03-09 • Abstract Security
     • Abstract Security Threat Research Organization (ASTRO)
     • osx.golangghost, py.pylangghost, win.golangghost
    
    
    Open article on Malpedia]]></description>
<link>https://tsecurity.de/de/3341490/malware-trojaner-viren/contagious-interview-evolution-of-vs-code-and-cursor-tasks-infection-chains-part-2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3341490/malware-trojaner-viren/contagious-interview-evolution-of-vs-code-and-cursor-tasks-infection-chains-part-2/</guid>
<pubDate>Wed, 11 Mar 2026 15:17:11 +0100</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!--  -->
<div>
    2026-03-09 • Abstract Security
     • Abstract Security Threat Research Organization (ASTRO)
     • osx.golangghost, py.pylangghost, win.golangghost
    
    <br>
    <a href="https://malpedia.caad.fkie.fraunhofer.de/library/9f17f935-a21f-4dbd-a31c-61a6ae417911/">Open article on Malpedia</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Webframework: Astro 6.0 experimentiert mit neuem Rust-Compiler]]></title>
<description><![CDATA[Ein experimenteller Rust-Compiler soll den bisherigen Go-Compiler ablösen und der Astro-Dev-Server unterstützt nun benutzerdefinierte Laufzeitumgebungen.]]></description>
<link>https://tsecurity.de/de/3340973/it-nachrichten/webframework-astro-60-experimentiert-mit-neuem-rust-compiler/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3340973/it-nachrichten/webframework-astro-60-experimentiert-mit-neuem-rust-compiler/</guid>
<pubDate>Wed, 11 Mar 2026 12:17:21 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein experimenteller Rust-Compiler soll den bisherigen Go-Compiler ablösen und der Astro-Dev-Server unterstützt nun benutzerdefinierte Laufzeitumgebungen.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-27829 | withastro up to 9.5.3 Image Parser server-side request forgery (GHSA-cj9f-h6r6-4cx2)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in withastro astro up to 9.5.3. This affects an unknown part of the component Image Parser. Such manipulation leads to server-side request forgery.

This vulnerability is traded as CVE-2026-27829. The attack may be launched remotely. There...]]></description>
<link>https://tsecurity.de/de/3336982/sicherheitsluecken/cve-2026-27829-withastro-up-to-953-image-parser-server-side-request-forgery-ghsa-cj9f-h6r6-4cx2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3336982/sicherheitsluecken/cve-2026-27829-withastro-up-to-953-image-parser-server-side-request-forgery-ghsa-cj9f-h6r6-4cx2/</guid>
<pubDate>Mon, 09 Mar 2026 23:20:45 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/?kb.risk">critical</a> has been identified in <a href="https://vuldb.com/?product.withastro:astro">withastro astro up to 9.5.3</a>. This affects an unknown part of the component <em>Image Parser</em>. Such manipulation leads to server-side request forgery.

This vulnerability is traded as <a href="https://vuldb.com/?source_cve.347955">CVE-2026-27829</a>. The attack may be launched remotely. There is no exploit available.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[You can still grab great deals on Bose headphones and Astro Bot this weekend]]></title>
<description><![CDATA[Welcome to the weekend, friends! While the rest of our team was checking out Samsung’s forthcoming Galaxy S26 lineup and prepping for Apple’s “special experience” next week, we’ve been sifting through Woot’s “Video Games for All” sale and a truly weird slate of deals that, frankly, don’t have a t...]]></description>
<link>https://tsecurity.de/de/3316943/it-nachrichten/you-can-still-grab-great-deals-on-bose-headphones-and-astro-bot-this-weekend/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3316943/it-nachrichten/you-can-still-grab-great-deals-on-bose-headphones-and-astro-bot-this-weekend/</guid>
<pubDate>Sat, 28 Feb 2026 17:16:16 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Welcome to the weekend, friends! While the rest of our team was checking out Samsung’s forthcoming Galaxy S26 lineup and prepping for Apple’s “special experience” next week, we’ve been sifting through Woot’s “Video Games for All” sale and a truly weird slate of deals that, frankly, don’t have a throughline. (Some of us have also […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Contagious Interview: Evolution of VS Code and Cursor Tasks Infection Chains - Part 1]]></title>
<description><![CDATA[2026-02-25 • Abstract Security
     • Abstract Security Threat Research Organization (ASTRO)
     • js.beavertail, py.pylangghost, win.golangghost
    
    
    Open article on Malpedia]]></description>
<link>https://tsecurity.de/de/3311809/malware-trojaner-viren/contagious-interview-evolution-of-vs-code-and-cursor-tasks-infection-chains-part-1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3311809/malware-trojaner-viren/contagious-interview-evolution-of-vs-code-and-cursor-tasks-infection-chains-part-1/</guid>
<pubDate>Thu, 26 Feb 2026 10:32:35 +0100</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!--  -->
<div>
    2026-02-25 • Abstract Security
     • Abstract Security Threat Research Organization (ASTRO)
     • js.beavertail, py.pylangghost, win.golangghost
    
    <br>
    <a href="https://malpedia.caad.fkie.fraunhofer.de/library/ef74e973-e26c-46b3-ab07-1d88c7d68b7d/">Open article on Malpedia</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[A Joint Vision for Simplified SASE Management at Scale]]></title>
<description><![CDATA[Unlock simplified SASE management at scale. The Prisma SASE app on ServiceNow unifies security, automates deployment, and accelerates time to value. The post A Joint Vision for Simplified SASE Management at Scale appeared first on Palo Alto Networks Blog. This…
Read more →
The post A Joint Vision...]]></description>
<link>https://tsecurity.de/de/3307582/it-security-nachrichten/a-joint-vision-for-simplified-sase-management-at-scale/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3307582/it-security-nachrichten/a-joint-vision-for-simplified-sase-management-at-scale/</guid>
<pubDate>Tue, 24 Feb 2026 16:35:51 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Unlock simplified SASE management at scale. The Prisma SASE app on ServiceNow unifies security, automates deployment, and accelerates time to value. The post A Joint Vision for Simplified SASE Management at Scale appeared first on Palo Alto Networks Blog. This…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/a-joint-vision-for-simplified-sase-management-at-scale/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/a-joint-vision-for-simplified-sase-management-at-scale/">A Joint Vision for Simplified SASE Management at Scale</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nvidia lines up partners to boost security for industrial operations]]></title>
<description><![CDATA[Nvidia has extended its collaborations with a handful of security vendors in an effort to improve real-time threat detection and response across operational technology (OT) environments and industrial control systems (ICS).



“Many of these systems were originally designed for reliability and lo...]]></description>
<link>https://tsecurity.de/de/3306140/it-security-nachrichten/nvidia-lines-up-partners-to-boost-security-for-industrial-operations/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3306140/it-security-nachrichten/nvidia-lines-up-partners-to-boost-security-for-industrial-operations/</guid>
<pubDate>Tue, 24 Feb 2026 03:05:34 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Nvidia has extended its collaborations with a handful of security vendors in an effort to improve real-time threat detection and response across operational technology (OT) environments and industrial control systems (ICS).</p>



<p>“Many of these systems were originally designed for reliability and longevity, not for today’s threat techniques,” wrote <a href="https://www.linkedin.com/in/itayozery/">Itay Ozery</a>, director of product marketing for networking at Nvidia, in a <a href="https://blogs.nvidia.com/blog/ai-cybersecurity-operational-technology-industrial-control-systems/">blog post</a> about the news. </p>



<p>Nvidia’s collaborations with Akamai, Forescout, Palo Alto Networks, Siemens and Xage Security are aimed at bringing accelerated computing and AI to OT cybersecurity, according to Ozery. “These efforts represent a fundamental shift in OT and ICS cybersecurity, where security is embedded into and distributed across infrastructure, enforced at the edge and coordinated through centralized, AI-driven intelligence, bringing modern cybersecurity to the systems that keep the physical world running,” he wrote.</p>



<p>Nvidia announced the news at the <a href="https://s4xevents.com/">S4x26</a> OT and ICS security conference.</p>



<p>The joint efforts will use Nvidia’s BlueField DPUs, which can directly handle security workloads, offloading those tasks from local host CPUs, and can enforce identity-based access, micro-segmentation and workload policies, according to Nvidia. </p>



<p>Here are some details of each collaborator’s plans to protect critical infrastructure:</p>



<h4 class="wp-block-heading">Akamai extends its micro-segmentation and zero-trust security platform Guardicore to run on Nvidia BlueField GPUs</h4>



<p>The integration offloads user-configurable security processes from the host system to the Nvidia BlueField DPU and enables zero-trust segmentation without requiring software agents on fragile or legacy systems, according to Akamai. Organizations can implement this hardware-isolated, “agentless” security approach to help align with regulatory requirements and lower their risk profile for cyber insurance.</p>



<p>“It delivers deep, out-of-band visibility across systems, networks, and applications without disrupting operations. Security policies can be enforced in real time and are capable of creating a strong protective boundary around critical operational systems. The result is trusted insight into operational activity and improved overall cyber resilience,” according to <a href="https://www.globenewswire.com/news-release/2026/02/23/3242805/0/en/Akamai-Secures-Critical-Infrastructure-with-Agentless-Zero-Trust-Segmentation-Powered-by-NVIDIA.html">Akamai</a>.</p>



<h4 class="wp-block-heading">Forescout works with Nvidia to bring zero-trust technology to OT networks</h4>



<p>Forescout applies network segmentation to contain lateral movement and enforce zero-trust controls. The technology would be further integrated into <a href="https://www.forescout.com/press-releases/forescout-taps-nvidia-accelerated-computing-to-improve-critical-infrastructure-security/">partnership</a> work already being done by the two companies. By running Forescout’s on-premises sensor directly on the Nvidia BlueField, part of Nvidia Cybersecurity AI platform, customers can offload intensive computing tasks, such as deep packet inspections. This speeds up data processing, enhances asset intelligence, and improves real-time monitoring, providing security teams with the insights needed to stay ahead of emerging threats, according to Forescout.</p>



<h4 class="wp-block-heading">Palo Alto to demo Prisma AIRS AI Runtime Security on Nvidia BlueField DPU</h4>



<p>Palo Alto Networks <a href="https://www.paloaltonetworks.com/blog/2026/01/support-nvidia-enterprise-ai-factory/">recently</a> partnered with Nvidia to run its Prisma AI-powered Radio Security(AIRs) package on the Nvidia BlueField DPU and will show off the technology at the conference. The technology is part of the Nvidia Enterprise AI Factory validated design and can offer real-time security protection for industrial network settings. </p>



<p>“Prisma AIRS AI Runtime Security delivers deep visibility into industrial traffic and continuous monitoring for abnormal behavior. By running these security services on Nvidia BlueField, inspection and enforcement happen directly at the infrastructure level, closer to the workloads,” Palo Alto stated.</p>



<h4 class="wp-block-heading">Siemens to demo Nvidia BlueField integration with its IT/OT platform</h4>



<p>At the S4x26 security conference, Siemens said it will demonstrate its AI-ready <a href="https://info.xage.com/hubfs/Datasheets/Xage%20Delivers%20Unified%20Zero%20Trust%20for%20AI%20with%20NVIDIA%20BlueField.pdf">Industrial Automation DataCenter</a>, a platform that collects, stores, processes, and serves operational and automation data across industrial environments. The system integrates Nvidia BlueField devices for and integrated secure edge infrastructure made up of industrial OT workloads and the data center or cloud, according to Siemens.</p>



<h4 class="wp-block-heading">Xage links its Fabric Platform with Nvidia BlueField</h4>



<p>In another technology demonstration, Xage said it will show how its distributed, identity-based security system, Xage Fabric Platform, operates with Nvidia BlueField devices to help customers protect energy assets, manage third-party access and secure AI-driven operations.</p>



<p>“Xage applies least-privilege controls at every step of these interactions, governing not only which agents can access specific data, pipelines, or models, but also the exact actions agents can perform—and for how long,” the company <a href="https://xage.com/press/xage-integrates-nvidia-bluefield-to-deliver-unified-zero-trust-for-ai/#:~:text=Xage's%20dynamic%20access%20control%20integration,datasets%2C%20workloads%2C%20and%20models.">wrote</a> on its website. “With role-based segmentation running at line speed on BlueField, organizations can prevent unauthorized privilege escalation and data leakage and enforce policy-based privilege deescalation to block risky actions, ensuring that AI agents remain trustworthy and compliant as they scale and evolve.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Palo Alto to acquire Israeli startup Koi for agentic AI security]]></title>
<description><![CDATA[Palo Alto Networks has entered an agreement to buy agentic endpoint security vendor Koi. Financial details were not disclosed, but some news outlets have estimated the deal is valued at around $400 million.



Members of Israel’s cyber warfare and intelligence group, Unit 8200,  founded Koi in 20...]]></description>
<link>https://tsecurity.de/de/3294188/it-security-nachrichten/palo-alto-to-acquire-israeli-startup-koi-for-agentic-ai-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3294188/it-security-nachrichten/palo-alto-to-acquire-israeli-startup-koi-for-agentic-ai-security/</guid>
<pubDate>Tue, 17 Feb 2026 23:18:49 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Palo Alto Networks has entered an agreement to buy agentic endpoint security vendor <a href="https://www.koi.ai/blog/koi-to-join-palo-alto-networks-a-defining-moment">Koi</a>. Financial details were not disclosed, but <a href="https://www.israelhayom.com/2026/02/17/palo-alto-acquires-israeli-koi-400-million/">some news outlets</a> have estimated the deal is valued at around $400 million.</p>



<p>Members of Israel’s cyber warfare and intelligence group, <a href="https://www.reuters.com/world/middle-east/what-is-israels-secretive-cyber-warfare-unit-8200-2024-09-18/">Unit 8200</a>,  founded <a href="https://www.koi.ai/">Koi</a> in 2024 to focus on building technology to protect what the company calls non-traditional, non-binary software, such as code packages, browser extensions, IDE plugins, scripts, local servers such as Model Context Servers, containers and model artifacts.</p>



<p>These non-binary software components “are installed directly by employees and developers without centralized oversight. Because these components are not classic binaries, they often fall outside the visibility and control of traditional endpoint security tooling,” wrote <a href="https://www.linkedin.com/in/hadar-oren-3421085a/">Hadar Oren</a>, senior vice president of product management for Cortex at Palo Alto Networks, in a <a href="https://www.paloaltonetworks.com/blog/2026/02/securing-the-agentic-endpoint/">blog post</a> about the news. “AI agents compound this problem. They are legitimate tools that operate with the user’s credentials and permissions, enabling them to read, write, move data and take privileged actions across systems. When compromised or misused, agents become the ‘ultimate insider.’”</p>



<p>Attackers are chaining exploits in agent frameworks — from authentication bypass to API-based remote code execution — while spoofing agent identities and hijacking credentials to weaponize trusted automation, according to Oren.</p>



<p>“We are convinced that agentic endpoint security will soon become a standard requirement for enterprise security,” Oren wrote. </p>



<p>After the close of the acquisition, Koi’s Agentic Endpoint Security will be integrated with Palo Alto Networks’ AI security platform, <a href="https://www.networkworld.com/article/3973866/palo-alto-unpacks-security-platform-to-protect-ai-resources.html">Prisma AIRS</a>.</p>



<p><a href="https://www.networkworld.com/article/4084195/palo-alto-networks-readies-security-for-ai-first-world.html">Prisma AIRS</a> features AI model scanning, which lets enterprises safely adopt AI models by scanning them for vulnerabilities and secure the AI ecosystem against risks such as model tampering, malicious scripts, and deserialization attacks. Posture management provides enterprises with insight into their security posture as related to the AI ecosystem and exposes risks such as excessive permissions, sensitive data exposure, platform misconfigurations, and access misconfigurations, according to Palo Alto. </p>



<p>“We believe Palo Alto is extending its platformization strategy deeper into AI with its acquisition of Koi as it can offer control and visibility of AI agents, plug-ins, and nontraditional software that have privileged access abilities on an endpoint. In our view, this deal builds on Palo Alto’s recent acquisition of <a href="https://www.paloaltonetworks.com/company/press/2026/palo-alto-networks-completes-chronosphere-acquisition--unifying-observability-and-security-for-the-ai-era">Chronosphere</a> in the observability space as it allows the company to pair richer AI data with new controls,” wrote Jonathan Ho, a research analyst with William Blair Equity Research, in a <a href="https://williamblair.bluematrix.com/links2/secure/pdf/a50a2105-2c87-4aee-a99f-5da932f1ea20">report</a> on the deal. </p>



<p>“We believe this should help Palo Alto better secure the lifecycle around AI from infrastructure and data to agents and endpoints, and we view this deal as the latest in Palo Alto’s moves to benefit from AI spending and security…it broadens Palo Alto’s coverage of risks around AI on endpoints, which should put the company in a better competitive position for the future as endpoint security evolves to include the governance of AI agents and autonomous workloads on those endpoints,” Ho stated. Ho said Koi’s technology competes with CrowdStrike, Microsoft, SentinelOne and others. </p>



<p>The Koi deal comes just one week after <a href="https://www.paloaltonetworks.com/company/press/2026/palo-alto-networks-completes-acquisition-of-cyberark-to-secure-the-ai-era">Palo Alto closed its acquisition of CyberArk</a>, which also tackles the protection of enterprise AI assets. In a <a href="https://www.wwt.com/blog/when-identity-becomes-the-battlefield-why-palo-alto-networks-cyberark-changes-the-map">blog</a> about the CyberArk deal, World Wide Technologies stated: “It raises the bar for AI security. </p>



<p>“Every vendor is claiming ‘AI security.’ Most of it is detection, guardrails, and posture. But the AI era introduces a new identity class: agentic processes that can initiate actions, call tools, use credentials, and persist across workflows. If AI agents are granted privileges, then the question becomes: Who governs the privilege of an agent that never sleeps?” WWT stated.</p>



<p>“CyberArk has been messaging identity security for AI agents and non-human identities; Palo Alto is explicitly tying the acquisition to securing “human, machine, and AI identities” at scale.  Whether the market fully agrees yet doesn’t matter. This acquisition forces the conversation into the open,” WWT stated.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Astro Protocol is a tactical space 4x game designed for people with little time]]></title>
<description><![CDATA[I sure do love 4x strategy games, but they really can take forever - which is where Astro Protocol is different with its tactical approach.Read the full article on GamingOnLinux.]]></description>
<link>https://tsecurity.de/de/3293244/linux-tipps/astro-protocol-is-a-tactical-space-4x-game-designed-for-people-with-little-time/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3293244/linux-tipps/astro-protocol-is-a-tactical-space-4x-game-designed-for-people-with-little-time/</guid>
<pubDate>Tue, 17 Feb 2026 14:50:22 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[I sure do love 4x strategy games, but they really can take forever - which is where Astro Protocol is different with its tactical approach.<p><img src="https://www.gamingonlinux.com/uploads/articles/tagline_images/1001971441id28511gol.jpg" alt></p><p>Read the full article on <a href="https://www.gamingonlinux.com/2026/02/astro-protocol-is-a-tactical-space-4x-game-designed-for-people-with-little-time/">GamingOnLinux</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-0122 | Palo Alto Prisma SD-WAN up to 6.1.9/6.2.0/6.3.3/6.4.1/6.5.0 Packets allocation of resources (Nessus ID 298998)]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in Palo Alto Prisma SD-WAN up to 6.1.9/6.2.0/6.3.3/6.4.1/6.5.0. This affects an unknown part of the component Packets Handler. The manipulation leads to allocation of resources.

This vulnerability is uniquely identified as CVE-2025-0122. The a...]]></description>
<link>https://tsecurity.de/de/3287488/sicherheitsluecken/cve-2025-0122-palo-alto-prisma-sd-wan-up-to-619620633641650-packets-allocation-of-resources-nessus-id-298998/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3287488/sicherheitsluecken/cve-2025-0122-palo-alto-prisma-sd-wan-up-to-619620633641650-packets-allocation-of-resources-nessus-id-298998/</guid>
<pubDate>Sat, 14 Feb 2026 03:07:50 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/?kb.risk">critical</a> has been reported in <a href="https://vuldb.com/?product.palo_alto:prisma_sd-wan">Palo Alto Prisma SD-WAN up to 6.1.9/6.2.0/6.3.3/6.4.1/6.5.0</a>. This affects an unknown part of the component <em>Packets Handler</em>. The manipulation leads to allocation of resources.

This vulnerability is uniquely identified as <a href="https://vuldb.com/?source_cve.304428">CVE-2025-0122</a>. The attack can only be initiated within the local network. No exploit exists.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-0228 | Palo Alto Cloud NGFW/PAN-OS/Prisma Access certificate validation]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in Palo Alto Cloud NGFW, PAN-OS and Prisma Access. Affected by this issue is some unknown functionality. The manipulation results in improper certificate validation.

This vulnerability was named CVE-2026-0228. The attack may be performed ...]]></description>
<link>https://tsecurity.de/de/3285315/sicherheitsluecken/cve-2026-0228-palo-alto-cloud-ngfwpan-osprisma-access-certificate-validation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3285315/sicherheitsluecken/cve-2026-0228-palo-alto-cloud-ngfwpan-osprisma-access-certificate-validation/</guid>
<pubDate>Fri, 13 Feb 2026 02:35:55 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/?kb.risk">critical</a> has been identified in <a href="https://vuldb.com/?product.palo_alto:cloud_ngfw">Palo Alto Cloud NGFW, PAN-OS and Prisma Access</a>. Affected by this issue is some unknown functionality. The manipulation results in improper certificate validation.

This vulnerability was named <a href="https://vuldb.com/?source_cve.345589">CVE-2026-0228</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-0229 | Palo Alto Cloud NGFW/PAN-OS/Prisma Access unusual condition]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in Palo Alto Cloud NGFW, PAN-OS and Prisma Access. Affected by this issue is some unknown functionality. This manipulation causes improper check for unusual conditions.

This vulnerability is tracked as CVE-2026-0229. The attack is...]]></description>
<link>https://tsecurity.de/de/3285313/sicherheitsluecken/cve-2026-0229-palo-alto-cloud-ngfwpan-osprisma-access-unusual-condition/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3285313/sicherheitsluecken/cve-2026-0229-palo-alto-cloud-ngfwpan-osprisma-access-unusual-condition/</guid>
<pubDate>Fri, 13 Feb 2026 02:35:52 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/?kb.risk">critical</a>, has been found in <a href="https://vuldb.com/?product.palo_alto:cloud_ngfw">Palo Alto Cloud NGFW, PAN-OS and Prisma Access</a>. Affected by this issue is some unknown functionality. This manipulation causes improper check for unusual conditions.

This vulnerability is tracked as <a href="https://vuldb.com/?source_cve.345578">CVE-2026-0229</a>. The attack is possible to be carried out remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-69618 | Tarot, Astro & Healing 11.4.0 privilege escalation]]></title>
<description><![CDATA[A vulnerability was found in Tarot, Astro & Healing 11.4.0. It has been classified as problematic. This affects an unknown function. The manipulation leads to privilege escalation.

This vulnerability is listed as CVE-2025-69618. The attack must be carried out from within the local network. There...]]></description>
<link>https://tsecurity.de/de/3283357/sicherheitsluecken/cve-2025-69618-tarot-astro-healing-1140-privilege-escalation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3283357/sicherheitsluecken/cve-2025-69618-tarot-astro-healing-1140-privilege-escalation/</guid>
<pubDate>Thu, 12 Feb 2026 08:22:25 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.tarot_astro__healing">Tarot, Astro &amp; Healing 11.4.0</a>. It has been classified as <a href="https://vuldb.com/?kb.risk">problematic</a>. This affects an unknown function. The manipulation leads to privilege escalation.

This vulnerability is listed as <a href="https://vuldb.com/?source_cve.344364">CVE-2025-69618</a>. The attack must be carried out from within the local network. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[The Bank Hacker - ZDFneo - TV-Programm - Prisma]]></title>
<description><![CDATA[The Bank Hacker. Mithilfe von Philip Daum betreten Alidor und seine Bande die Bank. Ein Geisel-Video zwingt Daum dazu, alle Alarmsysteme auszuschalten ...]]></description>
<link>https://tsecurity.de/de/3283246/hacking/the-bank-hacker-zdfneo-tv-programm-prisma/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3283246/hacking/the-bank-hacker-zdfneo-tv-programm-prisma/</guid>
<pubDate>Thu, 12 Feb 2026 07:36:18 +0100</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Bank <b>Hacker</b>. Mithilfe von Philip Daum betreten Alidor und seine Bande die Bank. Ein Geisel-Video zwingt Daum dazu, alle Alarmsysteme auszuschalten ...]]></content:encoded>
</item>
<item>
<title><![CDATA[The Bank Hacker - ZDFneo - TV-Programm - Prisma]]></title>
<description><![CDATA[The Bank Hacker. Die Staatsanwältin findet heraus, dass Jeremy sie bei der Befragung zum Banküberfall belogen hat. Sie droht ihm mit Gefängnis. Jeremy ...]]></description>
<link>https://tsecurity.de/de/3281875/hacking/the-bank-hacker-zdfneo-tv-programm-prisma/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3281875/hacking/the-bank-hacker-zdfneo-tv-programm-prisma/</guid>
<pubDate>Wed, 11 Feb 2026 15:21:22 +0100</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Bank <b>Hacker</b>. Die Staatsanwältin findet heraus, dass Jeremy sie bei der Befragung zum Banküberfall belogen hat. Sie droht ihm mit Gefängnis. Jeremy ...]]></content:encoded>
</item>
<item>
<title><![CDATA[This vintage-looking camera has been updated for shooting the stars]]></title>
<description><![CDATA[Just over a year after OM System launched its vintage-styled OM-3 Micro Four Thirds mirrorless camera, the company has announced a new version with a handful of upgrades catering to astrophotography. The new OM-3 Astro will be available starting in March 2026 for $2,499.99, which is $500 more exp...]]></description>
<link>https://tsecurity.de/de/3279655/it-nachrichten/this-vintage-looking-camera-has-been-updated-for-shooting-the-stars/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3279655/it-nachrichten/this-vintage-looking-camera-has-been-updated-for-shooting-the-stars/</guid>
<pubDate>Tue, 10 Feb 2026 16:32:07 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Just over a year after OM System launched its vintage-styled OM-3 Micro Four Thirds mirrorless camera, the company has announced a new version with a handful of upgrades catering to astrophotography. The new OM-3 Astro will be available starting in March 2026 for $2,499.99, which is $500 more expensive than the standard model. Both can […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Sophos Links Mount Locker to Astro Locker Ransomware]]></title>
<description><![CDATA[Experts suspect branding move to kick-start affiliate program]]></description>
<link>https://tsecurity.de/de/3259588/it-security-nachrichten/sophos-links-mount-locker-to-astro-locker-ransomware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3259588/it-security-nachrichten/sophos-links-mount-locker-to-astro-locker-ransomware/</guid>
<pubDate>Fri, 06 Feb 2026 12:51:14 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Experts suspect branding move to kick-start affiliate program]]></content:encoded>
</item>
<item>
<title><![CDATA[Modern networks for modern demands: How CIOs are building for what’s next]]></title>
<description><![CDATA[Enterprise networks weren’t built to support today’s demands, from artificial intelligence (AI) model training and real-time edge analytics to distributed work styles and cloud-first architectures. To keep pace, CIOs need new infrastructures designed for speed, scale, and security.



Compounding...]]></description>
<link>https://tsecurity.de/de/3238024/it-security-nachrichten/modern-networks-for-modern-demands-how-cios-are-building-for-whats-next/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3238024/it-security-nachrichten/modern-networks-for-modern-demands-how-cios-are-building-for-whats-next/</guid>
<pubDate>Tue, 27 Jan 2026 21:18:58 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Enterprise networks weren’t built to support today’s demands, from artificial intelligence (AI) model training and real-time edge analytics to distributed work styles and cloud-first architectures. To keep pace, CIOs need new infrastructures designed for speed, scale, and security.</p>



<h2 class="wp-block-heading"><strong>Compounding challenges in enterprise networks</strong></h2>



<p>Years of deferred upgrades and patchwork solutions have created brittle networks that increase complexity and inhibit business growth. MPLS architectures, hardware-heavy security stacks, and disparate tools make it challenging to provide the visibility and responsiveness that AI, edge, and cloud workloads require.</p>



<p>In a world where 44% of mission-critical infrastructure is at or nearing end-of-life, according to the Kyndryl Readiness Report, many leaders recognize that their aging environments hinder their ability to pivot. With AI-driven competitors making strategic moves in a matter of weeks, a legacy network that takes months to provision new capacity is a liability.</p>



<p>Meanwhile, enterprises are also dealing with organizational roadblocks. Infrastructure and security teams often work in silos, making it hard to drive operating model transformation. Skills shortages, long provisioning cycles, and rising cloud egress costs further compound this challenge.</p>



<h2 class="wp-block-heading"><strong>Improving network performance with SASE</strong></h2>



<p>To overcome these challenges, enterprises are shifting toward cloud-based, software-defined architectures that unify networking and security — with secure access service edge (SASE) playing a central role. SASE provides the technical pretext for CIOs and CISOs to finally merge their agendas. The question for leadership is no longer, “How do we fix the network?” but, “How do we restructure our teams to manage a unified, cloud-native environment?”</p>



<p>SASE combines SD‑WAN, zero-trust access, secure web gateways, cloud access security brokers, and other critical capabilities in a single platform. Increasingly, these frameworks also integrate AI to detect threats in real time, enforce policies dynamically, and route traffic intelligently. This creates a secure, high-speed data fabric necessary for AI model training and real-time edge analytics. By offloading heavy compute tasks to an AI-powered SASE framework, leadership can ensure that the infrastructure actually increases AI’s return on investment, rather than draining budget through egress fees and latency.</p>



<p>Enterprises adopting SASE are seeing stronger security postures, fewer false positives, improved uptime, and better user experiences. In fact, 82.9% of organizations that have adopted SASE report a noticeable improvement in network performance or threat detection, according to IDC. And because it’s delivered as a service, SASE reduces cost and complexity while providing the scalability needed for future growth.</p>



<h2 class="wp-block-heading"><strong>Network modernization from Palo Alto Networks and Kyndryl</strong></h2>



<p>Palo Alto Networks and Kyndryl provide the right combination of technology and expertise to make network modernization a reality. Palo Alto provides Prisma SASE, an AI-powered, zero-trust platform that unifies networking and security in the cloud. And Kyndryl’s services help large organizations plan, deploy, and manage at scale.</p>



<p>Kyndryl’s own modernization journey — replacing a legacy network with Prisma SASE — gives it a unique perspective on the challenges enterprises face. That firsthand experience informs every engagement, from assessments and roadmap planning to phased rollouts and 24/7 management.</p>



<p>By integrating Prisma SASE with Kyndryl Bridge — a digital operations platform that connects IT and business systems — organizations can also solve the talent crisis. Automating mundane tasks such as threat monitoring and traffic optimization allows skilled workers to focus more on higher-value, business-critical innovation.</p>



<p><em>AI, edge, and cloud workloads demand more from your network. Kyndryl and Palo Alto Networks offer a practical, proven path to network modernization. Visit us <a href="https://www.paloaltonetworks.com/partners/nextwave-for-gsi/kyndryl-and-palo-alto-networks" rel="sponsored">here</a> to learn more.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-0103 | Palo Alto Networks Cloud NGFW sql injection]]></title>
<description><![CDATA[A vulnerability was found in Palo Alto Networks Cloud NGFW, Expedition, Panorama, PAN-OS and Prisma Access. It has been rated as critical. The affected element is an unknown function. Performing a manipulation results in sql injection. This vulnerability only affects products that are no longer s...]]></description>
<link>https://tsecurity.de/de/3231442/sicherheitsluecken/cve-2025-0103-palo-alto-networks-cloud-ngfw-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3231442/sicherheitsluecken/cve-2025-0103-palo-alto-networks-cloud-ngfw-sql-injection/</guid>
<pubDate>Sat, 24 Jan 2026 04:50:51 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.palo_alto_networks:cloud_ngfw">Palo Alto Networks Cloud NGFW, Expedition, Panorama, PAN-OS and Prisma Access</a>. It has been rated as <a href="https://vuldb.com/?kb.risk">critical</a>. The affected element is an unknown function. Performing a manipulation results in sql injection. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is known as <a href="https://vuldb.com/?source_cve.291166">CVE-2025-0103</a>. Remote exploitation of the attack is possible. No exploit is available.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-0105 | Palo Alto Networks Cloud NGFW file inclusion]]></title>
<description><![CDATA[A vulnerability categorized as critical has been discovered in Palo Alto Networks Cloud NGFW, Expedition, Panorama, PAN-OS and Prisma Access. The impacted element is an unknown function. Executing a manipulation can lead to file inclusion. This vulnerability only affects products that are no long...]]></description>
<link>https://tsecurity.de/de/3231441/sicherheitsluecken/cve-2025-0105-palo-alto-networks-cloud-ngfw-file-inclusion/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3231441/sicherheitsluecken/cve-2025-0105-palo-alto-networks-cloud-ngfw-file-inclusion/</guid>
<pubDate>Sat, 24 Jan 2026 04:50:50 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/?kb.risk">critical</a> has been discovered in <a href="https://vuldb.com/?product.palo_alto_networks:cloud_ngfw">Palo Alto Networks Cloud NGFW, Expedition, Panorama, PAN-OS and Prisma Access</a>. The impacted element is an unknown function. Executing a manipulation can lead to file inclusion. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is handled as <a href="https://vuldb.com/?source_cve.291167">CVE-2025-0105</a>. The attack can be executed remotely. There is not any exploit available.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-0106 | Palo Alto Cloud NGFW matching]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in Palo Alto Cloud NGFW, Expedition, Panorama, PAN-OS and Prisma Access. This issue affects some unknown processing. The manipulation results in improper neutralization of wildcards or matching symbols. This vulnerability only affect...]]></description>
<link>https://tsecurity.de/de/3231440/sicherheitsluecken/cve-2025-0106-palo-alto-cloud-ngfw-matching/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3231440/sicherheitsluecken/cve-2025-0106-palo-alto-cloud-ngfw-matching/</guid>
<pubDate>Sat, 24 Jan 2026 04:50:49 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/?kb.risk">problematic</a>, was found in <a href="https://vuldb.com/?product.palo_alto:cloud_ngfw">Palo Alto Cloud NGFW, Expedition, Panorama, PAN-OS and Prisma Access</a>. This issue affects some unknown processing. The manipulation results in improper neutralization of wildcards or matching symbols. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is cataloged as <a href="https://vuldb.com/?source_cve.291175">CVE-2025-0106</a>. The attack may be launched remotely. There is no exploit available.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-0104 | Palo Alto Cloud NGFW cross site scripting]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in Palo Alto Cloud NGFW, Expedition, Panorama, PAN-OS and Prisma Access. This affects an unknown part. Performing a manipulation results in cross site scripting. This vulnerability only affects products that are no longer supported by the ma...]]></description>
<link>https://tsecurity.de/de/3231439/sicherheitsluecken/cve-2025-0104-palo-alto-cloud-ngfw-cross-site-scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3231439/sicherheitsluecken/cve-2025-0104-palo-alto-cloud-ngfw-cross-site-scripting/</guid>
<pubDate>Sat, 24 Jan 2026 04:50:47 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/?kb.risk">problematic</a> has been reported in <a href="https://vuldb.com/?product.palo_alto:cloud_ngfw">Palo Alto Cloud NGFW, Expedition, Panorama, PAN-OS and Prisma Access</a>. This affects an unknown part. Performing a manipulation results in cross site scripting. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability was named <a href="https://vuldb.com/?source_cve.291184">CVE-2025-0104</a>. The attack may be initiated remotely. There is no available exploit.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[칼럼 | 테일윈드 랩스의 엔지니어 75% 감원, AI 중심 개발의 미래는?]]></title>
<description><![CDATA[필자는 테일윈드(Tailwind)와 애증의 관계를 거쳐왔다.



테일윈드는 처음 공개됐을 당시 큰 화제를 모았다. 이는 미리 정의된 CSS 스타일을 클래스 형태로 제공해, 개발자가 별도의 스타일시트를 작성하지 않고도 HTML 안에서 바로 디자인을 완성할 수 있도록 한 유틸리티 중심의 CSS 프레임워크다. 이런 접근을 통해 개발자는 각 태그를 세밀하게 제어할 수 있는데, 당시에는 이 개념이 상당히 신선하고 인상적으로 느껴졌다.



하지만 필자는 ‘관심사의 분리(Separation of Concerns, SoC)’를 중요하게 ...]]></description>
<link>https://tsecurity.de/de/3227320/it-security-nachrichten/75-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3227320/it-security-nachrichten/75-ai/</guid>
<pubDate>Thu, 22 Jan 2026 07:20:21 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>필자는 <a href="https://tailwindcss.com/" target="_blank" rel="nofollow">테일윈드(Tailwind)</a>와 애증의 관계를 거쳐왔다.</p>



<p>테일윈드는 처음 공개됐을 당시 큰 화제를 모았다. 이는 미리 정의된 CSS 스타일을 클래스 형태로 제공해, 개발자가 별도의 스타일시트를 작성하지 않고도 HTML 안에서 바로 디자인을 완성할 수 있도록 한 유틸리티 중심의 CSS 프레임워크다. 이런 접근을 통해 개발자는 각 태그를 세밀하게 제어할 수 있는데, 당시에는 이 개념이 상당히 신선하고 인상적으로 느껴졌다.</p>



<p>하지만 필자는 ‘관심사의 분리(Separation of Concerns, SoC)’를 중요하게 여긴다. 화면의 구조를 정의하는 HTML과, 그 구조를 꾸미는 스타일 코드는 서로 섞이지 않는 것이 바람직하다는 생각이다. 초콜릿과 땅콩버터를 굳이 한데 섞지 않는 것과 같은 이치다. 하지만 테일윈드는 바로 그 둘을 섞으라고 요구하는 것처럼 보였다. CSS의 본래 목적 중 하나는 HTML 구조와 이를 꾸미는 스타일 코드를 분리하는 데 있었는데, 테일윈드는 그와 반대 방향으로 가는 것 아니냐는 의문이 들었다. 디자인 요소가 HTML 안에 들어가 있는 상태에서 과연 관심사의 분리가 가능할까? 결론적으로 말하면 쉽지 않다.</p>



<p>다만 CSS가 처음 만들어졌을 때와 비교하면 웹 디자인의 성격 자체가 크게 달라졌다. <a href="https://www.infoworld.com/article/3964105/catching-up-with-angular-19.html" target="_blank">앵귤러(Angular)</a>, <a href="https://www.infoworld.com/article/3962039/what-you-need-to-know-about-angular-react-vue-and-svelte-popular-javascript-frameworks-compared.html" target="_blank">리액트(React)</a>, <a href="https://www.infoworld.com/article/3842325/designing-a-dynamic-web-application-with-astro-js.html" target="_blank">아스트로(Astro)</a> 등 오늘날 대부분의 프레임워크는 컴포넌트 기반 구조를 채택하고 있다. 그렇다고 해도 이들 컴포넌트 역시 기본적으로는 CSS와 HTML의 분리를 전제로 설계됐다. 예를 들어 앵귤러에서 하나의 컴포넌트는 타입스크립트, HTML, CSS 등 3개의 파일로 구성된다.</p>



<p>이런 컴포넌트는 갈수록 더 잘게 쪼개지고 있는 동시에, 웹사이트의 전반적인 디자인은 점점 더 표준화되는 추세다. 대표적인 사례가 버튼 색상이다. 파란색 버튼은 ‘신뢰해도 되는 동작’을, 빨간색 버튼은 ‘주의가 필요한 동작’을 의미하는 식의 시각적 규칙이 사실상 관행처럼 굳어졌다. 그 결과 과거처럼 색상을 세세하게 조정해야 할 필요성은 크게 줄어들었다.</p>



<p>바로 이 지점에서 테일윈드의 강점이 드러난다. 표준화된 색상이 필요하다면 테일윈드는 이를 손쉽게 정의할 수 있다. 색상과 형태가 이미 정형화돼 있다면, 해당 스타일을 표현하는 테일윈드의 작은 유틸리티 클래스는 매우 유용하다. 더 나아가 컴포넌트 자체가 간결하고 독립적으로 구성돼 있다면, 과연 HTML과 CSS를 굳이 분리해야 할 필요가 있을까라는 질문도 자연스럽게 제기된다.</p>



<p>결국 테일윈드는 강력하면서도 사용하기 쉬운 도구다. 이런 이유로 테일윈드는 웹사이트를 스타일링하는 방식 가운데 사실상 표준에 가까운 위치까지 올라섰다.</p>



<p>그러나 이제 테일윈드의 인기가 오히려 약점이 될 가능성도 보이기 시작했다.</p>



<p>지난주 테일윈드 팀은 <a href="https://news.ycombinator.com/item?id=46527950" target="_blank" rel="nofollow">전체 개발 인력의 75%를 감원</a>했다. 배경은 무엇일까? 테일윈드의 창시자이자 테일윈드 랩스 설립자인 <a href="https://github.com/tailwindlabs/tailwindcss.com/pull/2388#issuecomment-3717222957" target="_blank" rel="nofollow">애덤 웨이선</a>은 AI 확산으로 인해 회사의 마케팅 파이프라인이 사실상 마르면서 이런 결정이 불가피했다고 밝혔다. 테일윈드는 MIT 라이선스를 채택해 거의 무료로 사용할 수 있는 프레임워크다. 테일윈드 랩스는 그동안 웹사이트 방문 트래픽을 기반으로 ‘평생 라이선스’ 판매와 <a href="https://tailwindcss.com/sponsor" target="_blank" rel="nofollow">스폰서십</a>을 통해 수익을 창출해 왔다. 그러나 AI가 점점 더 많은 코딩 작업을 대신하게 되면서 개발자들이 테일윈드 사이트를 찾는 빈도가 줄었고, 그 결과 구매나 후원 역시 이전만큼 이뤄지지 않게 됐다.</p>



<p>개인적으로는 이 상황이 씁쓸하게 느껴진다.</p>



<p>필자는 그동안 에이전틱 코딩에 대해 반복적으로 다뤄왔고, ‘<a href="https://www.infoworld.com/article/4078884/what-is-vibe-coding-ai-writes-the-code-so-developers-can-think-big.html" target="_blank">바이브 코딩</a>‘과 같은 AI 기반 개발 흐름에 비교적 우호적인 입장을 유지해 왔다. 그럼에도 이번 감원은 AI가 무엇을 바꾸고 있으며, 앞으로 무엇이 벌어질 수 있는지를 보여주는 매우 현실적인 사례라고 본다. 이미 <a href="https://www.cio.com/article/3537547/%EC%B9%BC%EB%9F%BC-%EB%B6%88%EC%B9%9C%EC%A0%88%ED%95%9C-%EA%B3%A0%EC%88%98-%EB%8C%80%EC%8B%A0-ai-%EC%A1%B0%EC%88%98-%ED%83%9D%ED%95%98%EB%8A%94-%EC%BD%94%EB%94%A9-%EC%9E%85%EB%AC%B8%EC%9E%90.html" target="_blank">스택오버플로우에서 질문이 사실상 사라지는 현상</a>도 목격했다. 이제는 AI로 인해 테일윈드 랩스조차 수익을 내기 어려운 상황에 놓이고 있다.</p>



<p>바로 이 지점이 가장 우려하는 부분이다. AI가 새로운 코드와 프레임워크를 만드는 일을 더 이상 투자 가치가 없는 영역으로 만들어버리는 것은 아닐까? 만약 그렇다면, 앞으로 새로운 코드와 프레임워크는 과연 어디에서 나오게 될까?</p>



<p>어쩌면 그 해답은 에이전틱 AI 자체에 있을지도 모른다. 하지만 AI가 사람을 대신해 더 나은 프레임워크와 라이브러리를 만들어내는 역할까지 온전히 맡을 수 있을지, 아니면 사람이 만든 라이브러리가 지속 가능한 수익을 낼 수 있도록 하는 새로운 모델을 다시 설계해야 할지는 시간이 지나야 알 수 있을 것이다.</p>



<p>필자는 테일윈드와 에이전틱 AI 모두를 지지하지만, 후자가 전자에게 미치고 있는 영향은 받아들이기 어렵다. 그렇다면 결국, 미래를 만들어갈 주체는 누가 될까?<br>dl-ciokorea@foundryco.com</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Webentwicklung: Cloudflare übernimmt Astro Technology Company]]></title>
<description><![CDATA[Das Unternehmen hinter dem Webframework Astro gehört nun zu Cloudflare. Astro soll jedoch Open Source bleiben und aktiv weiterentwickelt werden.]]></description>
<link>https://tsecurity.de/de/3221213/it-nachrichten/webentwicklung-cloudflare-uebernimmt-astro-technology-company/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3221213/it-nachrichten/webentwicklung-cloudflare-uebernimmt-astro-technology-company/</guid>
<pubDate>Mon, 19 Jan 2026 12:31:08 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Das Unternehmen hinter dem Webframework Astro gehört nun zu Cloudflare. Astro soll jedoch Open Source bleiben und aktiv weiterentwickelt werden.]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloudflare kauft JavaScript-Framework Astro]]></title>
<description><![CDATA[Cloudflare hat die Übernahme von The Astro Technology Company bekanntgegeben, dem Entwickler des gleichnamigen JavaScript-Frameworks. Astro wird von Unternehmen sowie Hunderttausenden Entwicklern weltweit genutzt, um performante, inhaltsorientierte Websites zu erstellen.

Tags: #Firmenübernahme |...]]></description>
<link>https://tsecurity.de/de/3220888/it-security-nachrichten/cloudflare-kauft-javascript-framework-astro/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3220888/it-security-nachrichten/cloudflare-kauft-javascript-framework-astro/</guid>
<pubDate>Mon, 19 Jan 2026 09:49:42 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2026/01/Cloudfl-are-Astro-Bildquelle-Cloudflare-1920.jpg" class="attachment-full size-full wp-post-image" alt="Cloudflare Astro" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2026/01/Cloudfl-are-Astro-Bildquelle-Cloudflare-1920.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2026/01/Cloudfl-are-Astro-Bildquelle-Cloudflare-1920-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2026/01/Cloudfl-are-Astro-Bildquelle-Cloudflare-1920-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2026/01/Cloudfl-are-Astro-Bildquelle-Cloudflare-1920-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2026/01/Cloudfl-are-Astro-Bildquelle-Cloudflare-1920-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Cloudflare kauft JavaScript-Framework Astro 1"></p>
    Cloudflare hat die Übernahme von The Astro Technology Company bekanntgegeben, dem Entwickler des gleichnamigen JavaScript-Frameworks. Astro wird von Unternehmen sowie Hunderttausenden Entwicklern weltweit genutzt, um performante, inhaltsorientierte Websites zu erstellen.

<p>Tags: <a href="https://www.it-daily.net/thema/firmenuebernahme">#Firmenübernahme</a> | <a href="https://www.it-daily.net/thema/java">#JAVA</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-0227 | Palo Alto Cloud NGFW/PAN-OS/Prisma Access unusual condition]]></title>
<description><![CDATA[A vulnerability categorized as critical has been discovered in Palo Alto Cloud NGFW, PAN-OS and Prisma Access. Affected is an unknown function. Such manipulation leads to improper check for unusual conditions.

This vulnerability is traded as CVE-2026-0227. The attack may be launched remotely. Th...]]></description>
<link>https://tsecurity.de/de/3218489/sicherheitsluecken/cve-2026-0227-palo-alto-cloud-ngfwpan-osprisma-access-unusual-condition/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3218489/sicherheitsluecken/cve-2026-0227-palo-alto-cloud-ngfwpan-osprisma-access-unusual-condition/</guid>
<pubDate>Sat, 17 Jan 2026 10:50:36 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/?kb.risk">critical</a> has been discovered in <a href="https://vuldb.com/?product.palo_alto:cloud_ngfw">Palo Alto Cloud NGFW, PAN-OS and Prisma Access</a>. Affected is an unknown function. Such manipulation leads to improper check for unusual conditions.

This vulnerability is traded as <a href="https://vuldb.com/?source_cve.341385">CVE-2026-0227</a>. The attack may be launched remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloudflare Acquires Team Behind Open Source Framework Astro]]></title>
<description><![CDATA[Cloudflare has acquired the core team behind the open source JavaScript framework Astro, bringing its creators in-house while pledging to keep Astro fully open source. The New Stack reports: Astro is used by major brands like IKEA, Unilever, Visa and OpenAI to build fast, content-driven websites....]]></description>
<link>https://tsecurity.de/de/3218088/it-security-nachrichten/cloudflare-acquires-team-behind-open-source-framework-astro/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3218088/it-security-nachrichten/cloudflare-acquires-team-behind-open-source-framework-astro/</guid>
<pubDate>Sat, 17 Jan 2026 00:34:57 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Cloudflare has acquired the core team behind the open source JavaScript framework Astro, bringing its creators in-house while pledging to keep Astro fully open source. The New Stack reports: Astro is used by major brands like IKEA, Unilever, Visa and OpenAI to build fast, content-driven websites. Search engines prioritize fast-loading and clean pages, the Cloudflare statement noted. Websites that rely heavily on JavaScript for initial rendering often struggle to deliver the required speed, which hinders search rankings and customer conversions.
 
Pages on Astro serve up only the code needed to display a page in a browser. That's in part because of its Island architecture, which it introduced in 2021. Astro's Islands allow developers to create "islands" of interactive client-side components, while most of the page is generated statically in HTML. Server Islands extend the same architecture to the server.
 
Astro is also UI-agnostic, meaning that while it has its own independent engine, it allows developers to bring in components from React, Svelte, Vue and other frameworks. This makes Astro a preferred choice for building high-performance, content-driven websites optimized for speed, according to Cloudflare. "Over the past few years, we've seen an incredibly diverse range of developers and companies use Astro to build for the web," said Astro's former CTO, Fred Schott, in a post with Cloudflare senior product manager Brendan Irvine-Broque. "At Cloudflare, we use Astro, too -- for our developer docs, website, landing pages and more." They said that the acquisition will allow them to "double down" on making Astro the best framework for content-driven websites.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Cloudflare+Acquires+Team+Behind+Open+Source+Framework+Astro%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F01%2F16%2F2120240%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F01%2F16%2F2120240%2Fcloudflare-acquires-team-behind-open-source-framework-astro%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/26/01/16/2120240/cloudflare-acquires-team-behind-open-source-framework-astro?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloudflare Acquired Open-source Web Framework Astro to Supercharge Development]]></title>
<description><![CDATA[Cloudflare has acquired the team behind Astro, the popular open-source web framework for building fast, content-driven sites. Announced on January 16, 2026, the deal brings The Astro Technology Company’s full-time employees under Cloudflare’s umbrella to accelerate Astro’s development. Cloudflare...]]></description>
<link>https://tsecurity.de/de/3217709/it-security-nachrichten/cloudflare-acquired-open-source-web-framework-astro-to-supercharge-development/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3217709/it-security-nachrichten/cloudflare-acquired-open-source-web-framework-astro-to-supercharge-development/</guid>
<pubDate>Fri, 16 Jan 2026 18:34:47 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Cloudflare has acquired the team behind Astro, the popular open-source web framework for building fast, content-driven sites. Announced on January 16, 2026, the deal brings The Astro Technology Company’s full-time employees under Cloudflare’s umbrella to accelerate Astro’s development. Cloudflare positions…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/cloudflare-acquired-open-source-web-framework-astro-to-supercharge-development/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/cloudflare-acquired-open-source-web-framework-astro-to-supercharge-development/">Cloudflare Acquired Open-source Web Framework Astro to Supercharge Development</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloudflare Acquired Open-source Web Framework Astro to Supercharge Development]]></title>
<description><![CDATA[Cloudflare has acquired the team behind Astro, the popular open-source web framework for building fast, content-driven sites. Announced on January 16, 2026, the deal brings The Astro Technology Company’s full-time employees under Cloudflare’s umbrella to accelerate Astro’s development. Cloudflare...]]></description>
<link>https://tsecurity.de/de/3217685/it-security-nachrichten/cloudflare-acquired-open-source-web-framework-astro-to-supercharge-development/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3217685/it-security-nachrichten/cloudflare-acquired-open-source-web-framework-astro-to-supercharge-development/</guid>
<pubDate>Fri, 16 Jan 2026 18:20:19 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Cloudflare has acquired the team behind Astro, the popular open-source web framework for building fast, content-driven sites. Announced on January 16, 2026, the deal brings The Astro Technology Company’s full-time employees under Cloudflare’s umbrella to accelerate Astro’s development. Cloudflare positions the move as a commitment to open-source innovation, with Astro staying MIT-licensed, contribution-friendly, and platform-agnostic. […]</p>
<p>The post <a href="https://cybersecuritynews.com/cloudflare-acquired-astro/">Cloudflare Acquired Open-source Web Framework Astro to Supercharge Development</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Palo Alto Networks patches firewalls after discovery of a new denial-of-service flaw]]></title>
<description><![CDATA[Palo Alto Networks has issued patches for its PAN-OS firewall platform after a researcher uncovered a high-severity vulnerability which could be exploited by attackers to cause a denial-of-service (DoS).



The flaw, identified as CVE-2026-0227 with a CVSS 7.7 (‘high’) severity rating, affects cu...]]></description>
<link>https://tsecurity.de/de/3216087/it-security-nachrichten/palo-alto-networks-patches-firewalls-after-discovery-of-a-new-denial-of-service-flaw/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3216087/it-security-nachrichten/palo-alto-networks-patches-firewalls-after-discovery-of-a-new-denial-of-service-flaw/</guid>
<pubDate>Fri, 16 Jan 2026 01:35:32 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Palo Alto Networks has issued patches for its PAN-OS firewall platform after a researcher uncovered a high-severity vulnerability which could be exploited by attackers to cause a denial-of-service (DoS).</p>



<p>The flaw, identified as CVE-2026-0227 with a CVSS 7.7 (‘high’) severity rating, affects customers running PAN-OS NGFW (Next-Generation Firewall) or Prisma Access configurations with the company’s GlobalProtect remote access gateway or portal enabled.</p>



<p>Unpatched, this would make it possible for “an unauthenticated attacker to cause a denial of service to the firewall. Repeated attempts to trigger this issue results in the firewall entering into maintenance mode,” said <a href="https://security.paloaltonetworks.com/CVE-2026-0227" target="_blank" rel="noreferrer noopener">Palo Alto’s advisory</a>.</p>



<p>The company doesn’t spell out the implications of a firewall entering maintenance mode, but it’s hard to imagine it wouldn’t cause network outages as admins scrambled to address the issue.</p>



<p>Although Palo Alto Networks said it wasn’t aware of exploitation in the wild, the advisory also states that the issue was reported to it by an unnamed researcher, and that proof of concept (PoC) code exists.</p>



<p>Given that PoCs have a habit of leaking out or being independently reproduced, this makes Palo Alto’s description of the issue as being of “moderate urgency” read as optimistic.</p>



<p>This new vulnerability brings to mind an almost identical Palo Alto Networks DoS issue from late 2024, <a href="https://security.paloaltonetworks.com/CVE-2024-3393" target="_blank" rel="noreferrer noopener">CVE-2024-3393</a>, that also put affected firewalls into maintenance mode. On that occasion, attackers found out about the issue before patches appeared, making it a zero-day vulnerability. </p>



<p>More recently, in December, threat intelligence company <a href="https://www.networkworld.com/article/4109637/attackers-bring-their-own-passwords-to-cisco-and-palo-alto-vpns-2.html" target="_blank">GreyNoise noticed</a> an uptick in automated login attempts targeting both GlobalProtect and Cisco VPNs, while earlier in 2025, PAN-OS was affected by a serious <a href="https://www.networkworld.com/article/3825364/palo-alto-networks-firewall-bug-being-exploited-by-threat-actors-report.html" target="_blank">zero day flaw</a>, CVE-2025-0108, that allowed attackers to bypass login authentication.</p>



<p>“According to Palo Alto Networks’ <a href="https://security.paloaltonetworks.com/" target="_blank" rel="noreferrer noopener">security advisories</a>, the company has reported almost 500 vulnerabilities to date, many of which affected PAN-OS. A significant minority related to DoS issues,” a spokesperson for threat intelligence company Flashpoint observed. “[But] a notable portion of Palo Alto disclosures historically did not receive CVE identifiers, particularly older PAN-OS issues, which can complicate longitudinal comparison across vendors.”</p>



<h2 class="wp-block-heading">Who is affected?</h2>



<p>The good news is that most customers using the company’s cloud-delivered Secure Access Service Edge (SASE) platform, Prisma Access, have already been patched.</p>



<p>“We have successfully completed the Prisma Access upgrade for most of the customers, with the exception of few in progress due to conflicting upgrade schedules. Remaining customers are being promptly scheduled for an upgrade through our standard upgrade process,” said the advisory.</p>



<p>That leaves a not inconsiderable number of PAN-OS NGFW customers using the GlobalProtect gateway or portal who will need to apply the patch themselves. Although Palo Alto said there are no known workarounds,  to mitigate the issue, it might be possible to temporarily disable the VPN interface at the cost of losing remote access until patching is complete.</p>



<p>Palo Alto Networks has published a <a href="https://security.paloaltonetworks.com/CVE-2026-0227#:~:text=Solution,later.%2A,-%2A%20See" target="_blank" rel="noreferrer noopener">detailed table</a> of applicable patches which vary depending on the underlying PAN-OS version (12.1, 11.2, 11.1 10.2) in use. Versions older than 10.2 are unsupported; the fix is to update to a supported patched version.</p>



<h2 class="wp-block-heading">Availability disruption</h2>



<p>According to Flashpoint, a DoS state wouldn’t expose enterprises to a wider security threat. “Modern enterprise firewalls are designed to ‘fail closed’ rather than ‘fail open’. Entering maintenance mode due to a DoS condition is therefore more accurately characterized as a potential availability disruption than a direct security exposure,” said the spokesperson. “The core risk here appears to be resilience rather than compromise.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Iberostar confía en la IA para mejorar la captación y gestión de empleados en un sector con alta rotación]]></title>
<description><![CDATA[La escasez de trabajadores disponible, la alta rotación y la poca digitalización de los puestos de trabajo son, según Luis Zamora, director de personas (CHRO) de Grupo Iberostar, una de las grandes multinacionales españolas del sector turismo y especialmente fuerte en el negocio hotelero, los tre...]]></description>
<link>https://tsecurity.de/de/3214713/it-security-nachrichten/iberostar-confa-en-la-ia-para-mejorar-la-captacin-y-gestin-de-empleados-en-un-sector-con-alta-rotacin/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3214713/it-security-nachrichten/iberostar-confa-en-la-ia-para-mejorar-la-captacin-y-gestin-de-empleados-en-un-sector-con-alta-rotacin/</guid>
<pubDate>Thu, 15 Jan 2026 12:50:38 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>La escasez de trabajadores disponible, la alta rotación y la poca digitalización de los puestos de trabajo son, según <strong>Luis Zamora, director de personas (CHRO) de <a href="https://www.cio.com/article/2091110/la-tecnologia-es-la-facilitadora-de-una-transformacion-obligada.html">Grupo Iberostar</a></strong>, una de las grandes multinacionales españolas del sector turismo y especialmente fuerte en el negocio hotelero, los tres grandes desafíos que afronta este vertical en la actualidad desde el prisma laboral. Así lo indicó el directivo en un <a href="https://www.computerworld.es/article/4116833/adolfo-pellicer-la-ia-ha-redefinido-el-modelo-operativo-de-workday.html">encuentro con prensa organizado por Workday</a>, compañía con la que el grupo turístico selló un contrato en 2025 para implantar su tecnología de gestión de recursos humanos, en aras de unificar sus procesos de contratación, desarrollo de talento y administración de nóminas y beneficios laborales.</p>



<p>“En este momento —contó Zamora— nos hallamos en pleno proceso de implementación de Workday, que esperamos que esté a pleno uso el próximo mes de septiembre. Esto nos permitirá ofrecer formación a la carta a nuestros empleados, facilitarles realizar cambios de turno sin que esto impacte en el negocio y en función de la ocupación del hotel donde trabajen y mejorar así su experiencia y la de sus <strong>managers</strong>, facilitar el cumplimiento de la regulación, etc.”. El proyecto, añadió el responsable, implica un “gran cambio cultural”, pues “se trata de que el área de personas deje de realizar una gestión administrativa y de nómina a abordar una gestión del capital humano”.</p>



<p>La compañía, relató, confía en las posibilidades que trae consigo el software de la firma estadounidense, que se apalanca en la analítica de datos y la más reciente aplicación de agentes de inteligencia artificial, una tecnología que el directivo de Iberostar ve con buenos ojos incluso de cara a la captación de empleados. “Ya hemos realizado pilotos con IA que nos permiten realizar entrevistas de filtro con personas; esta tendencia, la de hablar con máquinas, que la gente más joven ya ha normalizado, entrará en los procesos de selección”, afirmó Zamora, convencido de que “la IA ayudará a quitar tareas administrativas a los gestores de forma que estos, en lugar de dedicar tanto tiempo a hacer informes, puedan centrarse en lo importante: en las personas y en sus equipos”.</p>



<figure class="wp-block-pullquote"><blockquote><p><strong><em>“La IA entrará en los procesos de selección</em></strong><em><strong> […] pero la máquina nunca va a tener la última decisión”</strong></em></p></blockquote></figure>



<p>Con la IA, recalcó, “la mejora de la experiencia del empleado será importante”. Agregó que la naturalidad que traerá consigo a las conversaciones con las máquinas el uso de la IA generativa por voz será un factor determinante para ello; no obstante, subrayó, “hay que actuar con prudencia y tener en cuenta que en un proceso de selección de personal la máquina nunca va a tener la última decisión”. “En un sector donde la experiencia del cliente depende directamente de las personas, la IA no debe sustituir el criterio humano, sino potenciarlo”, recalcó.</p>



<p>La implantación de la tecnología de gestión de personal de Workday forma parte de una estrategia tecnológica a mayor escala que implica también el uso de soluciones de otras herramientas de gestión con las que estará integrada la primera, como una solución de planificación financiera de SAP u otra de Microsoft (Fabric) para hacer análisis avanzado de datos corporativos.</p>



<h2 class="wp-block-heading">Adopción de la IA en la parte operacional de Iberostar</h2>



<p>Zamora desgranó también otros proyectos del grupo en los que la inteligencia artificial tiene un rol relevante desde el punto de vista de la operación. Uno es el <strong>sistema Winnow</strong>, “basado en el <em>machine learning</em> de toda la vida” que ha implantado ya en decenas de sus hoteles y gracias al que ha conseguido ahorrar en estos establecimientos millones de comidas al año. “Nos preocupa el desperdicio alimentario”, apuntó el directivo. Este proyecto forma parte de su movimiento de sostenibilidad Wave of Change, que nació en 2022 con el objetivo de ahorrar 1.600 toneladas de residuos alimentarios al año, es decir, unos 5,3 millones de comidas.</p>



<p>El otro proyecto mencionado por Zamora fue <strong>BRAIAN</strong>, una inteligencia artificial diseñada para optimizar el consumo energético en los hoteles sin impactar en los huéspedes. La solución, desarrollada con la compañía Sener y que también forma parte del movimiento Wave of Change, tiene como objetivo reducir en un 35% el consumo energético y en un 85% las emisiones de alcance 1 y 2 para 2030.</p>



<p>Ya desde un punto de vista más general de transformación digital, Iberostar, bajo su <a href="https://www.cio.com/article/2071040/mantendremos-nuestra-apuesta-por-la-innovacion-abierta-con-caracter-indefinido.html">proyecto Hotel Digital</a>, utiliza la inteligencia artificial para mejorar la experiencia del cliente.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Gaming-Headset Logitech G Astro A50 Gen 5 im Test]]></title>
<description><![CDATA[Als Gaming-Headset überzeugt das Logitech G Astro A50 Gen 5 unter anderem mit einem hervorragenden Mikrofon und top Sound.]]></description>
<link>https://tsecurity.de/de/3210564/it-nachrichten/gaming-headset-logitech-g-astro-a50-gen-5-im-test/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3210564/it-nachrichten/gaming-headset-logitech-g-astro-a50-gen-5-im-test/</guid>
<pubDate>Tue, 13 Jan 2026 16:31:43 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Als Gaming-Headset überzeugt das Logitech G Astro A50 Gen 5 unter anderem mit einem hervorragenden Mikrofon und top Sound.]]></content:encoded>
</item>
<item>
<title><![CDATA[Vera-Rubin-Teleskop entdeckt viel zu schnell drehenden Asteroiden]]></title>
<description><![CDATA[Riesig, rasant und massiv: Der Asteroid "2025 MN45" stellt bis­her­ige Beobachtungen in den Schatten. Mit einer Rotation von 1,88 Minuten ist er der schnellste bekannte Körper seiner Klasse. Astro­nomen verdanken den Fund der neuen LSST-Kamera in Chile.			(Weiter lesen)]]></description>
<link>https://tsecurity.de/de/3205498/it-security-nachrichten/vera-rubin-teleskop-entdeckt-viel-zu-schnell-drehenden-asteroiden/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3205498/it-security-nachrichten/vera-rubin-teleskop-entdeckt-viel-zu-schnell-drehenden-asteroiden/</guid>
<pubDate>Sat, 10 Jan 2026 11:50:21 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://winfuture.de/news,156093.html"><img hspace="5" border="0" align="left" alt="Weltraum, Raumfahrt, Weltall, Mond, Planet, Sterne, Asteroid, Space, Asteroiden, Komet" width="1920" height="1080" src="https://i.wfcdn.de/teaser/1920/51694.jpg"></a>
			Riesig, rasant und massiv: Der Asteroid "2025 MN45" stellt bis­her­ige Beobachtungen in den Schatten. Mit einer Rotation von 1,88 Minuten ist er der schnellste bekannte Körper seiner Klasse. Astro­nomen verdanken den Fund der neuen LSST-Kamera in Chile.			(<a href="https://winfuture.de/news,156093.html">Weiter lesen</a>)]]></content:encoded>
</item>
<item>
<title><![CDATA[Raum 641a & FoxAcid: Wie die NSA deine Verschlüsselung knackt (Song) 🔐💀]]></title>
<description><![CDATA[⚛️ Q-DAY: FoxAcid, Logjam & Shor – Die Werkzeuge der totalen Entschlüsselung 🔓  Kernaussage (Lyrics-Analyse): 🕸️ Raum 641a: Der Song referenziert den berühmten Raum in San Francisco, wo AT&T mittels "Splittern" den Datenverkehr direkt am Glasfaserkabel kopierte und an die NSA weiterleitete ("Pris...]]></description>
<link>https://tsecurity.de/de/3202886/it-security-nachrichten/raum-641a-foxacid-wie-die-nsa-deine-verschluesselung-knackt-song/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3202886/it-security-nachrichten/raum-641a-foxacid-wie-die-nsa-deine-verschluesselung-knackt-song/</guid>
<pubDate>Fri, 09 Jan 2026 00:06:02 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<table> <tr><td> <a href="https://www.reddit.com/r/Computersicherheit/comments/1q7iazk/raum_641a_foxacid_wie_die_nsa_deine/"> <img src="https://external-preview.redd.it/OJfalQ0ho95D6IUFPIybXJ8Pn459PiwqCyi4FXN4mco.jpeg?width=320&amp;crop=smart&amp;auto=webp&amp;s=7ec3d61acab4e8895d07f61bde5c461fcde159d2" alt="Raum 641a &amp; FoxAcid: Wie die NSA deine Verschlüsselung knackt (Song) 🔐💀" title="Raum 641a &amp; FoxAcid: Wie die NSA deine Verschlüsselung knackt (Song) 🔐💀"> </a> </td><td> <!-- SC_OFF --><div class="md"><p>⚛️ Q-DAY: FoxAcid, Logjam &amp; Shor – Die Werkzeuge der totalen Entschlüsselung 🔓 </p> <p>Kernaussage (Lyrics-Analyse):<br> 🕸️ Raum 641a: Der Song referenziert den berühmten Raum in San Francisco, wo AT&amp;T mittels "Splittern" den Datenverkehr direkt am Glasfaserkabel kopierte und an die NSA weiterleitete ("Prisma im Kabel").<br> 💾 HNDL (Harvest Now, Decrypt Later): Im Utah Data Center werden "Exabytes an Bändern" gelagert. Die Wette auf die Zukunft: Was heute verschlüsselt ist, knackt der Quantencomputer morgen.<br> ⚔️ Aktive Angriffe: Erwähnung von "FoxAcid" (NSA-System für Quantum Insert Angriffe) und "Man-on-the-Side". Verbindungen werden aktiv manipuliert ("Downgrade"), um starke Krypto zu umgehen.<br> 🧮 Der Shor-Algorithmus: Wenn der Quantencomputer da ist ("1 Million Qubits"), frisst der Shor-Algorithmus die Primzahlen ("Bremsalen" im Transkript korrigiert), auf denen unsere Sicherheit (RSA) basiert.</p> <p><a href="https://www.youtube.com/watch?v=Nd2DeT9TS1M">Quantum Insert &amp; Backbone-Spionage: Die geheimen Werkzeuge der NSA</a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Horus_Sirius"> /u/Horus_Sirius </a> <br> <span><a href="https://www.youtube.com/watch?v=I8Q1rEaeLA4">[link]</a></span>   <span><a href="https://www.reddit.com/r/Computersicherheit/comments/1q7iazk/raum_641a_foxacid_wie_die_nsa_deine/">[comments]</a></span> </td></tr></table>]]></content:encoded>
</item>
<item>
<title><![CDATA[Raum 641a & FoxAcid: Wie die NSA deine Verschlüsselung knackt (Song) 🔐💀]]></title>
<description><![CDATA[Author: VAZULES Analysiert - Bewertung: 1x - Views:7 ▶️ MUSIKALISCHER TECH-THRILLER: Ein Cyberpunk-Track über Raum 641a, FoxAcid und den Tag, an dem die Krypto fällt (Q-Day). "Harvest Now, Decrypt Later" ist keine Theorie, es ist der Modus Operandi.

---Thema:
⚛️ Q-DAY: FoxAcid, Logjam & Shor – D...]]></description>
<link>https://tsecurity.de/de/3201219/it-security-video/raum-641a-foxacid-wie-die-nsa-deine-verschluesselung-knackt-song/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3201219/it-security-video/raum-641a-foxacid-wie-die-nsa-deine-verschluesselung-knackt-song/</guid>
<pubDate>Thu, 08 Jan 2026 09:33:12 +0100</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: VAZULES Analysiert - Bewertung: 1x - Views:7 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/I8Q1rEaeLA4?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>▶️ MUSIKALISCHER TECH-THRILLER: Ein Cyberpunk-Track über Raum 641a, FoxAcid und den Tag, an dem die Krypto fällt (Q-Day). "Harvest Now, Decrypt Later" ist keine Theorie, es ist der Modus Operandi.<br />
<br />
---Thema:<br />
⚛️ Q-DAY: FoxAcid, Logjam & Shor – Die Werkzeuge der totalen Entschlüsselung 🔓<br />
<br />
---<br />
<br />
Kernaussage (Lyrics-Analyse):<br />
🕸️ Raum 641a: Der Song referenziert den berühmten Raum in San Francisco, wo AT&T mittels "Splittern" den Datenverkehr direkt am Glasfaserkabel kopierte und an die NSA weiterleitete ("Prisma im Kabel").<br />
💾 HNDL (Harvest Now, Decrypt Later): Im Utah Data Center werden "Exabytes an Bändern" gelagert. Die Wette auf die Zukunft: Was heute verschlüsselt ist, knackt der Quantencomputer morgen.<br />
⚔️ Aktive Angriffe: Erwähnung von "FoxAcid" (NSA-System für Quantum Insert Angriffe) und "Man-on-the-Side". Verbindungen werden aktiv manipuliert ("Downgrade"), um starke Krypto zu umgehen.<br />
🧮 Der Shor-Algorithmus: Wenn der Quantencomputer da ist ("1 Million Qubits"), frisst der Shor-Algorithmus die Primzahlen ("Bremsalen" im Transkript korrigiert), auf denen unsere Sicherheit (RSA) basiert.<br />
<br />
Quellen:<br />
https://www.youtube.com/watch?v=Nd2DeT9TS1M<br />
PDF:<br />
https://tsecurity.de/eBooks/Utah%20Data%20Center,%20Root-Server,%20Quantencomputer.pdf<br />
<br />
#QDay #FoxAcid #Room641a #NSA #QuantumComputing #PostQuantum #HNDL #LaKanDoR #CyberSecurity<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-58179 | withastro up to 12.6.5 Generated Image Optimization Endpoint server-side request forgery (GHSA-qpr4-c339-7vq8 / EUVD-2025-26878)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in withastro astro up to 12.6.5. Impacted is an unknown function of the component Generated Image Optimization Endpoint. Such manipulation leads to server-side request forgery.

This vulnerability is uniquely identified as CVE-2025-58179. ...]]></description>
<link>https://tsecurity.de/de/3175111/sicherheitsluecken/cve-2025-58179-withastro-up-to-1265-generated-image-optimization-endpoint-server-side-request-forgery-ghsa-qpr4-c339-7vq8-euvd-2025-26878/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3175111/sicherheitsluecken/cve-2025-58179-withastro-up-to-1265-generated-image-optimization-endpoint-server-side-request-forgery-ghsa-qpr4-c339-7vq8-euvd-2025-26878/</guid>
<pubDate>Tue, 23 Dec 2025 03:36:36 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/?kb.risk">critical</a> has been identified in <a href="https://vuldb.com/?product.withastro:astro">withastro astro up to 12.6.5</a>. Impacted is an unknown function of the component <em>Generated Image Optimization Endpoint</em>. Such manipulation leads to server-side request forgery.

This vulnerability is uniquely identified as <a href="https://vuldb.com/?source_cve.322713">CVE-2025-58179</a>. The attack can be launched remotely. No exploit exists.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[Der unsichtbare Krieg - arte - TV-Programm - Prisma]]></title>
<description><![CDATA[Wie der Bundestagshack 2015 gezeigt hat, können Hacker einen Staat außer Gefecht setzen. Seither. Vergrößern. Fotoquelle: © Sven Wildenhayn/Gruppe 5.]]></description>
<link>https://tsecurity.de/de/3161976/hacking/der-unsichtbare-krieg-arte-tv-programm-prisma/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3161976/hacking/der-unsichtbare-krieg-arte-tv-programm-prisma/</guid>
<pubDate>Tue, 16 Dec 2025 11:51:14 +0100</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wie der Bundestagshack 2015 gezeigt hat, können <b>Hacker</b> einen Staat außer Gefecht setzen. Seither. Vergrößern. Fotoquelle: © Sven Wildenhayn/Gruppe 5.]]></content:encoded>
</item>
<item>
<title><![CDATA[Seagate’s Astro Bot Limited Edition HDD combines reliable storage with playful design — here’s how it stacks up in our review]]></title>
<description><![CDATA[Seagate's Astro Bot-themed game drive is a limited edition HDD that works for PC, PlayStation 5, and PlayStation 4. But is it worth buying for PC? Our review.]]></description>
<link>https://tsecurity.de/de/3158205/windows-tipps/seagates-astro-bot-limited-edition-hdd-combines-reliable-storage-with-playful-design-heres-how-it-stacks-up-in-our-review/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3158205/windows-tipps/seagates-astro-bot-limited-edition-hdd-combines-reliable-storage-with-playful-design-heres-how-it-stacks-up-in-our-review/</guid>
<pubDate>Sun, 14 Dec 2025 15:06:39 +0100</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Seagate's Astro Bot-themed game drive is a limited edition HDD that works for PC, PlayStation 5, and PlayStation 4. But is it worth buying for PC? Our review.]]></content:encoded>
</item>
<item>
<title><![CDATA[XXL Adventskalender 2025 (Tür 13)]]></title>
<description><![CDATA[Das dreizehnte Türchen unseres XXL Adventskalender öffnet sich und zusammen mit unserem Partner Seagate gibt es eine limitierte Astro Bot 5 TB Festplatte. Was gibt es zu gewinnen? 1x Seagate PlayStation Game Drive 5 TB Astro Bot   Teilnahme Wie immer setzen wir dafür das leicht zu bedienende Verl...]]></description>
<link>https://tsecurity.de/de/3157438/it-nachrichten/xxl-adventskalender-2025-tuer-13/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3157438/it-nachrichten/xxl-adventskalender-2025-tuer-13/</guid>
<pubDate>Sat, 13 Dec 2025 20:01:12 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Das dreizehnte Türchen unseres XXL Adventskalender öffnet sich und zusammen mit unserem Partner Seagate gibt es eine limitierte Astro Bot 5 TB Festplatte. Was gibt es zu gewinnen? 1x Seagate PlayStation Game Drive 5 TB Astro Bot   Teilnahme Wie immer setzen wir dafür das leicht zu bedienende Verlosungswidget von Gleam ein. Hier könnt ihr  ...</p>
<p>The post <a href="https://www.newgadgets.de/98911/xxl-adventskalender-2025-tuer-13/">XXL Adventskalender 2025 (Tür 13)</a> appeared first on <a href="https://www.newgadgets.de/">NewGadgets.de</a>.</p>
<img src="https://analytics.taquiri.de/piwik.php?idsite=35&amp;rec=1&amp;url=https%3A%2F%2Fwww.newgadgets.de%2F98911%2Fxxl-adventskalender-2025-tuer-13%2F&amp;action_name=XXL+Adventskalender+2025+%28T%C3%BCr+13%29&amp;urlref=https%3A%2F%2Fwww.newgadgets.de%2Ffeed%2F" width="0" height="0" alt="">]]></content:encoded>
</item>
<item>
<title><![CDATA[Linting-Stack für Node-Projekte: Code-Qualität, Formatierung und Prosa-Linting]]></title>
<description><![CDATA[Ein dreistufiger Linting-Ansatz mit ESLint, Prettier und Vale verbessert Qualität von Code und Dokumentation in Astro-Projekten durch automatisiertes Prüfen.]]></description>
<link>https://tsecurity.de/de/3156683/it-nachrichten/linting-stack-fuer-node-projekte-code-qualitaet-formatierung-und-prosa-linting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3156683/it-nachrichten/linting-stack-fuer-node-projekte-code-qualitaet-formatierung-und-prosa-linting/</guid>
<pubDate>Sat, 13 Dec 2025 08:50:22 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein dreistufiger Linting-Ansatz mit ESLint, Prettier und Vale verbessert Qualität von Code und Dokumentation in Astro-Projekten durch automatisiertes Prüfen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Redefining Workspace: Prisma Browser Secures Leadership in Frost Radar]]></title>
<description><![CDATA[Prisma Browser is the Frost Radar leader for ZTBS! Learn how our Precision AI-powered security transforms your browser from attack vector to defense. The post Redefining Workspace: Prisma Browser Secures Leadership in Frost Radar appeared first on Palo Alto Networks…
Read more →
The post Redefini...]]></description>
<link>https://tsecurity.de/de/3154058/it-security-nachrichten/redefining-workspace-prisma-browser-secures-leadership-in-frost-radar/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3154058/it-security-nachrichten/redefining-workspace-prisma-browser-secures-leadership-in-frost-radar/</guid>
<pubDate>Thu, 11 Dec 2025 23:50:41 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Prisma Browser is the Frost Radar leader for ZTBS! Learn how our Precision AI-powered security transforms your browser from attack vector to defense. The post Redefining Workspace: Prisma Browser Secures Leadership in Frost Radar appeared first on Palo Alto Networks…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/redefining-workspace-prisma-browser-secures-leadership-in-frost-radar/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/redefining-workspace-prisma-browser-secures-leadership-in-frost-radar/">Redefining Workspace: Prisma Browser Secures Leadership in Frost Radar</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Partners Are Fueling Innovation with Cortex XSIAM and Prisma SASE]]></title>
<description><![CDATA[Solution providers voted us #1 – Cortex XSIAM is CRN’s 2025 Product of the Year and Prisma SASE is a 2025 Tech Innovator. The post Partners Are Fueling Innovation with Cortex XSIAM and Prisma SASE appeared first on Palo Alto…
Read more →
The post Partners Are Fueling Innovation with Cortex XSIAM ...]]></description>
<link>https://tsecurity.de/de/3148751/it-security-nachrichten/partners-are-fueling-innovation-with-cortex-xsiam-and-prisma-sase/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3148751/it-security-nachrichten/partners-are-fueling-innovation-with-cortex-xsiam-and-prisma-sase/</guid>
<pubDate>Tue, 09 Dec 2025 19:34:58 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Solution providers voted us #1 – Cortex XSIAM is CRN’s 2025 Product of the Year and Prisma SASE is a 2025 Tech Innovator. The post Partners Are Fueling Innovation with Cortex XSIAM and Prisma SASE appeared first on Palo Alto…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/partners-are-fueling-innovation-with-cortex-xsiam-and-prisma-sase/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/partners-are-fueling-innovation-with-cortex-xsiam-and-prisma-sase/">Partners Are Fueling Innovation with Cortex XSIAM and Prisma SASE</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-66202 | withastro up to 5.15.7 non-canonical url paths for authorization decisions (GHSA-ggxq-hp9w-j794 / CNNVD-202512-1079)]]></title>
<description><![CDATA[A vulnerability was found in withastro astro up to 5.15.7 and classified as critical. Affected by this issue is some unknown functionality. The manipulation results in use of non-canonical url paths for authorization decisions.

This vulnerability is cataloged as CVE-2025-66202. The attack may be...]]></description>
<link>https://tsecurity.de/de/3148414/sicherheitsluecken/cve-2025-66202-withastro-up-to-5157-non-canonical-url-paths-for-authorization-decisions-ghsa-ggxq-hp9w-j794-cnnvd-202512-1079/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3148414/sicherheitsluecken/cve-2025-66202-withastro-up-to-5157-non-canonical-url-paths-for-authorization-decisions-ghsa-ggxq-hp9w-j794-cnnvd-202512-1079/</guid>
<pubDate>Tue, 09 Dec 2025 17:05:03 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.withastro:astro">withastro astro up to 5.15.7</a> and classified as <a href="https://vuldb.com/?kb.risk">critical</a>. Affected by this issue is some unknown functionality. The manipulation results in use of non-canonical url paths for authorization decisions.

This vulnerability is cataloged as <a href="https://vuldb.com/?source_cve.335095">CVE-2025-66202</a>. The attack may be launched remotely. There is no exploit available.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[PS5-Spieler müssen zuschlagen! MediaMarkt wirft euch jetzt für 29,99 Euro Astro Bot hinterher]]></title>
<description><![CDATA[Ein Spiel, das selbst abgebrühte Gamer zum Staunen bringt – und das aktuell für unter 30 Euro zu haben ist.]]></description>
<link>https://tsecurity.de/de/3138828/it-nachrichten/ps5-spieler-muessen-zuschlagen-mediamarkt-wirft-euch-jetzt-fuer-2999-euro-astro-bot-hinterher/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3138828/it-nachrichten/ps5-spieler-muessen-zuschlagen-mediamarkt-wirft-euch-jetzt-fuer-2999-euro-astro-bot-hinterher/</guid>
<pubDate>Thu, 04 Dec 2025 16:16:57 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein Spiel, das selbst abgebrühte Gamer zum Staunen bringt – und das aktuell für unter 30 Euro zu haben ist.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-9468 | Palo Alto PAN-OS/Cloud NGFW/Prisma Access Packet out-of-bounds write]]></title>
<description><![CDATA[A vulnerability was found in Palo Alto PAN-OS, Cloud NGFW and Prisma Access and classified as critical. This affects an unknown function of the component Packet Handler. Executing manipulation can lead to out-of-bounds write.

This vulnerability is tracked as CVE-2024-9468. The attack can be laun...]]></description>
<link>https://tsecurity.de/de/3131907/sicherheitsluecken/cve-2024-9468-palo-alto-pan-oscloud-ngfwprisma-access-packet-out-of-bounds-write/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3131907/sicherheitsluecken/cve-2024-9468-palo-alto-pan-oscloud-ngfwprisma-access-packet-out-of-bounds-write/</guid>
<pubDate>Mon, 01 Dec 2025 20:35:59 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.palo_alto:pan-os">Palo Alto PAN-OS, Cloud NGFW and Prisma Access</a> and classified as <a href="https://vuldb.com/?kb.risk">critical</a>. This affects an unknown function of the component <em>Packet Handler</em>. Executing manipulation can lead to out-of-bounds write.

This vulnerability is tracked as <a href="https://vuldb.com/?source_cve.279893">CVE-2024-9468</a>. The attack can be launched remotely. No exploit exists.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Perfekt für Weihnachten: PS5-Meisterwerk Astro Bot radikal reduziert]]></title>
<description><![CDATA[Wer glaubt, Astro Bot sei nur bunter Zeitvertreib für Kinder, verpasst eines der besten PS5-Spiele überhaupt. Der Plattformer ist eine Hommage an die PlayStation-Ära und fesselt Erwachsene mit Nostalgie und genialem Leveldesign genauso wie den Nachwuchs. Bei MediaMarkt fällt der Preis für das Top...]]></description>
<link>https://tsecurity.de/de/3130379/it-nachrichten/perfekt-fuer-weihnachten-ps5-meisterwerk-astro-bot-radikal-reduziert/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3130379/it-nachrichten/perfekt-fuer-weihnachten-ps5-meisterwerk-astro-bot-radikal-reduziert/</guid>
<pubDate>Mon, 01 Dec 2025 09:46:51 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img align="right" alt="" width="60" height="34" src="https://quadro.burda-forward.de/ctf/9521f661-f922-4d8e-9af4-b8c66fcf405e.c8db5697-d525-43c3-82f9-7fe7f5dcb0b1.jpg?im=AspectCrop%2Csize%3D%2830%2C+17%29%2Cgravity%3DCenter%2CallowExpansion%3BResize%3D%2860%2C+34%29%2Caspect%3Dfit%3BBackgroundColor%2Ccolor%3Dffffff&amp;impolicy=chip&amp;hash=e8d6f9df6b724ffd41143e6f4f022a6fbfe24b231a1336a7634585edc4b33b76"> Wer glaubt, Astro Bot sei nur bunter Zeitvertreib für Kinder, verpasst eines der besten PS5-Spiele überhaupt. Der Plattformer ist eine Hommage an die PlayStation-Ära und fesselt Erwachsene mit Nostalgie und genialem Leveldesign genauso wie den Nachwuchs. Bei MediaMarkt fällt der Preis für das Top-Spiel jetzt auf ein Rekordtief von unter 40 Euro.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-64765 | withastro up to 5.15.7 decodeURI path traversal]]></title>
<description><![CDATA[A vulnerability identified as critical has been detected in withastro astro up to 5.15.7. Affected by this issue is the function decodeURI. This manipulation causes path traversal.

This vulnerability is handled as CVE-2025-64765. The attack can be initiated remotely. There is not any exploit ava...]]></description>
<link>https://tsecurity.de/de/3123299/sicherheitsluecken/cve-2025-64765-withastro-up-to-5157-decodeuri-path-traversal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3123299/sicherheitsluecken/cve-2025-64765-withastro-up-to-5157-decodeuri-path-traversal/</guid>
<pubDate>Thu, 27 Nov 2025 08:50:46 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/?kb.risk">critical</a> has been detected in <a href="https://vuldb.com/?product.withastro:astro">withastro astro up to 5.15.7</a>. Affected by this issue is the function <code>decodeURI</code>. This manipulation causes path traversal.

This vulnerability is handled as <a href="https://vuldb.com/?source_cve.332972">CVE-2025-64765</a>. The attack can be initiated remotely. There is not any exploit available.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-65019 | withastro up to 5.15.8 Image Optimization Endpoint isRemoteAllowed cross site scripting]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in withastro astro up to 5.15.8. This issue affects the function isRemoteAllowed of the component Image Optimization Endpoint. Executing manipulation can lead to cross site scripting.

The identification of this vulnerability is CVE-202...]]></description>
<link>https://tsecurity.de/de/3123297/sicherheitsluecken/cve-2025-65019-withastro-up-to-5158-image-optimization-endpoint-isremoteallowed-cross-site-scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3123297/sicherheitsluecken/cve-2025-65019-withastro-up-to-5158-image-optimization-endpoint-isremoteallowed-cross-site-scripting/</guid>
<pubDate>Thu, 27 Nov 2025 08:50:44 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/?kb.risk">problematic</a> has been identified in <a href="https://vuldb.com/?product.withastro:astro">withastro astro up to 5.15.8</a>. This issue affects the function <code>isRemoteAllowed</code> of the component <em>Image Optimization Endpoint</em>. Executing manipulation can lead to cross site scripting.

The identification of this vulnerability is <a href="https://vuldb.com/?source_cve.332975">CVE-2025-65019</a>. The attack may be launched remotely. There is no exploit available.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-59837 | withastro up to 5.13.9 href server-side request forgery (GHSA-qcpr-679q-rhm2)]]></title>
<description><![CDATA[A vulnerability has been found in withastro astro up to 5.13.9 and classified as critical. The affected element is an unknown function. The manipulation of the argument href leads to server-side request forgery.

This vulnerability is uniquely identified as CVE-2025-59837. The attack is possible ...]]></description>
<link>https://tsecurity.de/de/3122994/sicherheitsluecken/cve-2025-59837-withastro-up-to-5139-href-server-side-request-forgery-ghsa-qcpr-679q-rhm2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3122994/sicherheitsluecken/cve-2025-59837-withastro-up-to-5139-href-server-side-request-forgery-ghsa-qcpr-679q-rhm2/</guid>
<pubDate>Thu, 27 Nov 2025 05:59:24 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/?product.withastro:astro">withastro astro up to 5.13.9</a> and classified as <a href="https://vuldb.com/?kb.risk">critical</a>. The affected element is an unknown function. The manipulation of the argument <em>href</em> leads to server-side request forgery.

This vulnerability is uniquely identified as <a href="https://vuldb.com/?source_cve.330348">CVE-2025-59837</a>. The attack is possible to be carried out remotely. No exploit exists.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[AI’s front door: Why the browser is your most critical control point]]></title>
<description><![CDATA[Enterprise security has a dark secret, one that threatens to undermine the multibillion dollar investments being made in artificial intelligence. Organizations have spent countless hours building fortified castles to protect their AI models and data lakes. Yet every day, the primary interface to ...]]></description>
<link>https://tsecurity.de/de/3122090/it-security-nachrichten/ais-front-door-why-the-browser-is-your-most-critical-control-point/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3122090/it-security-nachrichten/ais-front-door-why-the-browser-is-your-most-critical-control-point/</guid>
<pubDate>Wed, 26 Nov 2025 16:50:53 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Enterprise security has a dark secret, one that threatens to undermine the multibillion dollar investments being made in artificial intelligence. Organizations have spent countless hours building fortified castles to protect their AI models and data lakes. Yet every day, the primary interface to these powerful systems — the browser — remains an uncontrolled and unlocked front door.</p>



<p>Security leaders have rightly focused on securing the core of their AI infrastructure. Their focus, however, has often missed the most common point of interaction: the browser, a tool now transformed into a direct threat to innovation by the explosion of generative AI.</p>



<p>For all intents and purposes, the browser is the proverbial “front door” of the AI journey, the dynamic space where human ingenuity and machine intelligence converge. Unfortunately, leaving this front door ajar places a hard ceiling on the potential of an organization’s most strategic initiatives.</p>



<p><strong>Fresh wave of browser-borne risks</strong></p>



<p>The adoption of generative AI has introduced a new class of threats that are born and executed within the browser, far beyond the reach of traditional network security. The scale of this new risk is staggering. A recent internal study among our customers showed that GenAI traffic is up over 890% in 2024. Consequently, data security incidents related to GenAI had more than doubled.</p>



<p>These are not theoretical exploits; they are happening now, and one of the most common is the inadvertent exposure of sensitive data. For example, a well-meaning product manager, trying to summarize internal research, pastes confidential details about an upcoming product launch into a public LLM prompt. In that instant, sensitive intellectual property has been used to train a third-party model, with no visibility or control.</p>



<p>The risks, though, extend far beyond data leakage. Malicious prompt injection, where an attacker crafts a query to trick AI into performing an unauthorized action, <a href="https://unit42.paloaltonetworks.com/new-frontier-of-genai-threats-a-comprehensive-guide-to-prompt-attacks/">is another growing threat</a>. Imagine an AI-powered customer support bot, accessed through a standard web browser, being manipulated by a malicious prompt to reveal another customer’s personal information. These are serious application-layer attacks that exploit the trusted interface of the browser and put billions of data records at risk.</p>



<p><strong>New architecture of control</strong></p>



<p>To combat these new, browser-borne threats, the enterprise browser itself must become the new architecture of control. This is its new mandate: to evolve from a simple access tool into a sophisticated security platform, providing the deep visibility and granular control required to safely enable the widespread use of AI.</p>



<p>The foundation for this platform begins with a fundamental shift to a zero trust framework that extends to the browser itself — where all activity context is visible. This framework enforces rigorous device posture checks and continuous trust verification before granting access to any application. It means having the power to enforce a new standard of more granular digital hygiene directly at the point of interaction. This includes the ability to dynamically mask sensitive data within prompts, prevent unauthorized screenshots of sensitive data and manage file transfers to block uploads of intellectual property to personal drives. The framework creates a secure workspace within the browser, protecting business applications from web-based threats and compromised endpoints.</p>



<p>For too long, the browser has been the unspoken vulnerability in our security strategies. By transforming it into an intelligent control point, we categorically address this “dark secret.” Securing this critical avenue closes an important security gap and unlocks the full potential of AI. It provides the confidence needed to empower employees, accelerate development, and build the next wave of innovation safely.</p>



<p>The browser goes beyond just being the front door. It is also the foundation for enabling AI with confidence and control. See what the <a href="https://www.paloaltonetworks.com/sase/prisma-browser">browser can do for you</a>.</p>



<p>Curious about what else Anand has to say? Check out his other articles on <a href="https://www.paloaltonetworks.com/perspectives/author/anand-oswal/" rel="sponsored">Perspectives</a>.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Palo Alto kündigt Cortex AgentiX für sichere KI-Agenten an]]></title>
<description><![CDATA[Auf der digitale Veranstaltung „Ignite: Whats Next“ kündigt Palo Alto Networks die neue Cortex-AgentiX-Plattform an. Diese soll eine sichere, autonome und agentenbasierte Arbeitswelt ermöglichen. Dazu bekommen Prisma AIRS und Cortex Cloud ein 2.0-Update.]]></description>
<link>https://tsecurity.de/de/3111587/it-security-nachrichten/palo-alto-kuendigt-cortex-agentix-fuer-sichere-ki-agenten-an/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3111587/it-security-nachrichten/palo-alto-kuendigt-cortex-agentix-fuer-sichere-ki-agenten-an/</guid>
<pubDate>Fri, 21 Nov 2025 09:35:02 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Auf der digitale Veranstaltung „Ignite: Whats Next“ kündigt Palo Alto Networks die neue Cortex-AgentiX-Plattform an. Diese soll eine sichere, autonome und agentenbasierte Arbeitswelt ermöglichen. Dazu bekommen Prisma AIRS und Cortex Cloud ein 2.0-Update.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-64764 | withastro up to 5.15.7 cross site scripting]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in withastro astro up to 5.15.7. This vulnerability affects unknown code. Performing manipulation results in basic cross site scripting.

This vulnerability was named CVE-2025-64764. The attack may be initiated remotely. There is no availabl...]]></description>
<link>https://tsecurity.de/de/3111553/sicherheitsluecken/cve-2025-64764-withastro-up-to-5157-cross-site-scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3111553/sicherheitsluecken/cve-2025-64764-withastro-up-to-5157-cross-site-scripting/</guid>
<pubDate>Fri, 21 Nov 2025 09:24:02 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/?kb.risk">problematic</a> has been reported in <a href="https://vuldb.com/?product.withastro:astro">withastro astro up to 5.15.7</a>. This vulnerability affects unknown code. Performing manipulation results in basic cross site scripting.

This vulnerability was named <a href="https://vuldb.com/?source_cve.332974">CVE-2025-64764</a>. The attack may be initiated remotely. There is no available exploit.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Movistar Plus+ emprende la atención al cliente con agentes de IA]]></title>
<description><![CDATA[Movistar Plus+, la factoría de contenidos del grupo Telefónica que nació en 2015 tras la fusión de las plataformas Canal+ y Movistar TV, comenzó su andadura como un servicio de valor añadido a la oferta de conectividad de la operadora española, pero, desde verano de 2023, comercializa de forma in...]]></description>
<link>https://tsecurity.de/de/3104214/it-security-nachrichten/movistar-plus-emprende-la-atencin-al-cliente-con-agentes-de-ia/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3104214/it-security-nachrichten/movistar-plus-emprende-la-atencin-al-cliente-con-agentes-de-ia/</guid>
<pubDate>Tue, 18 Nov 2025 11:33:59 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><strong>Movistar Plus+</strong>, la factoría de contenidos del grupo Telefónica que nació en 2015 tras la fusión de las plataformas Canal+ y Movistar TV, comenzó su andadura como un servicio de valor añadido a la oferta de conectividad de la operadora española, pero, desde verano de 2023, comercializa de forma independiente el acceso a su plataforma de pago por suscripción, que alberga series, películas, documentales, programas de entretenimiento y múltiples canales de televisión en directo y bajo demanda. Esta evolución, según <strong>Roberto Rodríguez Fernández</strong>, director de soporte al cliente de Movistar Plus+, ha propiciado que la compañía aborde la atención a sus consumidores desde un prisma completamente diferente, para lo que se ha apoyado en la inteligencia artificial y, en concreto, en los <strong>agentes de IA que facilita la tecnológica Salesforce</strong>, que es también su proveedor de software CRM.</p>



<p>“La salida al mercado de forma independiente de Movistar Plus+ no solo nos ha permitido utilizar los datos que tenemos y monetizarlos, sino tener un producto de entrada para presentar toda la cadena de valor del grupo”, aseveró el portavoz en un encuentro con prensa organizado por la propia Salesforce, donde Rodríguez presentó el caso de éxito. El responsable explicó que la plataforma de acceso al contenido de Movistar Plus+ es “un producto digital gestionado por los clientes, con una web ideada para administrar la suscripción”. El proyecto, contó, arrancó con tres canales de contacto con el cliente: un formulario, un correo electrónico y un <em>chatbot </em>que empezaron a implementar en marzo de 2024 dentro de su centro de ayuda. </p>



<p>Este último, tras unos meses en piloto, empezó a funcionar en marzo de este año, convirtiéndose en el primer caso de uso de la plataforma de agentes de IA Agentforce de Salesforce que se implanta en la empresa de Telefónica.</p>



<h2 class="wp-block-heading">Respuestas automatizadas en milisegundos</h2>



<p>El nuevo agente de IA, contó Roberto Rodríguez, es capaz de responder las consultas e incidencias que trasladan los clientes basándose en los artículos de conocimiento de los que consta la plataforma de la factoría de contenidos; aquellas consultas que no es capaz de solventar por su complejidad, dijo el directivo, se las traslada a los profesionales de atención al cliente de Movistar Plus+ para que lo hagan estos.</p>



<p>“Elegimos Salesforce para la gestión del marketing y la atención al cliente, todo enlazado con nuestros portales y con el propósito de tener una foto de 360 grados y en tiempo récord de nuestros clientes”, explicó el portavoz, que relató que la funcionalidad de dicho agente de IA se ha ampliado recientemente —el pasado mes de julio— para ofrecer también respuestas sobre contenidos deportivos utilizando la plataforma de datos nativa del fabricante de CRM (Data Cloud). “Ahora el agente de IA es capaz de responder, por ejemplo, amplia información sobre los próximos partidos que vamos a emitir en nuestra plataforma en cuestión de milisegundos, y lo mejor es que lo hace a cualquier hora”.</p>



<figure class="wp-block-pullquote"><blockquote><p><strong><em>El 70% de los profesionales de atención al cliente de Movistar Plus+ ya utilizan los agentes de IA</em></strong></p></blockquote></figure>



<p>Rodríguez subrayó que, gracias al uso de la plataforma de agentes de IA, la compañía ahora puede aportar respuestas inteligentes automatizadas a sus clientes. El agente lo hace buscando la información en más de un millón de contenidos y diez planes de TV. “Este proyecto nos ha permitido mejorar significativamente el servicio al cliente; sin duda, el paso de la IA predictiva a la generativa es brutal. Con la IA predictiva no era posible dar una respuesta para cada una de las preguntas del cliente. Eso sí, lo retador de esta nueva tecnología es que, como no siempre contesta lo mismo, hay que garantizar la coherencia en el contenido de la respuesta”.</p>



<p>En este sentido, el portavoz de Movistar Plus+ afirmó que, “mientras con la IA predictiva ante dos preguntas diferentes el cliente podía obtener dos respuestas iguales, con la IA generativa ante dos preguntas iguales, el cliente puede recibir dos respuestas distintas”. Lo positivo de esto, añadió, es que “no da la sensación de que está contestando una máquina, lo que hace que la experiencia del cliente y la calidad de la respuesta que le damos mejore mucho, además, por supuesto, de acelerar la rapidez en dicha respuesta y de poder brindarla a cualquier hora del día o la noche, pues hay que tener en cuenta que muchas de las consultas que recibimos sobre nuestros contenidos son en tiempo de ocio e incluso en nuestra noche, como ocurre con la retransmisión de la gala de los Premios Oscar”.</p>



<p>En la actualidad, añadió el portavoz, los profesionales de soporte al cliente de la compañía gestionan todas las consultas e incidencias que pueden tramitar dentro de su horario de trabajo y, aquellas a las que no llegan, tanto por volumen como porque las reciben fuera de su horario laboral, se gestionan con la tecnología de agentes de Salesforce. “El uso de agentes de IA ha empoderado a nuestros agentes de atención al cliente humanos”, añadió, desvelando que el 70% de los profesionales de atención al cliente de Movistar Plus+ ya utilizan la plataforma de agentes autónomos de Salesforce en lo que define “un win-win entre la empresa y los empleados”.</p>



<p>Rodríguez subrayó la “robustez y sencillez” de la nueva plataforma de agentes de Salesforce, “a pesar de ser un producto nuevo”. Reconoció, no obstante, que disponer del CRM de Salesforce hizo que esta adopción fuera más sencilla.</p>



<figure class="wp-block-pullquote"><blockquote><p><strong><em>“El paso de la IA predictiva a la generativa es brutal. Con la primera no era posible dar una respuesta para cada una de las preguntas del cliente, aunque lo retador de la segunda es que, como no siempre contesta lo mismo, hay que garantizar la coherencia en el contenido de la respuesta”</em></strong></p></blockquote></figure>



<h2 class="wp-block-heading">Futuro: agilizar los casos no resueltos, hacer recomendaciones e incorporar la voz</h2>



<p>De cara al futuro, el equipo de atención al cliente de Movistar Plus+ trabaja en mejorar la tramitación de los casos no resueltos por parte de los agentes automatizados. “También queremos incorporar nuevas variables, por ejemplo, para que los clientes puedan tramitar una cancelación del servicio y que lo resuelva un agente de IA”.</p>



<p>Al margen de esto, Rodríguez tiene claro que su idea es “abrir el potencial de la plataforma de agentes de Salesforce al resto de canales con los que nos comunicamos con los clientes. Dos tercios de los contactos que nos llegan son a través del canal de datos, pero también recibimos a través del formulario o por mail, y queremos agilizar también estos últimos y usar Agentforce para monitorizar los casos de clientes”. </p>



<p>El objetivo, según el portavoz, es “implantar un modelo en tiempo real que nos permita tener información sobre todo lo que está pasando en lo que respecta a la gestión del cliente y, de cara a un futuro más lejano, queremos que los agentes no solo gestionen, sino que sean prescriptores de nuestra oferta, en función de las variables demográficas y geográficas del cliente que les consulta”. Además, agregó, explorarán la incorporación del canal de voz automatizado que acaba de presentar el pasado mes Salesforce dentro de su propuesta Agentforce.</p>



<p>“El mayor reto de este proyecto —culminó Rodríguez— es “implantar esta tecnología de agentes de IA de forma que sea transparente para el cliente y que éste siga percibiendo la misma calidad de atención que si tratara con él una persona; no obstante, en mi opinión, implantar la automatización garantiza una buena experiencia de cliente”.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-64745 | withastro up to 5.15.5 URL cross site scripting (GHSA-w2vj-39qv-7vh7 / EUVD-2025-175382)]]></title>
<description><![CDATA[A vulnerability was found in withastro astro up to 5.15.5 and classified as problematic. The affected element is an unknown function of the component URL Handler. The manipulation results in cross site scripting.

This vulnerability was named CVE-2025-64745. The attack may be performed from remot...]]></description>
<link>https://tsecurity.de/de/3100410/sicherheitsluecken/cve-2025-64745-withastro-up-to-5155-url-cross-site-scripting-ghsa-w2vj-39qv-7vh7-euvd-2025-175382/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3100410/sicherheitsluecken/cve-2025-64745-withastro-up-to-5155-url-cross-site-scripting-ghsa-w2vj-39qv-7vh7-euvd-2025-175382/</guid>
<pubDate>Sat, 15 Nov 2025 23:35:42 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.withastro:astro">withastro astro up to 5.15.5</a> and classified as <a href="https://vuldb.com/?kb.risk">problematic</a>. The affected element is an unknown function of the component <em>URL Handler</em>. The manipulation results in cross site scripting.

This vulnerability was named <a href="https://vuldb.com/?source_cve.332449">CVE-2025-64745</a>. The attack may be performed from remote. There is no available exploit.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-4618 | Palo Alto Prisma Browser up to 142.15.6.60 sensitive information in memory]]></title>
<description><![CDATA[A vulnerability categorized as problematic has been discovered in Palo Alto Prisma Browser up to 142.15.6.60. Affected by this vulnerability is an unknown functionality. The manipulation results in cleartext storage of sensitive information in memory.

This vulnerability was named CVE-2025-4618. ...]]></description>
<link>https://tsecurity.de/de/3099782/sicherheitsluecken/cve-2025-4618-palo-alto-prisma-browser-up-to-14215660-sensitive-information-in-memory/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3099782/sicherheitsluecken/cve-2025-4618-palo-alto-prisma-browser-up-to-14215660-sensitive-information-in-memory/</guid>
<pubDate>Sat, 15 Nov 2025 10:51:45 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/?kb.risk">problematic</a> has been discovered in <a href="https://vuldb.com/?product.palo_alto:prisma_browser">Palo Alto Prisma Browser up to 142.15.6.60</a>. Affected by this vulnerability is an unknown functionality. The manipulation results in cleartext storage of sensitive information in memory.

This vulnerability was named <a href="https://vuldb.com/?source_cve.332509">CVE-2025-4618</a>. The attack needs to be approached locally. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-4617 | Palo Alto Prisma Browser up to 142.15.6.60 on Windows Policy Enforcement improper protection of alternate path]]></title>
<description><![CDATA[A vulnerability was found in Palo Alto Prisma Browser up to 142.15.6.60 on Windows. It has been rated as problematic. Affected is an unknown function of the component Policy Enforcement Handler. The manipulation leads to improper protection of alternate path.

This vulnerability is uniquely ident...]]></description>
<link>https://tsecurity.de/de/3099742/sicherheitsluecken/cve-2025-4617-palo-alto-prisma-browser-up-to-14215660-on-windows-policy-enforcement-improper-protection-of-alternate-path/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3099742/sicherheitsluecken/cve-2025-4617-palo-alto-prisma-browser-up-to-14215660-on-windows-policy-enforcement-improper-protection-of-alternate-path/</guid>
<pubDate>Sat, 15 Nov 2025 10:22:40 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.palo_alto:prisma_browser">Palo Alto Prisma Browser up to 142.15.6.60</a> on Windows. It has been rated as <a href="https://vuldb.com/?kb.risk">problematic</a>. Affected is an unknown function of the component <em>Policy Enforcement Handler</em>. The manipulation leads to improper protection of alternate path.

This vulnerability is uniquely identified as <a href="https://vuldb.com/?source_cve.332508">CVE-2025-4617</a>. Local access is required to approach this attack. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-4616 | Palo Alto Prisma Browser up to 142.15.6.60 integrity check]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in Palo Alto Prisma Browser up to 142.15.6.60. Affected by this issue is some unknown functionality. This manipulation causes improper validation of integrity check value.

The identification of this vulnerability is CVE-2025-4616. The a...]]></description>
<link>https://tsecurity.de/de/3099741/sicherheitsluecken/cve-2025-4616-palo-alto-prisma-browser-up-to-14215660-integrity-check/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3099741/sicherheitsluecken/cve-2025-4616-palo-alto-prisma-browser-up-to-14215660-integrity-check/</guid>
<pubDate>Sat, 15 Nov 2025 10:22:38 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/?kb.risk">problematic</a> has been detected in <a href="https://vuldb.com/?product.palo_alto:prisma_browser">Palo Alto Prisma Browser up to 142.15.6.60</a>. Affected by this issue is some unknown functionality. This manipulation causes improper validation of integrity check value.

The identification of this vulnerability is <a href="https://vuldb.com/?source_cve.332510">CVE-2025-4616</a>. The attack can only be executed locally. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-4619 | Palo Alto Cloud NGFW/PAN-OS/Prisma Access Packet unusual condition]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in Palo Alto Cloud NGFW, PAN-OS and Prisma Access. Impacted is an unknown function of the component Packet Handler. This manipulation causes improper check for unusual conditions.

This vulnerability is registered as CVE-2025-4619. Remot...]]></description>
<link>https://tsecurity.de/de/3097868/sicherheitsluecken/cve-2025-4619-palo-alto-cloud-ngfwpan-osprisma-access-packet-unusual-condition/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3097868/sicherheitsluecken/cve-2025-4619-palo-alto-cloud-ngfwpan-osprisma-access-packet-unusual-condition/</guid>
<pubDate>Fri, 14 Nov 2025 08:40:47 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/?kb.risk">problematic</a> has been detected in <a href="https://vuldb.com/?product.palo_alto:cloud_ngfw">Palo Alto Cloud NGFW, PAN-OS and Prisma Access</a>. Impacted is an unknown function of the component <em>Packet Handler</em>. This manipulation causes improper check for unusual conditions.

This vulnerability is registered as <a href="https://vuldb.com/?source_cve.332426">CVE-2025-4619</a>. Remote exploitation of the attack is possible. No exploit is available.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[기업 보안의 새 변수 ‘MCP 서버’···CISO가 파악해야 할 주요 플랫폼 18개와 주요 위협]]></title>
<description><![CDATA[MCP(Model Context Protocol)은 AI 에이전트가 데이터 소스에 연결할 수 있도록 해주지만, 초기 버전 표준에는 핵심 보안 기능이 크게 부족했다. 최근 몇 달 동안 이 문제를 해결하려는 다양한 벤더가 등장했으며, 이제야 본격적인 도입이 가능해진 것인지, 여전히 실제 운영에 투입하기에는 이른 단계인지 논의가 이어지고 있다.



핵심 프로토콜 측면에서는 일부 진전이 있었다. 3월에는 OAuth 인증 지원이 추가됐고, 6월에는 오스제로(Auth0), 옥타(Okta), 또는 기업 자체의 ID 관리 시스템과 같은 서...]]></description>
<link>https://tsecurity.de/de/3097862/it-security-nachrichten/mcp-ciso-18/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3097862/it-security-nachrichten/mcp-ciso-18/</guid>
<pubDate>Fri, 14 Nov 2025 08:35:57 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>MCP(Model Context Protocol)은 AI 에이전트가 데이터 소스에 연결할 수 있도록 해주지만, 초기 버전 표준에는 핵심 보안 기능이 크게 부족했다. 최근 몇 달 동안 이 문제를 해결하려는 다양한 벤더가 등장했으며, 이제야 본격적인 도입이 가능해진 것인지, 여전히 실제 운영에 투입하기에는 이른 단계인지 논의가 이어지고 있다.</p>



<p>핵심 프로토콜 측면에서는 일부 진전이 있었다. 3월에는 OAuth 인증 지원이 추가됐고, 6월에는 오스제로(Auth0), 옥타(Okta), 또는 기업 자체의 ID 관리 시스템과 같은 서드파티 인증 서버 연동 기능도 포함됐다.<br>또한 MCP 표준 기구는 9월, 악성 MCP 서버가 정상 서버로 위장하는 문제를 해결하기 위해 <a href="https://modelcontextprotocol.info/tools/registry/" target="_blank" rel="nofollow">공식 MCP 레지스트리</a>를 공개했다.</p>



<p>그럼에도 여전히 상당한 보안 취약점이 남아 있다. 예를 들어 인증이 선택 사항으로 남아 있으며, 프롬프트 인젝션, 툴 포이즈닝, 토큰 탈취, 서버 간 공격, 메시지 변조 등 다양한 위협에 노출돼 있다.</p>



<p>에이전트 기반 AI 시스템에서 경쟁사보다 앞서고자 하는 기업은 민감 정보와 기업 비밀이 노출되지 않도록 상당한 보안 작업을 스스로 수행해야 한다.</p>



<p>이와 동시에 최근 몇 달 동안 주요 AI 플랫폼 기업뿐 아니라 핵심 기술업체, 기존 사이버보안 벤더, 그리고 신생 플레이어까지 다양한 기업이 MCP 보안 기능을 강화하며 대응에 나서고 있다.</p>



<h2 class="wp-block-heading">MCP 서버 활용 유형별 보안 과제</h2>



<p>MCP 서버 활용 방식에는 크게 세 가지 유형이 있으며, 각각 고유한 보안 과제가 따른다.</p>



<p>첫 번째는 기업이 자체적으로 관리하는 인프라에 내부 MCP 서버를 구축하고, 내부 데이터나 도구에 접근하도록 설정하는 방식이다. 비교적 위험이 낮은 활용 사례로는 직원이 제품 설명 등 민감하지 않은 문서나 데이터베이스를 AI 에이전트를 통해 검색하는 경우가 있다. 반면 고객 데이터를 다루는 방식은 위험도가 훨씬 높아진다.</p>



<p>두 번째 유형은 기업의 AI 에이전트가 MCP 서버를 통해 외부 데이터 소스나 도구에 접근하는 구조다. 이때는 서버나 데이터 소스가 공격자에 의해 침해될 경우, AI 에이전트가 악성 지시문을 전달받을 수 있다는 점이 주요 위험 요소로 꼽힌다.</p>



<p>세 번째는 내부 MCP 서버가 기업의 데이터나 도구를 외부에 개방하는 형태다. 제품 설명서나 사용자 매뉴얼처럼 위험도가 낮은 정보 제공이라면 문제가 크지 않지만, 일부 MCP 서버가 외부 파트너에게 주문 입력, 송장 제출, 결제 정보 변경 같은 기능까지 허용한다면 위험은 상당히 커진다.</p>



<p>노코드 AI 플랫폼 페퍼밀(PepperMill)의 공동 설립자이자 CEO인 앤 해초풀로스는 MCP 도입을 신중하게 단계적으로 접근해야 한다고 조언한다. 해초풀로스는 “공개된 링크드인 정보를 가져오는 MCP 서버는 비교적 안전하다”며 “반면 금융 거래를 처리하는 MCP는 위험 수준이 훨씬 크다. MCP의 보안 문제가 명확한데도 많은 기업이 지금 고위험 영역까지 빠르게 확장하는 점이 놀라울 정도다. 하지만 누군가는 결국 시도하게 될 것이고, 그 과정에서 취약점이 드러나게 된다”고 말했다.</p>



<p>특히 SaaS 기업을 포함한 많은 기술 기업에게 MCP 서버는 이미 필수 요소로 자리 잡고 있다. 클라우드 컨설팅 기업 올클라우드(AllCloud)의 최고전략책임자 피터 네벨은 “지금은 기다릴 시간이 없다”며 “망설이면 경쟁사가 먼저 MCP 기반 서비스를 제공해 우위를 확보하게 된다”고 전했다.</p>



<p>현재 페이팔, 노션, 허브스폿, 클라우드플레어, 아틀라시안, 슬랙, 깃허브 등 여러 기업이 공식 MCP 서버를 운영하고 있다. 서드파티 MCP 서버 제공업체도 늘고 있으며, 예를 들어 재피어(Zapier)는 8,000개 이상의 애플리케이션에 연결되는 MCP 환경을 지원하고 있다.</p>



<p>벤더가 공식 MCP 서버를 제공하지 않을 경우, 외부 개발자가 API를 활용해 비공식 MCP 서버를 구축하는 사례도 많다. 이미 링크드인, 스포티파이, 이베이, 유튜브, AWS, 질로우 등 다양한 플랫폼을 위한 MCP 서버가 존재하지만, 신뢰 수준은 각기 다르다. 개발자와 파워 유저는 이를 내려받아 AI 에이전트에 연결하고 있지만, 이들 비공식 서버의 출처나 유지관리 주체, 실제 동작 방식이 명확하지 않은 경우도 많다.</p>



<p>펄스MCP(Pulse MCP)에는 <a href="https://www.pulsemcp.com/servers" target="_blank" rel="nofollow">6,000개 이상의 서버</a>가, MCP 마켓플레이스 MCP.so에는 <a href="https://mcp.so/" target="_blank" rel="nofollow">1만 6,000개 이상</a>의 서버가 등록돼 있다. 깃허브에서 ‘MCP 서버’를 검색하면 4만 5,000개가 넘는 결과가 나온다.</p>



<h2 class="wp-block-heading">MCP 보안 플랫폼 선택 시 확인해야 할 요소</h2>



<p>기업이 자체 에이전트를 서드파티 MCP 서버에 연결하든, 자체 MCP 서버를 서드파티 에이전트에 개방하든, 혹은 자체 서버와 자체 에이전트를 서로 연동하든, 데이터 유출과 프롬프트 인젝션을 포함한 여러 보안 위협이 발생할 가능성은 항상 존재한다.</p>



<p>따라서 권한 및 접근 허용 여부를 면밀히 점검하고, 세분화된 접근 통제를 구현하며, 모든 활동을 기록해야 한다고 클라우드 컨설팅 기업 올클라우드(AllCloud)의 피터 네벨은 설명했다.</p>



<p>현재 벤더가 제공하는 주요 MCP 보안 도구는 다음과 같다.</p>



<p>• <strong>MCP </strong><strong>서버 탐지</strong>: 기업 직원들이 손쉽게 MCP 서버를 다운로드해 실행할 수 있어 생산성을 높일 수도 있지만, 새로운 공격 경로가 될 수도 있다. 이에 일부 보안 업체는 기업 환경 곳곳에 숨겨진 그림자 MCP 서버를 탐지하는 스캐닝 서비스를 제공하고 있다.</p>



<p>• <strong>런타임 보호</strong>: AI 에이전트와 MCP 서버는 자연어로 통신하기 때문에 프롬프트 인젝션, 데이터 유출 등 다양한 보안 문제가 발생할 수 있다. 여러 MCP 보안 벤더가 이러한 통신을 모니터링해 문제를 탐지하는 런타임 보호 도구를 제공하고 있다.</p>



<p>• <strong>인증 및 접근 제어</strong>: MCP 코어 프로토콜은 OAuth를 지원하지만, 이는 출발점에 불과하다. 벤더들은 추가 보안을 위해 제로 트러스트와 최소 권한 원칙 기반의 제어 프레임워크를 함께 제공한다.</p>



<p>• <strong>로깅 및 가시성 확보</strong>: 벤더는 MCP 로그를 수집하고 보안 팀에 이벤트나 정책 위반을 알리며, 컴플라이언스 데이터 수집 혹은 기존 보안 인프라와 연계할 수 있는 관측 플랫폼을 제공한다.</p>



<h2 class="wp-block-heading">MCP 보안 도구를 제공하는 주요 벤더</h2>



<p>아래는 MCP 보안 도구를 제공하는 기업들을 세 가지 범주로 나눠 살펴본 내용이다.</p>



<h3 class="wp-block-heading">하이퍼스케일러 기업</h3>



<p>특정 클라우드 플랫폼을 중심으로 기술 전략을 구축한 기업의 경우, 해당 하이퍼스케일러가 제공하는 MCP 보안 도구를 활용하는 것이 가장 손쉬운 출발점이 될 수 있다.</p>



<p>AWS는 7월 자체 에이전트 기반 AI 플랫폼을 공개했다. ‘아마존 베드록 에이전트코어(Amazon Bedrock AgentCore)’에는 MCP를 포함한 다중 프로토콜을 지원하는 게이트웨이, ID 관리 기능, 가시성 도구가 포함된다. AWS는 이어 10월, <a href="https://builder.aws.com/content/33oERPjcEutnPmaud1BvlPRP9zR/security-guidelines-for-model-context-protocol-in-aws" target="_blank" rel="nofollow">제로 트러스트 원칙</a>을 적용한 MCP 서버 보안 가이드라인을 발표했다.</p>



<p>마이크로소프트(MS)는 4월 기본 ‘애저 MCP 서버(Azure MCP Server)’를 공개한 데 이어, 5월 ‘애저 키 볼트(Azure Key Vault)’ 연동을 추가했다. 6월에는 ‘애저 AI 파운드리 에이전트 서비스(Azure AI Foundry Agent Service)’에 MCP 기능을 도입했으며, 8월에는 ‘애저 API 매니지먼트(Azure API Management)’를 통해 MCP 서버가 보안·거버넌스·관측 기능을 갖춘 상태로 리소스에 접근할 수 있도록 지원했다.<br>10월에는 MCP와 A2A(Agent2Agent) 프로토콜을 모두 지원하고, 프롬프트 인젝션 방지·PII 탐지·멀티 에이전트 가시성 기능을 갖춘 ‘마이크로소프트 에이전트 프레임워크(Microsoft Agent Framework)’를 발표했다.</p>



<p>구글 클라우드는 4월 인증과 관측 기능을 포함한 ‘MCP 툴박스 포 데이터베이스(MCP Toolbox for Databases)’를 발표했다. 9월에는 중앙화된 MCP 프록시 아키텍처를 기반으로 한 MCP 서버 보안 참조 아키텍처를 공개했다. 이 구조는 ‘구글 아이덴티티 플랫폼(Google Identity Platform)’을 통해 OAuth 토큰을 발급·검증하고, ‘모델 아머(Model Armor)’로 프롬프트 인젝션·탈출(jailbreak)·민감 정보 포함 여부를 점검하며, ‘시크릿 매니저(Secret Manager)’를 사용해 API 키나 민감 설정값을 안전하게 저장하도록 설계됐다.<br>또한 ‘아티팩트 레지스트리(Artifact Registry)’를 활용해 MCP 서버 이미지를 저장하고 배포 전 취약점을 스캔할 수 있다.</p>



<p>구글은 MCP 서버 간 측면 이동 위험을 줄이기 위해 네트워크 단위의 보안 통제를 적용할 것을 권고한다. 마지막으로 구글의 ‘시큐리티 커맨드 센터(Security Command Center)’는 무단 접근 및 데이터 반출 시도를 탐지할 수 있다.</p>



<h3 class="wp-block-heading">주요 기술 기업</h3>



<p>클라우드플레어(Cloudflare): 클라우드플레어는 기업이 모든 MCP 연결을 중앙에서 관리하고, 보안을 적용하며, 모니터링할 수 있는 ‘<a href="https://blog.cloudflare.com/zero-trust-mcp-server-portals/" target="_blank" rel="nofollow">MCP 서버 포털</a>(MCP Server Portals)’을 공개했다. 이 기능은 클라우드플레어의 SASE 플랫폼인 ‘클라우드플레어 원(Cloudflare One)’에 포함된다.</p>



<p>팔로알토네트웍스(Palo Alto Networks): 팔로알토네트웍스는 6월 ‘<a href="https://www.paloaltonetworks.com/blog/2025/06/securing-ai-agent-innovation-prisma-airs-mcp-server/" target="_blank" rel="nofollow">프리즈마 에어스 MCP 서버</a>(Prisma AIRS MCP Server)’를 선보였다. 이 제품은 AI 에이전트와 MCP 서버 사이에 위치해 데이터 내 악성 콘텐츠를 탐지하고, 프롬프트 인젝션 공격은 물론 웹·DNS 기반 공격으로부터도 보호한다. 또 다른 도구인 ‘코텍스 클라우드 WAAS(Cortex Cloud WAAS)’의 MCP Security는 네트워크 경계에서 MCP 통신을 분석해 악성 활동을 식별한다.</p>



<p>센티넬원(SentinelOne): <a href="https://www.sentinelone.com/blog/avoiding-mcp-mania-how-to-secure-the-next-frontier-of-ai/" target="_blank" rel="nofollow">센티넬원의 싱귤래리티 플랫폼</a>(Singularity Platform)은 MCP 상호작용 체인 전반에 대한 가시성을 제공하며, 경보 및 자동화된 사고 대응 기능을 지원한다. 로컬과 원격 MCP 서버 모두를 대상으로 한다.</p>



<p>VM웨어(VMware): 지난 8월 VM웨어의 모회사 브로드컴은 ‘브이엠웨어 클라우드 파운데이션(VMware Cloud Foundation)’이 MCP 서버를 포함한 에이전트 기반 워크플로우에 대해 보안을 강화한다고 <a href="https://www.networkworld.com/article/4045708/vmware-explore-2025-broadcom-tackles-agentic-ai-security-challenges.html" target="_blank">발표했다</a>.</p>



<h3 class="wp-block-heading">스타트업</h3>



<p>어큐비티(Acuvity): <a href="https://acuvity.ai/" rel="nofollow">어큐비티</a>는 최소 권한 실행, 불변 런타임, 지속적 취약점 스캔, 인증, 위협 탐지 기능을 적용해 MCP 서버 보안을 강화한다.</p>



<p>악토(Akto): API 보안 기업 악토는 6월 <a href="https://www.akto.io/mcp-security" target="_blank" rel="nofollow">MCP 전용 보안 솔루션</a>을 출시하며, MCP 서버 보호에 특화된 최초의 전용 보안 제품이라고 소개했다. 이 솔루션은 기업 내부에 배포된 MCP 서버를 찾는 디스커버리 도구, 보안 테스트 도구, 모니터링 및 위협 탐지 기능을 포함한다.</p>



<p>인베리언트 랩스(Invariant Labs): 이들의 오픈소스 도구 ‘<a href="https://github.com/invariantlabs-ai/mcp-scan" target="_blank" rel="nofollow">MCP-스캔</a>(MCP-Scan)’은 MCP 서버의 정적 분석과 실시간 모니터링을 수행해 툴 포이즈닝, 러그풀, 프롬프트 인젝션을 탐지한다. 상용 제품 ‘인베리언트 가드레일즈(Invariant Guardrails)’는 AI 에이전트와 MCP 서버 사이에서 프록시로 동작하며 각종 MCP 보안 위협을 차단하고, PII의 외부 이메일 전송 금지와 같은 정책 적용을 지원한다.</p>



<p>재블린(Javelin): 재블린의 ‘<a href="https://www.getjavelin.com/ai-security" target="_blank" rel="nofollow">AI 시큐리티 패브릭</a>(AI Security Fabric)’ 플랫폼은 위험한 MCP 서버를 스캔하거나, 에이전트 도구·데이터 요청을 차단 또는 검토하도록 요구하는 기능을 제공한다. MCP 가드레일은 실시간으로 비정상 호출과 악성 입력을 막아 프롬프트 인젝션과 데이터 유출을 방지한다.</p>



<p>라쏘 시큐리티(Lasso Security): 라쏘 시큐리티는 오픈소스 <a href="https://github.com/lasso-security/mcp-gateway" rel="nofollow">MCP 게이트웨이</a>를 제공하며, MCP 서버 구성·라이프사이클 관리와 MCP 메시지 내 민감 정보 정제를 지원한다.</p>



<p>MCP토털(MCPTotal): <a href="https://go.mcptotal.io/" rel="nofollow">MCP토털</a>은 안전한 샌드박스 환경에서 MCP 서버를 운영·관리·모니터링할 수 있는 허브를 제공한다. 또한 내부·외부 MCP 서버와 상호작용하는 AI 워크플로우를 보호하는 게이트웨이와 AI 도구 사용 정책을 모니터링·강제하는 거버넌스 도구도 포함한다.</p>



<p>노마(Noma): 노마가 최근 공개한 ‘<a href="https://noma.security/solutions/ai-agent-security/" target="_blank" rel="nofollow">AI 에이전트 시큐리티</a>(AI Agent Security)’는 MCP 연결 탐지, 취약점 스캔, 접근 정책 집행, 실시간 프롬프트 가드레일, 감사 추적 기능을 제공한다.</p>



<p>오봇(Obot): 오픈소스 기반 ‘<a href="https://obot.ai/" target="_blank" rel="nofollow">오봇 MCP 게이트웨이</a>(Obot MCP Gateway)’는 MCP 서버 관리, 보안 접근 정책 정의, 사용·컴플라이언스 추적 기능을 지원한다.</p>



<p>오퍼런트(Operant): 오퍼런트 <a href="https://www.operant.ai/solutions/mcp-gateway" target="_blank" rel="nofollow">MCP 게이트웨이</a>는 MCP 도구를 자동 카탈로그화하고 AI 에이전트를 탐지하며, 에이전트와 MCP 서버 간 트래픽을 추적해 운영 사각지대를 제거한다. 또한 툴 포이즈닝, 프롬프트 탈출(jailbreak), 무단 접근 등 위협을 식별하고, 데이터 유출을 방지하며, 기업 전반에서 중앙화된 에이전트·도구 거버넌스를 구축할 수 있다.</p>



<p>솔로(Solo): 솔로는 8월 ‘<a href="https://www.solo.io/products/agentgateway-enterprise" target="_blank" rel="nofollow">에이전트 게이트웨이</a>(Agent Gateway)’를 대폭 개편해 MCP와 A2A 프로토콜을 지원하도록 했다. 악성 프롬프트 및 데이터 유출 차단, 강력한 인증 적용, 모든 상호작용 로그·추적의 중앙화가 가능해졌다.</p>



<p>텔레포트(Teleport): 텔레포트의 ‘<a href="https://goteleport.com/use-cases/secure-model-context-protocol/" target="_blank" rel="nofollow">시큐어 MCP</a>(Secure MCP)’는 인프라 ID 플랫폼 내에서 사람·머신·워크로드·디바이스·AI 정체성을 통합 관리하도록 돕는다. 텔레포트의 MCP 보안 솔루션은 제로 트러스트 및 최소 권한 원칙 기반의 ID·접근 제어·거버넌스·감사 기능을 제공한다. <br>dl-ciokorea@foundryco.com</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Palo Alto PAN-OS Flaw Lets Attackers Force Firewall Reboots via Malicious Packets]]></title>
<description><![CDATA[Palo Alto Networks has disclosed a denial-of-service vulnerability in its PAN-OS software that allows attackers to force firewalls into unexpected reboots using specially crafted network packets. The flaw, tracked as CVE-2025-4619, affects multiple versions of PAN-OS running on PA-Series and VM-S...]]></description>
<link>https://tsecurity.de/de/3097652/hacking/palo-alto-pan-os-flaw-lets-attackers-force-firewall-reboots-via-malicious-packets/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3097652/hacking/palo-alto-pan-os-flaw-lets-attackers-force-firewall-reboots-via-malicious-packets/</guid>
<pubDate>Fri, 14 Nov 2025 06:51:14 +0100</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Palo Alto Networks has disclosed a denial-of-service vulnerability in its PAN-OS software that allows attackers to force firewalls into unexpected reboots using specially crafted network packets. The flaw, tracked as CVE-2025-4619, affects multiple versions of PAN-OS running on PA-Series and VM-Series firewalls, as well as Prisma Access deployments. The vulnerability enables unauthenticated attackers to trigger […]</p>
<p>The post <a href="https://gbhackers.com/palo-alto-pan-os-flaw/">Palo Alto PAN-OS Flaw Lets Attackers Force Firewall Reboots via Malicious Packets</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-64525 | withastro up to 5.15.4 Request Header x-forwarded-proto/x-forwarded-port server-side request forgery (GHSA-hr2q-hp5q-x767 / EUVD-2025-175298)]]></title>
<description><![CDATA[A vulnerability has been found in withastro astro up to 5.15.4 and classified as critical. Affected by this issue is some unknown functionality of the component Request Header Handler. This manipulation of the argument x-forwarded-proto/x-forwarded-port causes server-side request forgery.

This v...]]></description>
<link>https://tsecurity.de/de/3096931/sicherheitsluecken/cve-2025-64525-withastro-up-to-5154-request-header-x-forwarded-protox-forwarded-port-server-side-request-forgery-ghsa-hr2q-hp5q-x767-euvd-2025-175298/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3096931/sicherheitsluecken/cve-2025-64525-withastro-up-to-5154-request-header-x-forwarded-protox-forwarded-port-server-side-request-forgery-ghsa-hr2q-hp5q-x767-euvd-2025-175298/</guid>
<pubDate>Thu, 13 Nov 2025 18:54:17 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/?product.withastro:astro">withastro astro up to 5.15.4</a> and classified as <a href="https://vuldb.com/?kb.risk">critical</a>. Affected by this issue is some unknown functionality of the component <em>Request Header Handler</em>. This manipulation of the argument <em>x-forwarded-proto/x-forwarded-port</em> causes server-side request forgery.

This vulnerability is tracked as <a href="https://vuldb.com/?source_cve.332378">CVE-2025-64525</a>. The attack is possible to be carried out remotely. No exploit exists.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[The speed of innovation: Leading in a brave new era of AI-powered creation]]></title>
<description><![CDATA[I have had a front-row seat to some of the most profound technological shifts of the last two decades. I witnessed the rise of the cloud and mobile, watching as they rewired the fundamentals of how we work and connect. Later, I saw those foundations become the bedrock of daily life for billions o...]]></description>
<link>https://tsecurity.de/de/3093981/it-security-nachrichten/the-speed-of-innovation-leading-in-a-brave-new-era-of-ai-powered-creation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3093981/it-security-nachrichten/the-speed-of-innovation-leading-in-a-brave-new-era-of-ai-powered-creation/</guid>
<pubDate>Wed, 12 Nov 2025 16:05:19 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>I have had a front-row seat to some of the most profound technological shifts of the last two decades. I witnessed the rise of the cloud and mobile, watching as they rewired the fundamentals of how we work and connect. Later, I saw those foundations become the bedrock of daily life for billions of users. Each era has had its own cadence of change, its own rhythm of disruption.</p>



<p>None of it prepared me, though, for the sheer velocity of artificial intelligence (AI). The pace of AI is a fundamentally different force than anything we’ve seen before. While its evolution is rewriting the rules of creation, collaboration, and competition, the speed itself is forcing a new, urgent conversation about the very foundation of secure innovation.</p>



<p><strong>The experiment: A campaign at the speed of light</strong></p>



<p>This challenge of innovating securely (and at this new velocity) became intensely personal for my team and me recently. We set out to launch a new brand campaign for <a href="https://www.paloaltonetworks.com/prisma/prisma-ai-runtime-security">Prisma AIRS</a> called “<a href="https://www.paloaltonetworks.com/engage/be-a-genius" rel="sponsored">Be a Genius</a>,” celebrating the spirit of innovation. We had an audacious goal: to produce the campaign’s core creative — a series of videos honoring innovators from the past — using nothing but the very technology we aim to protect: generative AI.</p>



<p>This was more than a creative choice; it was, in a way, a mission statement. The process of creating the campaign had to mirror the product’s core purpose: securing AI innovation. For the first time in my career, we were not just using a new tool. We were partnering with an intelligence that was evolving faster than our project plan.</p>



<p><strong>The overnight leap</strong></p>



<p>The most stunning proof of this came early in the process. Our creative team hit a wall one day, struggling with a specific visual glitch that the AI models simply could not execute. The next morning, they came back to the same prompt, and the problem was gone. The model had been updated overnight by its developers, and the capability we needed now existed. In another instance, a completely new video tool was released, opening additional ways to achieve our vision.</p>



<p>These were the moments the ground shifted beneath our feet. For a leader, this is both thrilling and profoundly unsettling. How do you build a strategy, plan a budget, or lead a team when your most fundamental tools have a half-life measured in days? This is the new reality of innovation. It is happening on a daily, hourly, and even minute-by-minute basis. The creative cycle, once measured in months, is now measured in hours. This personal experience became a key insight, a clear sign of a massive industry-wide paradigm shift.</p>



<p><a></a><strong>From a marketing story to a market shift</strong></p>



<p>It cannot be overstated: AI’s momentum is disrupting every aspect of how we work. The rules of creation have changed. The ability to generate hundreds of variations of an image or video clip in minutes transforms creative iteration from a slow process of refinement into an explosive burst of possibility.</p>



<p>The rules of collaboration have also changed. The creative director’s role shifts from directing a human team to becoming a prompt engineer and curator for an AI, with the AI acting as a third collaborator in the room.</p>



<p>And the rules of competition have changed. The ability to launch a high-quality campaign in a fraction of the traditional time allows a business to react to market shifts with unprecedented agility.</p>



<p>This explosion of AI-driven creativity is happening in every function across every industry. Therefore, the new <a href="https://www.paloaltonetworks.com/perspectives/the-ai-imperative-security-designed-for-trust-control-and-cooperation/" rel="sponsored">mandate</a> for the CIO is to move beyond supporting isolated AI projects and instead build a secure, unified foundation that can empower this enterprise-wide wave of innovation.</p>



<p><strong>The foundation for innovation</strong></p>



<p>This brings us to the ultimate question: How do we unleash this incredible wave of innovation safely, securely, and responsibly?</p>



<p>My entire career has been a lesson in the mechanics of technology and trust. I believe the answer lies in a single, core philosophy: that true innovation is about building capabilities that earn and maintain the trust of customers, partners, and employees. This requires innovation to be secure by design, which is the ultimate enabler of sustainable growth and the mission that brought me to Palo Alto Networks.</p>



<p>We call this philosophy “Deploying Bravely.” It is a commitment to enabling innovation by providing that secure foundation. We deployed our “Be a Genius” campaign bravely, using the very technology we aim to protect to tell a story of what’s possible.</p>



<p>And this is how we will build the future: not just with speed, but with the confidence that comes from securing AI by design. Because in this new era, the boldest move is to <a href="https://www.deploybravely.com/">deploy bravely</a>.</p>
</div></div></div></div>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,11ms -->