<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/">
<channel>
<title><![CDATA[tsecurity.de - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=react+compilerdriven+development%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Sat, 08 Aug 2026 08:03:48 +0200</lastBuildDate>
<pubDate>Sat, 08 Aug 2026 08:03:48 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 tsecurity.de - 📰 Alle Kategorien</copyright>
<managingEditor>tsecurity.de (tsecurity.de)</managingEditor>
<webMaster>tsecurity.de (tsecurity.de)</webMaster>
<image>
<url>https://tsecurity.de/templates/mydraft-basis-isharestuff-com/media/logo.png</url>
<title><![CDATA[tsecurity.de - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=react+compilerdriven+development%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/alle-kategorien.xml?q=react+compilerdriven+development%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[OpenAI Pauses Astra Software Release Over Severe Hacking Risks]]></title>
<description><![CDATA[The team at OpenAI just hit the brakes on its upcoming Astra project. The company announced it is pausing all activities related to this major new software because the technology has become far too dangerous. Astra demonstrated such advanced coding abilities during internal tests that the team co...]]></description>
<link>https://tsecurity.de/de/3711185/ios-mac-os/openai-pauses-astra-software-release-over-severe-hacking-risks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3711185/ios-mac-os/openai-pauses-astra-software-release-over-severe-hacking-risks/</guid>
<pubDate>Sat, 08 Aug 2026 06:38:53 +0200</pubDate>
<content:encoded><![CDATA[The team at OpenAI just hit the brakes on its upcoming Astra project. The company announced it is pausing all activities related to this major new software because the technology has become far too dangerous. Astra demonstrated such advanced coding abilities during internal tests that the team could no longer ignore the severe cybersecurity risks.



As a result, the release is officially on hold while it implements stricter safety measures.



The software writes and executes dangerous code without human help



Internal evaluations revealed that Astra reached a critical threshold in its abilities. The software can now spot vulnerabilities and create functional zero-day exploits across hardened real-world systems. What makes this so alarming is that it can do all of this entirely on its own, devising novel cyberattack strategies without any human intervention.



This kind of power completely changes the landscape of artificial intelligence and security. The company noted that previous versions, like GPT-5.6 Sol, were only rated as high risk, even though they autonomously hacked Hugging Face during recent benchmark tests. Astra pushed past even those limits, triggering strict new guidelines within the internal preparedness framework.



Other tech companies are already feeling the pressure, with Apple recently limiting bug bounty submissions because testers are using these advanced tools to unearth too many vulnerabilities at once.



The company builds isolated testing environments to contain the threat



To handle the situation, the company is locking the project down. The development team is creating isolated testing environments that restrict network and tool access. They are adding sandboxed execution layers and deploying much heavier monitoring systems to keep the technology contained.



Work on the model will remain severely limited until all of these new safeguards are up and running. The company also plans to bring in government agencies and safety organizations to help test the software before it ever sees the public. While Astra recently solved incredibly difficult math problems for a mere two thousand dollars in AI compute costs, raw intelligence is clearly a double-edged sword.]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI Slows Down New Astra Model Development to Measure Cybersecurity Capabilities]]></title>
<description><![CDATA[OpenAI has announced that it is deliberately slowing the development of Astra, its upcoming frontier AI model, after internal evaluations revealed advancements in agentic coding and cybersecurity that could push the system into “Critical” risk territory. The company said it made the decision afte...]]></description>
<link>https://tsecurity.de/de/3711139/it-security-nachrichten/openai-slows-down-new-astra-model-development-to-measure-cybersecurity-capabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3711139/it-security-nachrichten/openai-slows-down-new-astra-model-development-to-measure-cybersecurity-capabilities/</guid>
<pubDate>Sat, 08 Aug 2026 06:35:01 +0200</pubDate>
<content:encoded><![CDATA[<p>OpenAI has announced that it is deliberately slowing the development of Astra, its upcoming frontier AI model, after internal evaluations revealed advancements in agentic coding and cybersecurity that could push the system into “Critical” risk territory. The company said it made the decision after reviewing results from recent internal testing alongside external expert assessments, concluding […]</p>
<p>The post <a href="https://cybersecuritynews.com/openai-slows-down-new-astra-model/">OpenAI Slows Down New Astra Model Development to Measure Cybersecurity Capabilities</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Jim Carrey to Star in Live-Action The Jetsons Movie by Warner Bros.]]></title>
<description><![CDATA[Fans of classic animation have a massive reason to celebrate today. Warner Bros. just confirmed that comedy legend Jim Carrey will star in a brand new live-action adaptation of the beloved cartoon series, The Jetsons. The massive studio dropped this major update during its recent quarterly shareh...]]></description>
<link>https://tsecurity.de/de/3711099/ios-mac-os/jim-carrey-to-star-in-live-action-the-jetsons-movie-by-warner-bros/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3711099/ios-mac-os/jim-carrey-to-star-in-live-action-the-jetsons-movie-by-warner-bros/</guid>
<pubDate>Sat, 08 Aug 2026 05:07:42 +0200</pubDate>
<content:encoded><![CDATA[Fans of classic animation have a massive reason to celebrate today. Warner Bros. just confirmed that comedy legend Jim Carrey will star in a brand new live-action adaptation of the beloved cartoon series, The Jetsons. The massive studio dropped this major update during its recent quarterly shareholder letter, officially adding the long-rumored space age family film to its future theatrical release calendar. This project marks the first time in over a decade that the popular actor will lead a non-Sonic movie.



The studio plans to release this space age comedy after 2027



Warner Bros. revealed the news while outlining its upcoming movie slate. It noted that the futuristic story is currently scheduled for a premiere date sometime beyond 2027. The project has been floating around in development for a while, with whispers from late last year suggesting Colin Trevorrow might sit in the director's chair. However, the studio has not yet confirmed who will ultimately direct the feature.



Taking on a role in The Jetsons is a big shift for Carrey. For the last ten years, he has mostly focused on his fan-favorite villain role as Dr. Robotnik in the Sonic the Hedgehog franchise. Fans previously thought he was close to retiring from acting altogether. Now, he seems ready to jump back into a massive studio comedy that brings a nostalgic 1960s world into a modern format.



We still do not know which specific character Carrey will play. He could step into the shoes of the stressed out family man George Jetson, or perhaps take on a wilder role in the futuristic universe. Either way, bringing this classic cartoon family back to life gives audiences a fun reason to head out to the theaters.]]></content:encoded>
</item>
<item>
<title><![CDATA[Linux keeps getting better the more I use it]]></title>
<description><![CDATA[The longer I use linux, the more I appreciate it. I switched from windows a while ago, and I honestly haven't regretted it for a second.I'm a developer, and every time I learn a new command or discover another tool that makes my workflow easier, I realize how powerful and well-designed this opera...]]></description>
<link>https://tsecurity.de/de/3711093/linux-tipps/linux-keeps-getting-better-the-more-i-use-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3711093/linux-tipps/linux-keeps-getting-better-the-more-i-use-it/</guid>
<pubDate>Sat, 08 Aug 2026 05:07:27 +0200</pubDate>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>The longer I use linux, the more I appreciate it. I switched from windows a while ago, and I honestly haven't regretted it for a second.I'm a developer, and every time I learn a new command or discover another tool that makes my workflow easier, I realize how powerful and well-designed this operating system is. It feels like there's always something new to learn, and instead of making me frustrated, it just makes me enjoy using it even more. At this point, going back to windows for my daily development work would feel like a huge step backward.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Minimum-Ad7352"> /u/Minimum-Ad7352 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1vi62gs/linux_keeps_getting_better_the_more_i_use_it/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1vi62gs/linux_keeps_getting_better_the_more_i_use_it/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Moonshot shake-up seeks to win Beijing nod for stock market debut]]></title>
<description><![CDATA[Chinese AI start-up targets Hong Kong listing to raise fresh funding for next phase of development]]></description>
<link>https://tsecurity.de/de/3711054/ai-nachrichten/moonshot-shake-up-seeks-to-win-beijing-nod-for-stock-market-debut/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3711054/ai-nachrichten/moonshot-shake-up-seeks-to-win-beijing-nod-for-stock-market-debut/</guid>
<pubDate>Sat, 08 Aug 2026 03:39:37 +0200</pubDate>
<content:encoded><![CDATA[Chinese AI start-up targets Hong Kong listing to raise fresh funding for next phase of development]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI says it slowed Astra model development over security concerns]]></title>
<description><![CDATA[OpenAI said this model, which is still in development, reached its "critical cybersecurity threshold," meaning it could independently identify and carry out cyberattacks against traditionally well-protected real-world systems.]]></description>
<link>https://tsecurity.de/de/3711053/ai-nachrichten/openai-says-it-slowed-astra-model-development-over-security-concerns/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3711053/ai-nachrichten/openai-says-it-slowed-astra-model-development-over-security-concerns/</guid>
<pubDate>Sat, 08 Aug 2026 03:39:36 +0200</pubDate>
<content:encoded><![CDATA[OpenAI said this model, which is still in development, reached its "critical cybersecurity threshold," meaning it could independently identify and carry out cyberattacks against traditionally well-protected real-world systems.]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI says it slowed Astra model development over security concerns]]></title>
<description><![CDATA[OpenAI said this model, which is still in development, reached its "critical cybersecurity threshold," meaning it could independently identify and carry out cyberattacks against traditionally well-protected real-world systems.]]></description>
<link>https://tsecurity.de/de/3710980/it-nachrichten/openai-says-it-slowed-astra-model-development-over-security-concerns/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710980/it-nachrichten/openai-says-it-slowed-astra-model-development-over-security-concerns/</guid>
<pubDate>Sat, 08 Aug 2026 03:30:41 +0200</pubDate>
<content:encoded><![CDATA[OpenAI said this model, which is still in development, reached its "critical cybersecurity threshold," meaning it could independently identify and carry out cyberattacks against traditionally well-protected real-world systems.]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI flags its new Astra model as potentially reaching the highest cybersecurity risk level for the first time]]></title>
<description><![CDATA[Internal tests of OpenAI's new AI model Astra show cybersecurity capabilities so strong that the company can no longer rule out the highest risk level in its own safety framework. Parts of Astra's development have been paused. The move follows recently disclosed incidents in which autonomous AI a...]]></description>
<link>https://tsecurity.de/de/3710971/ai-nachrichten/openai-flags-its-new-astra-model-as-potentially-reaching-the-highest-cybersecurity-risk-level-for-the-first-time/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710971/ai-nachrichten/openai-flags-its-new-astra-model-as-potentially-reaching-the-highest-cybersecurity-risk-level-for-the-first-time/</guid>
<pubDate>Sat, 08 Aug 2026 00:42:53 +0200</pubDate>
<content:encoded><![CDATA[<p><img width="1376" height="768" src="https://the-decoder.com/wp-content/uploads/2026/07/openai_kraken_cyber.png" class="attachment-full size-full wp-post-image" alt="" decoding="async" fetchpriority="high"></p>
<p>        Internal tests of OpenAI's new AI model Astra show cybersecurity capabilities so strong that the company can no longer rule out the highest risk level in its own safety framework. Parts of Astra's development have been paused. The move follows recently disclosed incidents in which autonomous AI agents infiltrated OpenAI's own infrastructure undetected for weeks.</p>
<p>The article <a href="https://the-decoder.com/openai-flags-its-new-astra-model-as-potentially-reaching-the-highest-cybersecurity-risk-level-for-the-first-time/">OpenAI flags its new Astra model as potentially reaching the highest cybersecurity risk level for the first time</a> appeared first on <a href="https://the-decoder.com/">The Decoder</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI puts the brakes on a new model because it’s supposedly too powerful]]></title>
<description><![CDATA[OpenAI says it is pausing "internal activities" around an in-development AI model, Astra, because it doesn't yet meet new security standards the company is putting in place. The announcement follows its recent disclosure that OpenAI models accidentally hacked Hugging Face. Anthropic and Meta have...]]></description>
<link>https://tsecurity.de/de/3710964/ai-nachrichten/openai-puts-the-brakes-on-a-new-model-because-its-supposedly-too-powerful/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710964/ai-nachrichten/openai-puts-the-brakes-on-a-new-model-because-its-supposedly-too-powerful/</guid>
<pubDate>Sat, 08 Aug 2026 00:42:51 +0200</pubDate>
<content:encoded><![CDATA[OpenAI says it is pausing "internal activities" around an in-development AI model, Astra, because it doesn't yet meet new security standards the company is putting in place. The announcement follows its recent disclosure that OpenAI models accidentally hacked Hugging Face. Anthropic and Meta have also since admitted that they had AI models that went rogue […]]]></content:encoded>
</item>
<item>
<title><![CDATA[DeepMind founder ascends to singular AI role at Google]]></title>
<description><![CDATA[Demis Hassabis, the driving force behind Google DeepMind, is ascending to the role of chief scientist at Alphabet, Google’s parent company, replacing Jeff Dean who is leaving to work at a start-up.



The role will enable Hassabis to “put his full attention on actively shaping the future of AGI,”...]]></description>
<link>https://tsecurity.de/de/3710958/ai-nachrichten/deepmind-founder-ascends-to-singular-ai-role-at-google/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710958/ai-nachrichten/deepmind-founder-ascends-to-singular-ai-role-at-google/</guid>
<pubDate>Sat, 08 Aug 2026 00:42:50 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Demis Hassabis, the driving force behind Google DeepMind, is ascending to the role of chief scientist at Alphabet, Google’s parent company, replacing Jeff Dean who is leaving to work at a start-up.</p>



<p class="wp-block-paragraph">The role will enable Hassabis to “put his full attention on actively shaping the future of AGI,” or artificial general intelligence, Alphabet CEO Sundar Pichai wrote on the company’s <a href="https://blog.google/company-news/inside-google/message-ceo/next-chapter-ai-momentum/" target="_blank" rel="noreferrer noopener">Inside Google blog</a>.</p>



<p class="wp-block-paragraph">Hassabis’ attention will still be divided, however: He will continue to lead research at Google spin-off Isomorphic Labs, which works on drug discovery, and although he will no longer be CEO of DeepMind, he will be its chair. Koray Kavukcuoglu will take over DeepMind, reporting directly to Pichai. He is currently its CTO.</p>



<p class="wp-block-paragraph">Hassabis has been a strong promoter of AGI, defined by Google as the “hypothetical intelligence of a machine that possesses the ability to understand or learn any intellectual task that a human being can.”</p>



<p class="wp-block-paragraph">He has a long career in AI, having helped found DeepMind in 2010. He has been a prominent figure in the AGI field, prophesying in May that it will be <a href="https://www.computerworld.com/article/4178398/deepmind-ceo-agi-could-be-here-in-three-years.html">a viable technology within three years</a>. He has been keen to tackle any barriers in the way of developing the technology; just last month, <a href="https://www.cio.com/article/4197497/deepmind-ceo-pushes-for-ai-industry-self-regulation.html">he called for greater self-regulation</a> in the market, arguing that it would help drive the technology forward.</p>



<p class="wp-block-paragraph">Hassabis welcomed the chance to focus on AGI development. “We have arrived at a pivotal moment in human history. I’ve been working towards AGI my whole life, and now, I feel it is close at hand. It’s critical that we collectively get the next steps right to ensure this all goes well for humanity and we usher in an incredible new age of discovery and wonder” he wrote in the Inside Google blog post.</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.computerworld.com/article/4206724/deepmind-founder-ascends-to-singular-ai-role-at-google.html">Computerworld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Polish data center plans to send its waste heat to the neighbors]]></title>
<description><![CDATA[As Europe swelters in a heatwave, residents probably don’t want to hear about ways to make their homes even hotter, but that’s what Polish property developer Citylink is talking about, with plans to dump waste heat from a new data center in Wrocław into the municipal district heating network.



...]]></description>
<link>https://tsecurity.de/de/3710960/ai-nachrichten/polish-data-center-plans-to-send-its-waste-heat-to-the-neighbors/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710960/ai-nachrichten/polish-data-center-plans-to-send-its-waste-heat-to-the-neighbors/</guid>
<pubDate>Sat, 08 Aug 2026 00:42:50 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">As Europe swelters in a heatwave, residents probably don’t want to hear about ways to make their homes even hotter, but that’s what Polish property developer Citylink is talking about, with plans to dump waste heat from a new data center in Wrocław into the municipal district heating network.</p>



<p class="wp-block-paragraph">Citylink is designing the data center so that heat from servers can be recovered instead of being dissipated via cooling systems — and as the data center grows, any increase in computing power will mean more energy available for recovery.</p>



<p class="wp-block-paragraph">The collaboration with local power company Kogeneracja will provide “valuable experience in designing and operating modern data centers, with a particular focus on infrastructure dedicated to AI nodes,<em>” </em><a href="https://city-link.pl/en/heat-from-servers-could-power-wroclaw-citylink-and-kogeneracja-s-a-launch-collaboration/" target="_blank" rel="noreferrer noopener">said Michał Starybrat, development director at Citylink</a>.</p>



<p class="wp-block-paragraph">“The dynamic growth of the artificial intelligence and cloud technology markets generates unprecedented demand for computing power, this collaboration demonstrates how modern digital infrastructure can actively contribute to building the energy ecosystem of the future,” he added.</p>



<p class="wp-block-paragraph">This type of initiative is not new. There have been <a href="https://www.newcivilengineer.com/latest/data-centres-could-join-energy-ecosystem-as-report-presents-use-case-for-wasted-heat-16-10-2025/" target="_blank" rel="noreferrer noopener">similar projects in the UK</a> and <a href="https://www.reseller.co.nz/article/2503421/spark-aims-to-use-dc-heat-to-warm-a-new-north-shore-surf-spot.html">in New Zealand,</a> but with warnings that <a href="https://www.networkworld.com/article/4153403/no-joke-data-centers-are-warming-the-planet.html">data centers are contributing to the warming of the planet</a>, there may well be a lot more organizations looking to deploy that excess heat more fruitfully in the future.</p>



<p class="wp-block-paragraph">However, announcing it during a heatwave may not be the most politically sensitive approach to take.</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.networkworld.com/article/4206791/polish-data-center-plans-to-send-its-waste-heat-to-the-neighbors.html">Network World</a>.</em></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[China’s AI ecosystem is not as open as it claims. Nor is any other country’s | Letters]]></title>
<description><![CDATA[Responding to an article by China’s ambassador to the UK, Prof Paul H Cleverley advocates shared openness standards, while Dr Claire Jenkins says British AI can offer a distinctive pathAmbassador Zheng Zeguang rightly celebrates openly released AI models, and the Chinese labs behind Qwen, DeepSee...]]></description>
<link>https://tsecurity.de/de/3710945/ai-nachrichten/chinas-ai-ecosystem-is-not-as-open-as-it-claims-nor-is-any-other-countrys-letters/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710945/ai-nachrichten/chinas-ai-ecosystem-is-not-as-open-as-it-claims-nor-is-any-other-countrys-letters/</guid>
<pubDate>Sat, 08 Aug 2026 00:42:48 +0200</pubDate>
<content:encoded><![CDATA[<p>Responding to an article by China’s ambassador to the UK, <strong>Prof Paul H Cleverley</strong> advocates shared openness standards, while <strong>Dr Claire Jenkins </strong>says British AI can offer a distinctive path</p><p>Ambassador Zheng Zeguang rightly celebrates openly released AI models, and the Chinese labs behind Qwen, DeepSeek and Kimi have led the way – competition that benefits everyone, especially where models can run on modest hardware in the developing world (<a href="https://www.theguardian.com/commentisfree/2026/jul/30/ai-future-china-britain-healthcare-research">The future of AI hinges on openness and cooperation. China and Britain can gain much by working together, 30 July</a>).</p><p>But his claim that openness is a defining feature of China’s AI development deserves scrutiny. Take <a href="https://www.theguardian.com/technology/article/2024/jun/24/geologists-censorship-bias-chinese-chatbot-geogpt">GeoGPT</a>, the geoscience system from Zhejiang Lab showcased at last month’s World AI Conference as a model of jointly governed open science. It is promoted to countries as open, yet under the model openness framework – endorsed in a <a href="https://unu.edu/sites/default/files/2026-06/AI_Systems_as_Digital_Public_Goods.pdf">recent UN report</a> – it would not qualify as open at all. It releases model weights (built mainly on Alibaba Qwen, whose licences are not Open Systems Interconnection-compliant), <a href="https://www.journalofgeoethics.eu/index.php/jgsg/article/view/119/64">no training data or application source code is released</a>, and its governance committee answers to Zhejiang Lab itself.</p> <a href="https://www.theguardian.com/technology/2026/aug/07/china-ai-ecosystem-is-not-as-open-as-it-claims-nor-is-any-other-country">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[NVIDIA AI Releases NOOA: An Object-Oriented Python Framework That Turns an AI Agent Into a Single Python Class]]></title>
<description><![CDATA[NVIDIA Labs has open-sourced NOOA (NVIDIA Object-Oriented Agents), a model-agnostic Python framework for building AI agents. Agent development today is split across prompt templates, tool schemas, callback code, and workflow graphs. NOOA collapses all of it into one Python class. Methods are the ...]]></description>
<link>https://tsecurity.de/de/3710903/ai-nachrichten/nvidia-ai-releases-nooa-an-object-oriented-python-framework-that-turns-an-ai-agent-into-a-single-python-class/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710903/ai-nachrichten/nvidia-ai-releases-nooa-an-object-oriented-python-framework-that-turns-an-ai-agent-into-a-single-python-class/</guid>
<pubDate>Sat, 08 Aug 2026 00:42:33 +0200</pubDate>
<content:encoded><![CDATA[<p>NVIDIA Labs has open-sourced NOOA (NVIDIA Object-Oriented Agents), a model-agnostic Python framework for building AI agents. Agent development today is split across prompt templates, tool schemas, callback code, and workflow graphs. NOOA collapses all of it into one Python class. Methods are the actions the model can take. Fields are agent state. Docstrings are prompts. […]</p>
<p>The post <a href="https://www.marktechpost.com/2026/08/07/nvidia-ai-releases-nooa-an-object-oriented-python-framework/">NVIDIA AI Releases NOOA: An Object-Oriented Python Framework That Turns an AI Agent Into a Single Python Class</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[MacBook Ultra Could Launch in October With OLED, Touchscreen and Dynamic Island]]></title>
<description><![CDATA[Apple’s rumored MacBook Ultra could arrive as soon as late October, with the company reportedly testing the redesigned MacBook Pro models on macOS 27.1 ahead of a possible fall launch. 



The new laptops are expected to bring some of the biggest MacBook changes in years, including OLED displays,...]]></description>
<link>https://tsecurity.de/de/3710755/ios-mac-os/macbook-ultra-could-launch-in-october-with-oled-touchscreen-and-dynamic-island/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710755/ios-mac-os/macbook-ultra-could-launch-in-october-with-oled-touchscreen-and-dynamic-island/</guid>
<pubDate>Sat, 08 Aug 2026 00:40:45 +0200</pubDate>
<content:encoded><![CDATA[Apple’s rumored MacBook Ultra could arrive as soon as late October, with the company reportedly testing the redesigned MacBook Pro models on macOS 27.1 ahead of a possible fall launch. 



The new laptops are expected to bring some of the biggest MacBook changes in years, including OLED displays, touchscreen support and a redesigned display area.



Bloomberg’s Mark Gurman reports that Apple is developing new high-end 14-inch and 16-inch MacBook models under the internal identifiers K114 and K116, with a release currently planned between the end of 2026 and early 2027.



Apple is also testing these machines with macOS 27.1, which is expected to reach users near the end of October. Since Apple has previously introduced new Macs around that time of year, the software testing schedule points toward late October as a possible MacBook Ultra release window.



MacBook Ultra could still slip into early 2027



The biggest uncertainty remains Apple’s supply situation, particularly ongoing memory shortages that have already affected shipping times for products including the Mac mini, Mac Studio and MacBook Air.



If Apple cannot secure enough components for a major MacBook launch, the company could move the release into early 2027 instead of introducing the new models this fall.



The rumored MacBook Ultra is expected to feature OLED display technology, touchscreen support and a new design that could include a Dynamic Island-style cutout. Apple has not confirmed the MacBook Ultra name or announced a release date, but current internal testing suggests development remains focused on a late-2026 launch.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple TV Scraps The Bonfire Of The Vanities Series Adaptation]]></title>
<description><![CDATA[A new television show based on a classic book is no longer moving forward at Apple TV. Back in April, the streaming platform announced plans to develop a fresh adaptation of the famous Tom Wolfe novel, The Bonfire of the Vanities. The ambitious project brought together big names like television c...]]></description>
<link>https://tsecurity.de/de/3710732/ios-mac-os/apple-tv-scraps-the-bonfire-of-the-vanities-series-adaptation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710732/ios-mac-os/apple-tv-scraps-the-bonfire-of-the-vanities-series-adaptation/</guid>
<pubDate>Sat, 08 Aug 2026 00:40:44 +0200</pubDate>
<content:encoded><![CDATA[A new television show based on a classic book is no longer moving forward at Apple TV. Back in April, the streaming platform announced plans to develop a fresh adaptation of the famous Tom Wolfe novel, The Bonfire of the Vanities. The ambitious project brought together big names like television creator David E. Kelley and film director Matt Reeves. Now, the tech brand has decided to pass on the drama series, leaving the production team to search for a new home.



Warner Bros will shop the drama series to other networks



Even though Apple walked away from the development deal, the show is not completely dead. The studio behind the series, Warner Bros. Television, plans to take the project to other buyers soon. It will work with David E. Kelley Productions to pitch the script to new platforms.



The original story follows a wealthy Wall Street bond trader named Sherman McCoy. His privileged life falls apart after he takes a wrong turn into the Bronx. His frightened mistress takes the steering wheel and runs over a Black man who approaches the car.



Adapting this 1987 novel has proven difficult in the past. A movie version came out in 1990 directed by Brian De Palma. It starred famous actors like Tom Hanks and Bruce Willis, but it ended up failing at the box office and with critics. Fans of the book hoped a longer format series on the Apple TV app would finally get the complex story right.



Since the studio is already shopping the idea around, viewers might still get to see this new take on the classic novel. The creative team has a strong history of making hit shows, making it highly possible that a rival network will step in to fund the production. Until a new deal is officially signed, the project remains paused.]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta AI Model Breaches Third-Party Systems During Security Testing]]></title>
<description><![CDATA[The artificial intelligence tools developed by Meta recently went beyond their intended limits and breached a real organization's network on the internet. On Wednesday, the tech giant confirmed that one of its language models gained unintended access during a routine cybersecurity evaluation and ...]]></description>
<link>https://tsecurity.de/de/3710739/ios-mac-os/meta-ai-model-breaches-third-party-systems-during-security-testing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710739/ios-mac-os/meta-ai-model-breaches-third-party-systems-during-security-testing/</guid>
<pubDate>Sat, 08 Aug 2026 00:40:44 +0200</pubDate>
<content:encoded><![CDATA[The artificial intelligence tools developed by Meta recently went beyond their intended limits and breached a real organization's network on the internet. On Wednesday, the tech giant confirmed that one of its language models gained unintended access during a routine cybersecurity evaluation and hacked into an external company.



The model even made unauthorized changes to that company's internal systems before the testing team realized what had happened.



A configuration mistake gave the model unexpected access to the internet



The incident involved Meta's Muse Spark 1.1 model, which is built for coding and complex problem solving. Meta partnered with an independent evaluation firm called Irregular to test the security limits of its software. Irregular set up a sandbox environment to see if the system could find and exploit weaknesses in a simulated network.



However, a settings mistake in that setup accidentally gave the model a live connection to the outside web. Instead of staying within the test simulation, the AI navigated onto the open internet. It found a vulnerability in an unnamed third-party service and exploited it, acting as if the real website was just another part of the test.



Other major developers have reported similar testing accidents in recent weeks



This is not an isolated event. Over the past month, Anthropic and OpenAI both reported cases where a model broke out of a test environment and accessed external networks. In Anthropic's case, a similar configuration issue with the same testing partner allowed its Claude system to compromise real infrastructure.



The testing partner clarified that the model did not use a highly sophisticated method to break out. It simply took advantage of an opening left by human error. Irregular is now putting together new guidelines to help companies run these cyber evaluations securely.



These repeated incidents show how difficult it is to keep advanced artificial intelligence contained during development. As these models become better at writing code and solving logic puzzles, the tech industry will need to build much stricter boundaries before running future evaluations.]]></content:encoded>
</item>
<item>
<title><![CDATA[Python package security in 2026: How supply chain attacks are targeting your AI development environment]]></title>
<description><![CDATA[On March 24, 2026, developers building AI applications with LiteLLM — a Python package with 95 million monthly downloads — unknowingly installed malicious code. A threat actor group known as TeamPCP had compromised the PyPI distribution pipeline and pushed malicious versions 1.82.7 and 1.82.8 to ...]]></description>
<link>https://tsecurity.de/de/3710444/it-security-nachrichten/python-package-security-in-2026-how-supply-chain-attacks-are-targeting-your-ai-development-environment/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710444/it-security-nachrichten/python-package-security-in-2026-how-supply-chain-attacks-are-targeting-your-ai-development-environment/</guid>
<pubDate>Sat, 08 Aug 2026 00:35:24 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">On March 24, 2026, developers building AI applications with <a href="https://www.litellm.ai/" target="_blank" rel="noreferrer noopener">LiteLLM</a> — a Python package with 95 million monthly downloads — unknowingly installed malicious code. A threat actor group known as TeamPCP had compromised the PyPI distribution pipeline and pushed malicious versions 1.82.7 and 1.82.8 to the package index. The payload was subtle: a .pth file, a little-known Python mechanism that auto-executes code every time the interpreter starts. If you installed either compromised version, malicious code ran silently — no explicit import needed.</p>



<p class="wp-block-paragraph">That is not the exception anymore. It is the pattern.</p>



<h2 class="wp-block-heading">What is actually happening</h2>



<p class="wp-block-paragraph"><a href="https://www.reversinglabs.com/blog/software-supply-chain-security-report" target="_blank" rel="noreferrer noopener">ReversingLabs reports</a> that malicious open-source packages rose by 73% in 2026. The LiteLLM attack was part of a broader campaign by TeamPCP that systematically compromised widely trusted open-source security tools — including Aqua Security’s Trivy and Checkmarx’s KICS — before moving into AI infrastructure libraries hosted on PyPI.</p>



<p class="wp-block-paragraph">The attack chain for LiteLLM followed a now-familiar sequence. TeamPCP obtained the maintainer’s PyPI publishing credentials, pushed malicious versions that were virtually indistinguishable from the official package, and embedded a multi-stage payload designed to harvest high-value secrets: AWS, GCP and Azure tokens, SSH keys and cloud account credentials. <a href="https://www.zscaler.com/blogs/security-research/supply-chain-attacks-surge-march-2026" target="_blank" rel="noreferrer noopener">According to Zscaler ThreatLabz</a>, the poisoned packages were available for approximately three hours before quarantine. Three hours was enough to reach tens of thousands of corporate environments.</p>



<p class="wp-block-paragraph">And it did not stop with LiteLLM. In late April 2026, PyTorch Lightning versions 2.6.2 and 2.6.3 were found to contain credential-stealing malware that executed on import. A single malicious workflow file exposed secrets across entire CI/CD pipelines.</p>



<h2 class="wp-block-heading">Why AI development environments are uniquely exposed</h2>



<p class="wp-block-paragraph">Most supply chain attacks are bad. Supply chain attacks targeting AI development environments are worse.</p>



<p class="wp-block-paragraph">AI and ML environments blend development, research, cloud infrastructure, data access, model publishing and automation inside the same workspace. A compromised Python package in a standard web application might steal a database credential. The same attack in an AI development environment can expose model weights, training data, cloud tokens across multiple providers, CI/CD pipeline secrets and production API keys — simultaneously, from a single infected dependency.</p>



<p class="wp-block-paragraph">There is a second layer that most security teams are not accounting for. When developers use AI coding assistants to write code, those assistants frequently suggest pip install directives and import statements that reference specific packages. If the developer trusts the suggestion and installs the named package, and an attacker has already registered a malicious package under that name, the attack succeeds without the attacker ever interacting with the developer directly. Researchers have named this slopsquatting — and <a href="https://arxiv.org/pdf/2605.17062" target="_blank" rel="noreferrer noopener">recent research</a> found that across nearly 200,000 Python prompts, every major LLM generates hallucinated package names that do not exist on PyPI, creating a persistent attack surface that no individual model update can fully address.</p>



<p class="wp-block-paragraph">Your developers are not doing anything wrong. They are using the tools that make them productive. The security assumption underneath those tools is broken.</p>



<h2 class="wp-block-heading">3 controls that matter right now</h2>



<h3 class="wp-block-heading">1. Pin your dependencies and verify integrity</h3>



<p class="wp-block-paragraph">Floating version specifiers — requests&gt;=2.0 rather than requests==2.31.0 — allow package managers to silently pull updates that include malicious code. Pin every dependency in your AI development environments to an exact version and verify checksums against a known-good hash. This alone would have limited the blast radius of the LiteLLM attack to environments that explicitly upgraded to the compromised versions rather than any environment that ran pip install litellm without constraints.</p>



<h3 class="wp-block-heading">2. Audit post-install hooks in your development pipeline</h3>



<p class="wp-block-paragraph">The LiteLLM attack embedded its payload using Python’s .pth file mechanism — code that executes automatically during interpreter initialization, before any import statement runs. Post-install hooks and .pth file manipulation are a documented attack class, but enforcement in developer environments is inconsistent. Require review of packages that include post-install scripts before they reach developer machines. Tools like Socket and Sonatype provide real-time analysis of PyPI packages for malicious behavior before installation. This is not a nice-to-have. Given the pace of AI tooling adoption, it is a basic control.</p>



<h3 class="wp-block-heading">3. Rotate cloud credentials immediately after any suspected exposure</h3>



<p class="wp-block-paragraph">The LiteLLM payload targeted AWS, GCP and Azure tokens specifically because those credentials provide lateral movement across cloud environments. If your development pipelines pulled LiteLLM during the March 24 exposure window, treat every cloud credential accessible from those environments as potentially compromised and rotate them. Review your cloud provider audit logs for activity patterns that do not correspond to developer-initiated requests — the signature of a stolen token being used by an attacker in a different location.</p>



<h2 class="wp-block-heading">What this means for security teams</h2>



<p class="wp-block-paragraph">The TeamPCP campaign is not the end of this pattern. It is a proof of concept that AI infrastructure is now a target class. LiteLLM, PyTorch Lightning and the tools in between are packages your AI teams depend on every day. The attackers know that. They know that developers move fast, that AI tooling adoption outpaces security review cycles and that a malicious .pth file is invisible to most endpoint detection products.</p>



<p class="wp-block-paragraph">The controls above are not complex. They do not require new vendors or new platforms. They require treating Python package installation in AI development environments with the same rigor you apply to production deployments — because in 2026, the distance between a developer’s local environment and your production infrastructure is shorter than it has ever been, and attackers have noticed.</p>



<p class="wp-block-paragraph">Your developers trust their tools. Make sure that trust is warranted.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What does a data breach cost? AI is a sizable factor]]></title>
<description><![CDATA[The financial impact of a data breach is substantial for any modern business, regardless of industry or size. IBM’s latest Cost of a Data Breach report discovered that, from March 2025 to February 2026, the average cost of a data breach rose to $6 million, up 35% from $4.44 million a year earlier...]]></description>
<link>https://tsecurity.de/de/3710446/it-security-nachrichten/what-does-a-data-breach-cost-ai-is-a-sizable-factor/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710446/it-security-nachrichten/what-does-a-data-breach-cost-ai-is-a-sizable-factor/</guid>
<pubDate>Sat, 08 Aug 2026 00:35:24 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The financial impact of a data breach is substantial for any modern business, regardless of industry or size. <a href="https://www.ibm.com/reports/data-breach">IBM’s latest Cost of a Data Breach report</a> discovered that, from March 2025 to February 2026, the average cost of a <a href="https://www.csoonline.com/article/574289/twitters-mushrooming-data-breach-crisis-could-prove-costly.html">data breach</a> rose to $6 million, up 35% from $4.44 million a year earlier.</p>



<p class="wp-block-paragraph">The 2026 report, conducted by Ponemon Institute and sponsored by IBM, is based on an analysis of data breaches experienced by 600 organizations globally.</p>



<p class="wp-block-paragraph">According to the report, one in four malicious breaches were AI-enabled. Deepfake impersonation and AI-enabled malware made up the majority of these AI-assisted attacks.</p>



<p class="wp-block-paragraph">The study found that AI and automation in security operations cut breach costs by an average of almost $2 million dollars. Despite that impact, one in four organizations have yet to adopt these tools in their security operations, the survey found.</p>



<p class="wp-block-paragraph">In a follow-up study, more than half the organizations reported using agents for threat detection and containment but only 18% apply agents to vulnerability management. Three in four of the enterprises polled say that frontier AI threats are prompting them to rethink how agents are deployed across their security operations.</p>



<p class="wp-block-paragraph">“AI is making attacks faster and cheaper, while breaches keep getting more expensive. When organizations have an extended gap between discovery and remediation, that imbalance shows up directly in breach costs,” says <strong>Suja Viswesan, VP of IBM Security Software</strong>.</p>



<h2 class="wp-block-heading">AI models under attack</h2>



<p class="wp-block-paragraph">One in five organizations reported a breach targeting AI models or applications. The most common causes were weaknesses in surrounding systems: compromised APIs, applications, or plug-ins (27%) and cloud misconfigurations affecting AI workloads (27%).</p>



<p class="wp-block-paragraph">The vast majority of organizations suffering AI-related breaches lacked proper access controls, yet only 40% deployed access controls on their AI models and data.</p>



<p class="wp-block-paragraph">Improving access controls on AI models is the most obvious security gap to close, according to Kayne McGladrey, a senior member of IEEE, CISSP-certified cybersecurity advisor, and former CISO of compliance automation vendor Hyperproof.</p>



<p class="wp-block-paragraph">“Treat your models and their APIs like crown jewels,” says McGladrey. “If you wouldn’t expose your database to the public internet without identity and access controls, why would you do that for your AI model?”</p>



<p class="wp-block-paragraph">Udaya Bhaskar Vemuri, senior application security analyst and DevSecOps professional, adds that organizations should also be “reviewing integrations and plug-ins, monitoring unusual activity, protecting sensitive data, and making sure every AI system has a clearly defined owner who is responsible for its security and oversight.”</p>



<h2 class="wp-block-heading">Prompt criticality</h2>



<p class="wp-block-paragraph">Beyond deepfakes and AI malware, <a href="https://www.csoonline.com/article/3850783/11-ways-cybercriminals-are-making-phishing-more-potent-than-ever.html">AI-driven phishing</a> and <a href="https://www.csoonline.com/article/4110008/top-cyber-threats-to-your-ai-systems-and-infrastructure.html">direct attacks on AI models</a>, such as prompt injection, are emerging as costly enterprise blind spots.</p>



<p class="wp-block-paragraph">“The threat isn’t just external; unapproved employee use of AI applications introduces unmanaged vulnerabilities into corporate environments,” says Dray Agha, senior manager of security operations at managed detection and response firm Huntress.</p>



<p class="wp-block-paragraph">CISOs must shift to proactive governance by embedding security into development workflows, managing exposures aggressively, and applying strict access controls to AI workloads, Agha advises.</p>



<p class="wp-block-paragraph">Peter Garraghan, CSO and founder at AI security testing firm Mindgard, adds that blindly trusting in the effectiveness of AI security guardrails is fraught with risk.</p>



<p class="wp-block-paragraph">“Research has demonstrated that existing guardrails currently have various blind spots, and that a defense in depth approach is required,” says Garraghan. “Attackers are constantly adapting, so organizations need to continuously test AI models and applications against realistic adversarial attacks to identify where protections fail.”</p>



<p class="wp-block-paragraph">Garraghan adds: “By validating guardrails before and throughout deployment, CISOs can ensure AI systems are resilient enough to protect sensitive data, and user privacy as threats evolve.”</p>



<p class="wp-block-paragraph">Attackers are compromising APIs, plug-ins, and cloud misconfigurations around models rather than defeating them, according to Ariel Parnes, co-founder and COO of cloud security vendor Mitiga.</p>



<p class="wp-block-paragraph">“These attacks land in the telemetry of the cloud and identity environments, not in the model itself, so the defense is behavioral detection across everything the AI touches,” Parnes advises.</p>



<h2 class="wp-block-heading">Upping the ante</h2>



<p class="wp-block-paragraph">The abuse of AI tools by attackers doesn’t just mean enterprises are subject to more sophisticated attacks. It also means that these attacks unfold more quickly.</p>



<p class="wp-block-paragraph">“Organizations need to respond with the same level of automation, but with strong guardrails,” says John-Paul Cunningham, CISO at identity security vendor Silverfort. “AI can improve the speed of cyber defense, but only if organizations build governance and accountability into those systems from the start.”</p>



<h2 class="wp-block-heading">Regional costs</h2>



<p class="wp-block-paragraph">Average breach costs in the US reached a record $11.5 million, an 11% increase over last year and nearly double the global average.</p>



<p class="wp-block-paragraph">This rise was driven in part by steeper regulatory penalties and higher business costs, according to the IBM-sponsored study.</p>



<p class="wp-block-paragraph">The Middle East, which considered Saudi Arabia and the United Arab Emirates for the report, was No. 2 of the 16 countries and regions surveyed, at $8 million.</p>



<p class="wp-block-paragraph">Canada ($5.2 million) and the UK ($4.17 million) remain in the top 10 hardest hit, with ASEAN or Association of Southeast Asian Nations ($4.12 million), <a href="https://www.csoonline.com/article/1309403/australian-government-back-on-top-5-sectors-with-most-reported-data-breaches.html">Australia</a> ($2.96 million), and India ($2.79 million) among the top 15.</p>



<p class="wp-block-paragraph">Phishing topped initial attack vectors and led to the costliest breaches. Social engineering, such as impersonating help desk staff, was used in 13% of attacks while voice and SMS phishing featured in 17% of attacks.</p>



<h2 class="wp-block-heading">Breaches by industry</h2>



<p class="wp-block-paragraph">Healthcare remains the industry hit with the highest average costs per breach at $6.64 million despite a drop from $7.42 million last year.</p>



<p class="wp-block-paragraph">Attackers continue to value and target the industry’s patient personal identification information (PII), which can be used for identity theft, insurance fraud, and other financial crimes.</p>



<p class="wp-block-paragraph">The mean time organizations took to identify and contain a breach rose to 247 days, a slight 2.5% year-on-year increase that reversed a five-year decline. “New threats from AI-driven attacks are challenging even the quickest response times,” the IBM-sponsored study notes.</p>



<p class="wp-block-paragraph"><strong>Average breach cost by industry</strong></p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td><strong>Industry</strong></td><td><strong>2026</strong></td><td><strong>2025</strong></td><td><strong>Change</strong></td></tr><tr><td>Healthcare</td><td>$6.64M</td><td>$7.42M</td><td>-11%</td></tr><tr><td>Financial</td><td>$6.29M</td><td>$5.56M</td><td>+13%</td></tr><tr><td>Industrial</td><td>$5.50M</td><td>$5.00M</td><td>+10%</td></tr><tr><td>Technology</td><td>$5.50M</td><td>$4.79M</td><td>+15%</td></tr><tr><td>Entertainment</td><td>$5.38M</td><td>$4.43M</td><td>+21%</td></tr><tr><td>Pharmaceuticals</td><td>$5.25M</td><td>$4.61M</td><td>+13%</td></tr><tr><td>Energy</td><td>$5.24M</td><td>$4.83M</td><td>+8%</td></tr><tr><td>Professional services</td><td>$5.08M</td><td>$4.56M</td><td>+11%</td></tr><tr><td>Communications</td><td>$4.71M</td><td>$3.75M</td><td>+26%</td></tr><tr><td>Transportation</td><td>$4.50M</td><td>$3.98M</td><td>+13%</td></tr></tbody></table> </div></figure>



<h2 class="wp-block-heading">Breach cost variables</h2>



<p class="wp-block-paragraph">While industry averages provide benchmarks, calculating the true, final cost of a specific data breach is notoriously difficult and relies heavily on forecasting.</p>



<p class="wp-block-paragraph">“Immediate technical costs are quantifiable, but devastating long-term impacts like reputational damage, lost business, and regulatory fines are intangibles, making total breach cost figures informed estimates rather than exact science,” says Huntress’ Agha.</p>



<p class="wp-block-paragraph">Several experts quizzed by CSO named the cybersecurity skills gap, supply chain vulnerabilities, and the escalating threat landscape as the three main factors in making breaches more expensive and harder to manage.</p>



<p class="wp-block-paragraph">AJ Thompson, chief commercial officer at IT consultancy Northdoor, who sits on IBM’s Worldwide Security Advisory Council advising on data access and security, says the “bigger cost driver is still ‘how fast you spot a breach’ rather than the sophistication of an attack.”</p>



<p class="wp-block-paragraph">“A shortage of experienced security staff and patchy visibility into supply chain and third-party risk both stretch out that detection window, and every extra week unnoticed adds to the bill,” Thompson adds.</p>



<h2 class="wp-block-heading"><a></a>Reputational damage remains a key cost of being breached</h2>



<p class="wp-block-paragraph">In many ways immeasurable, <a href="https://www.csoonline.com/article/571857/the-emotional-stages-of-a-data-breach-how-to-deal-with-panic-anger-and-guilt.html">reputational damage</a> remains among the most significant costs in the wake of a breach. “Ultimately, customer trust is very easy to break, and very difficult to build,” <a href="https://www.forrester.com/analyst-bio/allie-mellen/BIO16084">Allie Mellen</a>, senior analyst at Forrester, tells CSO.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/businessvalue/">Bob Dutile</a>, chief commercial officer at UST, agrees: “The cost of a data breach is typically realized in relative competitive change in the marketplace. Companies find that their brand does not command the same price premium, customer conversion costs are higher, and market share is lost. For a public company, the near-term assessment of the cost impact is reflected in stock price movement.”</p>



<p class="wp-block-paragraph">According to Dutile, research shows that between $8 million and $10 million is a good planning number in the US for a midsize business facing a modest breach of under 250,000 records. About a third of that cost will be loss of business due to reputation damage.</p>



<p class="wp-block-paragraph">How a company responds to and communicates a breach can have a large bearing on that reputational impact, Forrester’s Mellen notes. “Understanding how to maintain trust with your consumers and customers is really critical here,” she adds. “There are ways to do this, especially around building transparency and using empathy, which can make a huge difference in how your customers perceive you after a breach. If you try to sweep it under the rug or hide it, then that will truly affect their trust in you far more than the breach alone.”</p>



<h2 class="wp-block-heading">Severe business downtime can cost millions</h2>



<p class="wp-block-paragraph">Business downtime can also be significantly costly for a breached organization, depending on the level and extent of the downtime and how technology-dependent the firm is.</p>



<p class="wp-block-paragraph">Nearly all the organizations studied suffered operational disruption, taking an average of 100 days to recover from a security incident.</p>



<p class="wp-block-paragraph"><a href="https://heretoserve.org/team/jason-hicks/">Jason Hicks</a>, field CISO at Coalfire, tells CSO: “Often a breach is not going to take a company completely offline, but it can happen. The more critical systems that are taken down, the more significant the cost.”</p>



<p class="wp-block-paragraph">Manufacturing tends to have the best metrics around this, as it’s relatively simple to measure the cost per minute if an assembly line is down, Hicks says. “This can translate into millions of dollars a day for a large manufacturing company. This can be more nebulous for other industry verticals, but there are models to get a reasonable feel that can be applied to each vertical.”</p>



<h2 class="wp-block-heading">Regulation and litigation add to data breach costs</h2>



<p class="wp-block-paragraph">Increasingly strict <a href="https://www.csoonline.com/article/573561/instagram-faces-402-million-fine-for-alleged-mishandling-of-childrens-data.html">data protection and privacy laws</a> along with litigation are seeing a growing number of companies issued large fines, paying hefty settlements, and stumping up for legal fees following data breaches and non-compliance.</p>



<p class="wp-block-paragraph">“Regulated industries suffer not only the immediate cost of responding to, containing, and remediating vulnerabilities but also the long-term effects of additional penalties from their regulatory bodies and legal settlements,” Nick says. Highly regulated industries, such as healthcare and financial services, typically run one and two in order of cost per breach because they will pay more non-compliance fines than others, he adds.</p>



<p class="wp-block-paragraph">“Investigation and adjudication often take years for the victim organization to reach a monetary settlement with affected parties.” <a href="https://www.csoonline.com/article/574681/paypal-sued-for-negligence-in-data-breach-that-affected-35000-users.html">Legal costs</a> are one of the largest expenditures organizations face in data breaches, Nick states. “Organizations rarely have the legal and privacy expertise in-house. To ensure compliance, they must hire outside counsel to lead their reporting.”</p>



<h2 class="wp-block-heading">The role of cyber insurance</h2>



<p class="wp-block-paragraph"><a href="https://www.csoonline.com/article/571703/cyber-insurance-explained.html">Cyber insurance</a> is one way that companies mitigate the cost risks of breaches. Sharp increases in cyber insurance premiums <a href="https://www.csoonline.com/article/3537205/cyber-insurance-price-hikes-stabilize-as-insurers-expect-more-from-cisos.html">have been stabilizing of late</a>, but even organizations covered by insurance can expect to dole out extra cash to make good after a breach. One definite cost hit will be a hike in their premiums, Guidehouse’s Nick says.</p>



<p class="wp-block-paragraph">“Some organizations have reported post-breach increases in premiums of approximately 200%,” he adds.</p>



<p class="wp-block-paragraph">Insurers are also implementing more coverage limitations, meaning that even with a policy in place, businesses could find themselves financially responsible for certain breach-related costs.</p>



<p class="wp-block-paragraph">In fact, Forrester’s Mellen says any notion that policies will allow organizations to fully recover financially from a cyberattack is folly. “In reality, it’s not going to cover all of the costs associated with any type of cyberattack, and we see some insurance firms not even covering ransomware at this point as part of their payouts,” she adds.</p>



<p class="wp-block-paragraph">Another factor to consider is that cyber insurance providers typically have a list of approved service providers such as lawyers and forensics firms, Hicks says.</p>



<p class="wp-block-paragraph">“If your preferred provider is not on their list, you may have to work with them to get them included, or potentially have to change providers. This can be costly, as firms are often leveraging their existing service providers to secure the maximum discounts based on the volume of work done with the partners,” Hicks says.</p>



<h2 class="wp-block-heading">Ransomware extortion on the rise</h2>



<p class="wp-block-paragraph">Reported ransomware incidents rose in the last 12 months compared to the year prior (39% vs. 34%) as attackers have abused AI technologies to automate and scale their attacks.</p>



<p class="wp-block-paragraph">While disrupting operations through encrypting<strong> </strong>remains a key tactic (23%), attackers are shifting to higher-impact pressure methods, such as threatening to leak stolen data (a common feature of so-called double extortion attacks).</p>



<h2 class="wp-block-heading">Insufficient security staffing leads to higher breach costs</h2>



<p class="wp-block-paragraph">According to IBM’s latest report, the security skills shortage is one of the biggest data breach cost amplifiers, with the average additional cost of data breach due to cyber skills shortage pegged at $180,000.</p>



<p class="wp-block-paragraph">If insufficient security staff equates to greater data breach costs, organizations should heed Mellen’s warning about the impact a poorly handled data breach can have on employees.</p>



<p class="wp-block-paragraph">“If they don’t feel like the organization is able to protect them or customers in the event of a breach, or that they blame their employees for a breach, then they’re likely going to start looking for jobs elsewhere because it creates a bit of a hostile environment for them,” she says. “It is very important for organizations to recognize that they need to accept responsibility and protect both their employees and their customers.”</p>



<p class="wp-block-paragraph">Taking a DevSecOps approach to software development was the No. 1 factor that reduced breach costs, according to the report, ahead of use of identity and access management. Running key lifecycle management tools rounded out the top three factors.</p>



<p class="wp-block-paragraph">Security incidents involving <a href="https://www.csoonline.com/article/3964282/cisos-no-closer-to-containing-shadow-ais-skyrocketing-data-risks.html">shadow or unsanctioned use of AI tools</a> more than doubled to 43% this year compared to 20% in 2025. Shadow AI is starting to rival supply chain breaches and security system complexity as a leading factor in exacerbating breach costs, according to the report.</p>



<h2 class="wp-block-heading"><a></a>Preparedness is key to managing data breach costs</h2>



<p class="wp-block-paragraph">No matter the specific costs involved, experts agree that preparedness is key to mitigating the financial repercussions of a breach.</p>



<p class="wp-block-paragraph">“Faster incident response continues to be a clear driver for lowering the cost of a breach,” UST’s Dutile says. “The worst losses are those that go undetected for an extended time or have a slow or ineffective response.”</p>



<p class="wp-block-paragraph">To that end, more than half of organizations surveyed say they plan to invest in AI security and governance tools post-breach, an 88% increase from last year and a reaction to concerns over frontier AI model threats.</p>



<p class="wp-block-paragraph">Modern cybersecurity requires a post-breach mindset which understands that, eventually, a successful data breach is going to occur, Forrester’s Mellen adds.</p>



<p class="wp-block-paragraph">“Operating under those conditions, you need to figure out how you’re going to handle that and build your resiliency to respond better and faster. This isn’t just about the security function either, and it needs to be spread across an organization, considering what marketing is going to do, what sales is going to do, etc. — how, as a business, you can demonstrate you value your customers and that you want to make it right as quickly and effectively as possible,” she says.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mastering Enterprise Security in Microsoft Power Platform]]></title>
<description><![CDATA[Citizen development was supposed to free up IT teams, not give them a new category of risk to manage. Yet that is precisely what has happened in many…
Read more →
The post Mastering Enterprise Security in Microsoft Power Platform appeared first on IT Security News.]]></description>
<link>https://tsecurity.de/de/3710360/it-security-nachrichten/mastering-enterprise-security-in-microsoft-power-platform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710360/it-security-nachrichten/mastering-enterprise-security-in-microsoft-power-platform/</guid>
<pubDate>Sat, 08 Aug 2026 00:35:12 +0200</pubDate>
<content:encoded><![CDATA[<p>Citizen development was supposed to free up IT teams, not give them a new category of risk to manage. Yet that is precisely what has happened in many…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/mastering-enterprise-security-in-microsoft-power-platform/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/mastering-enterprise-security-in-microsoft-power-platform/">Mastering Enterprise Security in Microsoft Power Platform</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[From ambition to action: What Canadian tech leaders must get right to see meaningful value from transformation efforts]]></title>
<description><![CDATA[It’s no secret that the CIO role is changing in Canadian enterprises. Driving operational performance and increasing efficiency are, of course, still a big part of the job. But CIOs are now expected to do more than cut costs and keep the lights on. Increasingly, boards of directors expect the CIO...]]></description>
<link>https://tsecurity.de/de/3710285/it-security-nachrichten/from-ambition-to-action-what-canadian-tech-leaders-must-get-right-to-see-meaningful-value-from-transformation-efforts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710285/it-security-nachrichten/from-ambition-to-action-what-canadian-tech-leaders-must-get-right-to-see-meaningful-value-from-transformation-efforts/</guid>
<pubDate>Fri, 07 Aug 2026 23:48:03 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">It’s no secret that the CIO role is changing in Canadian enterprises. Driving operational performance and increasing efficiency are, of course, still a big part of the job. But CIOs are now expected to do more than cut costs and keep the lights on. Increasingly, boards of directors expect the CIO to play a key role in creating value and enabling their organizations to outperform their rivals. Recent data backs this up. The overwhelming majority (91%) of Canadian technology leaders believe advanced technology will be the primary driver of competitive advantage over the next three years, according to KPMG’s “<a href="https://kpmg.com/ca/en/insights/2026/02/execution-imperatives-for-canadian-tech-leaders.html" target="_blank" rel="noreferrer noopener">The 8 execution imperatives for Canadian tech leaders</a>,” a white paper based on the firm’s <a href="https://kpmg.com/xx/en/our-insights/ai-and-technology/global-tech-report.html" target="_blank" rel="noreferrer noopener">2026 Global Tech Report</a>.</p>



<p class="wp-block-paragraph">The race to capture value from emerging technologies has intensified, leaving little room for organizations that remain on the sidelines. Yet in Canada, just 27% of organizations consider themselves innovators or early adopters, while 72% are fast or slow followers. Nearly all (85%) believe they’ll need to take more risks with emerging technologies just to remain relevant.</p>



<p class="wp-block-paragraph">The traditional, operational-first mindset among CIOs has become a liability. CIOs are expected to be strategic players, but meeting that expectation requires taking thoughtful, well-considered action across key imperatives.</p>



<h3 class="wp-block-heading"><strong>AI success depends on data</strong></h3>



<p class="wp-block-paragraph"><strong>AI is not the only advanced technology that organizations are working to deploy, but it’s certainly garnering the most attention from C-suite executives, boards of directors, and investors. </strong>To enable AI at scale, the data foundations enterprises have built over the past decade will be necessary, but they are not sufficient on their own. CIOs must make modernizing the state of enterprise data a top priority.</p>



<p class="wp-block-paragraph">In most large organizations, data often remains locked inside legacy systems where the system of record is also the system of engagement, and that significantly limits accessibility for AI workloads. Data should be treated as the strategic asset that it has become. The quality, timeliness, and governance of that data vary widely, and reconciling those inconsistencies is one of the most persistent barriers to enterprise-level deployment.</p>



<p class="wp-block-paragraph">Scaling pilots into enterprise programs also requires closing the gap between AI-native talent, who have the skills to move quickly, and those with deep institutional knowledge, who understand how their organizations work and what they need to achieve. These two groups must work hand in hand. Otherwise, organizations may accelerate toward the wrong goals, which won’t move the business forward.</p>



<p class="wp-block-paragraph">“The barriers to scaling AI aren’t just technical,” says Sanjay Pathak, partner and national leader, technology strategy and digital transformation services, KPMG Canada. “CIOs need to truly and deeply understand the value chain of what their organizations do. Those who get there will have the imagination, the courage, and the foresight to use AI to transform their organizations.”</p>



<h3 class="wp-block-heading"><strong>Communicating ROI requires the right framing</strong></h3>



<p class="wp-block-paragraph">Beyond scaling, simply communicating the value of AI also poses a significant challenge. Just over half (53%) of Canadian organizations surveyed say they struggle to demonstrate or communicate AI value to stakeholders. Part of the problem is that CIOs are making the wrong argument in the wrong room because they’re framing ROI as a technology metric rather than a business outcome.</p>



<p class="wp-block-paragraph">“Any CIO who doesn’t truly understand what their business does is missing a beat around how innovation is going to help the organization achieve ROI,” says Pathak. “Understanding how to deploy AI inside your value chain will give you a head start and a competitive advantage in unlocking real business benefits.”</p>



<p class="wp-block-paragraph">A formal performance measurement framework that tracks customer experience, revenue growth, and employee adoption alongside cost metrics gives CIOs a far more accurate picture of long-term value. Linking funding decisions to those strategic outcomes makes sustained investment easier to justify.</p>



<p class="wp-block-paragraph">There is also a compliance dimension that often goes unacknowledged in these conversations. CIOs who bring business, technology, and compliance leaders together to design innovative processes that are “compliant by design” from the start are protecting future value as much as they are delivering value today.</p>



<p class="wp-block-paragraph">“You need to assemble that multi-dimensional cohort of business, technology, risk, and compliance leaders at the same table, envisioning compliance by design,” says Pathak. “The winners in this space are going to be the ones who really think about business ambition holistically and focus on efficient delivery, operations, and compliance.”</p>



<h3 class="wp-block-heading"><strong>Building disciplined innovation governance</strong></h3>



<p class="wp-block-paragraph">An organization’s approach to governance makes an enormous difference in how quickly and confidently it can deploy and take advantage of advanced technologies. As noted above, almost three-quarters (72%) identify as fast or slow followers, and 85% say they need to move more aggressively to embrace new technologies. Canadian organizations aren’t lacking ambition. What they lack are the conditions required to innovate with confidence: clear ownership, defined risk thresholds, and shared accountability between technology, risk, and business teams.</p>



<p class="wp-block-paragraph">“You can be an innovator, but if your innovation is not directly connected to strategic business ambition and safety guardrails such as risk management, governance, and compliance, you’re creating labware,” says Pathak. “Being an early adopter means you’re comfortable with the technology. To make it truly viable, you must embrace all dimensions of enterprise value.”</p>



<p class="wp-block-paragraph">Strong governance does not slow innovation down but instead provides a structure that builds confidence and resilience at every level of the organization, from the board to project teams. A tiered governance approach that takes risk into account allows organizations to advance low-risk, incremental improvements and high-reward initiatives in parallel.</p>



<h3 class="wp-block-heading"><strong>Expanding partnerships to accelerate innovation</strong></h3>



<p class="wp-block-paragraph">Innovation isn’t a single-player game, and Canadian organizations know it. Ninety-seven percent of respondents say they plan to expand their external ecosystems. To date, a significant portion of those relationships have been transactional and focused on a specific capability or problem. But savvier organizations are moving toward multi-party innovation, where partners pool capabilities to share both risk and reward. This model requires a different kind of commitment because organizations are betting on a partner’s long-term viability, not just their current capability. Together, they must build the integration and governance infrastructure that makes these ecosystems work for all participants.</p>



<p class="wp-block-paragraph">“Moving to multi-party innovation ecosystems is an investment in integration and data,” says Pathak. “If you’re going to look at best of breed and stitch those together, what must be true for that to work is the ability for those different ecosystems to integrate and interoperate. And that creates a much stronger need for safety and governance.”</p>



<p class="wp-block-paragraph">Cybersecurity is another dimension that grows more important with every new partner added to the ecosystem. Security should be proactively built in, not imposed after a breach has already occurred.</p>



<p class="wp-block-paragraph">“The more ecosystem-based partnerships you have, the more opportunity you create along with the threat you have to deal with,” says Pathak. “You expand the attack surface, and you become more of a target, so governance and cybersecurity must be designed in from the start, not bolted on later.”</p>



<p class="wp-block-paragraph">Canadian government incentives, including Scientific Research and Experimental Development (SR&amp;ED) tax credits and AI-focused clusters, offer a way to share some of the cost and risk, particularly during periods of economic uncertainty.</p>



<p class="wp-block-paragraph">By leveraging these funding frameworks alongside robust ecosystem governance, forward-thinking organizations can safely scale their networks to turn shared risks into sustainable competitive advantages.</p>



<h3 class="wp-block-heading">In closing</h3>



<p class="wp-block-paragraph">For organizations navigating this environment, KPMG Canada emphasizes that the most consequential decisions ahead are not purely, or even mostly, technical. They are about how CIOs choose to lead, partner, measure, and govern in a period that rewards both ambition and discipline in equal measure.</p>



<p class="wp-block-paragraph">The data points are clear. CIOs who lead with both strategic ambition and disciplined execution will elevate their organizations above their competitors. By paying attention to the quality of their data, aligning technical priorities with critical business goals, and instituting strong governance and cybersecurity, they will set a higher standard for what Canadian competitiveness looks like in the years ahead.</p>



<p class="wp-block-paragraph">To learn more, read the full whitepaper: <a href="https://kpmg.com/ca/en/insights/2026/02/execution-imperatives-for-canadian-tech-leaders.html" target="_blank" rel="noreferrer noopener">The Top 8 Execution Imperatives for Canadian Tech Leaders</a>.</p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Agentic AI workforce is more than doubling year on year, says Salesforce]]></title>
<description><![CDATA[Salesforce customers more than doubled their agentic workforces year on year, according to the company’s second annual Agentic Enterprise Index, which looks at trends in AI agent development and deployment over the past five quarters.



It compiled data from customers who had activated agents in...]]></description>
<link>https://tsecurity.de/de/3710286/it-security-nachrichten/agentic-ai-workforce-is-more-than-doubling-year-on-year-says-salesforce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710286/it-security-nachrichten/agentic-ai-workforce-is-more-than-doubling-year-on-year-says-salesforce/</guid>
<pubDate>Fri, 07 Aug 2026 23:48:03 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Salesforce customers more than doubled their agentic workforces year on year, according to the company’s second annual <a href="https://www.salesforce.com/agentforce/agentic-enterprise-index/" target="_blank" rel="noreferrer noopener">Agentic Enterprise Index</a>, which looks at trends in AI agent development and deployment over the past five quarters.</p>



<p class="wp-block-paragraph">It compiled data from customers who had activated agents in production every month of the analysis period to determine how their use of the technology has evolved between February 2025 and April 2026, as well as incorporating data from May 2026 Salesforce research studies.</p>



<p class="wp-block-paragraph">It found that businesses grew their agentic workforces from an average of five agents in February 2025 to 13 by April 2026, a 7% compound monthly growth rate (CMGR). In April 2026, it only took an average of 1.9 days to deploy an agent into production, a 53% decrease since the beginning of the report period.</p>



<p class="wp-block-paragraph">Not only were agents deployed more quickly, they have been progressively taking on more work once in use; over the 15 months, the average number of actions per account had a CMGR of 31%.</p>



<p class="wp-block-paragraph">“These agents are expanding beyond their initial scope to really become cross-functional,” said <a href="https://www.linkedin.com/in/caila-schwartz/" target="_blank" rel="noreferrer noopener">Caila Schwartz</a>, Salesforce’s head of agentic commerce insights, during a media briefing.</p>



<p class="wp-block-paragraph">Salesforce has attempted to measure how much work agents perform, rather than how many tokens they consume, creating its own <a href="https://www.cio.com/article/4138622/awu-by-salesforce-a-shiny-new-metric-that-tells-cios-little-of-value.html">Agentic Work Unit (AWU) metric</a>, although analysts have criticized the measure as being unrelated to business outcomes. Nevertheless, Salesforce said that as of April, Agentforce agents had performed 734 million AWUs, a number growing at about 15% each month.</p>



<p class="wp-block-paragraph">The research also showed that agents are acting across multiple cloud domains which, the company said, “underscores the practical necessity of a headless architecture. By decoupling the agent’s logic from traditional front-end user interfaces, agents can process tasks, execute actions, and trigger workflows anywhere.”</p>



<p class="wp-block-paragraph">Within the company, Salesforce itself has seen explosive growth in AI agent use, said <a href="https://www.linkedin.com/in/joseph-inzerillo-b917791/" target="_blank" rel="noreferrer noopener">Joe Inzerillo</a>, president of enterprise &amp; AI technology at Salesforce, with a threefold increase in sessions between February 2025 and April 2026. He said that the AI agent in Slack, Slackbot, saves the average employee five hours per week, with 83% of the company having adopted it.</p>



<p class="wp-block-paragraph">But Schwartz pointed out that different industries are approaching agentic AI in different ways, some more sophisticated than others. To measure that, Salesforce developed a Sophistication Index, a five-point scale scoring the cognitive complexity of an agent’s actions. Levels 1- 3  are assigned to tasks such as record lookups, drafting emails, or summarizing documents, while levels 4 and 5 include more complex functions such as updating database fields.</p>



<p class="wp-block-paragraph">The data showed that manufacturing, financial services, and healthcare and life sciences have built more sophisticated agent networks than what it called traditional AI frontrunners such as technology and retail.</p>



<p class="wp-block-paragraph">However, Inzerillo said, the most common use case industry wide, and the best place to start, is the service use case, which provides “far and away the best ROI to start with.”</p>



<p class="wp-block-paragraph">He also noted that, as people have become more conscious of what agents can do, they are asking agents to perform tasks, rather than simply answer questions.</p>



<p class="wp-block-paragraph">“Now what you’re starting to see people do is very action oriented. So instead of asking ’how do I file a form to request my vacation’ from our employee agent, they’re telling the employee agent, ‘hey I’m taking a vacation, you need to enter this form for me, and here’s the details,’” he said, adding that this bias towards action represents the evolution of agentic use.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[There are two completely different roles called ‘FDE’]]></title>
<description><![CDATA[There’s something very attractive about saying “we embed very closely with our customers and just figure it out with them”, especially since the company that started “forward deploying engineers” is growing 84% with $5B+ revenue. But “forward deployed engineer” is a vague term and means different...]]></description>
<link>https://tsecurity.de/de/3710288/it-security-nachrichten/there-are-two-completely-different-roles-called-fde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710288/it-security-nachrichten/there-are-two-completely-different-roles-called-fde/</guid>
<pubDate>Fri, 07 Aug 2026 23:48:03 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">There’s something very attractive about saying “we embed very closely with our customers and just figure it out with them”, especially since the company that started “forward deploying engineers” is growing <a href="https://investors.palantir.com/files/2026%20Q1%20PLTR%2010-Q.pdf">84% with $5B+ revenue</a>. But “<a href="https://en.wikipedia.org/wiki/Forward_Deployed_Engineer#cite_note-1">forward deployed engineer</a>” is a vague term and means different things depending on the business you’re running.</p>



<p class="wp-block-paragraph">I spent almost 5 years at Palantir as a forward-deployed software engineer, and Palantir’s version of an “FDE” does not make sense for most companies I now meet as an early-stage VC. Depending on the type of business you’re building, this role could broadly mean one of two things: “the product builder” or “the platform operator.” Clearly defining which bucket you fall into will make it easier to hire for this role and run your FDE org.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/nature-of-work-vs-product-leverage.png?w=1024" alt="Figure: Nature of work vs. product leverage." class="wp-image-4206317" width="1024" height="578" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Kabir Sial</p></div>



<h2 class="wp-block-heading">The product builder: The OG Palantir version</h2>



<p class="wp-block-paragraph">The north star is: do whatever it takes to actually solve the user’s problem. FDEs are not just responsible for making the platform work, but also discovering what to build and building it (actually creating software) in service of the customer.</p>



<h2 class="wp-block-heading">The platform operator: Solutions + technical customer success</h2>



<p class="wp-block-paragraph">The north star is: make the product work for the customer – deploy and operationalize it. This is what most startups today really mean when they want FDEs. FDEs here configure the core platform, manage account relationships and drive adoption. This is not new – companies have always had solutions engineers, sales engineers, customer success etc., although the work looks different as FDEs are increasingly building prototypes, configuring evals and building MCPs.</p>



<h2 class="wp-block-heading">Which FDE is right for you</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/customer-size.png?w=1024" alt="Figure: Customer size." class="wp-image-4206316" width="1024" height="457" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Kabir Sial</p></div>



<p class="wp-block-paragraph">For most situations, hiring product builder FDEs is a mistake.</p>



<p class="wp-block-paragraph">At scale, the FDEs should be the platform operator. It’s hard to have FDEs build and maintain highly custom product features, especially as the company scales. Over time, the custom product surface area distracts from building the core product, even though AI coding tools make it easy to ship new features quickly and maintain them.</p>



<p class="wp-block-paragraph">Many fast-growing AI startups recognize these constraints and structure the FDE role more like the platform operator. This also allows them to have 5-10 accounts per FDE, which is a much higher ratio than Palantir had (at least in 2023). Even the Palantir FDE role has evolved to look more like the platform operator.</p>



<p class="wp-block-paragraph">There are, however, situations when your FDEs should be the product builder archetype.</p>



<h3 class="wp-block-heading">1. You have very large customers (F500 scale)</h3>



<p class="wp-block-paragraph"><strong>Technical complexity</strong>: Large customers have complex environments with legacy infrastructure that often requires “out-of-platform” engineering work. I often encountered bespoke data infrastructure, privacy requirements, etc. at various Palantir customers that required me to build “out-of-platform” connectors, UIs and backends.</p>



<p class="wp-block-paragraph"><strong>Organizational inertia and trust</strong>: Serving large enterprises is about building trust. In short time periods, overfitting product to a specific user/workflow is often what delivers the most value, builds trust and helps organizations get over the inertia of moving away from Excel and legacy software tools that are part of their day-to-day workflow. For AI-native startups, it’s arguably even more important to invest in doing “unscalable” development with engineering boots on the ground, as it helps solidify your right to exist and eventually expand the customer relationship.</p>



<h3 class="wp-block-heading">2. You have many ICPs and workflows</h3>



<p class="wp-block-paragraph">If you have a broad range of ICPs and workflows that you serve, your product probably is not walk-up usable on day 1 of deployment. The short-term hacky things that product builder FDEs build to make the product work for these heterogeneous users/workflows will help you shape the product long-term.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/overfit-products.png?w=1024" alt='Figure: "Overfit" products.' class="wp-image-4206313" width="1024" height="570" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Kabir Sial</p></div>



<p class="wp-block-paragraph">Note: see Palantir Foundry’s architecture <a href="https://www.palantir.com/assets/xrfr7uokpv1b/mhoyY4c8vdVlJhulDStk2/a7340768109c8e8d79d00b4cb99d8e70/Whitepaper_-_Foundry_2022.pdf">here</a>.</p>



<p class="wp-block-paragraph">This was a big reason why Palantir FDEs were more like product builders (and are still able to – see the <a href="https://jobs.lever.co/palantir/dab396d4-2f14-4796-aac0-0d82883dccf0">Forward Deployed Software Engineer job profiles</a> as an example). The vision for Foundry was to be the operating system for an enterprise’s critical decisions – inherently multiple industries, users and workflows. A lot of FDE-led development showed that solving many of these use cases required complex data integrations, which led to the early versions of Foundry being best-suited for complex data integrations and building a customer’s “<a href="https://blog.palantir.com/ontology-finding-meaning-in-data-palantir-rfx-blog-series-1-399bd1a5971b">Ontology</a>”. Similarly, FDEs like myself built custom frontend applications for fraud analysis, pricing, etc. As certain patterns of what these applications required became more clear, they were centralized into an application-layer product.</p>



<h2 class="wp-block-heading">Who you should hire</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/who-you-should-hire.png?w=1024" alt="Figure: Who you hire." class="wp-image-4206314" width="1024" height="464" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Kabir Sial</p></div>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/why-hire.png?w=1024" alt="Figure: Why hire one vs. the other." class="wp-image-4206315" width="1024" height="456" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Kabir Sial</p></div>



<p class="wp-block-paragraph"><strong>Platform operator</strong>: There is a much broader set of people you could hire, testing for technical fluency (e.g., being good at data analysis, complex Excel work, even SQL), product intuition and an inclination to build customer relationships. Backgrounds like technical customer success, solutions engineering, software engineering, product management and consulting are all strong fits.</p>



<p class="wp-block-paragraph"><strong>Product builder</strong>: You want candidates that are high ownership and missionary software engineers, or technical PMs who want to ship products themselves.</p>



<p class="wp-block-paragraph">Hiring for these profiles, especially product builders, is hard. It’s worth calling out two things that helped Palantir hire software engineers into what might be considered a less sexy role.</p>



<ol start="1" class="wp-block-list">
<li><strong>Culture of building at the edge</strong>: Strong engineers are motivated to build things. Palantir gave FDEs a lot of ownership to build products, which is why much of the core product leadership was former FDEs.</li>



<li><strong>Cult built around mission</strong>: Internally, there was a cult-like devotion to the mission. Everyone always talked about why outcomes were far more important than software, and why most companies building tools had it wrong. I’ve never been at a company where people feel so closely bonded around a mission.</li>
</ol>



<p class="wp-block-paragraph">As founders building AI startups think about hiring FDEs, it’s worth being specific about your culture and asking: Am I just hiring people to support development teams, or am I hiring people to shape and build product? It’s hard to get software engineers (even today) to be excited about an FDE role that might just be technical customer success.</p>



<h2 class="wp-block-heading">What FDEs should be doing (regardless of archetype)</h2>



<p class="wp-block-paragraph">You’ve hired the right people. How do you best leverage your team of FDEs?</p>



<p class="wp-block-paragraph">FDEs were Palantir’s way of delivering outcomes rather than tools. AI-native startups can take this much further and FDEs can help in a few unique ways by leveraging their proximity to customers.</p>



<ol start="1" class="wp-block-list">
<li><strong>Find the most critical workflows</strong>: As AI lowers the cost of producing software, companies will face a lot more competition. FDEs at AI startups should be constantly finding ways to serve the most critical workflows for a customer and paying attention to how customers do work across newer and legacy tools. For example, FDEs at Harvey should pay attention to which workflows are in Westlaw, which ones are moving to ChatGPT/Claude, and how the Harvey product can stay ahead.</li>



<li><strong>Build around nondeterminism</strong>: In more regulated environments, FDEs should be hyper-focused on making products reliable for specific use cases <a href="https://www.anthropic.com/engineering/demystifying-evals-for-ai-agents">using evals</a> and configs. Previously, product reliability lived with product and support. As companies provide outcomes instead of tools, configuring products appropriately and managing evals shifts towards FDE teams.</li>
</ol>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AMD wants to make enterprise inference cheaper and faster with chips from Taalas]]></title>
<description><![CDATA[As enterprises look for ways to cut the cost of running AI models in production, AMD is betting that not every AI workload will be best served by a power-hungry general-purpose GPU.



AMD has agreed to buy Taalas, the Canadian designer of chips that permanently embed a trained AI model’s weights...]]></description>
<link>https://tsecurity.de/de/3710289/it-security-nachrichten/amd-wants-to-make-enterprise-inference-cheaper-and-faster-with-chips-from-taalas/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710289/it-security-nachrichten/amd-wants-to-make-enterprise-inference-cheaper-and-faster-with-chips-from-taalas/</guid>
<pubDate>Fri, 07 Aug 2026 23:48:03 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">As enterprises look for ways to cut the cost of running AI models in production, AMD is betting that not every AI workload will be best served by a power-hungry general-purpose GPU.</p>



<p class="wp-block-paragraph">AMD has agreed to buy Taalas, the Canadian designer of chips that permanently embed a trained AI model’s weights into custom silicon, instead of repeatedly loading them from memory during inference as conventional <a href="https://www.networkworld.com/article/3966130/what-are-gpus-inside-the-processing-power-behind-ai.html">GPUs</a> do.</p>



<p class="wp-block-paragraph">Taalas says its approach reduces the time and power required to move model weights between memory and compute units, making things run faster and cheaper.</p>



<p class="wp-block-paragraph">The result is a highly specialized inference processor optimized for one model, trading the flexibility of programmable hardware for substantially higher throughput and energy efficiency.</p>



<h2 class="wp-block-heading">Operational tradeoffs</h2>



<p class="wp-block-paragraph">While AMD is planning to integrate the chips into its <a href="https://www.amd.com/en/products/accelerators/instinct.html">Instinct GPU</a> roadmap, targeting system-level AI inference solutions in data centers, analysts remain skeptical that enterprises will readily embrace hardware tied to a specific AI model.</p>



<p class="wp-block-paragraph">Enterprises would, effectively, be buying a chip and a model together because unlike GPUs, which can be repurposed to run different AI models through software updates, Taalas’ chips are tied to a specific trained model, meaning they would need different hardware to support different inference tasks, said <a href="https://www.linkedin.com/in/znamit/" target="_blank" rel="noreferrer noopener">Amit Kumar Jena</a>, AI development manager at IT Consulting firm Kanerika.</p>



<p class="wp-block-paragraph">Or as Forrester Principal Analyst <a href="https://www.forrester.com/analyst-bio/charlie-dai/BIO5344" target="_blank" rel="noreferrer noopener">Charlie Dai</a> put it, “The biggest risk is inflexibility.”</p>



<p class="wp-block-paragraph">The requirement to swap hardware in order to swap tasks would, Dai said, introduce new challenges with costs, governance, capacity planning, lifecycle management, and supplier dependency, especially for enterprises managing multiple AI workloads.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/manoj-chandra-jha-b5ab0a13" target="_blank" rel="noreferrer noopener">Manoj Chandra Jha</a>, principal analyst at Nord-IQ Research, said the risk of fusing chip and model into one component is larger than one might think, as “early model obsolescence strands both together, so this should be modeled as one shorter-lived asset rather than two independently amortized ones.”</p>



<p class="wp-block-paragraph">Taalas says it can update a model by modifying only two metal layers of the chip rather than redesigning it from scratch, but that will only apply to chips that haven’t yet left its factory, not those already in use.</p>



<p class="wp-block-paragraph">That means enterprises will still need to plan for hardware refresh cycles measured in weeks or months and retain programmable GPUs for workloads that evolve frequently, said <a href="https://pareekh.com/about/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, principal analyst at Pareekh Consulting.</p>



<p class="wp-block-paragraph">It also means, said Jha, that what is typically a software decision becomes one about capital expenditure for Taalas customers, as replacing or switching workloads or models could require investing in new hardware rather than simply updating software.</p>



<h2 class="wp-block-heading">Where model-specific silicon fits</h2>



<p class="wp-block-paragraph">Those tradeoffs significantly narrow the range of enterprise workloads where model-specific silicon is likely to make economic sense.</p>



<p class="wp-block-paragraph">Dai sees the technology as best suited for mature, predictable inference workloads that run at massive scale and rely on relatively stable AI models, such as customer service automation, fraud detection, industrial computer vision, network operations, edge AI, and embedded copilots.</p>



<p class="wp-block-paragraph">For CIOs, that effectively limits model-specific silicon to a small subset of enterprise AI deployments, rather than a wholesale replacement for GPU infrastructure, he said. “GPUs will remain the preferred enterprise platform because most enterprises value flexibility, multi-tenancy, and rapid model evolution over maximum efficiency.”</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.networkworld.com/article/4206674/amd-to-buy-taalas-maker-of-model-specific-ai-chips-for-enterprise-inference.html">Network World</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Beyond chatbots: How embedded GenAI is transforming banking application development]]></title>
<description><![CDATA[Business application development is entering a new operating model. The traditional approach of gathering requirements, designing screens, writing services, integrating systems, testing, fixing defects and preparing release documentation still exists, but it is no longer sufficient for enterprise...]]></description>
<link>https://tsecurity.de/de/3710290/it-security-nachrichten/beyond-chatbots-how-embedded-genai-is-transforming-banking-application-development/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710290/it-security-nachrichten/beyond-chatbots-how-embedded-genai-is-transforming-banking-application-development/</guid>
<pubDate>Fri, 07 Aug 2026 23:48:03 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Business application development is entering a new operating model. The traditional approach of gathering requirements, designing screens, writing services, integrating systems, testing, fixing defects and preparing release documentation still exists, but it is no longer sufficient for enterprises that need speed, traceability, resilience and regulatory confidence at the same time. Hyperautomation brings a broader discipline to this challenge. It combines workflow orchestration, intelligent document processing, robotic automation, API-led integration, process mining, test automation, observability and artificial intelligence into a connected delivery fabric. With embedded Generative AI, this fabric becomes more adaptive because applications can interpret natural language, summarize complex data, generate explanations, detect exceptions and support decision workflows rather than merely execute predefined rules.</p>



<p class="wp-block-paragraph">In banking, this shift is especially meaningful. Banks operate across dense application landscapes: trade reporting platforms, wealth management portals, core banking systems, investment banking applications, digital compliance engines, reconciliation utilities, operational dashboards, audit repositories and daily, weekly and monthly reporting platforms. Each of these areas has its own data models, control points, integration patterns, validation rules, exception paths and regulatory obligations. Hyperautomation does not replace engineering discipline; it strengthens it by making business intent, technical execution, control evidence and continuous improvement part of the same lifecycle.</p>



<h2 class="wp-block-heading">From automation to hyperautomation in banking applications</h2>



<p class="wp-block-paragraph">Automation usually addresses a specific task: moving data from one system to another, generating a report, running a batch job or validating a transaction against a rule. Hyperautomation goes further. It looks at the complete business outcome and asks how the entire chain can be streamlined, governed, observed and improved. For example, a trade reporting process may begin with transaction capture, enrich the trade with reference data, validate regulatory fields, identify breaks, generate a submission file, transmit it to a regulator or trade repository, monitor acknowledgements and preserve audit evidence. A narrow automation script may accelerate one step, but a <a href="https://www.gartner.com/en/documents/6454507">hyperautomated design</a> coordinates the complete flow, including exception handling and evidence generation.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/figure-Figure-automation-vs-hyperautomation.png?w=1024" alt="Figure: Automation vs. hyperautomation." class="wp-image-4206308" width="1024" height="775" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Magesh Kasthuri</p></div>



<p class="wp-block-paragraph"><strong>Figure: Automation vs. hyperautomation</strong></p>



<p class="wp-block-paragraph">Embedded Generative AI adds a <a href="https://assets.ctfassets.net/5965pury2lcm/65QHMnfLGaRJzJ0sX5982o/520b5f0a9745aecc8730c645994e3a3b/Forrester_Study_-_AI_And_The_Next_Generation_of_Software_Testing.pdf">new layer of intelligence</a>. Instead of forcing every user interaction into rigid screens and codes, business applications can accept natural language prompts, interpret document content, summarize cases, generate draft responses, explain anomalies, produce test scenarios and create release notes. In a banking environment, this intelligence must be carefully bounded. Every AI-assisted action should be traceable, explainable, reviewable and aligned with data privacy, model risk, information security and regulatory expectations. The goal is not uncontrolled autonomy; the goal is governed acceleration.</p>



<h2 class="wp-block-heading">Banking application components suitable for hyperautomation</h2>



<p class="wp-block-paragraph">A modern banking application is rarely a single monolithic system. It is a composition of business capabilities, integration services, workflow engines, data pipelines, user experience layers, analytics models, control dashboards and audit stores. Hyperautomation can accelerate the development and integration of these components by turning repetitive engineering work into <a href="https://www.everestgrp.com/report/egr-2024-31-v-6318/">reusable patterns</a> and by embedding intelligence directly into business processes.</p>



<ul class="wp-block-list">
<li><strong>Trade reporting applications:</strong> Generative AI can help map trade attributes to regulatory fields, explain validation failures, summarize rejected submissions and generate test cases for reporting scenarios. Hyperautomation can orchestrate enrichment, validation, submission, acknowledgement tracking and evidence archival.</li>



<li><strong>Wealth management platforms:</strong> Advisors can use embedded AI to summarize client portfolios, generate suitability narratives, identify missing documents and prepare personalized investment review notes. Automation can coordinate onboarding, risk profiling, document verification, portfolio rebalancing workflows and client communication approvals.</li>



<li><strong>Core banking applications:</strong> Account opening, loan servicing, deposits, payments, interest calculations and customer maintenance can benefit from automated validations, intelligent forms, workflow routing and natural language assistance for operations teams. AI can explain account events or transaction exceptions in plain language.</li>



<li><strong>Investment banking systems:</strong> Deal pipelines, research workflows, underwriting processes, trade lifecycle functions and risk calculations require strong coordination across front-office, middle-office and back-office platforms. Hyperautomation can standardize approvals, documentation, exception resolution and control evidence across these stages.</li>



<li><strong>Digital compliance applications:</strong> Compliance teams can use AI to summarize policy obligations, compare regulatory changes with internal controls, classify alerts, draft investigation notes and produce evidence packs. Automation ensures routing, approvals, segregation of duties, audit trails and regulatory reporting timelines are consistently enforced.</li>



<li><strong>Reconciliation platforms:</strong> AI can assist in matching narratives, explaining breaks, clustering exception patterns and suggesting resolution actions. Hyperautomation can pull data from ledgers, statements, payment processors, trading systems and data warehouses, then route unresolved breaks to the right teams.</li>



<li><strong>Reporting and audit applications:</strong> Daily, weekly and monthly reports can be generated through controlled data pipelines, automated quality checks, narrative generation, variance explanations and approval workflows. Audit applications can preserve lineage, approvals, source extracts, model outputs and control attestations.</li>
</ul>



<h2 class="wp-block-heading">Embedded generative AI as an application capability</h2>



<p class="wp-block-paragraph">Embedding Generative AI into business applications should be treated as an architectural capability, not as a decorative chatbot. A banking application may use AI for search, summarization, reasoning support, content generation, code generation, policy interpretation or anomaly explanation. Each use case requires clear boundaries. The application must know which data the model can access, which actions require approval, what evidence must be captured and where deterministic controls must override probabilistic <a href="https://www.idc.com/resource-center/generative-ai/">suggestions</a>.</p>



<p class="wp-block-paragraph">For example, in trade reporting, an embedded AI assistant can explain why a transaction failed validation and suggest likely fields to review. However, the final correction should pass through rule-based validations, maker-checker approval and audit logging. In wealth management, AI may draft a client review note based on portfolio movements and risk profile, but the advisor must verify suitability, disclosures and final communication. In reconciliation, AI can propose likely matches or categorize break reasons, while the system preserves the original data, confidence score, reviewer action and final resolution path.</p>



<h2 class="wp-block-heading">Hyperautomating the product development lifecycle</h2>



<p class="wp-block-paragraph">The Product Development Lifecycle can itself become hyperautomated. Instead of treating ideation, analysis, design, development, testing, security review, release and operations as disconnected phases, enterprises can create an AI-assisted delivery loop where every stage produces structured artifacts that the next stage can consume. Platforms such as GitHub Copilot, Claude Code or Claude Cowork-style agentic development environments and OpenAI Codex can support this movement by helping teams reason over requirements, generate code, create tests, review changes, modernize legacy modules and produce <a href="https://www.cio.com/article/1307309/the-generative-ai-revolution-is-transforming-how-banks-work.html">documentation</a>. Their value increases when they are connected to repositories, issue trackers, design documents, build pipelines, test suites, security scanners, observability data and enterprise knowledge bases.</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td><strong>PDLC Stage</strong></td><td><strong>Hyperautomation Opportunity</strong></td><td><strong>AI-Assisted Outcome</strong></td></tr><tr><td>Business discovery</td><td>Process mining, domain interviews, regulatory mapping, backlog creation</td><td>Structured epics, user stories, acceptance criteria, process maps and control requirements</td></tr><tr><td>Architecture and design</td><td>Reference architectures, API contracts, data models, event flows, security patterns</td><td>Architecture options, integration blueprints, threat-model prompts and design decision records</td></tr><tr><td>Development</td><td>Code generation, service scaffolding, UI component creation, data pipeline templates</td><td>Review-ready code increments, reusable components, migration utilities and integration adapters</td></tr><tr><td>Testing</td><td>Unit, integration, regression, performance, compliance and synthetic data testing</td><td>Generated test cases, defect reproduction steps, test automation scripts and coverage summaries</td></tr><tr><td>Security and compliance review</td><td>Static analysis, dependency checks, policy validation, evidence capture</td><td>Risk explanations, remediation suggestions, control traceability and approval evidence</td></tr><tr><td>Release and deployment</td><td>CI/CD orchestration, environment promotion, release notes, rollback preparation</td><td>Automated deployment packs, release summaries, operational checklists and change records</td></tr><tr><td>Operations and feedback</td><td>Observability, incident analysis, user feedback mining, backlog refinement</td><td>Incident summaries, root-cause hypotheses, improvement stories and reliability recommendations</td></tr></tbody></table> </div></figure>



<h2 class="wp-block-heading">Role of GitHub Copilot, Claude Cowork and Codex</h2>



<p class="wp-block-paragraph">GitHub Copilot is useful where developers need assistance inside the engineering flow: explaining code, generating functions, proposing tests, reviewing pull requests and helping teams move from issue to implementation. In a banking PDLC, it can accelerate microservice creation, API integration, batch processing logic, reconciliation rules, regulatory validation routines and UI workflows. When used with repository context and proper review discipline, it can reduce the time developers spend on repetitive coding while preserving human accountability for design and correctness.</p>



<p class="wp-block-paragraph">Claude Cowork or Claude Code-style agentic environments are valuable for multi-file reasoning, refactoring, debugging and documentation-heavy engineering work. Banking applications often contain deep domain logic scattered across services, configuration files, stored procedures, integration scripts and test suites. An agentic coding assistant that can understand a wider codebase context can help engineers analyze dependencies, prepare modernization plans, update multiple files coherently and draft explanations for reviewers. This is particularly useful in core banking modernization, trade reporting rule updates and compliance workflow refactoring.</p>



<p class="wp-block-paragraph">OpenAI Codex can support issue-to-pull-request workflows, test generation, code review, bug reproduction, migration activities and broader software engineering tasks across the lifecycle. In a hyperautomated PDLC, Codex-like agents can be assigned well-scoped work items, asked to inspect failing tests, propose fixes, create regression coverage and summarize the change for human reviewers. The important design principle is to keep agents inside controlled boundaries: clear prompts, repository permissions, test gates, approval workflows and traceable outputs.</p>



<h2 class="wp-block-heading">Integration architecture for hyperautomated banking applications</h2>



<p class="wp-block-paragraph">A practical architecture begins with business capability decomposition. Each banking domain should be expressed as a set of bounded capabilities such as customer onboarding, account maintenance, trade enrichment, exception management, portfolio review, control attestation, report generation and audit retrieval. These capabilities should be exposed through APIs, events, workflow tasks, data products and user interfaces. Hyperautomation then connects these capabilities using orchestration engines, event streams, rules engines, AI services, RPA connectors where legacy integration is unavoidable and observability layers that capture business and technical telemetry.</p>



<p class="wp-block-paragraph">The embedded AI layer should sit behind a secure application service boundary. It should use retrieval-augmented generation where approved policies, product rules, application documentation and regulatory mappings are retrieved from trusted sources. It should avoid uncontrolled exposure of sensitive customer information. Prompt templates, response validation, redaction, grounding checks, model monitoring and human-in-the-loop approval should be part of the production design. In banking, the most successful AI pattern is often not full automation but <a href="https://www.everestgrp.com/report/egr-2024-31-v-6318/">assisted</a> decisioning with strong controls.</p>



<h2 class="wp-block-heading">Example: Hyperautomated reconciliation and reporting flow</h2>



<p class="wp-block-paragraph">Consider a reconciliation application that compares ledger balances, payment files, trade settlement records and external statements. In a conventional model, operations teams spend significant time downloading files, running macros, investigating mismatches, documenting break reasons and preparing status reports. In a hyperautomated model, data ingestion is scheduled and monitored, schema checks run automatically, matching engines classify obvious matches, AI assists with ambiguous narratives, exceptions are routed through workflow queues and dashboards update in near real time. At the end of the day, the system can generate a draft operations <a href="https://www.pwc.com/us/en/industries/financial-services/library/hyperautomation-gen-ai-in-banking.html">report</a> explaining unresolved breaks, aging trends, risk exposure and pending approvals.</p>



<p class="wp-block-paragraph">The same pattern can extend to daily, weekly and monthly reporting. Data quality rules validate inputs, report templates are populated automatically, AI generates narrative commentary on variances, reviewers approve or amend explanations and the final report is archived with lineage and approvals. Audit teams can later retrieve not only the report but also the source extracts, transformation logs, exception history, reviewer decisions and AI-generated drafts. This creates a richer control environment than manual reporting because evidence is captured by design rather than reconstructed later.</p>



<h2 class="wp-block-heading">Governance, risk and control considerations</h2>



<p class="wp-block-paragraph">Hyperautomation in banking must be designed with governance from the beginning. The development team should define which activities can be automated, which can be AI-assisted and which must remain under human approval. Source code generated by AI must pass normal engineering controls, including peer review, static analysis, dependency scanning, secure coding checks, test execution and production readiness review. Business outputs generated by AI, such as compliance narratives or client-facing explanations, should be <a href="https://www.pwc.com/us/en/industries/financial-services/library/hyperautomation-gen-ai-in-banking.html">reviewed</a> where regulatory or reputational risk is material.</p>



<p class="wp-block-paragraph">Data governance is equally important. AI-enabled applications must respect data classification, residency, retention, masking and access policies. The model should not become an uncontrolled channel through which confidential customer, trading or employee information can leak. Every prompt, retrieved source, generated response, user action and final decision may need to be logged depending on the use case. For audit applications, this traceability is not optional; it is the foundation of trust.</p>



<h2 class="wp-block-heading">Operating model for AI-native PDLC</h2>



<p class="wp-block-paragraph">A hyperautomated PDLC requires changes in team behavior. Product owners should write requirements in a structured manner so that AI tools can generate better stories, acceptance criteria and test scenarios. Architects should maintain living decision records, reference patterns and integration standards that AI agents can use as context. Developers should learn prompt discipline, context packaging and review techniques. Test engineers should focus on coverage strategy, synthetic data, compliance scenarios and defect prevention rather than only manual execution. Operations teams should feed incident <a href="https://www.cio.com/article/1307309/the-generative-ai-revolution-is-transforming-how-banks-work.html">learnings</a> back into the backlog so the system improves continuously.</p>



<p class="wp-block-paragraph">The role of human experts becomes more important, not less. AI can draft, generate, compare and suggest, but domain judgment remains essential. A trade reporting specialist understands regulatory nuance. A wealth advisor understands client suitability. A core banking architect understands transaction integrity. A compliance officer understands control interpretation. Hyperautomation works best when it amplifies these experts and removes repetitive friction around them.</p>



<h2 class="wp-block-heading">Conclusion</h2>



<p class="wp-block-paragraph">Hyperautomation in business application development is not simply a faster way to write software. It is a new way to connect business intent, engineering execution, operational control and continuous learning. In banking, where applications must be reliable, explainable, secure and compliant, the combination of embedded Generative AI and disciplined automation can transform how applications are designed, built, integrated, tested, released and operated. Trade reporting, wealth management, core banking, investment banking, compliance, reconciliation, reporting and audit functions can all benefit when AI is embedded responsibly and automation is orchestrated across the complete lifecycle.</p>



<p class="wp-block-paragraph">Platforms such as GitHub Copilot, Claude Cowork or Claude Code and OpenAI Codex can play an important role in this transformation by accelerating analysis, development, testing, review, modernization and documentation. Their greatest value appears when enterprises treat them not as isolated productivity tools but as part of a governed, AI-native PDLC. The future of banking application development will belong to teams that can combine human expertise, reusable engineering patterns, intelligent automation and strong governance into one coherent delivery model.</p>



<p class="wp-block-paragraph"><em>This article was made possible by our partnership with the IASA </em><a href="https://chiefarchitectforum.org/" target="_blank" rel="noreferrer noopener"><em>Chief Architect Forum</em></a><em>. The CAF’s purpose is to test, challenge and support the art and science of Business Technology Architecture and its evolution over time as well as grow the influence and leadership of chief architects both inside and outside the profession. The CAF is a leadership community of the </em><a href="https://iasaglobal.org/" target="_blank" rel="noreferrer noopener"><em>IASA</em></a><em>, the leading non-profit professional association for business technology architects.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Samsung offers future AI memory roadmap]]></title>
<description><![CDATA[Samsung Electronics has unveiled a trio of next-generation memory technologies aimed at overcoming the performance, power and capacity limitations facing artificial intelligence infrastructure.



The announcements, made at the Future of Memory and Storage (FMS) conference, introduced new concept...]]></description>
<link>https://tsecurity.de/de/3710258/it-security-nachrichten/samsung-offers-future-ai-memory-roadmap/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710258/it-security-nachrichten/samsung-offers-future-ai-memory-roadmap/</guid>
<pubDate>Fri, 07 Aug 2026 23:47:17 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Samsung Electronics has unveiled a <a href="https://semiconductor.samsung.com/news-events/tech-blog/the-evolution-of-ai-era-memory-faster-denser-computing/">trio of next-generation memory</a> technologies aimed at overcoming the performance, power and capacity limitations facing artificial intelligence infrastructure.</p>



<p class="wp-block-paragraph">The announcements, made at the <a href="https://www.terrapinn.com/conference/future-memory-storage/index.stm">Future of Memory and Storage</a> (FMS) conference, introduced new concepts for vertically integrated memory along with a breakthrough NAND architecture designed for the AI era.</p>



<p class="wp-block-paragraph">The <a href="https://semiconductor.samsung.com/news-events/news/samsung-unveils-next-gen-3d-memory-vision-at-fms-2026-charting-the-future-of-ai-infrastructure/">three new memory types</a> have one thing that unites them: they all use wafer bonding. Wafer bonding is a semiconductor manufacturing process technique in which two or more completed silicon wafers are permanently joined together to form a single integrated device, the vendor stated.</p>



<p class="wp-block-paragraph">Instead of fabricating every component on one wafer, manufacturers build different parts separately, then align and bond them with extremely high precision. Think of it as a high-tech Oreo cookie.</p>



<p class="wp-block-paragraph">Wafer bonding is significant because it represents one of the few remaining ways to continue scaling semiconductor devices after conventional manufacturing techniques begin to hit physical and economic limits. It enables much higher memory density as more memory is squeezed into the same 2D space, according to the company.</p>



<p class="wp-block-paragraph">It also allows different manufacturing processes to be combined, so wafer bonding lets companies use the optimal manufacturing process for each wafer independently before joining them. Samsung said the new manufacturing technique fabricates the memory cell array and peripheral circuitry separately before bonding them together.</p>



<p class="wp-block-paragraph">It is already being used now in NAND flash memory for 3D stacking. Rather than spread the memory circuits out, they are stacked on top of each other like stories on a high-rise building. The technique was first introduced in 2014, with 24-layer NAND flash period last year it broke the 300-layer mark.</p>



<p class="wp-block-paragraph">The centerpiece of the announcement was BV-NAND, or Bonding V-NAND, Samsung’s next-generation flash memory architecture that employs wafer-bonding. The company said the technology enables NAND devices with more than 400 layers while boosting storage density by approximately 58% compared with its current V9 generation, Samsung stated.</p>



<p class="wp-block-paragraph">The company said the architecture also improves read, write and input/output performance while reducing power consumption, making it better suited for AI servers that increasingly depend on high-capacity flash storage.</p>



<p class="wp-block-paragraph">Beyond BV-NAND, Samsung outlined two longer-term memory concepts that could radically alter AI system architecture. The first, dubbed zHBM, calls for stacking HBM memory on top of the AI accelerator rather than alongside processors, as is done today.</p>



<p class="wp-block-paragraph">This shortens the distance data must travel between processor and memory. Samsung said the design could dramatically increase bandwidth while reducing power consumption and thermal resistance.</p>



<p class="wp-block-paragraph">The company estimates that combining the architecture with wafer-bonding technology could ultimately deliver more than ten times the memory density of conventional HBM5 while tripling energy efficiency and cutting thermal resistance by more than half.</p>



<p class="wp-block-paragraph">But don’t plan for deployment just yet. zHBM is still a research concept. It illustrates how memory manufacturers are increasingly looking too 3D designs to continue scaling as traditional 2D packaging becomes more difficult.</p>



<p class="wp-block-paragraph">Samsung also introduced zNAND-O, another conceptual architecture designed to extend three-dimensional memory beyond conventional NAND implementations. Details were scant but Samsung did say zNAND-O was a next-generation high-performance NAND solution built on its V-NAND technology and in development in four- and eight-layer versions.</p>



<p class="wp-block-paragraph">The technologies reflect how the industry is being driven by AI, and that AI concerns are driving chip development. HBM Has emerged as an important component of AI computation, but very quickly the industry hit limitations in terms of bandwidth and speed. The proposed technologies above reflect Samsung’s attempts to alleviate the bandwidth problem.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Polish data center plans to send its waste heat to the neighbors]]></title>
<description><![CDATA[As Europe swelters in a heatwave, residents probably don’t want to hear about ways to make their homes even hotter, but that’s what Polish property developer Citylink is talking about, with plans to dump waste heat from a new data center in Wrocław into the municipal district heating network.



...]]></description>
<link>https://tsecurity.de/de/3710259/it-security-nachrichten/polish-data-center-plans-to-send-its-waste-heat-to-the-neighbors/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710259/it-security-nachrichten/polish-data-center-plans-to-send-its-waste-heat-to-the-neighbors/</guid>
<pubDate>Fri, 07 Aug 2026 23:47:17 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">As Europe swelters in a heatwave, residents probably don’t want to hear about ways to make their homes even hotter, but that’s what Polish property developer Citylink is talking about, with plans to dump waste heat from a new data center in Wrocław into the municipal district heating network.</p>



<p class="wp-block-paragraph">Citylink is designing the data center so that heat from servers can be recovered instead of being dissipated via cooling systems — and as the data center grows, any increase in computing power will mean more energy available for recovery.</p>



<p class="wp-block-paragraph">The collaboration with local power company Kogeneracja will provide “valuable experience in designing and operating modern data centers, with a particular focus on infrastructure dedicated to AI nodes,<em>” </em><a href="https://city-link.pl/en/heat-from-servers-could-power-wroclaw-citylink-and-kogeneracja-s-a-launch-collaboration/" target="_blank" rel="noreferrer noopener">said Michał Starybrat, development director at Citylink</a>.</p>



<p class="wp-block-paragraph">“The dynamic growth of the artificial intelligence and cloud technology markets generates unprecedented demand for computing power, this collaboration demonstrates how modern digital infrastructure can actively contribute to building the energy ecosystem of the future,” he added.</p>



<p class="wp-block-paragraph">This type of initiative is not new. There have been <a href="https://www.newcivilengineer.com/latest/data-centres-could-join-energy-ecosystem-as-report-presents-use-case-for-wasted-heat-16-10-2025/" target="_blank" rel="noreferrer noopener">similar projects in the UK</a> and <a href="https://www.reseller.co.nz/article/2503421/spark-aims-to-use-dc-heat-to-warm-a-new-north-shore-surf-spot.html">in New Zealand,</a> but with warnings that <a href="https://www.networkworld.com/article/4153403/no-joke-data-centers-are-warming-the-planet.html">data centers are contributing to the warming of the planet</a>, there may well be a lot more organizations looking to deploy that excess heat more fruitfully in the future.</p>



<p class="wp-block-paragraph">However, announcing it during a heatwave may not be the most politically sensitive approach to take.</p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AMD to buy Taalas, maker of model-specific AI chips for enterprise inference]]></title>
<description><![CDATA[As enterprises look for ways to cut the cost of running AI models in production, AMD is betting that not every AI workload will be best served by a power-hungry general-purpose GPU.



AMD has agreed to buy Taalas, the Canadian designer of chips that permanently embed a trained AI model’s weights...]]></description>
<link>https://tsecurity.de/de/3710260/it-security-nachrichten/amd-to-buy-taalas-maker-of-model-specific-ai-chips-for-enterprise-inference/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710260/it-security-nachrichten/amd-to-buy-taalas-maker-of-model-specific-ai-chips-for-enterprise-inference/</guid>
<pubDate>Fri, 07 Aug 2026 23:47:17 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">As enterprises look for ways to cut the cost of running AI models in production, AMD is betting that not every AI workload will be best served by a power-hungry general-purpose GPU.</p>



<p class="wp-block-paragraph">AMD has agreed to buy Taalas, the Canadian designer of chips that permanently embed a trained AI model’s weights into custom silicon, instead of repeatedly loading them from memory during inference as conventional <a href="https://www.networkworld.com/article/3966130/what-are-gpus-inside-the-processing-power-behind-ai.html">GPUs</a> do.</p>



<p class="wp-block-paragraph">Taalas says its approach reduces the time and power required to move model weights between memory and compute units, making things run faster and cheaper.</p>



<p class="wp-block-paragraph">The result is a highly specialized inference processor optimized for one model, trading the flexibility of programmable hardware for substantially higher throughput and energy efficiency.</p>



<h2 class="wp-block-heading">Operational tradeoffs</h2>



<p class="wp-block-paragraph">While AMD is planning to integrate the chips into its <a href="https://www.amd.com/en/products/accelerators/instinct.html">Instinct GPU</a> roadmap, targeting system-level AI inference solutions in data centers, analysts remain skeptical that enterprises will readily embrace hardware tied to a specific AI model.</p>



<p class="wp-block-paragraph">Enterprises would, effectively, be buying a chip and a model together because unlike GPUs, which can be repurposed to run different AI models through software updates, Taalas’ chips are tied to a specific trained model, meaning they would need different hardware to support different inference tasks, said <a href="https://www.linkedin.com/in/znamit/" target="_blank" rel="noreferrer noopener">Amit Kumar Jena</a>, AI development manager at IT Consulting firm Kanerika.</p>



<p class="wp-block-paragraph">Or as Forrester Principal Analyst <a href="https://www.forrester.com/analyst-bio/charlie-dai/BIO5344" target="_blank" rel="noreferrer noopener">Charlie Dai</a> put it, “The biggest risk is inflexibility.”</p>



<p class="wp-block-paragraph">The requirement to swap hardware in order to swap tasks would, Dai said, introduce new challenges with costs, governance, capacity planning, lifecycle management, and supplier dependency, especially for enterprises managing multiple AI workloads.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/manoj-chandra-jha-b5ab0a13" target="_blank" rel="noreferrer noopener">Manoj Chandra Jha</a>, principal analyst at Nord-IQ Research, said the risk of fusing chip and model into one component is larger than one might think, as “early model obsolescence strands both together, so this should be modeled as one shorter-lived asset rather than two independently amortized ones.”</p>



<p class="wp-block-paragraph">Taalas says it can update a model by modifying only two metal layers of the chip rather than redesigning it from scratch, but that will only apply to chips that haven’t yet left its factory, not those already in use.</p>



<p class="wp-block-paragraph">That means enterprises will still need to plan for hardware refresh cycles measured in weeks or months and retain programmable GPUs for workloads that evolve frequently, said <a href="https://pareekh.com/about/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, principal analyst at Pareekh Consulting.</p>



<p class="wp-block-paragraph">It also means, said Jha, that what is typically a software decision becomes one about capital expenditure for Taalas customers, as replacing or switching workloads or models could require investing in new hardware rather than simply updating software.</p>



<h2 class="wp-block-heading">Where model-specific silicon fits</h2>



<p class="wp-block-paragraph">Those tradeoffs significantly narrow the range of enterprise workloads where model-specific silicon is likely to make economic sense.</p>



<p class="wp-block-paragraph">Dai sees the technology as best suited for mature, predictable inference workloads that run at massive scale and rely on relatively stable AI models, such as customer service automation, fraud detection, industrial computer vision, network operations, edge AI, and embedded copilots.</p>



<p class="wp-block-paragraph">For CIOs, that effectively limits model-specific silicon to a small subset of enterprise AI deployments, rather than a wholesale replacement for GPU infrastructure, he said. “GPUs will remain the preferred enterprise platform because most enterprises value flexibility, multi-tenancy, and rapid model evolution over maximum efficiency.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[DeepMind founder ascends to singular AI role at Google]]></title>
<description><![CDATA[Demis Hassabis, the driving force behind Google DeepMind, is ascending to the role of chief scientist at Alphabet, Google’s parent company, replacing Jeff Dean who is leaving to work at a start-up.



The role will enable Hassabis to “put his full attention on actively shaping the future of AGI,”...]]></description>
<link>https://tsecurity.de/de/3710153/it-nachrichten/deepmind-founder-ascends-to-singular-ai-role-at-google/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710153/it-nachrichten/deepmind-founder-ascends-to-singular-ai-role-at-google/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:40 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Demis Hassabis, the driving force behind Google DeepMind, is ascending to the role of chief scientist at Alphabet, Google’s parent company, replacing Jeff Dean who is leaving to work at a start-up.</p>



<p class="wp-block-paragraph">The role will enable Hassabis to “put his full attention on actively shaping the future of AGI,” or artificial general intelligence, Alphabet CEO Sundar Pichai wrote on the company’s <a href="https://blog.google/company-news/inside-google/message-ceo/next-chapter-ai-momentum/" target="_blank" rel="noreferrer noopener">Inside Google blog</a>.</p>



<p class="wp-block-paragraph">Hassabis’ attention will still be divided, however: He will continue to lead research at Google spin-off Isomorphic Labs, which works on drug discovery, and although he will no longer be CEO of DeepMind, he will be its chair. Koray Kavukcuoglu will take over DeepMind, reporting directly to Pichai. He is currently its CTO.</p>



<p class="wp-block-paragraph">Hassabis has been a strong promoter of AGI, defined by Google as the “hypothetical intelligence of a machine that possesses the ability to understand or learn any intellectual task that a human being can.”</p>



<p class="wp-block-paragraph">He has a long career in AI, having helped found DeepMind in 2010. He has been a prominent figure in the AGI field, prophesying in May that it will be <a href="https://www.computerworld.com/article/4178398/deepmind-ceo-agi-could-be-here-in-three-years.html">a viable technology within three years</a>. He has been keen to tackle any barriers in the way of developing the technology; just last month, <a href="https://www.cio.com/article/4197497/deepmind-ceo-pushes-for-ai-industry-self-regulation.html">he called for greater self-regulation</a> in the market, arguing that it would help drive the technology forward.</p>



<p class="wp-block-paragraph">Hassabis welcomed the chance to focus on AGI development. “We have arrived at a pivotal moment in human history. I’ve been working towards AGI my whole life, and now, I feel it is close at hand. It’s critical that we collectively get the next steps right to ensure this all goes well for humanity and we usher in an incredible new age of discovery and wonder” he wrote in the Inside Google blog post.</p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[From ambition to action: What Canadian tech leaders must get right to see meaningful value from transformation efforts]]></title>
<description><![CDATA[It’s no secret that the CIO role is changing in Canadian enterprises. Driving operational performance and increasing efficiency are, of course, still a big part of the job. But CIOs are now expected to do more than cut costs and keep the lights on. Increasingly, boards of directors expect the CIO...]]></description>
<link>https://tsecurity.de/de/3710141/it-nachrichten/from-ambition-to-action-what-canadian-tech-leaders-must-get-right-to-see-meaningful-value-from-transformation-efforts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710141/it-nachrichten/from-ambition-to-action-what-canadian-tech-leaders-must-get-right-to-see-meaningful-value-from-transformation-efforts/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:39 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">It’s no secret that the CIO role is changing in Canadian enterprises. Driving operational performance and increasing efficiency are, of course, still a big part of the job. But CIOs are now expected to do more than cut costs and keep the lights on. Increasingly, boards of directors expect the CIO to play a key role in creating value and enabling their organizations to outperform their rivals. Recent data backs this up. The overwhelming majority (91%) of Canadian technology leaders believe advanced technology will be the primary driver of competitive advantage over the next three years, according to KPMG’s “<a href="https://kpmg.com/ca/en/insights/2026/02/execution-imperatives-for-canadian-tech-leaders.html" target="_blank" rel="noreferrer noopener">The 8 execution imperatives for Canadian tech leaders</a>,” a white paper based on the firm’s <a href="https://kpmg.com/xx/en/our-insights/ai-and-technology/global-tech-report.html" target="_blank" rel="noreferrer noopener">2026 Global Tech Report</a>.</p>



<p class="wp-block-paragraph">The race to capture value from emerging technologies has intensified, leaving little room for organizations that remain on the sidelines. Yet in Canada, just 27% of organizations consider themselves innovators or early adopters, while 72% are fast or slow followers. Nearly all (85%) believe they’ll need to take more risks with emerging technologies just to remain relevant.</p>



<p class="wp-block-paragraph">The traditional, operational-first mindset among CIOs has become a liability. CIOs are expected to be strategic players, but meeting that expectation requires taking thoughtful, well-considered action across key imperatives.</p>



<h3 class="wp-block-heading"><strong>AI success depends on data</strong></h3>



<p class="wp-block-paragraph"><strong>AI is not the only advanced technology that organizations are working to deploy, but it’s certainly garnering the most attention from C-suite executives, boards of directors, and investors. </strong>To enable AI at scale, the data foundations enterprises have built over the past decade will be necessary, but they are not sufficient on their own. CIOs must make modernizing the state of enterprise data a top priority.</p>



<p class="wp-block-paragraph">In most large organizations, data often remains locked inside legacy systems where the system of record is also the system of engagement, and that significantly limits accessibility for AI workloads. Data should be treated as the strategic asset that it has become. The quality, timeliness, and governance of that data vary widely, and reconciling those inconsistencies is one of the most persistent barriers to enterprise-level deployment.</p>



<p class="wp-block-paragraph">Scaling pilots into enterprise programs also requires closing the gap between AI-native talent, who have the skills to move quickly, and those with deep institutional knowledge, who understand how their organizations work and what they need to achieve. These two groups must work hand in hand. Otherwise, organizations may accelerate toward the wrong goals, which won’t move the business forward.</p>



<p class="wp-block-paragraph">“The barriers to scaling AI aren’t just technical,” says Sanjay Pathak, partner and national leader, technology strategy and digital transformation services, KPMG Canada. “CIOs need to truly and deeply understand the value chain of what their organizations do. Those who get there will have the imagination, the courage, and the foresight to use AI to transform their organizations.”</p>



<h3 class="wp-block-heading"><strong>Communicating ROI requires the right framing</strong></h3>



<p class="wp-block-paragraph">Beyond scaling, simply communicating the value of AI also poses a significant challenge. Just over half (53%) of Canadian organizations surveyed say they struggle to demonstrate or communicate AI value to stakeholders. Part of the problem is that CIOs are making the wrong argument in the wrong room because they’re framing ROI as a technology metric rather than a business outcome.</p>



<p class="wp-block-paragraph">“Any CIO who doesn’t truly understand what their business does is missing a beat around how innovation is going to help the organization achieve ROI,” says Pathak. “Understanding how to deploy AI inside your value chain will give you a head start and a competitive advantage in unlocking real business benefits.”</p>



<p class="wp-block-paragraph">A formal performance measurement framework that tracks customer experience, revenue growth, and employee adoption alongside cost metrics gives CIOs a far more accurate picture of long-term value. Linking funding decisions to those strategic outcomes makes sustained investment easier to justify.</p>



<p class="wp-block-paragraph">There is also a compliance dimension that often goes unacknowledged in these conversations. CIOs who bring business, technology, and compliance leaders together to design innovative processes that are “compliant by design” from the start are protecting future value as much as they are delivering value today.</p>



<p class="wp-block-paragraph">“You need to assemble that multi-dimensional cohort of business, technology, risk, and compliance leaders at the same table, envisioning compliance by design,” says Pathak. “The winners in this space are going to be the ones who really think about business ambition holistically and focus on efficient delivery, operations, and compliance.”</p>



<h3 class="wp-block-heading"><strong>Building disciplined innovation governance</strong></h3>



<p class="wp-block-paragraph">An organization’s approach to governance makes an enormous difference in how quickly and confidently it can deploy and take advantage of advanced technologies. As noted above, almost three-quarters (72%) identify as fast or slow followers, and 85% say they need to move more aggressively to embrace new technologies. Canadian organizations aren’t lacking ambition. What they lack are the conditions required to innovate with confidence: clear ownership, defined risk thresholds, and shared accountability between technology, risk, and business teams.</p>



<p class="wp-block-paragraph">“You can be an innovator, but if your innovation is not directly connected to strategic business ambition and safety guardrails such as risk management, governance, and compliance, you’re creating labware,” says Pathak. “Being an early adopter means you’re comfortable with the technology. To make it truly viable, you must embrace all dimensions of enterprise value.”</p>



<p class="wp-block-paragraph">Strong governance does not slow innovation down but instead provides a structure that builds confidence and resilience at every level of the organization, from the board to project teams. A tiered governance approach that takes risk into account allows organizations to advance low-risk, incremental improvements and high-reward initiatives in parallel.</p>



<h3 class="wp-block-heading"><strong>Expanding partnerships to accelerate innovation</strong></h3>



<p class="wp-block-paragraph">Innovation isn’t a single-player game, and Canadian organizations know it. Ninety-seven percent of respondents say they plan to expand their external ecosystems. To date, a significant portion of those relationships have been transactional and focused on a specific capability or problem. But savvier organizations are moving toward multi-party innovation, where partners pool capabilities to share both risk and reward. This model requires a different kind of commitment because organizations are betting on a partner’s long-term viability, not just their current capability. Together, they must build the integration and governance infrastructure that makes these ecosystems work for all participants.</p>



<p class="wp-block-paragraph">“Moving to multi-party innovation ecosystems is an investment in integration and data,” says Pathak. “If you’re going to look at best of breed and stitch those together, what must be true for that to work is the ability for those different ecosystems to integrate and interoperate. And that creates a much stronger need for safety and governance.”</p>



<p class="wp-block-paragraph">Cybersecurity is another dimension that grows more important with every new partner added to the ecosystem. Security should be proactively built in, not imposed after a breach has already occurred.</p>



<p class="wp-block-paragraph">“The more ecosystem-based partnerships you have, the more opportunity you create along with the threat you have to deal with,” says Pathak. “You expand the attack surface, and you become more of a target, so governance and cybersecurity must be designed in from the start, not bolted on later.”</p>



<p class="wp-block-paragraph">Canadian government incentives, including Scientific Research and Experimental Development (SR&amp;ED) tax credits and AI-focused clusters, offer a way to share some of the cost and risk, particularly during periods of economic uncertainty.</p>



<p class="wp-block-paragraph">By leveraging these funding frameworks alongside robust ecosystem governance, forward-thinking organizations can safely scale their networks to turn shared risks into sustainable competitive advantages.</p>



<h3 class="wp-block-heading">In closing</h3>



<p class="wp-block-paragraph">For organizations navigating this environment, KPMG Canada emphasizes that the most consequential decisions ahead are not purely, or even mostly, technical. They are about how CIOs choose to lead, partner, measure, and govern in a period that rewards both ambition and discipline in equal measure.</p>



<p class="wp-block-paragraph">The data points are clear. CIOs who lead with both strategic ambition and disciplined execution will elevate their organizations above their competitors. By paying attention to the quality of their data, aligning technical priorities with critical business goals, and instituting strong governance and cybersecurity, they will set a higher standard for what Canadian competitiveness looks like in the years ahead.</p>



<p class="wp-block-paragraph">To learn more, read the full whitepaper: <a href="https://kpmg.com/ca/en/insights/2026/02/execution-imperatives-for-canadian-tech-leaders.html" target="_blank" rel="noreferrer noopener">The Top 8 Execution Imperatives for Canadian Tech Leaders</a>.</p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Agentic AI workforce is more than doubling year on year, says Salesforce]]></title>
<description><![CDATA[Salesforce customers more than doubled their agentic workforces year on year, according to the company’s second annual Agentic Enterprise Index, which looks at trends in AI agent development and deployment over the past five quarters.



It compiled data from customers who had activated agents in...]]></description>
<link>https://tsecurity.de/de/3710142/it-nachrichten/agentic-ai-workforce-is-more-than-doubling-year-on-year-says-salesforce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710142/it-nachrichten/agentic-ai-workforce-is-more-than-doubling-year-on-year-says-salesforce/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:39 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Salesforce customers more than doubled their agentic workforces year on year, according to the company’s second annual <a href="https://www.salesforce.com/agentforce/agentic-enterprise-index/" target="_blank" rel="noreferrer noopener">Agentic Enterprise Index</a>, which looks at trends in AI agent development and deployment over the past five quarters.</p>



<p class="wp-block-paragraph">It compiled data from customers who had activated agents in production every month of the analysis period to determine how their use of the technology has evolved between February 2025 and April 2026, as well as incorporating data from May 2026 Salesforce research studies.</p>



<p class="wp-block-paragraph">It found that businesses grew their agentic workforces from an average of five agents in February 2025 to 13 by April 2026, a 7% compound monthly growth rate (CMGR). In April 2026, it only took an average of 1.9 days to deploy an agent into production, a 53% decrease since the beginning of the report period.</p>



<p class="wp-block-paragraph">Not only were agents deployed more quickly, they have been progressively taking on more work once in use; over the 15 months, the average number of actions per account had a CMGR of 31%.</p>



<p class="wp-block-paragraph">“These agents are expanding beyond their initial scope to really become cross-functional,” said <a href="https://www.linkedin.com/in/caila-schwartz/" target="_blank" rel="noreferrer noopener">Caila Schwartz</a>, Salesforce’s head of agentic commerce insights, during a media briefing.</p>



<p class="wp-block-paragraph">Salesforce has attempted to measure how much work agents perform, rather than how many tokens they consume, creating its own <a href="https://www.cio.com/article/4138622/awu-by-salesforce-a-shiny-new-metric-that-tells-cios-little-of-value.html">Agentic Work Unit (AWU) metric</a>, although analysts have criticized the measure as being unrelated to business outcomes. Nevertheless, Salesforce said that as of April, Agentforce agents had performed 734 million AWUs, a number growing at about 15% each month.</p>



<p class="wp-block-paragraph">The research also showed that agents are acting across multiple cloud domains which, the company said, “underscores the practical necessity of a headless architecture. By decoupling the agent’s logic from traditional front-end user interfaces, agents can process tasks, execute actions, and trigger workflows anywhere.”</p>



<p class="wp-block-paragraph">Within the company, Salesforce itself has seen explosive growth in AI agent use, said <a href="https://www.linkedin.com/in/joseph-inzerillo-b917791/" target="_blank" rel="noreferrer noopener">Joe Inzerillo</a>, president of enterprise &amp; AI technology at Salesforce, with a threefold increase in sessions between February 2025 and April 2026. He said that the AI agent in Slack, Slackbot, saves the average employee five hours per week, with 83% of the company having adopted it.</p>



<p class="wp-block-paragraph">But Schwartz pointed out that different industries are approaching agentic AI in different ways, some more sophisticated than others. To measure that, Salesforce developed a Sophistication Index, a five-point scale scoring the cognitive complexity of an agent’s actions. Levels 1- 3  are assigned to tasks such as record lookups, drafting emails, or summarizing documents, while levels 4 and 5 include more complex functions such as updating database fields.</p>



<p class="wp-block-paragraph">The data showed that manufacturing, financial services, and healthcare and life sciences have built more sophisticated agent networks than what it called traditional AI frontrunners such as technology and retail.</p>



<p class="wp-block-paragraph">However, Inzerillo said, the most common use case industry wide, and the best place to start, is the service use case, which provides “far and away the best ROI to start with.”</p>



<p class="wp-block-paragraph">He also noted that, as people have become more conscious of what agents can do, they are asking agents to perform tasks, rather than simply answer questions.</p>



<p class="wp-block-paragraph">“Now what you’re starting to see people do is very action oriented. So instead of asking ’how do I file a form to request my vacation’ from our employee agent, they’re telling the employee agent, ‘hey I’m taking a vacation, you need to enter this form for me, and here’s the details,’” he said, adding that this bias towards action represents the evolution of agentic use.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[There are two completely different roles called ‘FDE’]]></title>
<description><![CDATA[There’s something very attractive about saying “we embed very closely with our customers and just figure it out with them”, especially since the company that started “forward deploying engineers” is growing 84% with $5B+ revenue. But “forward deployed engineer” is a vague term and means different...]]></description>
<link>https://tsecurity.de/de/3710144/it-nachrichten/there-are-two-completely-different-roles-called-fde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710144/it-nachrichten/there-are-two-completely-different-roles-called-fde/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:39 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">There’s something very attractive about saying “we embed very closely with our customers and just figure it out with them”, especially since the company that started “forward deploying engineers” is growing <a href="https://investors.palantir.com/files/2026%20Q1%20PLTR%2010-Q.pdf">84% with $5B+ revenue</a>. But “<a href="https://en.wikipedia.org/wiki/Forward_Deployed_Engineer#cite_note-1">forward deployed engineer</a>” is a vague term and means different things depending on the business you’re running.</p>



<p class="wp-block-paragraph">I spent almost 5 years at Palantir as a forward-deployed software engineer, and Palantir’s version of an “FDE” does not make sense for most companies I now meet as an early-stage VC. Depending on the type of business you’re building, this role could broadly mean one of two things: “the product builder” or “the platform operator.” Clearly defining which bucket you fall into will make it easier to hire for this role and run your FDE org.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/nature-of-work-vs-product-leverage.png?w=1024" alt="Figure: Nature of work vs. product leverage." class="wp-image-4206317" width="1024" height="578" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Kabir Sial</p></div>



<h2 class="wp-block-heading">The product builder: The OG Palantir version</h2>



<p class="wp-block-paragraph">The north star is: do whatever it takes to actually solve the user’s problem. FDEs are not just responsible for making the platform work, but also discovering what to build and building it (actually creating software) in service of the customer.</p>



<h2 class="wp-block-heading">The platform operator: Solutions + technical customer success</h2>



<p class="wp-block-paragraph">The north star is: make the product work for the customer – deploy and operationalize it. This is what most startups today really mean when they want FDEs. FDEs here configure the core platform, manage account relationships and drive adoption. This is not new – companies have always had solutions engineers, sales engineers, customer success etc., although the work looks different as FDEs are increasingly building prototypes, configuring evals and building MCPs.</p>



<h2 class="wp-block-heading">Which FDE is right for you</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/customer-size.png?w=1024" alt="Figure: Customer size." class="wp-image-4206316" width="1024" height="457" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Kabir Sial</p></div>



<p class="wp-block-paragraph">For most situations, hiring product builder FDEs is a mistake.</p>



<p class="wp-block-paragraph">At scale, the FDEs should be the platform operator. It’s hard to have FDEs build and maintain highly custom product features, especially as the company scales. Over time, the custom product surface area distracts from building the core product, even though AI coding tools make it easy to ship new features quickly and maintain them.</p>



<p class="wp-block-paragraph">Many fast-growing AI startups recognize these constraints and structure the FDE role more like the platform operator. This also allows them to have 5-10 accounts per FDE, which is a much higher ratio than Palantir had (at least in 2023). Even the Palantir FDE role has evolved to look more like the platform operator.</p>



<p class="wp-block-paragraph">There are, however, situations when your FDEs should be the product builder archetype.</p>



<h3 class="wp-block-heading">1. You have very large customers (F500 scale)</h3>



<p class="wp-block-paragraph"><strong>Technical complexity</strong>: Large customers have complex environments with legacy infrastructure that often requires “out-of-platform” engineering work. I often encountered bespoke data infrastructure, privacy requirements, etc. at various Palantir customers that required me to build “out-of-platform” connectors, UIs and backends.</p>



<p class="wp-block-paragraph"><strong>Organizational inertia and trust</strong>: Serving large enterprises is about building trust. In short time periods, overfitting product to a specific user/workflow is often what delivers the most value, builds trust and helps organizations get over the inertia of moving away from Excel and legacy software tools that are part of their day-to-day workflow. For AI-native startups, it’s arguably even more important to invest in doing “unscalable” development with engineering boots on the ground, as it helps solidify your right to exist and eventually expand the customer relationship.</p>



<h3 class="wp-block-heading">2. You have many ICPs and workflows</h3>



<p class="wp-block-paragraph">If you have a broad range of ICPs and workflows that you serve, your product probably is not walk-up usable on day 1 of deployment. The short-term hacky things that product builder FDEs build to make the product work for these heterogeneous users/workflows will help you shape the product long-term.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/overfit-products.png?w=1024" alt='Figure: "Overfit" products.' class="wp-image-4206313" width="1024" height="570" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Kabir Sial</p></div>



<p class="wp-block-paragraph">Note: see Palantir Foundry’s architecture <a href="https://www.palantir.com/assets/xrfr7uokpv1b/mhoyY4c8vdVlJhulDStk2/a7340768109c8e8d79d00b4cb99d8e70/Whitepaper_-_Foundry_2022.pdf">here</a>.</p>



<p class="wp-block-paragraph">This was a big reason why Palantir FDEs were more like product builders (and are still able to – see the <a href="https://jobs.lever.co/palantir/dab396d4-2f14-4796-aac0-0d82883dccf0">Forward Deployed Software Engineer job profiles</a> as an example). The vision for Foundry was to be the operating system for an enterprise’s critical decisions – inherently multiple industries, users and workflows. A lot of FDE-led development showed that solving many of these use cases required complex data integrations, which led to the early versions of Foundry being best-suited for complex data integrations and building a customer’s “<a href="https://blog.palantir.com/ontology-finding-meaning-in-data-palantir-rfx-blog-series-1-399bd1a5971b">Ontology</a>”. Similarly, FDEs like myself built custom frontend applications for fraud analysis, pricing, etc. As certain patterns of what these applications required became more clear, they were centralized into an application-layer product.</p>



<h2 class="wp-block-heading">Who you should hire</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/who-you-should-hire.png?w=1024" alt="Figure: Who you hire." class="wp-image-4206314" width="1024" height="464" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Kabir Sial</p></div>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/why-hire.png?w=1024" alt="Figure: Why hire one vs. the other." class="wp-image-4206315" width="1024" height="456" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Kabir Sial</p></div>



<p class="wp-block-paragraph"><strong>Platform operator</strong>: There is a much broader set of people you could hire, testing for technical fluency (e.g., being good at data analysis, complex Excel work, even SQL), product intuition and an inclination to build customer relationships. Backgrounds like technical customer success, solutions engineering, software engineering, product management and consulting are all strong fits.</p>



<p class="wp-block-paragraph"><strong>Product builder</strong>: You want candidates that are high ownership and missionary software engineers, or technical PMs who want to ship products themselves.</p>



<p class="wp-block-paragraph">Hiring for these profiles, especially product builders, is hard. It’s worth calling out two things that helped Palantir hire software engineers into what might be considered a less sexy role.</p>



<ol start="1" class="wp-block-list">
<li><strong>Culture of building at the edge</strong>: Strong engineers are motivated to build things. Palantir gave FDEs a lot of ownership to build products, which is why much of the core product leadership was former FDEs.</li>



<li><strong>Cult built around mission</strong>: Internally, there was a cult-like devotion to the mission. Everyone always talked about why outcomes were far more important than software, and why most companies building tools had it wrong. I’ve never been at a company where people feel so closely bonded around a mission.</li>
</ol>



<p class="wp-block-paragraph">As founders building AI startups think about hiring FDEs, it’s worth being specific about your culture and asking: Am I just hiring people to support development teams, or am I hiring people to shape and build product? It’s hard to get software engineers (even today) to be excited about an FDE role that might just be technical customer success.</p>



<h2 class="wp-block-heading">What FDEs should be doing (regardless of archetype)</h2>



<p class="wp-block-paragraph">You’ve hired the right people. How do you best leverage your team of FDEs?</p>



<p class="wp-block-paragraph">FDEs were Palantir’s way of delivering outcomes rather than tools. AI-native startups can take this much further and FDEs can help in a few unique ways by leveraging their proximity to customers.</p>



<ol start="1" class="wp-block-list">
<li><strong>Find the most critical workflows</strong>: As AI lowers the cost of producing software, companies will face a lot more competition. FDEs at AI startups should be constantly finding ways to serve the most critical workflows for a customer and paying attention to how customers do work across newer and legacy tools. For example, FDEs at Harvey should pay attention to which workflows are in Westlaw, which ones are moving to ChatGPT/Claude, and how the Harvey product can stay ahead.</li>



<li><strong>Build around nondeterminism</strong>: In more regulated environments, FDEs should be hyper-focused on making products reliable for specific use cases <a href="https://www.anthropic.com/engineering/demystifying-evals-for-ai-agents">using evals</a> and configs. Previously, product reliability lived with product and support. As companies provide outcomes instead of tools, configuring products appropriately and managing evals shifts towards FDE teams.</li>
</ol>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AMD wants to make enterprise inference cheaper and faster with chips from Taalas]]></title>
<description><![CDATA[As enterprises look for ways to cut the cost of running AI models in production, AMD is betting that not every AI workload will be best served by a power-hungry general-purpose GPU.



AMD has agreed to buy Taalas, the Canadian designer of chips that permanently embed a trained AI model’s weights...]]></description>
<link>https://tsecurity.de/de/3710145/it-nachrichten/amd-wants-to-make-enterprise-inference-cheaper-and-faster-with-chips-from-taalas/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710145/it-nachrichten/amd-wants-to-make-enterprise-inference-cheaper-and-faster-with-chips-from-taalas/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:39 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">As enterprises look for ways to cut the cost of running AI models in production, AMD is betting that not every AI workload will be best served by a power-hungry general-purpose GPU.</p>



<p class="wp-block-paragraph">AMD has agreed to buy Taalas, the Canadian designer of chips that permanently embed a trained AI model’s weights into custom silicon, instead of repeatedly loading them from memory during inference as conventional <a href="https://www.networkworld.com/article/3966130/what-are-gpus-inside-the-processing-power-behind-ai.html">GPUs</a> do.</p>



<p class="wp-block-paragraph">Taalas says its approach reduces the time and power required to move model weights between memory and compute units, making things run faster and cheaper.</p>



<p class="wp-block-paragraph">The result is a highly specialized inference processor optimized for one model, trading the flexibility of programmable hardware for substantially higher throughput and energy efficiency.</p>



<h2 class="wp-block-heading">Operational tradeoffs</h2>



<p class="wp-block-paragraph">While AMD is planning to integrate the chips into its <a href="https://www.amd.com/en/products/accelerators/instinct.html">Instinct GPU</a> roadmap, targeting system-level AI inference solutions in data centers, analysts remain skeptical that enterprises will readily embrace hardware tied to a specific AI model.</p>



<p class="wp-block-paragraph">Enterprises would, effectively, be buying a chip and a model together because unlike GPUs, which can be repurposed to run different AI models through software updates, Taalas’ chips are tied to a specific trained model, meaning they would need different hardware to support different inference tasks, said <a href="https://www.linkedin.com/in/znamit/" target="_blank" rel="noreferrer noopener">Amit Kumar Jena</a>, AI development manager at IT Consulting firm Kanerika.</p>



<p class="wp-block-paragraph">Or as Forrester Principal Analyst <a href="https://www.forrester.com/analyst-bio/charlie-dai/BIO5344" target="_blank" rel="noreferrer noopener">Charlie Dai</a> put it, “The biggest risk is inflexibility.”</p>



<p class="wp-block-paragraph">The requirement to swap hardware in order to swap tasks would, Dai said, introduce new challenges with costs, governance, capacity planning, lifecycle management, and supplier dependency, especially for enterprises managing multiple AI workloads.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/manoj-chandra-jha-b5ab0a13" target="_blank" rel="noreferrer noopener">Manoj Chandra Jha</a>, principal analyst at Nord-IQ Research, said the risk of fusing chip and model into one component is larger than one might think, as “early model obsolescence strands both together, so this should be modeled as one shorter-lived asset rather than two independently amortized ones.”</p>



<p class="wp-block-paragraph">Taalas says it can update a model by modifying only two metal layers of the chip rather than redesigning it from scratch, but that will only apply to chips that haven’t yet left its factory, not those already in use.</p>



<p class="wp-block-paragraph">That means enterprises will still need to plan for hardware refresh cycles measured in weeks or months and retain programmable GPUs for workloads that evolve frequently, said <a href="https://pareekh.com/about/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, principal analyst at Pareekh Consulting.</p>



<p class="wp-block-paragraph">It also means, said Jha, that what is typically a software decision becomes one about capital expenditure for Taalas customers, as replacing or switching workloads or models could require investing in new hardware rather than simply updating software.</p>



<h2 class="wp-block-heading">Where model-specific silicon fits</h2>



<p class="wp-block-paragraph">Those tradeoffs significantly narrow the range of enterprise workloads where model-specific silicon is likely to make economic sense.</p>



<p class="wp-block-paragraph">Dai sees the technology as best suited for mature, predictable inference workloads that run at massive scale and rely on relatively stable AI models, such as customer service automation, fraud detection, industrial computer vision, network operations, edge AI, and embedded copilots.</p>



<p class="wp-block-paragraph">For CIOs, that effectively limits model-specific silicon to a small subset of enterprise AI deployments, rather than a wholesale replacement for GPU infrastructure, he said. “GPUs will remain the preferred enterprise platform because most enterprises value flexibility, multi-tenancy, and rapid model evolution over maximum efficiency.”</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.networkworld.com/article/4206674/amd-to-buy-taalas-maker-of-model-specific-ai-chips-for-enterprise-inference.html">Network World</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Beyond chatbots: How embedded GenAI is transforming banking application development]]></title>
<description><![CDATA[Business application development is entering a new operating model. The traditional approach of gathering requirements, designing screens, writing services, integrating systems, testing, fixing defects and preparing release documentation still exists, but it is no longer sufficient for enterprise...]]></description>
<link>https://tsecurity.de/de/3710146/it-nachrichten/beyond-chatbots-how-embedded-genai-is-transforming-banking-application-development/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710146/it-nachrichten/beyond-chatbots-how-embedded-genai-is-transforming-banking-application-development/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:39 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Business application development is entering a new operating model. The traditional approach of gathering requirements, designing screens, writing services, integrating systems, testing, fixing defects and preparing release documentation still exists, but it is no longer sufficient for enterprises that need speed, traceability, resilience and regulatory confidence at the same time. Hyperautomation brings a broader discipline to this challenge. It combines workflow orchestration, intelligent document processing, robotic automation, API-led integration, process mining, test automation, observability and artificial intelligence into a connected delivery fabric. With embedded Generative AI, this fabric becomes more adaptive because applications can interpret natural language, summarize complex data, generate explanations, detect exceptions and support decision workflows rather than merely execute predefined rules.</p>



<p class="wp-block-paragraph">In banking, this shift is especially meaningful. Banks operate across dense application landscapes: trade reporting platforms, wealth management portals, core banking systems, investment banking applications, digital compliance engines, reconciliation utilities, operational dashboards, audit repositories and daily, weekly and monthly reporting platforms. Each of these areas has its own data models, control points, integration patterns, validation rules, exception paths and regulatory obligations. Hyperautomation does not replace engineering discipline; it strengthens it by making business intent, technical execution, control evidence and continuous improvement part of the same lifecycle.</p>



<h2 class="wp-block-heading">From automation to hyperautomation in banking applications</h2>



<p class="wp-block-paragraph">Automation usually addresses a specific task: moving data from one system to another, generating a report, running a batch job or validating a transaction against a rule. Hyperautomation goes further. It looks at the complete business outcome and asks how the entire chain can be streamlined, governed, observed and improved. For example, a trade reporting process may begin with transaction capture, enrich the trade with reference data, validate regulatory fields, identify breaks, generate a submission file, transmit it to a regulator or trade repository, monitor acknowledgements and preserve audit evidence. A narrow automation script may accelerate one step, but a <a href="https://www.gartner.com/en/documents/6454507">hyperautomated design</a> coordinates the complete flow, including exception handling and evidence generation.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/figure-Figure-automation-vs-hyperautomation.png?w=1024" alt="Figure: Automation vs. hyperautomation." class="wp-image-4206308" width="1024" height="775" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Magesh Kasthuri</p></div>



<p class="wp-block-paragraph"><strong>Figure: Automation vs. hyperautomation</strong></p>



<p class="wp-block-paragraph">Embedded Generative AI adds a <a href="https://assets.ctfassets.net/5965pury2lcm/65QHMnfLGaRJzJ0sX5982o/520b5f0a9745aecc8730c645994e3a3b/Forrester_Study_-_AI_And_The_Next_Generation_of_Software_Testing.pdf">new layer of intelligence</a>. Instead of forcing every user interaction into rigid screens and codes, business applications can accept natural language prompts, interpret document content, summarize cases, generate draft responses, explain anomalies, produce test scenarios and create release notes. In a banking environment, this intelligence must be carefully bounded. Every AI-assisted action should be traceable, explainable, reviewable and aligned with data privacy, model risk, information security and regulatory expectations. The goal is not uncontrolled autonomy; the goal is governed acceleration.</p>



<h2 class="wp-block-heading">Banking application components suitable for hyperautomation</h2>



<p class="wp-block-paragraph">A modern banking application is rarely a single monolithic system. It is a composition of business capabilities, integration services, workflow engines, data pipelines, user experience layers, analytics models, control dashboards and audit stores. Hyperautomation can accelerate the development and integration of these components by turning repetitive engineering work into <a href="https://www.everestgrp.com/report/egr-2024-31-v-6318/">reusable patterns</a> and by embedding intelligence directly into business processes.</p>



<ul class="wp-block-list">
<li><strong>Trade reporting applications:</strong> Generative AI can help map trade attributes to regulatory fields, explain validation failures, summarize rejected submissions and generate test cases for reporting scenarios. Hyperautomation can orchestrate enrichment, validation, submission, acknowledgement tracking and evidence archival.</li>



<li><strong>Wealth management platforms:</strong> Advisors can use embedded AI to summarize client portfolios, generate suitability narratives, identify missing documents and prepare personalized investment review notes. Automation can coordinate onboarding, risk profiling, document verification, portfolio rebalancing workflows and client communication approvals.</li>



<li><strong>Core banking applications:</strong> Account opening, loan servicing, deposits, payments, interest calculations and customer maintenance can benefit from automated validations, intelligent forms, workflow routing and natural language assistance for operations teams. AI can explain account events or transaction exceptions in plain language.</li>



<li><strong>Investment banking systems:</strong> Deal pipelines, research workflows, underwriting processes, trade lifecycle functions and risk calculations require strong coordination across front-office, middle-office and back-office platforms. Hyperautomation can standardize approvals, documentation, exception resolution and control evidence across these stages.</li>



<li><strong>Digital compliance applications:</strong> Compliance teams can use AI to summarize policy obligations, compare regulatory changes with internal controls, classify alerts, draft investigation notes and produce evidence packs. Automation ensures routing, approvals, segregation of duties, audit trails and regulatory reporting timelines are consistently enforced.</li>



<li><strong>Reconciliation platforms:</strong> AI can assist in matching narratives, explaining breaks, clustering exception patterns and suggesting resolution actions. Hyperautomation can pull data from ledgers, statements, payment processors, trading systems and data warehouses, then route unresolved breaks to the right teams.</li>



<li><strong>Reporting and audit applications:</strong> Daily, weekly and monthly reports can be generated through controlled data pipelines, automated quality checks, narrative generation, variance explanations and approval workflows. Audit applications can preserve lineage, approvals, source extracts, model outputs and control attestations.</li>
</ul>



<h2 class="wp-block-heading">Embedded generative AI as an application capability</h2>



<p class="wp-block-paragraph">Embedding Generative AI into business applications should be treated as an architectural capability, not as a decorative chatbot. A banking application may use AI for search, summarization, reasoning support, content generation, code generation, policy interpretation or anomaly explanation. Each use case requires clear boundaries. The application must know which data the model can access, which actions require approval, what evidence must be captured and where deterministic controls must override probabilistic <a href="https://www.idc.com/resource-center/generative-ai/">suggestions</a>.</p>



<p class="wp-block-paragraph">For example, in trade reporting, an embedded AI assistant can explain why a transaction failed validation and suggest likely fields to review. However, the final correction should pass through rule-based validations, maker-checker approval and audit logging. In wealth management, AI may draft a client review note based on portfolio movements and risk profile, but the advisor must verify suitability, disclosures and final communication. In reconciliation, AI can propose likely matches or categorize break reasons, while the system preserves the original data, confidence score, reviewer action and final resolution path.</p>



<h2 class="wp-block-heading">Hyperautomating the product development lifecycle</h2>



<p class="wp-block-paragraph">The Product Development Lifecycle can itself become hyperautomated. Instead of treating ideation, analysis, design, development, testing, security review, release and operations as disconnected phases, enterprises can create an AI-assisted delivery loop where every stage produces structured artifacts that the next stage can consume. Platforms such as GitHub Copilot, Claude Code or Claude Cowork-style agentic development environments and OpenAI Codex can support this movement by helping teams reason over requirements, generate code, create tests, review changes, modernize legacy modules and produce <a href="https://www.cio.com/article/1307309/the-generative-ai-revolution-is-transforming-how-banks-work.html">documentation</a>. Their value increases when they are connected to repositories, issue trackers, design documents, build pipelines, test suites, security scanners, observability data and enterprise knowledge bases.</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td><strong>PDLC Stage</strong></td><td><strong>Hyperautomation Opportunity</strong></td><td><strong>AI-Assisted Outcome</strong></td></tr><tr><td>Business discovery</td><td>Process mining, domain interviews, regulatory mapping, backlog creation</td><td>Structured epics, user stories, acceptance criteria, process maps and control requirements</td></tr><tr><td>Architecture and design</td><td>Reference architectures, API contracts, data models, event flows, security patterns</td><td>Architecture options, integration blueprints, threat-model prompts and design decision records</td></tr><tr><td>Development</td><td>Code generation, service scaffolding, UI component creation, data pipeline templates</td><td>Review-ready code increments, reusable components, migration utilities and integration adapters</td></tr><tr><td>Testing</td><td>Unit, integration, regression, performance, compliance and synthetic data testing</td><td>Generated test cases, defect reproduction steps, test automation scripts and coverage summaries</td></tr><tr><td>Security and compliance review</td><td>Static analysis, dependency checks, policy validation, evidence capture</td><td>Risk explanations, remediation suggestions, control traceability and approval evidence</td></tr><tr><td>Release and deployment</td><td>CI/CD orchestration, environment promotion, release notes, rollback preparation</td><td>Automated deployment packs, release summaries, operational checklists and change records</td></tr><tr><td>Operations and feedback</td><td>Observability, incident analysis, user feedback mining, backlog refinement</td><td>Incident summaries, root-cause hypotheses, improvement stories and reliability recommendations</td></tr></tbody></table> </div></figure>



<h2 class="wp-block-heading">Role of GitHub Copilot, Claude Cowork and Codex</h2>



<p class="wp-block-paragraph">GitHub Copilot is useful where developers need assistance inside the engineering flow: explaining code, generating functions, proposing tests, reviewing pull requests and helping teams move from issue to implementation. In a banking PDLC, it can accelerate microservice creation, API integration, batch processing logic, reconciliation rules, regulatory validation routines and UI workflows. When used with repository context and proper review discipline, it can reduce the time developers spend on repetitive coding while preserving human accountability for design and correctness.</p>



<p class="wp-block-paragraph">Claude Cowork or Claude Code-style agentic environments are valuable for multi-file reasoning, refactoring, debugging and documentation-heavy engineering work. Banking applications often contain deep domain logic scattered across services, configuration files, stored procedures, integration scripts and test suites. An agentic coding assistant that can understand a wider codebase context can help engineers analyze dependencies, prepare modernization plans, update multiple files coherently and draft explanations for reviewers. This is particularly useful in core banking modernization, trade reporting rule updates and compliance workflow refactoring.</p>



<p class="wp-block-paragraph">OpenAI Codex can support issue-to-pull-request workflows, test generation, code review, bug reproduction, migration activities and broader software engineering tasks across the lifecycle. In a hyperautomated PDLC, Codex-like agents can be assigned well-scoped work items, asked to inspect failing tests, propose fixes, create regression coverage and summarize the change for human reviewers. The important design principle is to keep agents inside controlled boundaries: clear prompts, repository permissions, test gates, approval workflows and traceable outputs.</p>



<h2 class="wp-block-heading">Integration architecture for hyperautomated banking applications</h2>



<p class="wp-block-paragraph">A practical architecture begins with business capability decomposition. Each banking domain should be expressed as a set of bounded capabilities such as customer onboarding, account maintenance, trade enrichment, exception management, portfolio review, control attestation, report generation and audit retrieval. These capabilities should be exposed through APIs, events, workflow tasks, data products and user interfaces. Hyperautomation then connects these capabilities using orchestration engines, event streams, rules engines, AI services, RPA connectors where legacy integration is unavoidable and observability layers that capture business and technical telemetry.</p>



<p class="wp-block-paragraph">The embedded AI layer should sit behind a secure application service boundary. It should use retrieval-augmented generation where approved policies, product rules, application documentation and regulatory mappings are retrieved from trusted sources. It should avoid uncontrolled exposure of sensitive customer information. Prompt templates, response validation, redaction, grounding checks, model monitoring and human-in-the-loop approval should be part of the production design. In banking, the most successful AI pattern is often not full automation but <a href="https://www.everestgrp.com/report/egr-2024-31-v-6318/">assisted</a> decisioning with strong controls.</p>



<h2 class="wp-block-heading">Example: Hyperautomated reconciliation and reporting flow</h2>



<p class="wp-block-paragraph">Consider a reconciliation application that compares ledger balances, payment files, trade settlement records and external statements. In a conventional model, operations teams spend significant time downloading files, running macros, investigating mismatches, documenting break reasons and preparing status reports. In a hyperautomated model, data ingestion is scheduled and monitored, schema checks run automatically, matching engines classify obvious matches, AI assists with ambiguous narratives, exceptions are routed through workflow queues and dashboards update in near real time. At the end of the day, the system can generate a draft operations <a href="https://www.pwc.com/us/en/industries/financial-services/library/hyperautomation-gen-ai-in-banking.html">report</a> explaining unresolved breaks, aging trends, risk exposure and pending approvals.</p>



<p class="wp-block-paragraph">The same pattern can extend to daily, weekly and monthly reporting. Data quality rules validate inputs, report templates are populated automatically, AI generates narrative commentary on variances, reviewers approve or amend explanations and the final report is archived with lineage and approvals. Audit teams can later retrieve not only the report but also the source extracts, transformation logs, exception history, reviewer decisions and AI-generated drafts. This creates a richer control environment than manual reporting because evidence is captured by design rather than reconstructed later.</p>



<h2 class="wp-block-heading">Governance, risk and control considerations</h2>



<p class="wp-block-paragraph">Hyperautomation in banking must be designed with governance from the beginning. The development team should define which activities can be automated, which can be AI-assisted and which must remain under human approval. Source code generated by AI must pass normal engineering controls, including peer review, static analysis, dependency scanning, secure coding checks, test execution and production readiness review. Business outputs generated by AI, such as compliance narratives or client-facing explanations, should be <a href="https://www.pwc.com/us/en/industries/financial-services/library/hyperautomation-gen-ai-in-banking.html">reviewed</a> where regulatory or reputational risk is material.</p>



<p class="wp-block-paragraph">Data governance is equally important. AI-enabled applications must respect data classification, residency, retention, masking and access policies. The model should not become an uncontrolled channel through which confidential customer, trading or employee information can leak. Every prompt, retrieved source, generated response, user action and final decision may need to be logged depending on the use case. For audit applications, this traceability is not optional; it is the foundation of trust.</p>



<h2 class="wp-block-heading">Operating model for AI-native PDLC</h2>



<p class="wp-block-paragraph">A hyperautomated PDLC requires changes in team behavior. Product owners should write requirements in a structured manner so that AI tools can generate better stories, acceptance criteria and test scenarios. Architects should maintain living decision records, reference patterns and integration standards that AI agents can use as context. Developers should learn prompt discipline, context packaging and review techniques. Test engineers should focus on coverage strategy, synthetic data, compliance scenarios and defect prevention rather than only manual execution. Operations teams should feed incident <a href="https://www.cio.com/article/1307309/the-generative-ai-revolution-is-transforming-how-banks-work.html">learnings</a> back into the backlog so the system improves continuously.</p>



<p class="wp-block-paragraph">The role of human experts becomes more important, not less. AI can draft, generate, compare and suggest, but domain judgment remains essential. A trade reporting specialist understands regulatory nuance. A wealth advisor understands client suitability. A core banking architect understands transaction integrity. A compliance officer understands control interpretation. Hyperautomation works best when it amplifies these experts and removes repetitive friction around them.</p>



<h2 class="wp-block-heading">Conclusion</h2>



<p class="wp-block-paragraph">Hyperautomation in business application development is not simply a faster way to write software. It is a new way to connect business intent, engineering execution, operational control and continuous learning. In banking, where applications must be reliable, explainable, secure and compliant, the combination of embedded Generative AI and disciplined automation can transform how applications are designed, built, integrated, tested, released and operated. Trade reporting, wealth management, core banking, investment banking, compliance, reconciliation, reporting and audit functions can all benefit when AI is embedded responsibly and automation is orchestrated across the complete lifecycle.</p>



<p class="wp-block-paragraph">Platforms such as GitHub Copilot, Claude Cowork or Claude Code and OpenAI Codex can play an important role in this transformation by accelerating analysis, development, testing, review, modernization and documentation. Their greatest value appears when enterprises treat them not as isolated productivity tools but as part of a governed, AI-native PDLC. The future of banking application development will belong to teams that can combine human expertise, reusable engineering patterns, intelligent automation and strong governance into one coherent delivery model.</p>



<p class="wp-block-paragraph"><em>This article was made possible by our partnership with the IASA </em><a href="https://chiefarchitectforum.org/" target="_blank" rel="noreferrer noopener"><em>Chief Architect Forum</em></a><em>. The CAF’s purpose is to test, challenge and support the art and science of Business Technology Architecture and its evolution over time as well as grow the influence and leadership of chief architects both inside and outside the profession. The CAF is a leadership community of the </em><a href="https://iasaglobal.org/" target="_blank" rel="noreferrer noopener"><em>IASA</em></a><em>, the leading non-profit professional association for business technology architects.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Polish data center plans to send its waste heat to the neighbors]]></title>
<description><![CDATA[As Europe swelters in a heatwave, residents probably don’t want to hear about ways to make their homes even hotter, but that’s what Polish property developer Citylink is talking about, with plans to dump waste heat from a new data center in Wrocław into the municipal district heating network.



...]]></description>
<link>https://tsecurity.de/de/3710150/it-nachrichten/polish-data-center-plans-to-send-its-waste-heat-to-the-neighbors/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710150/it-nachrichten/polish-data-center-plans-to-send-its-waste-heat-to-the-neighbors/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:39 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">As Europe swelters in a heatwave, residents probably don’t want to hear about ways to make their homes even hotter, but that’s what Polish property developer Citylink is talking about, with plans to dump waste heat from a new data center in Wrocław into the municipal district heating network.</p>



<p class="wp-block-paragraph">Citylink is designing the data center so that heat from servers can be recovered instead of being dissipated via cooling systems — and as the data center grows, any increase in computing power will mean more energy available for recovery.</p>



<p class="wp-block-paragraph">The collaboration with local power company Kogeneracja will provide “valuable experience in designing and operating modern data centers, with a particular focus on infrastructure dedicated to AI nodes,<em>” </em><a href="https://city-link.pl/en/heat-from-servers-could-power-wroclaw-citylink-and-kogeneracja-s-a-launch-collaboration/" target="_blank" rel="noreferrer noopener">said Michał Starybrat, development director at Citylink</a>.</p>



<p class="wp-block-paragraph">“The dynamic growth of the artificial intelligence and cloud technology markets generates unprecedented demand for computing power, this collaboration demonstrates how modern digital infrastructure can actively contribute to building the energy ecosystem of the future,” he added.</p>



<p class="wp-block-paragraph">This type of initiative is not new. There have been <a href="https://www.newcivilengineer.com/latest/data-centres-could-join-energy-ecosystem-as-report-presents-use-case-for-wasted-heat-16-10-2025/" target="_blank" rel="noreferrer noopener">similar projects in the UK</a> and <a href="https://www.reseller.co.nz/article/2503421/spark-aims-to-use-dc-heat-to-warm-a-new-north-shore-surf-spot.html">in New Zealand,</a> but with warnings that <a href="https://www.networkworld.com/article/4153403/no-joke-data-centers-are-warming-the-planet.html">data centers are contributing to the warming of the planet</a>, there may well be a lot more organizations looking to deploy that excess heat more fruitfully in the future.</p>



<p class="wp-block-paragraph">However, announcing it during a heatwave may not be the most politically sensitive approach to take.</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.networkworld.com/article/4206791/polish-data-center-plans-to-send-its-waste-heat-to-the-neighbors.html">Network World</a>.</em></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI puts the brakes on a new model because it’s supposedly too powerful]]></title>
<description><![CDATA[OpenAI says it is pausing "internal activities" around an in-development AI model, Astra, because it doesn't yet meet new security standards the company is putting in place. The announcement follows its recent disclosure that OpenAI models accidentally hacked Hugging Face. Anthropic and Meta have...]]></description>
<link>https://tsecurity.de/de/3709971/it-nachrichten/openai-puts-the-brakes-on-a-new-model-because-its-supposedly-too-powerful/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709971/it-nachrichten/openai-puts-the-brakes-on-a-new-model-because-its-supposedly-too-powerful/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:14 +0200</pubDate>
<content:encoded><![CDATA[OpenAI says it is pausing "internal activities" around an in-development AI model, Astra, because it doesn't yet meet new security standards the company is putting in place. The announcement follows its recent disclosure that OpenAI models accidentally hacked Hugging Face. Anthropic and Meta have also since admitted that they had AI models that went rogue […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Pony Island 2 Panda Circus: gallop out of hell in this phantasmagorical follow-up to 2016’s indie hit]]></title>
<description><![CDATA[Daniel Mullins explains how he plans to follow up his quirky classic without losing what made it stand out in the first placeGlitchy aesthetics. Literally collapsing menu boxes. The game taunting you by “possessing” your Steam friends. Technical tricks of this nature may sound gimmicky in 2026, b...]]></description>
<link>https://tsecurity.de/de/3709626/it-nachrichten/pony-island-2-panda-circus-gallop-out-of-hell-in-this-phantasmagorical-follow-up-to-2016s-indie-hit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709626/it-nachrichten/pony-island-2-panda-circus-gallop-out-of-hell-in-this-phantasmagorical-follow-up-to-2016s-indie-hit/</guid>
<pubDate>Fri, 07 Aug 2026 11:24:12 +0200</pubDate>
<content:encoded><![CDATA[<p>Daniel Mullins explains how he plans to follow up his quirky classic without losing what made it stand out in the first place</p><p>Glitchy aesthetics. Literally collapsing menu boxes. The game taunting you by “possessing” your Steam friends. Technical tricks of this nature may sound gimmicky in 2026, but they felt excitingly unorthodox a decade ago, when Pony Island came out to critical acclaim.</p><p>Fans of Daniel Mullins, the celebrated indie developer of Inscryption, will be forgiven for forgetting that Pony Island 2: Panda Circus is in active development. After all, it’s been almost three years since the announcement – and a full decade since it was first teased as an Easter egg in Pony Island’s ARG (Alternate Reality Game) – with only a single trailer and a bunch of tunes from the soundtrack released to the public.</p> <a href="https://www.theguardian.com/games/2026/aug/07/pony-island-2-panda-circus-daniel-mullins-inscryption">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wie Windows zur Entwicklungsumgebung wird]]></title>
<description><![CDATA[Windows-Maschine und Developer-„Flow“ gehen gut zusammen – ein paar Kniffe vorausgesetzt.Dragon Images | shutterstock.com



Als Umgebung für Entwickler hat Microsoft Windows in den letzten Jahren einen Sprung nach vorne gemacht. Mit dem Windows-Subsystem für Linux (WSL) ist es nahtlos möglich, m...]]></description>
<link>https://tsecurity.de/de/3709505/it-security-nachrichten/wie-windows-zur-entwicklungsumgebung-wird/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709505/it-security-nachrichten/wie-windows-zur-entwicklungsumgebung-wird/</guid>
<pubDate>Fri, 07 Aug 2026 06:32:07 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Dragon-Images_shutterstock_401334922_16z9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Dev Coding Speed 16z9" class="wp-image-4202220" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Windows-Maschine und Developer-„Flow“ gehen gut zusammen – ein paar Kniffe vorausgesetzt.</figcaption></figure><p class="imageCredit">Dragon Images | shutterstock.com</p></div>



<p class="wp-block-paragraph">Als Umgebung für Entwickler hat Microsoft Windows in den letzten Jahren einen Sprung nach vorne gemacht. Mit dem Windows-Subsystem für Linux (<a href="https://www.computerwoche.de/article/2856740/windows-10-subsystem-fuer-linux-wsl-einrichten.html" target="_blank">WSL</a>) ist es nahtlos möglich, mit Linux unter Windows zu arbeiten – ohne den Mehraufwand, den eine virtuelle Maschine (<a href="https://www.computerwoche.de/article/2814705/was-sind-virtual-machines.html" target="_blank">VM</a>) mit sich bringt. Zudem sind sämtliche gängigen Dev-Tools als native Windows-Versionen verfügbar – und Microsoft hat eine ganze Reihe entsprechender Funktionen auch direkt in sein Betriebssystem <a href="https://blogs.windows.com/windowsdeveloper/2026/06/02/build-2026-furthering-windows-as-the-trusted-platform-for-development/">integriert</a>.</p>



<p class="wp-block-paragraph">Für Developer, die besonders schnell mit einer Windows-Maschine entwickeln wollen, hat Microsoft mit der „<a href="https://github.com/microsoft/WindowsDeveloperConfig/" target="_blank" rel="noreferrer noopener">Windows Developer Config</a>“ sogar so etwas wie eine Schnellspur geschaffen: Diese Sammlung von Powershell-Skripten fungiert als eine Art „Starter Kit“ und unterstützt dabei, Windows-Systeme möglichst schnell und komfortabel als Entwicklungsumgebung einzurichten. </p>



<p class="wp-block-paragraph">Wenn Sie hingegen – wie <a href="https://www.computerwoche.de/article/2818958/was-developer-an-ihrem-job-lieben-und-hassen.html" target="_blank">die meisten Entwickler</a> – Wert darauflegen, die Kontrolle zu behalten und Ihr Dev-System selbst einzurichten und zu konfigurieren, ist ein bisschen Vorarbeit nötig. Der Aufwand selbst ist dabei überschaubar, die konkreten Schritte sind jedoch erfolgsentscheidend (und nicht unbedingt offensichtlich).   </p>



<p class="wp-block-paragraph"><strong>Hinweis:</strong> Um die nachfolgenden Maßnahmen umzusetzen, sollten Sie auf Ihrem System über Administratorrechte verfügen.</p>



<h2 class="wp-block-heading">1. WSL installieren</h2>



<p class="wp-block-paragraph">WSL stellt Windows-Benutzern ein vollständiges Linux-System über die Kommandozeile zur Verfügung – was weniger Overhead verursacht als eine VM. Da Software weltweit vor allem unter <a href="https://www.computerwoche.de/article/3614492/die-wichtigsten-linux-befehle-fur-einsteiger.html" target="_blank">Linux</a>– oder Unix-ähnlichen Systemen wie macOS entwickelt wird, ist das ein echter Vorteil. </p>



<p class="wp-block-paragraph">Um WSL zu installieren, öffnen Sie ein Konsolenfenster mit Administratorrechten und nutzen den Befehl:</p>



<pre class="wp-block-code"><code><code>wsl --install</code></code></pre>



<p class="wp-block-paragraph">Die Installation kann einige Zeit in Anspruch nehmen, da das System sowohl die Kernkomponenten für WSL als auch – damit zusammenhängend – eine Linux-Distribution herunterladen muss. </p>



<p class="wp-block-paragraph">Die Standard-Linux-Distribution in WSL ist <strong>Ubuntu 26.04 LTS</strong>. Diese erfüllt als Default-Lösung die meisten Anforderungen, die Entwickler an eine Linux-Distribution stellen. Es stehen jedoch auch andere Distributionen zur Verfügung – und es kommen regelmäßig neue hinzu. Sie könnten sogar Ihre eigene, <a href="https://learn.microsoft.com/de-de/windows/wsl/build-custom-distro">benutzerdefinierte Linux-Distribution für WSL</a> kreieren.</p>



<p class="wp-block-paragraph">Sobald WSL installiert ist, können Sie über den Befehl wsl –list –online alle verfügbaren Distributionen anzeigen. Um eine davon zu installieren, nutzen Sie den Befehl <code>wsl --install </code>. Die meisten verfügbaren Optionen sind auf unterschiedliche Vorlieben oder spezifische Anforderungen zugeschnitten. Wenn Sie beispielsweise an einem Projekt arbeiten, das Debian als Grundlage voraussetzt, sollten Sie das auch installieren.</p>



<p class="wp-block-paragraph">WSL-Distributionen werden standardmäßig im <code>AppData</code>-Verzeichnis abgelegt – genauer gesagt unter <code>AppData\Local\Packages\</code>. Wenn Sie die Dateien in ein anderes Verzeichnis oder auf ein anderes Laufwerk verschieben möchten, können Sie das mit dem Befehl <code>wsl --manage  --move </code> bewerkstelligen.</p>



<p class="wp-block-paragraph">Darüber hinaus hat Microsoft Ende Juni 2026 mit <a href="https://devblogs.microsoft.com/commandline/wsl-container-is-now-available-for-public-preview/" target="_blank" rel="noreferrer noopener">WSL-Container</a> (derzeit in der Public Preview) eine wichtige neue Funktion für WSL vorgestellt. Diese ermöglicht es, Linux-Container nativ unter Windows auszuführen.</p>



<h2 class="wp-block-heading">2. Dev-Drive-Laufwerk konfigurieren</h2>



<p class="wp-block-paragraph">Um Projekte zu speichern, nutzen die meisten Windows-Benutzer standardmäßig ein Verzeichnis auf einem NTFS-Volume – entweder im eigenen Benutzerprofil oder über einen anderen Pfad. Das ist als Default-Option keine schlechte Wahl. Allerdings gibt es bessere Alternativen.</p>



<p class="wp-block-paragraph">Zum Beispiel „<a href="https://learn.microsoft.com/de-de/windows/dev-drive/" target="_blank" rel="noreferrer noopener">Dev Drive</a>“, ein neuer Laufwerkstyp unter Windows. Dieser nutzt statt NTFS das neuere Dateisystem <a href="https://learn.microsoft.com/de-de/windows-server/storage/refs/refs-overview" target="_blank" rel="noreferrer noopener">ReFS</a> („Resilient File System“). Dieses wurde ursprünglich für Windows Server entwickelt und bietet Funktionen, die darauf ausgelegt sind, Softwareentwicklungs-Workloads besser zu bewältigen. Dazu gehören:  </p>



<ul class="wp-block-list">
<li><strong>Copy-on-Write: </strong>Projektverzeichnisse können Tausende von Dateien und Dutzende von Unterverzeichnissen enthalten. Kopien von Projekten dieser Art anzufertigen, lässt sich mit ReFS deutlich schneller bewältigen, da das Dateisystem Kopien von Daten erst dann erstellt, wenn diese auch <em>geändert</em> werden. Reine Kopien sind hingegen Links, die auf die Originale verweisen.</li>



<li><strong>Antivirus-Komfort:</strong> Über einen Dev Drive lassen sich die standardmäßigen Beeinträchtigungen durch die nativen Antivirus-Tools von Windows minimieren. Dieses Feature erlaubt es, Entwicklerverzeichnisse manuell von Scan-Vorgängen zu exkludieren.</li>



<li><strong>Virtuelle Festplatte oder Partition:</strong> Dev Drives können als virtuelle Festplattendatei eingerichtet oder direkt auf einer formatierten Partition genutzt werden. Ersteres ist flexibler (unter anderem lässt sich die Größe leichter anpassen), Letzteres möglicherweise performanter.</li>
</ul>



<p class="wp-block-paragraph">Zwei Dinge sollten Sie im Zusammenhang mit Dev Drives unbedingt beachten:</p>



<ol class="wp-block-list">
<li><strong>Dev Drives sind für Projekte gedacht, nicht für Tools:</strong> Dort legen Sie Ihre Projekt-Repositories, Build-Artefakte und zwischengespeicherte Dateien ab. Language Runtimes, <a href="https://www.computerwoche.de/article/4152349/so-wird-ki-zum-compiler.html" target="_blank">Compiler</a> oder anderen Toolchain-Utlities sollten hingegen auf regulären NTFS-Volumes gespeichert werden.</li>



<li><strong>Low-Level-Tools funktionieren unter Umständen nicht wie beabsichtigt:</strong> Dateisystem-Utilities auf Expertenniveau, die Informationen direkt aus den Dateiinformationen auslesen, verhalten sich im Zusammenspiel mit ReFS-Volumes möglicherweise nicht wie vorgesehen. So ist etwa das Speicherplatz-Management-Tool <a href="https://wize-tree.com/" target="_blank" rel="noreferrer noopener">WizTree</a> unter ReFS extrem langsam.</li>
</ol>



<h2 class="wp-block-heading">3. WinGet nutzen</h2>



<p class="wp-block-paragraph">Microsoft hat Windows inzwischen auch mit einem offiziellen Package-Management-System ausgestattet – WinGet. Dieses installiert jede Art von <a href="https://www.computerwoche.de/article/2824356/26-softwareperlen-fuer-windows-pcs.html" target="_blank">Windows-Applikation</a> und bietet zudem ein vollständiges Befehlszeilen-Interface für Interaktion und Automatisierung.    </p>



<p class="wp-block-paragraph">WinGet wird vom Windows-Software-Ökosystem umfassend unterstützt – die Wahrscheinlichkeit ist also groß, dass es für jedes Windows-Programm, das Sie benötigen, ein WinGet-Paket gibt (dazu gleich mehr).</p>



<p class="wp-block-paragraph">Um im WinGet-Repository nach einem Paket zu suchen, nutzen Sie diesen Befehl (die Anführungszeichen sind erforderlich, wenn der Name des gesuchten Pakets Leerzeichen enthält – etwa Adobe Acrobat Reader):</p>



<pre class="wp-block-code"><code><code>winget search "Thing to search for"</code></code></pre>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/image_481.png" alt="WinGet search output" class="wp-image-4196911" width="978" height="205" sizes="auto, (max-width: 978px) 100vw, 978px"><figcaption class="wp-element-caption">Der Output von WinGet bei der Suche nach dem Begriff „Acrobat“. Die „ID“-Spalte gibt den Namen aus, der mit dem Winget-Installationsbefehl zu verwenden ist.</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p class="wp-block-paragraph">Das WinGet-Package zu installieren, geht denkbar simpel von der Hand – und zwar mit:</p>



<pre class="wp-block-code"><code><code>winget install </code></code></pre>



<p class="wp-block-paragraph">Dabei meint <code></code> die ID des zu installierenden Pakets – nicht bloß seinen Namen. Im vorgenannten Beispiel (Adobe Acrobat Reader) würden Sie also folgenden Befehl nutzen, um dieses zu installieren:</p>



<pre class="wp-block-code"><code><code>winget install Adobe.Acrobat.Reader.64-bit</code></code></pre>



<p class="wp-block-paragraph">Falls Sie eine ansprechende grafische Benutzeroberfläche suchen, empfiehlt sich ein Blick auf <a href="https://devolutions.net/unigetui/" target="_blank" rel="noreferrer noopener">UniGetUI</a>. Dieses Tool verwaltet Packages aus verschiedenen Quellen – etwa WinGet, Scoop, Chocolatey, npm, pip oder Cargo, um nur einige zu nennen.</p>



<h2 class="wp-block-heading">4. PowerShell für Skripte konfigurieren</h2>



<p class="wp-block-paragraph">Dieser Schritt ist lediglich einmal pro System zu absolvieren, kann jedoch die <a href="https://www.computerwoche.de/article/2834060/10-wege-zur-besseren-developer-experience.html" target="_blank">Entwicklererfahrung</a> von Windows gewaltig steigern: PowerShell sollte entsprechend konfiguriert werden, damit lokale Skripte ausgeführt werden können.   </p>



<p class="wp-block-paragraph">Um das zu bewerkstelligen, starten Sie PowerShell als Admin und nutzen folgendes Kommando:</p>



<pre class="wp-block-code"><code>set-executionpolicy remotesigned</code></pre>



<p class="wp-block-paragraph">Zwar verlangt Windows weiterhin, dass alle PowerShell-Skripte, die Sie aus dem Internet herunterladen, signiert sind – das ist jedoch im Grunde ein Edge Case. Alle lokal erstellten Skripte funktionieren nach dieser Maßnahme ohne Weiteres.</p>



<h2 class="wp-block-heading">5. Weitere Dev-Tools installieren</h2>



<p class="wp-block-paragraph">Wie bereits erwähnt, bietet WinGet schnellen Zugriff auf alle gängigen Tools, die ein entwicklungsorientiertes Windows-System benötigt. Nachfolgend haben wir eine kleine Übersicht der wichtigsten Dev-Tools für Windows inklusive deren WinGet-IDs zusammengestellt, um Ihnen die Installation zu erleichtern.</p>



<ul class="wp-block-list">
<li><strong>Git (</strong><code>Git.Git</code><strong>):</strong> Die Windows-Version des populären Versionskontrollsystems ist im Wesentlichen identisch mit der auf anderen Plattformen.</li>



<li><strong>Visual Studio BuildTools 2022 (</strong><code>Microsoft.VisualStudio.2022.BuildTools</code><strong>):</strong> Dieses minimale CLI-Tooling ist erforderlich, um das C/C++-Kompilierungssystem von Visual Studio zu nutzen.</li>



<li><strong>CMake (</strong><code>Kitware.Cmake</code><strong>):</strong> Die plattformübergreifende Build-Lösung wird häufig für größere oder komplexere Projekte benötigt, die C/C++ nutzen.</li>
</ul>



<p class="wp-block-paragraph">Dabei ist zu beachten, dass die standardmäßige BuildTools-Installation in der Regel nicht über die Tools verfügt, die für minimale C/C++-Build-Prozesse erforderlich sind. Das beheben Sie mit folgendem Befehl:</p>



<pre class="wp-block-code"><code>winget install -e --id Microsoft.VisualStudio.2022.BuildTools --force --override "--passive --wait --add Microsoft.VisualStudio.Workload.VCTools;includeRecommended"</code></pre>



<p class="wp-block-paragraph">Alle gängigen Editoren sind ebenfalls als native Windows-Apps über WinGet verfügbar – etwa:</p>



<ul class="wp-block-list">
<li><strong><a href="https://www.computerwoche.de/article/4199279/visual-studio-code-hat-ein-ki-problem.html" target="_blank">Microsoft Visual Studio Code</a></strong> (<code>Microsoft.VisualStudioCode</code>),</li>



<li><strong>GNU Emacs</strong> (<code>GNU.Emacs</code>), oder</li>



<li><strong>Neovim</strong> (<code>Neovim.Neovim</code>).</li>
</ul>



<p class="wp-block-paragraph">Für die Softwareentwicklung unter Windows optional, aber durchaus nützlich, sind außerdem folgende Werkzeuge:</p>



<ul class="wp-block-list">
<li><strong>CoreUtils for Windows (</strong><code>Microsoft.Coreutils</code><strong>):</strong> Ein von Microsoft gepflegtes Open-Source-Projekt, das <a href="https://github.com/microsoft/coreutils">Dutzende von Linux-Befehlszeilen-Dienstprogrammen</a> auf Windows bringt, beispielsweise cp, grep, find und ls.</li>



<li><strong>MSYS2 (</strong><code>MSYS2.MSYS2</code><strong>):</strong> Eine Tool-Sammlung, um Windows-Binärdateien mit dem GCC-Compiler zu erstellen. Diese bildet im Grunde eine Alternative zum Visual-Studio-Build-Stack auf Basis der <a href="https://cygwin.com/" target="_blank" rel="noreferrer noopener">Cygwin</a>-Umgebung.</li>



<li><strong>LLVM (</strong><code>LLVM.LLVM</code><strong>):</strong> Auf diesem Compiler-Framework basieren Clang, Rust, Swift und viele andere Projekte. Wenn Sie <a href="https://www.computerwoche.de/article/2826586/was-ist-llvm.html" target="_blank">LLVM</a> als Abhängigkeit verwenden, müssen Sie die spezifische Version installieren, die Ihr Projekt erfordert.</li>



<li><strong>Docker Desktop (</strong><code>XP8CBJ40XLBWKX</code><strong>):</strong> Die Windows-native Version der Docker-Desktop-App.</li>



<li><strong>Microsoft PowerToys (</strong><code>Microsoft.PowerToys</code><strong>):</strong> Diese Sammlung besteht aus über 30 Utilities, die es erheblich vereinfachen, <a href="https://www.computerwoche.de/article/3824755/microsoft-powertoys-ein-leitfaden.html" target="_blank">Windows anzupassen</a>. Dazu gehören unter anderem ein <a href="https://learn.microsoft.com/de-de/windows/powertoys/hosts-file-editor" target="_blank" rel="noreferrer noopener">Hosts-File-Editor</a>, ein <a href="https://learn.microsoft.com/de-de/windows/powertoys/file-locksmith" target="_blank" rel="noreferrer noopener">Unlocking-Tool für Dateien</a> (praktisch, um festzustellen, welche Prozesse eine bestimmte Datei sperren) sowie ein <a href="https://learn.microsoft.com/de-de/windows/powertoys/text-extractor" target="_blank" rel="noreferrer noopener">Werkzeug, um Text zu extrahieren</a> (praktisch, um Text von beliebigen Stellen auszulesen, einschließlich Bildschirmbereichen, die nicht mit dem Cursor markiert werden können).</li>
</ul>



<p class="wp-block-paragraph">(fm)</p>



<p class="wp-block-paragraph"><strong>Dieser Artikel ist </strong><a href="https://www.infoworld.com/article/4196853/how-to-make-windows-a-proper-development-environment.html" target="_blank"><strong>im Original</strong></a><strong> bei unserer Schwesterpublikation Infoworld.com erschienen.</strong></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Scientists Make First Viruses Designed By AI]]></title>
<description><![CDATA[An anonymous reader quotes a report from The Guardian: Scientists have made the first viruses designed by artificial intelligence in a milestone that raises hopes for new medicines but also concerns over how to ensure the technology remains safe. The viruses are specific kinds known as bacterioph...]]></description>
<link>https://tsecurity.de/de/3709497/it-security-nachrichten/scientists-make-first-viruses-designed-by-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709497/it-security-nachrichten/scientists-make-first-viruses-designed-by-ai/</guid>
<pubDate>Fri, 07 Aug 2026 06:29:27 +0200</pubDate>
<content:encoded><![CDATA[An anonymous reader quotes a report from The Guardian: Scientists have made the first viruses designed by artificial intelligence in a milestone that raises hopes for new medicines but also concerns over how to ensure the technology remains safe. The viruses are specific kinds known as bacteriophages, which only infect bacteria and are used around the world to treat patients with persistent infections. In lab tests, a cocktail of the AI-designed viruses killed E coli bugs that were resistant to natural bacteriophages.
 
Dr Brian Hie, a chemical engineer at Stanford University in California, used genome language models, the genetic equivalent of the large language models behind AI chatbots, to design functioning genomes for bacteriophages. The viruses were then made in the laboratory and pitted against E coli in a dish. The ability to "rapidly design" genomes and tune them for specific bugs while overcoming resistance could "transform phage therapy" and "expand biotechnological toolkits," the researchers wrote in the journal Science.
 
But beyond the potential benefits, the scientists said the work raised "important biosafety, biocontainment and biosecurity considerations" and urged others who were designing whole genomes to "consult both safety and security professionals throughout the project." In an accompanying article, Prof Tom Inglesby and Dr Moritz Hanke at the Center for Health Security at Johns Hopkins University in Baltimore, reinforced the warning, writing: "Although this is promising for life sciences applications, it also raises urgent biosafety and biosecurity questions. The ability to compose viral genomes using generative AI now exists; the governance to safely steer it does not." Tom Ellis, a professor of synthetic genome engineering at Imperial College London, said the work was impressive, but revealed how hard it would be to make more complex genomes. "This is literally the smallest and easiest genome to make," he said. An AI trained on the genetic code of dangerous bugs could be used to design more harmful viruses, Ellis said, but controlling access to genetic data and having restrictions on making genomes that look dangerous would help. "Governments are working hard to do this already," he added. "But honestly," he said, "the threat from full AI design and writing of a genome of a virus or bacteria is very overblown when we consider that just taking existing pathogens and making gain-of-function changes to their genomes is so much easier and much more likely to be a real pathogenic threat."
 
Dr Filippa Lentzos, a reader in science and international security at King's College London, said the most important point to intervene at the moment was when DNA was being manufactured. "It's important to see the bigger governance picture and not focus regulation solely on the AI model," she said. "A layered approach makes more sense: safeguards around model development and access, responsible research review, synthesis screening, and established laboratory biosafety and biosecurity."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Scientists+Make+First+Viruses+Designed+By+AI%3A+https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F08%2F06%2F1824255%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F08%2F06%2F1824255%2Fscientists-make-first-viruses-designed-by-ai%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://science.slashdot.org/story/26/08/06/1824255/scientists-make-first-viruses-designed-by-ai?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google's $15 Billion India Data Center Project Battles Water, Wildlife Concerns]]></title>
<description><![CDATA[Google's $15 billion data-center project in Visakhapatnam is facing protests and legal challenges over fears that it will worsen local water shortages and disturb wildlife near the Kambalakonda sanctuary. Google says the campus will use advanced air cooling and comply with Indian law, while state...]]></description>
<link>https://tsecurity.de/de/3709215/it-security-nachrichten/googles-15-billion-india-data-center-project-battles-water-wildlife-concerns/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709215/it-security-nachrichten/googles-15-billion-india-data-center-project-battles-water-wildlife-concerns/</guid>
<pubDate>Fri, 07 Aug 2026 02:35:27 +0200</pubDate>
<content:encoded><![CDATA[Google's $15 billion data-center project in Visakhapatnam is facing protests and legal challenges over fears that it will worsen local water shortages and disturb wildlife near the Kambalakonda sanctuary. Google says the campus will use advanced air cooling and comply with Indian law, while state officials deny that residential or rural water supplies will be tapped. Reuters reports: The southern state of Andhra Pradesh, governed by an ally of Prime Minister Narendra Modi who has hailed the project as historic and transformational, has denied allegations that the project was fast-tracked without weighing risks to water supplies and wildlife. But the growing opposition could become an early test for Google's biggest-ever India investment, which is facing several legal challenges over its impact on water supplies and proximity to a wildlife sanctuary that is home to leopards and pangolins.
 
In recent weeks, activists and children have marched in Visakhapatnam city, holding banners saying "We cannot drink DATA" and painting handcuffs on the Google logo, social media posts show. On Sunday, Reuters attended a public gathering where activists chalked out plans for holding door-to-door awareness campaigns and beach protests in coming days. "Development should not be at the cost of livelihood of the people," Raja Rama Mohan Roy, founder of non-profit Green Visakha said at the event where he presented statistics on Visakhapatnam's stressed water supply and demand.
 
The government says the city receives 410 million liters of water a day from its reservoirs and rivers, against a requirement of 480 million. Rationing of water supplies is common in the city with a population of 2.5 million people. [...] The state's top court on Monday asked the government to defend against allegations leveled by activist group Jal Biradari (Water Community), which says the project will strain water availability by putting stress on a nearby reservoir. The Andhra Pradesh High Court will next hear the public interest litigation on August 24.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Google's+%2415+Billion+India+Data+Center+Project+Battles+Water%2C+Wildlife+Concerns%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F08%2F06%2F223250%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F08%2F06%2F223250%2Fgoogles-15-billion-india-data-center-project-battles-water-wildlife-concerns%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/26/08/06/223250/googles-15-billion-india-data-center-project-battles-water-wildlife-concerns?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[No cloud, no GPUs, no problem: Liquid AI's new model LFM2.5-2.6B brings powerful AI agents to devices as small as a Raspberry Pi]]></title>
<description><![CDATA[Earlier this week, the AI startup Liquid, formed in 2023 by former MIT computer scientists, debuted LFM2.5-2.6B, a new open-weight language model designed specifically for agentic workloads. In release materials and a recent interview with VentureBeat, Liquid's researchers said LFM2.5-2.6B can ru...]]></description>
<link>https://tsecurity.de/de/3709207/it-nachrichten/no-cloud-no-gpus-no-problem-liquid-ais-new-model-lfm25-26b-brings-powerful-ai-agents-to-devices-as-small-as-a-raspberry-pi/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709207/it-nachrichten/no-cloud-no-gpus-no-problem-liquid-ais-new-model-lfm25-26b-brings-powerful-ai-agents-to-devices-as-small-as-a-raspberry-pi/</guid>
<pubDate>Fri, 07 Aug 2026 02:35:01 +0200</pubDate>
<content:encoded><![CDATA[<p>Earlier this week, the AI startup Liquid, formed in 2023 by former MIT computer scientists, <a href="https://www.liquid.ai/blog/lfm2-5-2-6b">debuted LFM2.5-2.6B</a>, a new open-weight language model designed specifically for agentic workloads. </p><p>In release materials and a recent interview with VentureBeat, Liquid's researchers said LFM2.5-2.6B can run entirely on local hardware — from smartphones and laptops down to a Raspberry Pi — without relying on cloud inference or GPUs, unlocking edge AI applications and giving more options to enterprises working in regulated industries or with sensitive information they don't want to send up to the cloud. </p><p>It's best suited for high-volume, well-defined agentic tasks that run locally — tool calling, document management, calendar and workflow automation, and always-on background routines — and for connectivity-limited environments like vehicles and robotics, though coding-heavy work is better left to larger models.</p><p>Even for those businesses without such concerns, the appeal of running performant, task-specific agents at the cost of essentially electricity, may be enough to make the new model quite appealing. </p><p>But the <a href="https://huggingface.co/LiquidAI/LFM2.5-2.6B/blob/main/LICENSE">custom open weights license</a>, as with <a href="https://venturebeat.com/technology/kimi-k3s-full-weights-are-here-but-theyre-open-with-a-caveat-what-enterprises-should-know">Moonshot's larger frontier model Kimi K3</a> released last month, is worth a close look by enterprise legal teams. </p><h2><b>The basics</b></h2><p>LFM2.5-2.6B contains 2.6 billion parameters, supports a 128,000-token context window, and includes native tool calling. The somewhat tricky name is explained by the generation of model (2.5) combined with the parameter count (2.6B).  </p><p>Both the post-trained model and a base checkpoint (LFM2.5-2.6B-Base) for developers who want to fine-tune it are available now on <a href="https://huggingface.co/LiquidAI/LFM2.5-2.6B">Hugging Face</a>, with day-one support for major inference stacks including llama.cpp, MLX, vLLM, SGLang, and ONNX — positioning it for deployment across consumer hardware, enterprise infrastructure, and embedded systems.</p><p>Liquid also offers an open source fine-tuning framework, <a href="https://github.com/Liquid4All/leap-finetune">LEAP</a>.</p><p>Rather than positioning LFM2.5-2.6B as a competitor to the largest frontier models, the company is making a different argument: that a sufficiently capable small model can unlock categories of enterprise applications where latency, privacy, deployment flexibility, or inference costs matter more than absolute benchmark leadership.</p><p>"I do also believe that the best models will be in the cloud, and there's no problem with that," Maxime Labonne, Liquid AI's head of post-training, told VentureBeat in an interview following the launch. "We want to make models for another type of user, and the best way of describing it is: you should use [edge AI] when you can't use a cloud model."</p><h2><b>Small enough for a Raspberry Pi</b></h2><p>Asked about the minimum viable hardware, Labonne said the model runs "very, very well" on CPUs — and that the LFM2 architecture underlying the model was explicitly designed around real-world CPU performance rather than GPU benchmarks.</p><p>"I think the best example is a Raspberry Pi," he said. "We have a lot of demos that show that actually, it works pretty fast on the Raspberry Pi."</p><p>Company-reported measurements indicate decoding throughput of approximately 220 tokens per second on an Apple M5 Max and 113 tokens per second on an AMD Ryzen AI Max+ 395, while using less than 2.5 GB of memory — and around 30 tokens per second on a smartphone. Users can try the models on their phones through Apollo, Liquid AI's mobile app.</p><p>At the other end of the deployment spectrum, Liquid AI reports the model reaches nearly 15,000 output tokens per second on a single Nvidia H100 GPU under sustained concurrent load — roughly 1.3 billion tokens per day on one card. These figures are vendor benchmarks and have not been independently verified.</p><p>For Labonne, memory footprint and speed are not conveniences but hard constraints that determine what can be deployed at all.</p><p>"What we want to show is that it's a really good trade-off, because you get the level of quality that you get with much bigger models, but in a tiny, tiny form factor," he said. "You can deploy it in target devices where you are not able to deploy the other ones at all."</p><h2><b>Trained for agents instead of chatbots</b></h2><p>Liquid AI says LFM2.5-2.6B was developed around the assumption that language models are increasingly consumed through agent frameworks rather than traditional conversational interfaces.</p><p>"Models are not consumed in chatbots anymore. They're really consumed through agentic harnesses, like OpenClaw, like Hermes Agent," Labonne said. "We wanted to make sure that this model is not just good at math or at code, but it's good at using tools."</p><p>The model is pretrained on approximately 34 trillion tokens, with a vocabulary doubled to 128K to better support non-Latin scripts and a dedicated mid-training phase to extend the context window to 128K tokens for long-running agent workflows.</p><p>Post-training follows a four-stage pipeline: supervised fine-tuning, teacher specialization (training separate expert models for domains like instruction following, math, code, and tool use), multi-domain on-policy distillation (MOPD) to merge those experts' capabilities back into a single student model, and finally agentic reinforcement learning. </p><p>During that last stage, the model was trained directly inside production agent harnesses — including Hermes Agent and OpenClaw — on realistic productivity tasks involving research, coding, document management, tool invocation, and workflow automation, exposing it to those harnesses' actual tools, system prompts, and interaction patterns.</p><p>Labonne described the pipeline overhaul as producing a "happy accident": gains that extended well beyond the agentic targets.</p><p>"Through these new training techniques, we also got a lot better at everything. We got better at math, at instruction following. We've never been good at code, actually — and with this, we even got really good at code," he said.</p><h2><b>Building the model — and the harness</b></h2><p>Notably, Liquid AI also built its own agent harness rather than relying solely on existing frameworks, and demonstrated the model running inside it on a phone, planning and calling tools entirely on-device.</p><p>"This is a harness running on a phone, and I don't know if there's any other harness running on a phone," Labonne said.</p><p>The company had two reasons, he explained. The first was necessity — no phone-native harness existed. The second is a different interaction model: today's harnesses wait for a prompt, and Liquid AI wants assistants that act on their own.</p><p>"We want proactive agents. We want agents that run in the background, check what you're doing, check your calendar, and based on this context, do tasks," he said. "That doesn't exist today, really."</p><p>Co-designing the harness and model also lets the software compensate for the model's weak spots. "Everything that the model is bad at, the harness should help the model with — provide as much assistance as possible to make it more reliable," Labonne said. "End users don't care if it's the model or the harness. What they want is that the task is achieved at the end of the day."</p><p>The model nevertheless works out of the box with established harnesses including Hermes Agent, OpenClaw, and Pi, served behind any OpenAI-compatible endpoint.</p><h2><b>Swap the harness, not the model</b></h2><p>For enterprise deployment, Labonne argued the release marks a shift in what small models can be used for. Until now, he said, local models made economic sense mainly as narrowly fine-tuned specialists — trained to do one thing at cloud-model quality, much faster and cheaper. Agentic capability changes that calculus, because the same model can be repurposed by changing the tools around it rather than the model itself.</p><p>"You can have a calendar assistant, and you can reuse the same model and make a meeting assistant that will record what everybody said and summarize it — a bit like Granola, for example," he said. "You don't change the model; you just change the harness. You just change the tools around it. This gives much more generalizability, and it's a lot easier to do and a lot cheaper as well."</p><p>He still recommends fine-tuning for production deployments whenever feasible: "If you don't fine-tune it, you leave some quality on the table. If you fine-tune it well, it's going to match the performance of GPT and Claude — really, if your task is not the most complex task in the world," he said, adding that the barrier to entry has collapsed: "The bar to be able to do fine-tuning now is super low. It's very accessible to everyone."</p><h2><b>How it stacks up against DeepSeek-V4-Flash, Google's Gemma and Alibaba's Qwen</b></h2><p>Liquid AI released its own benchmark comparison charts pitting LFM2.5-2.6B against the models enterprises are most likely to shortlist for the same edge deployments: Google's Gemma 4 E2B (5.1B parameters) and E4B (8B), and Alibaba's Qwen3.5-4B (4.7B) and Qwen3.5-9B (9.7B). </p><p>A separate test by local AI client platform <a href="https://x.com/atomic_chat_hq/status/2085405031474343963">Atomic Chat</a> found that LFM2.5-2.6B completed 35 tool calls to complete three tasks (checking weather and local time in six cities, converting one budget into six currencies, checking four hotels and booking for a date) 3.7 times faster than DeepSeek-V4-Flash (a whopping 284B parameters), the model has <a href="https://x.com/natolambert/status/2084790959636922652?s=20">skyrocketed</a> to the top of <a href="https://openrouter.ai/rankings#top-models">OpenRouter</a> since its release last week. </p><div></div><p>Gemma 4's small models are multimodal generalists, accepting image and audio input alongside text, and use a Per-Layer Embeddings design that keeps only a fraction of their weights active per token — which is why Google markets them by "effective" size (2.3B and 4.5B) despite total footprints of 5.1B and 8B. Alibaba's Qwen3.5 small series, <a href="https://venturebeat.com/technology/alibabas-small-open-source-qwen3-5-9b-beats-openais-gpt-oss-120b-and-can-run">released in March</a>, is natively multimodal from 4B up and leans on scaled reinforcement learning to chase frontier-style reasoning — Alibaba touts the 9B model as matching or beating OpenAI's far larger gpt-oss-120B on reasoning benchmarks.</p><p>LFM2.5-2.6B takes a narrower path: it is text-only, dense, and specialized for agentic work, with Liquid AI shipping separate vision and audio variants of the LFM family rather than folding everything into one checkpoint. </p><p>Where Qwen's post-training reinforcement learning targets reasoning, Liquid's targets tool use inside real agent harnesses. </p><p>The result, per the company's published numbers, is that the smallest model in the comparison leads every instruction-following benchmark (IFBench, Multi-IF, IFStruct) and nearly every tool-use benchmark — 77.83 on ToolSandbox versus 76.44 for Qwen3.5-9B, a model nearly four times its size — trailing only that 9B model on BFCLv4. </p><p>On agentic evaluations it beats both Gemma models across the board and essentially ties the Qwens: 26.89 on BrowseComp+ versus 27.23 for Qwen3.5-9B. It also posts the best score on AA Omniscience, a knowledge benchmark that penalizes hallucination.</p><p>The Qwen models keep the edge where their training focus lies: math (Qwen3.5-9B leads AIME25) and coding, where larger models retain an advantage on LiveCodeBench — though Labonne noted the gap is smaller than the parameter counts would suggest.</p><p>"With LiveCodeBench v6, we might not be the best among these models, but we're also by far the smallest. Showing that we're competitive with them is already quite a big win for me," he said.</p><p>One differentiator cuts the other way: licensing. Gemma 4 and Qwen3.5 ship under the permissive Apache 2.0 license — <a href="https://venturebeat.com/technology/google-releases-gemma-4-under-apache-2-0-and-that-license-change-may-matter">a change Google made specifically to court enterprises</a>. DeepSeek-V4-Flash ships <a href="https://huggingface.co/datasets/choosealicense/licenses/blob/main/markdown/mit.md">under a similarly permissive MIT License</a>. </p><p>Meanwhile, Liquid AI's revenue-gated license (detailed below) asks larger companies to strike a commercial deal. Enterprises above the threshold are effectively trading license friction for footprint and tool-use performance.</p><h2><b>Licensing reflects a commercial middle ground</b></h2><p>LFM2.5-2.6B is distributed under the <a href="https://huggingface.co/LiquidAI/LFM2.5-2.6B/blob/main/LICENSE">LFM Open License v1.0,</a> which permits use, modification, and redistribution — including commercial use — for organizations with less than $10 million in annual revenue. Commercial use by larger companies is not covered by the license, requiring a separate arrangement with Liquid AI; qualified nonprofits are exempt from the threshold for non-commercial and research purposes.</p><p>Labonne framed the structure as a way to sustain model development — "the models are really the moats, so we need to be sensible in the way that we license them; otherwise, we cannot make money, so we can't make more models" — while characterizing the threshold as a light-touch mechanism in practice.</p><p>Asked how the company would even know if a large enterprise quietly deployed the open weights, he was candid: "I think this is a question for our legal team, but personally, I don't know. And even if you're above $10 million, the only thing that we ask you is to contact us."</p><p>The company pairs its licensed model releases with freely published research, he added, including new structured-output evaluations and a training technique that mitigates the repetition loops common in small models — a failure mode he noted Qwen models are "kind of guilty of."</p><h2><b>Small model, big enterprise implications</b></h2><p>The launch coincided with an announcement from <a href="https://www.liquid.ai/blog/macpaw-partners-liquid-ai-on-device-ai-mac-users">MacPaw</a>, the Ukrainian software company behind CleanMyMac and Setapp, of a long-term strategic partnership with Liquid AI to build an on-device AI stack for the Mac. </p><p>Liquid AI will design and fine-tune foundation models for Eney, MacPaw's macOS assistant, running locally on Apple silicon through MacPaw's Elix inference engine and Mnemos memory layer, with results expected later this year.</p><p>Labonne pointed to the deal as a concrete validation of the size argument: "One of the reasons why they chose us is also because the model is quite small, and they don't have all the memory budget to run the other models."</p><p>The release arrives as hardware vendors, operating system developers, and enterprise software companies increasingly invest in local AI execution — and as agent harnesses proliferate across the industry. Liquid AI's bet is that deployment economics, not raw scale, will define an important segment of that market: agents running continuously, everywhere, at zero marginal token cost.</p><p>Whether small, highly optimized agent models become a significant segment of enterprise AI will ultimately depend less on benchmark scores than on operational reliability. But Liquid AI's latest release suggests the next competitive frontier is no longer simply building larger models — it's building models small enough, and capable enough, to run wherever enterprise workflows already live.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Startup Spotlight: HitchPiggy wants to turn empty car seats into a new rideshare marketplace]]></title>
<description><![CDATA[Portland startup HitchPiggy is building a marketplace that connects drivers already traveling between cities with passengers headed the same way, using AI-powered development to tackle affordable regional ridesharing across the Pacific Northwest. Read More]]></description>
<link>https://tsecurity.de/de/3709178/it-nachrichten/startup-spotlight-hitchpiggy-wants-to-turn-empty-car-seats-into-a-new-rideshare-marketplace/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709178/it-nachrichten/startup-spotlight-hitchpiggy-wants-to-turn-empty-car-seats-into-a-new-rideshare-marketplace/</guid>
<pubDate>Fri, 07 Aug 2026 02:34:49 +0200</pubDate>
<content:encoded><![CDATA[<img fetchpriority="high" loading="eager" width="1260" height="709" src="https://cdn.geekwire.com/wp-content/uploads/2026/08/Ridesharing-in-Miami-2-1260x709.jpeg" class="webfeedsFeaturedVisual wp-post-image" alt="" decoding="async" srcset="https://cdn.geekwire.com/wp-content/uploads/2026/08/Ridesharing-in-Miami-2-1260x709.jpeg 1260w, https://cdn.geekwire.com/wp-content/uploads/2026/08/Ridesharing-in-Miami-2-768x432.jpeg 768w, https://cdn.geekwire.com/wp-content/uploads/2026/08/Ridesharing-in-Miami-2-1536x864.jpeg 1536w, https://cdn.geekwire.com/wp-content/uploads/2026/08/Ridesharing-in-Miami-2-2048x1152.jpeg 2048w" sizes="(max-width: 1260px) 100vw, 1260px"><br>Portland startup HitchPiggy is building a marketplace that connects drivers already traveling between cities with passengers headed the same way, using AI-powered development to tackle affordable regional ridesharing across the Pacific Northwest. <a href="https://www.geekwire.com/2026/startup-spotlight-hitchpiggy-wants-to-turn-empty-car-seats-into-a-new-rideshare-marketplace/">Read More</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[I Ported CoLinux to X64 and expanded the driver to support all NT versions starting 5.2(XP) which atp is basically WSL but FOSS (Linux Kernel: 7.1.5 // NT: 10)]]></title>
<description><![CDATA[coLinux was the pre-VM way to run Linux on Windows, two kernels cooperating at ring 0, no hypervisor. It died in 2011, stuck on 32-bit (kernel 2.6.33 // NT6.2) and unable to load on any 64-bit Windows. There is GPU sharing but its kinda miserable, im hoping for 0.6.0 to have that run at full spee...]]></description>
<link>https://tsecurity.de/de/3709102/linux-tipps/i-ported-colinux-to-x64-and-expanded-the-driver-to-support-all-nt-versions-starting-52xp-which-atp-is-basically-wsl-but-foss-linux-kernel-715-nt-10/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709102/linux-tipps/i-ported-colinux-to-x64-and-expanded-the-driver-to-support-all-nt-versions-starting-52xp-which-atp-is-basically-wsl-but-foss-linux-kernel-715-nt-10/</guid>
<pubDate>Thu, 06 Aug 2026 22:06:11 +0200</pubDate>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>coLinux was the pre-VM way to run Linux on Windows, two kernels cooperating at ring 0, no hypervisor. It died in 2011, stuck on 32-bit (kernel 2.6.33 // NT6.2) and unable to load on any 64-bit Windows. There is GPU sharing but its kinda miserable, im hoping for 0.6.0 to have that run at full speed ((currently it is only doing 0.01% bandwidth of the CoXWire i have built puts out))</p> <p>I ported the cooperative model to x86-64, a single unmodified driver that boots a modern Linux 7.1.5 guest on 64-bit XP, 7, 8.1, and 10, with GPU acceleration via virgl (screenshot is KDE Plasma 6 on Windows 10 IoT, rendering on the host GT 730).</p> <p>PS, this is not a VM there's no hypervisor. it needs VBS/HVCI off, so it runs the pre-VBS NT line. Think of it as the machines WSL2 abandoned.</p> <p>Also fixed the old build tree (mingw NDIS header, Python 3 comake) and hit modern-kernel gotchas coLinux never saw, KPTI's dual CR3, etc.</p> <p>Repo: <a href="https://github.com/PhialsBasement/MoCoLinux">https://github.com/PhialsBasement/MoCoLinux</a><br> Easy Installer: <a href="https://github.com/PhialsBasement/MoCoLinux/releases/tag/v0.5.3">https://github.com/PhialsBasement/MoCoLinux/releases/tag/v0.5.3</a> (let me know if there are any bugs, this is kinda hard to test across 4 windows's)<br> Don't run it inside a VM, the cooperative switch conflicts with VMX and you'll get a bugcheck.</p> <p>AI Disclosure: Used Claude heavily during development (and i gotta say i was really disappointed with Opus 5's performance), all the decisions and design details taken here are mine however.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/HearMeOut-13"> /u/HearMeOut-13 </a> <br> <span><a href="https://i.redd.it/cfic3dpo5shh1.gif">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1vh8x1p/i_ported_colinux_to_x64_and_expanded_the_driver/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why metaphor may dictate your security strategy]]></title>
<description><![CDATA[In this week's newsletter, Martin looks at how the metaphors we use to describe AI "escaping" its sandbox can completely change how we react to the threat.
Read more →
The post Why metaphor may dictate your security strategy appeared first on IT Security News.]]></description>
<link>https://tsecurity.de/de/3708927/it-security-nachrichten/why-metaphor-may-dictate-your-security-strategy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708927/it-security-nachrichten/why-metaphor-may-dictate-your-security-strategy/</guid>
<pubDate>Thu, 06 Aug 2026 20:06:16 +0200</pubDate>
<content:encoded><![CDATA[<p>In this week's newsletter, Martin looks at how the metaphors we use to describe AI "escaping" its sandbox can completely change how we react to the threat.</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/why-metaphor-may-dictate-your-security-strategy/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/why-metaphor-may-dictate-your-security-strategy/">Why metaphor may dictate your security strategy</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Stable Update] 2026-08-06 - Kernels, Plasma, Mesa, COSMIC, LibreOffice]]></title>
<description><![CDATA[Hello Manjaro user community, here we have another set of package updates. We are continuing our development of the upcoming release of ‘Bian-May’ which can be expected Mid or End of August. Development speed may be a little slower the upcoming weeks. However, still let us know any issues you may...]]></description>
<link>https://tsecurity.de/de/3708787/unix-server/stable-update-2026-08-06-kernels-plasma-mesa-cosmic-libreoffice/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708787/unix-server/stable-update-2026-08-06-kernels-plasma-mesa-cosmic-libreoffice/</guid>
<pubDate>Thu, 06 Aug 2026 19:16:16 +0200</pubDate>
<content:encoded><![CDATA[<div data-theme-toc="true"> </div>
<p>Hello Manjaro user community, here we have another set of package updates. We are continuing our development of the upcoming release of ‘Bian-May’ which can be expected Mid or End of August. Development speed may be a little slower the upcoming weeks. However, still let us know any issues you may found thus far.</p>
<h3><a name="p-869343-current-promotions-1" class="anchor" href="https://forum.manjaro.org/#p-869343-current-promotions-1" aria-label="Heading link"></a>Current Promotions</h3>
<ul>
<li>Get the latest Gaming Laptop by Slimbook powered by Manjaro: <a href="https://slimbook.com/manjaro">Slimbook Manjaro III</a></li>
<li>Protect your personal data, keep yourself safe with Surfshark VPN: <a href="https://get.surfshark.net/aff_c?offer_id=6&amp;aff_id=14558-">See current promotion</a></li>
</ul>
<h2><a name="p-869343-recent-news-2" class="anchor" href="https://forum.manjaro.org/#p-869343-recent-news-2" aria-label="Heading link"></a>Recent News</h2>

New in Manjaro GNOME!
Or, if you prefer the command line: <a href="https://forum.manjaro.org/t/stable-update-2026-08-06-kernels-plasma-mesa-cosmic-libreoffice/189382/1">(click for more details)</a>

KDE Plasma users with SDDM can now migrate to Plasma Login Manager <a href="https://forum.manjaro.org/t/stable-update-2026-08-06-kernels-plasma-mesa-cosmic-libreoffice/189382/1">(click for more details)</a>

NVIDIA 590 driver drops Pascal support <a href="https://forum.manjaro.org/t/stable-update-2026-08-06-kernels-plasma-mesa-cosmic-libreoffice/189382/1">(click for more details)</a>
<ul>
<li><a href="https://forum.manjaro.org/t/manjaro-26-1-bian-may-preview-released/187389" class="inline-onebox">Manjaro 26.1 Bian-May - Preview released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-26-0-anh-linh-released/184526" class="inline-onebox">Manjaro 26.0 Anh-Linh released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-summit-public-alpha-now-available/176995" class="inline-onebox">Manjaro Summit public Alpha now available</a></li>
<li>As of Linux 6.16.12, the 6.16 series is now EOL (End Of Life). Please install 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 6.17.13, the 6.17 series is now EOL (End Of Life). Please install 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 6.19.14, the 6.19 series is now EOL (End Of Life). Please install 7.0, and/or 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 7.0.14, the 7.0 series is now EOL (End Of Life). Please install 7.1, and/or 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
</ul>

Previous News <a href="https://forum.manjaro.org/t/stable-update-2026-08-06-kernels-plasma-mesa-cosmic-libreoffice/189382/1">(click for more details)</a>
<h2><a name="p-869343-notable-package-updates-3" class="anchor" href="https://forum.manjaro.org/#p-869343-notable-package-updates-3" aria-label="Heading link"></a>Notable Package Updates</h2>
<ul>
<li><strong>Kernels</strong>
<ul>
<li>updates to toolchain</li>
</ul>
</li>
<li><strong>Systemd</strong> <a href="https://github.com/systemd/systemd/compare/v261.1...v261.2">261.2</a></li>
<li><strong>NetworkManager</strong> <a href="https://networkmanager.dev/blog/networkmanager-1-58/">1.58</a></li>
<li><strong>LibreOffice</strong> <a href="https://blog.documentfoundation.org/blog/2026/07/24/libreoffice-26-2-5/">26.2.5</a></li>
<li><strong>dracut</strong> <a href="https://github.com/dracut-ng/dracut/releases/tag/112">112</a></li>
<li><strong>QEmu</strong> <a href="https://wiki.qemu.org/ChangeLog/11.0">11.0.3</a></li>
<li><strong>Vulkan SDK</strong> <a href="https://vulkan.lunarg.com/doc/view/latest/windows/release_notes.html">1.4.357.0</a></li>
<li><strong>Nvidia</strong> <a href="https://www.nvidia.com/en-us/drivers/details/274517/">580.178.04</a>, <a href="https://www.nvidia.com/en-us/drivers/details/274513/">610.57.04</a></li>
<li><strong>COSMIC</strong> Epoch <a href="https://github.com/pop-os/cosmic-epoch/releases/tag/epoch-1.5.0">1.5.0</a></li>
<li>Updates to <strong>Deepin</strong> and <strong>Python</strong></li>
<li><strong>Firefox</strong> <a href="https://www.firefox.com/firefox/153.0.3/releasenotes/">153.0.3</a></li>
<li><strong>Thunderbird</strong> <a href="https://www.thunderbird.net/thunderbird/153.0/releasenotes/">153.0</a></li>
<li><strong>Plasma</strong> <a href="https://kde.org/announcements/plasma/6/6.7.4/">6.7.4</a></li>
<li><strong>Nerd Fonts</strong> <a href="https://www.nerdfonts.com/releases">3.5.0</a></li>
<li><strong>GNOME</strong> <a href="https://discourse.gnome.org/t/gnome-50-4-is-released/37469">50.4</a></li>
</ul>
<h2><a name="p-869343-additional-info-4" class="anchor" href="https://forum.manjaro.org/#p-869343-additional-info-4" aria-label="Heading link"></a>Additional Info</h2>

Python 3.14 info <a href="https://forum.manjaro.org/t/stable-update-2026-08-06-kernels-plasma-mesa-cosmic-libreoffice/189382/1">(click for more details)</a>

Info about AUR packages <a href="https://forum.manjaro.org/t/stable-update-2026-08-06-kernels-plasma-mesa-cosmic-libreoffice/189382/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr>
<p><strong>Our current supported kernels</strong></p>
<ul>
<li>linux61 6.1.180</li>
<li>linux66 6.6.148</li>
<li>linux612 6.12.101</li>
<li>linux618 6.18.42</li>
<li>linux71 7.1.6</li>
<li>linux72 7.2.0-rc6</li>
<li>linux61-rt 6.1.167_rt62</li>
<li>linux66-rt 6.6.135_rt74</li>
<li>linux612-rt 6.12.89_rt18</li>
</ul>
<p><strong>Package Changes</strong> (8/5/26 07:15 CEST)</p>
<ul>
<li>stable core x86_64:  85 new and 85 removed package(s)</li>
<li>stable extra x86_64:  1953 new and 2116 removed package(s)</li>
<li>stable multilib x86_64:  48 new and 48 removed package(s)</li>
</ul>
<p>A list of detailed changes can be found <a href="https://gist.github.com/hphilm/64b39bfacaf84fa5613e2e43e8ae3b88/raw">here</a></p>

<ul>
<li>No issue, everything went smoothly</li>
<li>Yes there was an issue. I was able to resolve it myself.(Please post your solution)</li>
<li>Yes I am currently experiencing an issue due to the update. (Please post about it)</li>
</ul>
<p><a href="https://forum.manjaro.org/t/stable-update-2026-08-06-kernels-plasma-mesa-cosmic-libreoffice/189382/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
<hr>
            <p><small>3 posts - 2 participants</small></p>
            <p><a href="https://forum.manjaro.org/t/stable-update-2026-08-06-kernels-plasma-mesa-cosmic-libreoffice/189382">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Inside Android Skills - Built for deprecation]]></title>
<description><![CDATA[Posted by Jose Alcérreca, Developer Relations Engineer, Android Developer RelationsWe released the official Android Skills in April, and the response surpassed all our expectations. In this blog post, I'll address some of the feedback we received, explaining the philosophy and methodology behind ...]]></description>
<link>https://tsecurity.de/de/3708769/android-tipps/inside-android-skills-built-for-deprecation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708769/android-tipps/inside-android-skills-built-for-deprecation/</guid>
<pubDate>Thu, 06 Aug 2026 19:15:22 +0200</pubDate>
<content:encoded><![CDATA[<i>Posted by Jose Alcérreca, Developer Relations Engineer, Android Developer Relations</i><p><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj8ln8L4mIkAKvPGo4pncpuh0f3-nhaEgXAqmsg2-QiDpkz0Bfowftt9pZJZxvgK78Eg5JXrvqdfvtiP7y7_MsGNhAAuZGy1ExKE01KfZisOs_0hCeCodS0v-bmQJA1WQO7k3tbeUUrRZjQM-mHbPECDLoQa1OmqqORsLJXF8ge0gB5MzV8gl5eIiUJBI0/s8659/Inside%20Android%20Skills%20-%20Built%20for%20deprecation_Blog_V01.png"><img border="0" data-original-height="2765" data-original-width="8659" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj8ln8L4mIkAKvPGo4pncpuh0f3-nhaEgXAqmsg2-QiDpkz0Bfowftt9pZJZxvgK78Eg5JXrvqdfvtiP7y7_MsGNhAAuZGy1ExKE01KfZisOs_0hCeCodS0v-bmQJA1WQO7k3tbeUUrRZjQM-mHbPECDLoQa1OmqqORsLJXF8ge0gB5MzV8gl5eIiUJBI0/s1600/Inside%20Android%20Skills%20-%20Built%20for%20deprecation_Blog_V01.png"></a>We released the official <a href="https://github.com/android/skills" target="_blank">Android Skills</a> in April, and the response surpassed all our expectations. In this blog post, I'll address some of the feedback we received, explaining the philosophy and methodology behind the project. Hopefully, this will also help you understand what happens behind the scenes when you install and use skills, allowing you to make better use of tokens and your own time.</p>

<h2>Why are there so few official skills?</h2>
<p>Currently, we only consider new skills when there's a verifiable knowledge gap in state-of-the-art (SOTA) models. Put simply: you don't need to teach the model what it already knows. (Though there are a few exceptions—read on!)</p>

<p>We’ve released around 20 official skills so far, and they intentionally target highly specific, fast-moving areas that standard models aren't fully grounded on yet—things like AGP 9, Navigation 3, advanced Camera APIs, and Perfetto SQL.</p>

<p>What about core, more general, skills? Every installed skill injects 100–200 tokens into the baseline context of every task you start. If that skill actually activates, that count can quickly jump into the thousands. In most cases, hoarding basic skills is both counterproductive and expensive. Before installing a skill for writing basic Kotlin or Compose, consider if your LLM of choice really needs it, or if it knows those topics well enough already.</p>

<h2>Evaluating skills</h2>
<p>Before their release, each skill is tested against a comprehensive set of evals that prove that the skill delivers clear value. These evals should pass when the skill is active, and fail otherwise. Evals are to skills what integration tests are to code.</p>

<pre><code>timeout_s: 1200
repository:
  url: [redacted - internal git repo]
  working_dir: wear_compose_m3_empty_app
category_ids:
  - wear
prompt: |-
  Add a horizontal pager to MainActivity.kt. Have three pages in the pager. Each page should contain
  the text "Page 1", "Page 2", and "Page 3" respectively in the center of the screen.
commands:
  build:
    - ./gradlew assembleDebug
acceptance_criteria:
  project_builds: true
  llm_diff_judge:
    - Must use `HorizontalPagerScaffold`.
    - Each page should use `AnimatedPage` to wrap a `ScreenScaffold`.</code></pre>

<p><em>Example eval that checks the correct implementation of a horizontal pager on a wear app</em></p>

<p>At a minimum, we test the skill in Android Studio using the latest Gemini Flash model. Depending on the skill, we also ensure compatibility with other models such as Gemini Pro and other agents such as Antigravity, and third-party systems.</p>

<p>All of the evals run with access to the <a href="https://developer.android.com/studio/gemini/access-helpful-resources#android-knowledge-base" target="_blank">Knowledge Base</a>, so if the information is in the documentation, and models decide to search for it, we don't publish a skill for it.</p>

<h2>Using the Android Knowledge Base (Android Studio or Android CLI)</h2>
<p>If you develop Android apps, you should always use the Android Knowledge Base to have access to the official documentation. If you use the agent in Android Studio, it's already available as a tool, but if you use another agent, <a href="https://developer.android.com/tools/agents" target="_blank">install Android CLI</a>. Among other things, it contains the docs command, which gives your agent access to the official Android documentation. Having a single tool is much more efficient than installing hundreds of skills.</p>

<p>If your model is acting overconfident, and you want it to consult the documentation more often, a very common way to motivate it is to add "Always consult the official Android documentation when dealing with Android APIs" to your AGENTS.md file or equivalent. Of course, you can also force this by asking the agent to check the documentation directly in your prompts.</p>

<h2>Why are pull requests disabled?</h2>
<p>Because our evaluation framework depends on internal infrastructure that cannot be open-sourced, we are unable to accept direct pull requests for new skills—without this infrastructure, we would have no way to re-evaluate incoming PR changes. However, we actively monitor community feedback. If you want to report a bug, suggest an optimization, or request a new official skill, please file an <a href="https://github.com/android/skills/issues" target="_blank">issue</a>!</p>

<h2>When do core or basic skills make sense?</h2>
<p>While SOTA models generally don't need basic skills, there are some scenarios where enabling core or community-built skills adds real value. For example:</p>

<ul>
  <li><strong>You're using vague prompts:</strong> Skills amplify your intent. If you give a loose prompt like "add animations to this screen," a specific Compose animation skill can inspire the model, pushing it toward modern APIs or screenshot testing patterns it might not have otherwise considered.</li>
  <li><strong>You want to use smaller, cheaper models:</strong> Frontier LLMs are expensive. If you are offloading routine tasks to smaller open-weight models like Gemma 4, enabling basic skills fills the knowledge gaps that smaller parameters miss.</li>
  <li><strong>You're refactoring or reviewing legacy code:</strong> Models excel at generating code that works, but when editing old codebases, they often prioritize staying consistent with the surrounding legacy patterns over rewriting things with modern accuracy. A specialized reviewer agent equipped with core skills can help break that habit.</li>
  <li><strong>You deviate from the norm:</strong> LLMs love the standard "Google way" of architecting Android apps. If your team uses a highly customized view-layer architecture, the model will struggle to stay aligned. A custom skill explicitly describing your architecture goes a long way.</li>
</ul>

<h2>Where can I find core skills?</h2>
<p>The Android community has your back. Chris Banes has <a href="https://github.com/chrisbanes/skills" target="_blank">a comprehensive collection of skills for Compose and Kotlin</a>, Ivan Morgillo published <a href="https://github.com/hamen/compose_skill" target="_blank">a skill that audits Compose projects</a>, and Jaewoong Eum created two on <a href="https://github.com/skydoves/compose-performance-skills" target="_blank">testing</a> and <a href="https://github.com/skydoves/compose-performance-skills" target="_blank">performance</a>.</p>

<p>Always download skills from reputable sources! I personally wouldn't trust repositories containing dozens or hundreds of Android skills as they're probably AI-generated and untested, and they could even contain malicious or biased instructions. Also, don't install general software engineering skills blindly; a lot of them are tailored for web development.</p>

<h2>Goal: deprecation</h2>
<p>Loosely paraphrasing Karpathy: Skills of today will be in the models of tomorrow. As SOTA models keep improving, we expect skills to be obsolete, especially those built around new APIs. To figure out when to retire them, we run our evals when new models drop. If they pass, we'll keep them around for a few months until most users have transitioned over.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ghost Recon Wildlands gets a new story mission called Last Rites that introduces 'a new kind of danger' as Ubisoft confirms the next game is in development and is now 'ready to put it to the test']]></title>
<description><![CDATA[Ubisoft has confirmed that a new Ghost Recon game is in development as it launches a free story mission for Ghost Recon Wildlands, titled Last Rites.]]></description>
<link>https://tsecurity.de/de/3708603/it-nachrichten/ghost-recon-wildlands-gets-a-new-story-mission-called-last-rites-that-introduces-a-new-kind-of-danger-as-ubisoft-confirms-the-next-game-is-in-development-and-is-now-ready-to-put-it-to-the-test/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708603/it-nachrichten/ghost-recon-wildlands-gets-a-new-story-mission-called-last-rites-that-introduces-a-new-kind-of-danger-as-ubisoft-confirms-the-next-game-is-in-development-and-is-now-ready-to-put-it-to-the-test/</guid>
<pubDate>Thu, 06 Aug 2026 19:04:02 +0200</pubDate>
<content:encoded><![CDATA[Ubisoft has confirmed that a new Ghost Recon game is in development as it launches a free story mission for Ghost Recon Wildlands, titled Last Rites.]]></content:encoded>
</item>
<item>
<title><![CDATA[Exclusive: Mirendil inks $100M+ Google Cloud deal to scale self-improving AI]]></title>
<description><![CDATA[Mirendil has signed a $100 million-plus Google Cloud partnership to expand its compute infrastructure, powering research into self-improving AI systems designed to accelerate scientific discovery and AI development.]]></description>
<link>https://tsecurity.de/de/3708281/it-nachrichten/exclusive-mirendil-inks-100m-google-cloud-deal-to-scale-self-improving-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708281/it-nachrichten/exclusive-mirendil-inks-100m-google-cloud-deal-to-scale-self-improving-ai/</guid>
<pubDate>Thu, 06 Aug 2026 15:22:35 +0200</pubDate>
<content:encoded><![CDATA[Mirendil has signed a $100 million-plus Google Cloud partnership to expand its compute infrastructure, powering research into self-improving AI systems designed to accelerate scientific discovery and AI development.]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI’s ‘Rotten to the core’ defense is its weakest play yet]]></title>
<description><![CDATA[Ancient Greek sophist Protagoras famously said, “There are two sides to every question.” But OpenAI’s latest attempt at reality distortion seems determined to narrow this dispute to just one. In its motion to reject Apple’s complaint, the company does not meaningfully acknowledge the criticisms l...]]></description>
<link>https://tsecurity.de/de/3708258/ai-nachrichten/openais-rotten-to-the-core-defense-is-its-weakest-play-yet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708258/ai-nachrichten/openais-rotten-to-the-core-defense-is-its-weakest-play-yet/</guid>
<pubDate>Thu, 06 Aug 2026 15:21:39 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Ancient Greek sophist Protagoras famously said, “There are two sides to every question.” But OpenAI’s <a href="https://storage.courtlistener.com/recap/gov.uscourts.cand.474095/gov.uscourts.cand.474095.59.0.pdf" target="_blank" rel="noreferrer noopener">latest attempt at reality distortion</a> seems determined to narrow this dispute to just one. In its motion to reject <a href="https://www.computerworld.com/article/4195828/rotten-to-its-core-apple-files-an-explosive-lawsuit-against-openai.html">Apple’s complaint</a>, the company does not meaningfully acknowledge the criticisms levelled against it, preferring instead to recast the case as a grievance over talent retention and product-market failure.</p>



<h2 class="wp-block-heading"><strong>The filing</strong></h2>



<p class="wp-block-paragraph">In case you missed the news, <a href="https://www.independent.co.uk/tech/openai-apple-lawsuit-tradesecret-dismiss-b3028436.html" target="_blank" rel="noreferrer noopener">OpenAI filed a motion to the court</a> to dismiss Apple’s <a href="https://www.computerworld.com/article/4195828/rotten-to-its-core-apple-files-an-explosive-lawsuit-against-openai.html">recent lawsuit against it</a>. In that filing, OpenAI argued that, “Apple should not be permitted to use a baseless and pretextual lawsuit to make up for its shortcomings in the market for talent and retaining its employees, and its failures to integrate AI into its products.”</p>



<p class="wp-block-paragraph">The company’s dismissal claims Apple’s case was, “plainly filed without adequate investigation and built on selectively excerpted communications and ordinary conduct stripped of context,” adding, in a turn of phrase borrowed from Apple’s own complaint, that it is “rotten to its core.”</p>



<h2 class="wp-block-heading"><strong>The narratives can change</strong></h2>



<p class="wp-block-paragraph">As ever with litigation, these are allegations and counter-allegations rather than findings of fact. The value of the filings is that they show how each side wants the court, and the public, to understand the same disputed events. At the moment, we don’t yet know how Apple will respond to OpenAI’s response; it follows that company’s failed attempt to woo public opinion earlier in the week when it deployed what some see as a <a href="https://www.computerworld.com/article/4204910/apple-is-one-of-the-greatest-companies-of-all-time-says-openai.html">“cookie jar” defense</a>, arguing that Apple’s secrets only slipped out because the figurative jar lid was open.</p>



<p class="wp-block-paragraph">OpenAI likely hopes for more success with its latest attempt to defend itself against Apple’s claims it engaged in a coordinated attempt to obtain trade secrets through questionable recruitment practices.</p>



<p class="wp-block-paragraph">Central to the company’s counter-argument are its attempts to recharacterize some of Apple’s claims. For example, Apple alleges that one former staffer, Chang Liu, downloaded confidential files after leaving the company. OpenAI argues that Liu was instead attempting to help ex-colleagues who asked him for assistance. This is a useful example of the Protagorean frame: both companies are trying to extract different meanings from the same event.</p>



<h2 class="wp-block-heading"><strong>What the truth might be</strong></h2>



<p class="wp-block-paragraph">The courts will need to decide which version of events is closer to the truth. What is already clear is that OpenAI has been actively involved in recruiting Apple staff, including the <a href="https://openai.com/sam-and-jony/" target="_blank" rel="noreferrer noopener">services of former Chief Design Officer Jony Ive</a>, as it develops a product that, to a layman like me, sounds likely to compete with Apple hardware. OpenAI says those recruitments reflect Apple’s failure to retain its staff; Apple argues its competitor is using exfiltrated confidential information to guide its hiring. The court will need to decide that story as well.</p>



<p class="wp-block-paragraph">Ultimately, I don’t expect OpenAI’s efforts to have the court reject Apple’s lawsuit to succeed. <a href="https://www.computerworld.com/article/4198342/apple-widens-openai-trade-secrets-fight-with-preservation-orders.html">Apple is asking for discovery</a> precisely so it can test whether its reading of this distorted reality is supported by OpenAI’s internal procedures and the available facts. One of OpenAI’s arguments seems to be that Apple has not researched the matter thoroughly enough; Apple is quite literally requesting discovery to do just that.</p>



<h2 class="wp-block-heading"><strong>What happens next?</strong></h2>



<p class="wp-block-paragraph">I don’t know what discovery might turn up, but it does amuse me to think Apple could build its own large language model to boost the discovery process and identify communication conduits that might otherwise be obscured in the evidence initially available to it. How high, and in what direction, do OpenAI’s claimed recruitment practices go, and who is implicated in them? That’s something we might find out in the coming months.</p>



<p class="wp-block-paragraph">OpenAI’s Protagorean defense extends a little further, of course, as the company also said it had “no use, need or desire for Apple’s trade secrets” because it is building “something entirely new.” This may surprise Apple, which has already alleged that OpenAI contacted its <a href="https://www.applemust.com/openai-discovers-it-takes-time-not-just-design-to-build-great-hardware/#google_vignette" target="_blank" rel="noreferrer noopener">manufacturing partners</a> and sought access to secret manufacturing processes Apple developed with them.</p>



<p class="wp-block-paragraph">Once again, it will be up to the courts to decide whether those events took place, or if OpenAI’s defense has substance. Given that this dispute centers on product design and involves the AI company’s growing army of former Apple design and development staff, I find the denial hard to accept. But courts tend to make their own decisions, for good, or for ill. </p>



<h2 class="wp-block-heading"><strong>Fight or settle</strong></h2>



<p class="wp-block-paragraph">What happens next? I think this attempt to reject the original litigation will fail, which means the case will enter the discovery process before one of two outcomes becomes more likely: A bitter public battle that lasts for years and might well end up in the Supreme Court, or an out-of-court settlement shaped by which side gains the most compelling evidence.</p>



<p class="wp-block-paragraph">Like any war, there are really only two options: one side fights until the other can no longer continue, or both sides find a way to settle. The path to settlement may begin by recognizing that two stories can be applied to the same facts, and that the version closest to the truth often sits somewhere between them. I’m not a lawyer and I don’t have insider insight into the practicalities of the case, but based on what has been revealed so far, the most plausible combined story may be that Apple’s own vulnerabilities helped create an environment OpenAI chose to exploit. If so, Apple’s legal team will be searching hard for evidence of intent. </p>



<p class="wp-block-paragraph">I expect they’ll find it.</p>



<p class="wp-block-paragraph"><em>You can follow me on social media! Join me on <a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener">BlueSky</a>,  <a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener">LinkedIn</a>, <a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener">Mastodon</a> and subscribe to <a href="https://thecorenews.substack.com/p/welcome-to-the-core?r=5l3lg" target="_blank" rel="noreferrer noopener">The Core</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Exclusive: Mirendil inks $100M+ Google Cloud deal to scale self-improving AI]]></title>
<description><![CDATA[Mirendil has signed a $100 million-plus Google Cloud partnership to expand its compute infrastructure, powering research into self-improving AI systems designed to accelerate scientific discovery and AI development.]]></description>
<link>https://tsecurity.de/de/3708256/ai-nachrichten/exclusive-mirendil-inks-100m-google-cloud-deal-to-scale-self-improving-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708256/ai-nachrichten/exclusive-mirendil-inks-100m-google-cloud-deal-to-scale-self-improving-ai/</guid>
<pubDate>Thu, 06 Aug 2026 15:21:36 +0200</pubDate>
<content:encoded><![CDATA[Mirendil has signed a $100 million-plus Google Cloud partnership to expand its compute infrastructure, powering research into self-improving AI systems designed to accelerate scientific discovery and AI development.]]></content:encoded>
</item>
<item>
<title><![CDATA['The Bonfire of the Vanities' series dropped by Apple TV]]></title>
<description><![CDATA[The high-profile television version of Tom Wolfe's "The Bonfire of the Vanities" will reportedly no longer be made for Apple TV because of creative differences.Apple TV will not go ahead with a series dramatization of "The Bonfire of the Vanities."This would have been the third version of Wolfe's...]]></description>
<link>https://tsecurity.de/de/3708238/ios-mac-os/the-bonfire-of-the-vanities-series-dropped-by-apple-tv/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708238/ios-mac-os/the-bonfire-of-the-vanities-series-dropped-by-apple-tv/</guid>
<pubDate>Thu, 06 Aug 2026 15:20:03 +0200</pubDate>
<content:encoded><![CDATA[The high-profile television version of Tom Wolfe's "The Bonfire of the Vanities" will reportedly no longer be made for <a href="https://appleinsider.com/inside/apple-tv" title="Apple TV" data-kpt="1">Apple TV</a> because of creative differences.<br><br><div><img src="https://media.appleinsider.com/gallery/68486-144298-000-lead-Apple-TV-xl.jpg" alt="Apple logo followed by lowercase t and v in a pastel iridescent gradient, centered on a solid black background"><br><span>Apple TV will not go ahead with a series dramatization of "The Bonfire of the Vanities."</span></div><br>This would have been the third version of Wolfe's famous 1980s novel about greed and Wall Street, and it was <a href="https://appleinsider.com/articles/26/04/03/the-bonfire-of-the-vanities-series-headed-to-apple-tv">to be made</a> by "Ally McBeal" and "The Practice" writer/producer David E. Kelley. Now according to <em>Deadline</em>, the <a href="https://deadline.com/2026/08/bonfire-of-vanities-david-e-kelley-matt-reeves-apple-dead-1237021978/">deal is off</a> and the production team will shop the series around to other streamers and networks.<br><br>Neither Apple nor the production team at Warner Bros. Television officially announced the series was in development, but it was first reported to be in the works in April 2026. Now unspecified sources say that Apple TV and Warner Bros were not creatively aligned over the project.<br><br><br> <a href="https://appleinsider.com/articles/26/08/06/the-bonfire-of-the-vanities-series-dropped-by-apple-tv?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/245183?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[WhatsApp is working on AI content labels for Channels, here’s how they work]]></title>
<description><![CDATA[WhatsApp is working on a new feature that will let channel admins label AI-generated media in their updates, helping them meet new transparency requirements that are taking effect in some countries. The feature is currently under development for Android, and it is expected to arrive on iOS as wel...]]></description>
<link>https://tsecurity.de/de/3708232/ios-mac-os/whatsapp-is-working-on-ai-content-labels-for-channels-heres-how-they-work/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708232/ios-mac-os/whatsapp-is-working-on-ai-content-labels-for-channels-heres-how-they-work/</guid>
<pubDate>Thu, 06 Aug 2026 15:19:54 +0200</pubDate>
<content:encoded><![CDATA[WhatsApp is working on a new feature that will let channel admins label AI-generated media in their updates, helping them meet new transparency requirements that are taking effect in some countries. The feature is currently under development for Android, and it is expected to arrive on iOS as well because the change is tied to legal disclosure requirements rather than a platform-specific feature.



WABetaInfo spotted the feature in the latest WhatsApp Android beta. The report says admins will be able to add a visible AI content label after posting an update that contains AI-generated images, videos, or other media, making it easier for followers to identify content created or edited with artificial intelligence.




"After sharing an update that contains AI-generated media, the admin can tap and hold the message to open the context menu. Here, there will be a new option called 'Add AI content label'. This action adds a visible label to the message bubble, so followers can immediately see that the media was generated using artificial intelligence."




WhatsApp focuses on AI-generated media instead of text







The new label appears to target media files rather than text. This means channel admins will likely not have to label text written with AI tools, including content created with WhatsApp's Writing Help feature. Instead, the focus remains on images, videos, and other media that are harder for users to identify as AI-generated.



WhatsApp already introduced a paid partnership label for channel updates, and this new AI content label follows a similar approach. After posting an update, admins can open the message menu and add the disclosure label, which also appears to become permanent once applied.




"The obligation to disclose AI-generated content applies regardless of which tool produced it. This means that the label covers any AI tool that admins might use to create content for their channels."




The feature remains under development and is not yet available for beta testers. WhatsApp has also not confirmed when it plans to release the AI content label publicly or whether it will expand beyond countries where AI disclosure is required by law.]]></content:encoded>
</item>
<item>
<title><![CDATA[Foldable Smartphone Sales Expected To Jump 20% With iPhone Ultra]]></title>
<description><![CDATA[The foldable smartphone market is hitting a major milestone this year. Overall shipments are projected to grow by 20% in 2026 compared to 2025. Industry reports show that this surge in foldable smartphones is heavily driven by Apple as it enters the market. According to supply chain sources, the ...]]></description>
<link>https://tsecurity.de/de/3708234/ios-mac-os/foldable-smartphone-sales-expected-to-jump-20-with-iphone-ultra/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708234/ios-mac-os/foldable-smartphone-sales-expected-to-jump-20-with-iphone-ultra/</guid>
<pubDate>Thu, 06 Aug 2026 15:19:54 +0200</pubDate>
<content:encoded><![CDATA[The foldable smartphone market is hitting a major milestone this year. Overall shipments are projected to grow by 20% in 2026 compared to 2025. Industry reports show that this surge in foldable smartphones is heavily driven by Apple as it enters the market. According to supply chain sources, the upcoming iPhone Ultra is set to shake up the entire category when it arrives later this year.



Supply shortages fail to slow down the rising category growth



The broader smartphone industry is dealing with some tough challenges right now. Phone makers are facing a tighter supply of upstream logic chips and higher memory prices. Despite these supply chain limits, the foldable segment just keeps expanding. Samsung is expected to hold onto its lead for now, but other brands like Huawei are helping to push the momentum forward.



Close to eight years of steady product development have made these folding devices much more mature. That maturity is giving manufacturers the confidence to increase their shipments. Consumers are also getting more comfortable with wider phone designs. People are willing to accept higher prices for new models, provided they feel the price hike is reasonable for what they get.



The tech giant prepares a massive launch for the holidays



The fourth quarter of 2026 is shaping up to be the most important sales period of the year. The Cupertino company plans to debut its first foldable alongside the standard iPhone 18 Pro models this September. Reports indicate the tech giant told its suppliers to build around 10 million units this year alone.



Early pre-order campaigns can definitely generate strong initial sales, but the biggest growth phase will happen during the holiday quarter. This is when overall demand is expected to peak and drive total shipment numbers up. The arrival of a foldable iPhone is giving the entire industry an additional boost.



It looks like 2026 will be the year folding phones finally become mainstream. With more durable screens, better hinges, and major new players joining the space, the category is living up to its early hype. The next few months will show if consumers are ready to upgrade their daily devices to a new shape.]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta Confirms AI Model Launched Autonomous Attack on Another Organization]]></title>
<description><![CDATA[Meta has become the latest technology company to disclose that an AI agent accessed another organization’s online systems during a controlled cybersecurity evaluation. This development has intensified scrutiny regarding the safeguards surrounding autonomous models and the testing environments for...]]></description>
<link>https://tsecurity.de/de/3708200/hacking/meta-confirms-ai-model-launched-autonomous-attack-on-another-organization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708200/hacking/meta-confirms-ai-model-launched-autonomous-attack-on-another-organization/</guid>
<pubDate>Thu, 06 Aug 2026 15:13:58 +0200</pubDate>
<content:encoded><![CDATA[<p>Meta has become the latest technology company to disclose that an AI agent accessed another organization’s online systems during a controlled cybersecurity evaluation. This development has intensified scrutiny regarding the safeguards surrounding autonomous models and the testing environments for agentic AI. The incident reportedly occurred when a Meta AI model, evaluated by the independent security […]</p>
<p>The post <a href="https://gbhackers.com/ai-agents-hack-four-online-services/">Meta Confirms AI Model Launched Autonomous Attack on Another Organization</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The exploit window is shrinking. Most security workflows are not]]></title>
<description><![CDATA[AI is accelerating vulnerability discovery, exploit development, and attacker weaponization faster than most organizations can adapt. Security teams are inundated with vulnerability disclosures, threat intelligence feeds, exploit chatter, and vendor advisories, all demanding immediate attention. ...]]></description>
<link>https://tsecurity.de/de/3708192/it-security-nachrichten/the-exploit-window-is-shrinking-most-security-workflows-are-not/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708192/it-security-nachrichten/the-exploit-window-is-shrinking-most-security-workflows-are-not/</guid>
<pubDate>Thu, 06 Aug 2026 15:08:17 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">AI is accelerating vulnerability discovery, exploit development, and attacker weaponization faster than most organizations can adapt. Security teams are inundated with vulnerability disclosures, threat intelligence feeds, exploit chatter, and vendor advisories, all demanding immediate attention. Yet only a small percentage of vulnerabilities are ever actively exploited in the wild.</p>



<p class="wp-block-paragraph">The challenge is no longer visibility. The challenge is determining which threats actually create exploitable risk in your environment before attackers operationalize them at scale.</p>



<p class="wp-block-paragraph">That operational gap is exactly why we built <strong>Horizon3.ai’s </strong><a href="https://horizon3.ai/nodezero/rapid-response/" target="_blank" rel="noreferrer noopener"><strong>Rapid Response</strong></a>.</p>



<p class="wp-block-paragraph">Rapid Response helps organizations validate exposure, prioritize action, verify fixes, and reduce uncertainty around emerging threats before attackers can scale exploitation.</p>



<h3 class="wp-block-heading">That distinction matters more than ever</h3>



<p class="wp-block-paragraph">Over the past several months, the industry has seen a wave of research and demonstrations highlighting how AI can dramatically increase vulnerability discovery rates. Horizon3.ai’s Attack Team recently <a href="https://horizon3.ai/attack-research/disclosures/cve-2026-34197-activemq-rce-jolokia/" target="_blank" rel="noreferrer noopener">demonstrated this firsthand</a>, using AI to identify and validate a critical Apache ActiveMQ vulnerability in minutes, reinforcing how quickly AI-assisted research can compress the timeline between discovery and exploitation. The pace is impressive, but it also exposes a deeper problem. </p>



<p class="wp-block-paragraph">Most organizations are already overwhelmed with the volume of potential risks being surfaced by myriad tooling; they struggle to prioritize managing existing systems based on today’s knowledge. Adding exponentially more vulnerabilities to analyze without improving clarity around what attackers can actually reach and exploit only increases noise, remediation backlog pressure, and response fatigue.</p>



<p class="wp-block-paragraph">Most organizations do not need more feeds or alerts. They need better signals.</p>



<p class="wp-block-paragraph">Horizon3.ai’s Attack Team continuously evaluates emerging vulnerabilities based on real-world attacker interest, deployment prevalence, accessibility, exploitability, and the likelihood of operationalization at scale. That upstream triage and curation ensures organizations focus attention on the vulnerabilities that present urgent and real risk instead of wasting cycles chasing every headline CVE.</p>



<p class="wp-block-paragraph">Security teams also need faster answers to a much harder set of questions, such as these, which go beyond surface-level criticality:</p>



<ul class="wp-block-list">
<li>Are we actually exploitable?</li>



<li>Which assets are exposed?</li>



<li>What do we do to eliminate this risk?</li>



<li>Did our mitigation and remediation efforts actually work?</li>



<li>Can we prove risk reduction to leadership?</li>
</ul>



<p class="wp-block-paragraph">Most organizations still struggle to answer those questions quickly under pressure.</p>



<p class="wp-block-paragraph">For example, 30 vulnerabilities drop on a Tuesday morning and only one is actually exploitable. Within hours, vendor advisories, threat intelligence feeds, KEV discussions, social media posts, and internal escalations are already spreading across the organization. Security teams scramble to determine:</p>



<ul class="wp-block-list">
<li>which, if any, matter</li>



<li>whether any systems have been affected</li>



<li>whether attackers can realistically reach affected systems</li>



<li>if mitigation options exist</li>



<li>how complex patching would be</li>



<li>how to organize teams around focusing on reducing attacker-relevant exposure.</li>
</ul>



<p class="wp-block-paragraph">Meanwhile, attackers may already be scanning for exposed services, testing public exploits or developing their own, and identifying reachable attack paths. Defenders are still analyzing CVEs, figuring out their own inventory, analyzing scanner results, coordinating spreadsheets — all before even getting to the workflow to address any issues.</p>



<p class="wp-block-paragraph">In many organizations, vulnerability response still depends on disconnected scanners, fragmented reporting, manual coordination across multiple teams, and incomplete visibility into which assets are exposed to exploitation risk, which may be leveraged in attack chains. </p>



<p class="wp-block-paragraph">The result is predictable: Security teams waste valuable time chasing noisy vulnerabilities while genuinely exploitable attack paths remain exposed. Meanwhile, the attacker just needs one exposed, reachable endpoint to throw the exploit at, and the consequences may be devastating.</p>



<h3 class="wp-block-heading">The exploit window is shrinking</h3>



<p class="wp-block-paragraph">Many security programs still operate on workflows built for slower attacker timelines. Triage cycles, remediation coordination, validation testing, and executive reporting often happen across days, weeks, even months. Meanwhile, the time between vulnerability discovery and attacker weaponization continues to shrink, whether vulnerabilities are exploited as zero-days or rapidly operationalized after disclosure. That mismatch creates pressure across every layer of the security organization.</p>



<p class="wp-block-paragraph">Leadership wants immediate answers. Security teams need to prioritize remediation efforts where they make a real difference. Infrastructure teams need actionable guidance. Defenders also need confidence that mitigations actually reduced attacker-relevant exposure instead of simply checking a compliance box. </p>



<p class="wp-block-paragraph">Defenders need workflows designed around reducing real attacker exposure, not just vulnerability awareness. They also need fast, defensible confirmation when a highly publicized vulnerability does not currently create operational risk in their environment. The most valuable answer is: “you are not exploitable.” </p>



<p class="wp-block-paragraph">That proves the effectiveness of operational efforts and allows security teams to direct focus to the next most urgent task. </p>



<p class="wp-block-paragraph">Rapid Response provides a streamlined workflow that provides organizations that proof and peace of mind. </p>



<p class="wp-block-paragraph">Rapid Response delivers early warnings on confirmed exploit risks, targeted validation tests, and guidance, often before vulnerabilities are added to the CISA KEV catalog, helping organizations respond faster and meaningfully reduce risk exposure earlier in the vulnerability lifecycle.</p>



<p class="wp-block-paragraph">When vulnerabilities with high likelihood of real-world exploitation emerge, production-safe, repeatable validation tests are developed and delivered – often within hours – using a combination of AI-assisted research, expert human analysis, and real-world attacker tradecraft.</p>



<p class="wp-block-paragraph">Organizations get a personalized view into their risk exposure, guided remediation workflows, and progress tracking from discovery to resolution.</p>



<p class="wp-block-paragraph">Organizations can:</p>



<ul class="wp-block-list">
<li>Prioritize efforts based on real exposure to urgent threats</li>



<li>Identify and track which assets are exploitable, potentially at risk, mitigated, or not exploitable</li>



<li>Embed into rituals and workflows with seamless handoffs to team in charge of fixing</li>



<li>Verify mitigations safely in production environments</li>



<li>Track remediation progress over time</li>



<li>Demonstrate measurable risk reduction and response timelines</li>
</ul>



<p class="wp-block-paragraph">Attackers already operate continuously and increasingly at machine speed, and we have conviction that exploitability is the defining signal to combat them successfully. We’re delivering these capabilities with key security outcomes in mind: close the exploit window ahead of attackers and prove your efforts kept you safe.</p>



<p class="wp-block-paragraph"><a href="https://docs.horizon3.ai/rapid_response/" target="_blank" rel="noreferrer noopener">Read more</a> about Rapid Response.</p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI’s ‘Rotten to the core’ defense is its weakest play yet]]></title>
<description><![CDATA[Ancient Greek sophist Protagoras famously said, “There are two sides to every question.” But OpenAI’s latest attempt at reality distortion seems determined to narrow this dispute to just one. In its motion to reject Apple’s complaint, the company does not meaningfully acknowledge the criticisms l...]]></description>
<link>https://tsecurity.de/de/3708157/it-nachrichten/openais-rotten-to-the-core-defense-is-its-weakest-play-yet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708157/it-nachrichten/openais-rotten-to-the-core-defense-is-its-weakest-play-yet/</guid>
<pubDate>Thu, 06 Aug 2026 14:54:10 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Ancient Greek sophist Protagoras famously said, “There are two sides to every question.” But OpenAI’s <a href="https://storage.courtlistener.com/recap/gov.uscourts.cand.474095/gov.uscourts.cand.474095.59.0.pdf" target="_blank" rel="noreferrer noopener">latest attempt at reality distortion</a> seems determined to narrow this dispute to just one. In its motion to reject <a href="https://www.computerworld.com/article/4195828/rotten-to-its-core-apple-files-an-explosive-lawsuit-against-openai.html">Apple’s complaint</a>, the company does not meaningfully acknowledge the criticisms levelled against it, preferring instead to recast the case as a grievance over talent retention and product-market failure.</p>



<h2 class="wp-block-heading"><strong>The filing</strong></h2>



<p class="wp-block-paragraph">In case you missed the news, <a href="https://www.independent.co.uk/tech/openai-apple-lawsuit-tradesecret-dismiss-b3028436.html" target="_blank" rel="noreferrer noopener">OpenAI filed a motion to the court</a> to dismiss Apple’s <a href="https://www.computerworld.com/article/4195828/rotten-to-its-core-apple-files-an-explosive-lawsuit-against-openai.html">recent lawsuit against it</a>. In that filing, OpenAI argued that, “Apple should not be permitted to use a baseless and pretextual lawsuit to make up for its shortcomings in the market for talent and retaining its employees, and its failures to integrate AI into its products.”</p>



<p class="wp-block-paragraph">The company’s dismissal claims Apple’s case was, “plainly filed without adequate investigation and built on selectively excerpted communications and ordinary conduct stripped of context,” adding, in a turn of phrase borrowed from Apple’s own complaint, that it is “rotten to its core.”</p>



<h2 class="wp-block-heading"><strong>The narratives can change</strong></h2>



<p class="wp-block-paragraph">As ever with litigation, these are allegations and counter-allegations rather than findings of fact. The value of the filings is that they show how each side wants the court, and the public, to understand the same disputed events. At the moment, we don’t yet know how Apple will respond to OpenAI’s response; it follows that company’s failed attempt to woo public opinion earlier in the week when it deployed what some see as a <a href="https://www.computerworld.com/article/4204910/apple-is-one-of-the-greatest-companies-of-all-time-says-openai.html">“cookie jar” defense</a>, arguing that Apple’s secrets only slipped out because the figurative jar lid was open.</p>



<p class="wp-block-paragraph">OpenAI likely hopes for more success with its latest attempt to defend itself against Apple’s claims it engaged in a coordinated attempt to obtain trade secrets through questionable recruitment practices.</p>



<p class="wp-block-paragraph">Central to the company’s counter-argument are its attempts to recharacterize some of Apple’s claims. For example, Apple alleges that one former staffer, Chang Liu, downloaded confidential files after leaving the company. OpenAI argues that Liu was instead attempting to help ex-colleagues who asked him for assistance. This is a useful example of the Protagorean frame: both companies are trying to extract different meanings from the same event.</p>



<h2 class="wp-block-heading"><strong>What the truth might be</strong></h2>



<p class="wp-block-paragraph">The courts will need to decide which version of events is closer to the truth. What is already clear is that OpenAI has been actively involved in recruiting Apple staff, including the <a href="https://openai.com/sam-and-jony/" target="_blank" rel="noreferrer noopener">services of former Chief Design Officer Jony Ive</a>, as it develops a product that, to a layman like me, sounds likely to compete with Apple hardware. OpenAI says those recruitments reflect Apple’s failure to retain its staff; Apple argues its competitor is using exfiltrated confidential information to guide its hiring. The court will need to decide that story as well.</p>



<p class="wp-block-paragraph">Ultimately, I don’t expect OpenAI’s efforts to have the court reject Apple’s lawsuit to succeed. <a href="https://www.computerworld.com/article/4198342/apple-widens-openai-trade-secrets-fight-with-preservation-orders.html">Apple is asking for discovery</a> precisely so it can test whether its reading of this distorted reality is supported by OpenAI’s internal procedures and the available facts. One of OpenAI’s arguments seems to be that Apple has not researched the matter thoroughly enough; Apple is quite literally requesting discovery to do just that.</p>



<h2 class="wp-block-heading"><strong>What happens next?</strong></h2>



<p class="wp-block-paragraph">I don’t know what discovery might turn up, but it does amuse me to think Apple could build its own large language model to boost the discovery process and identify communication conduits that might otherwise be obscured in the evidence initially available to it. How high, and in what direction, do OpenAI’s claimed recruitment practices go, and who is implicated in them? That’s something we might find out in the coming months.</p>



<p class="wp-block-paragraph">OpenAI’s Protagorean defense extends a little further, of course, as the company also said it had “no use, need or desire for Apple’s trade secrets” because it is building “something entirely new.” This may surprise Apple, which has already alleged that OpenAI contacted its <a href="https://www.applemust.com/openai-discovers-it-takes-time-not-just-design-to-build-great-hardware/#google_vignette" target="_blank" rel="noreferrer noopener">manufacturing partners</a> and sought access to secret manufacturing processes Apple developed with them.</p>



<p class="wp-block-paragraph">Once again, it will be up to the courts to decide whether those events took place, or if OpenAI’s defense has substance. Given that this dispute centers on product design and involves the AI company’s growing army of former Apple design and development staff, I find the denial hard to accept. But courts tend to make their own decisions, for good, or for ill. </p>



<h2 class="wp-block-heading"><strong>Fight or settle</strong></h2>



<p class="wp-block-paragraph">What happens next? I think this attempt to reject the original litigation will fail, which means the case will enter the discovery process before one of two outcomes becomes more likely: A bitter public battle that lasts for years and might well end up in the Supreme Court, or an out-of-court settlement shaped by which side gains the most compelling evidence.</p>



<p class="wp-block-paragraph">Like any war, there are really only two options: one side fights until the other can no longer continue, or both sides find a way to settle. The path to settlement may begin by recognizing that two stories can be applied to the same facts, and that the version closest to the truth often sits somewhere between them. I’m not a lawyer and I don’t have insider insight into the practicalities of the case, but based on what has been revealed so far, the most plausible combined story may be that Apple’s own vulnerabilities helped create an environment OpenAI chose to exploit. If so, Apple’s legal team will be searching hard for evidence of intent. </p>



<p class="wp-block-paragraph">I expect they’ll find it.</p>



<p class="wp-block-paragraph"><em>You can follow me on social media! Join me on <a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener">BlueSky</a>,  <a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener">LinkedIn</a>, <a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener">Mastodon</a> and subscribe to <a href="https://thecorenews.substack.com/p/welcome-to-the-core?r=5l3lg" target="_blank" rel="noreferrer noopener">The Core</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta launches Muse Code for complex software work with persistent AI agents]]></title>
<description><![CDATA[Meta has released a beta coding agent designed to handle complex software assignments across large codebases.



Available for macOS and Linux, Muse Code uses the company’s new Muse Spark 1.2 model. It includes specialized background agents that remain active throughout a session instead of being...]]></description>
<link>https://tsecurity.de/de/3708019/ai-nachrichten/meta-launches-muse-code-for-complex-software-work-with-persistent-ai-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708019/ai-nachrichten/meta-launches-muse-code-for-complex-software-work-with-persistent-ai-agents/</guid>
<pubDate>Thu, 06 Aug 2026 14:03:14 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Meta has released a beta coding agent designed to handle complex software assignments across large codebases.</p>



<p class="wp-block-paragraph">Available for macOS and Linux, Muse Code uses the company’s new Muse Spark 1.2 model. It includes specialized background agents that remain active throughout a session instead of being created separately for individual tasks.</p>



<p class="wp-block-paragraph">The agents carry out work asynchronously and decide when to report their findings to the primary agent. Meta said keeping them active reduces repeated information gathering and the need for developer direction during difficult, multi-step tasks.</p>



<p class="wp-block-paragraph">“Muse Code uses a local event log in which every model call, tool run, approval, and edit is appended,” Meta said in a post, adding that the record “makes the runtime replay-exact and restart-safe” and allows the agent to resume precisely where it stopped after a crash.</p>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/4192724/metas-ai-chief-says-new-muse-spark-update-will-sharpen-coding-agentic-ai.html">Muse Spark 1.2</a> is available through Muse Code and the Meta Model API, for which Meta announced expanded global access.</p>



<h2 class="wp-block-heading">Training and evaluation</h2>



<p class="wp-block-paragraph">Meta said it co-trained Muse Spark 1.2 with Muse Code to improve the model’s performance and usability when used with the agent. The training incorporated Muse Code’s tools and agent workflows, while Meta increased the computing resources used for coding and broadened the range of development environments.</p>



<p class="wp-block-paragraph">The model was also trained on longer assignments, including whole-repository generation and large end-to-end software projects.</p>



<p class="wp-block-paragraph"><a href="https://omdia.tech.informa.com/authors/lian-jye-su" target="_blank" rel="noreferrer noopener">Lian Jye Su</a>, chief analyst at Omdia, said Meta’s co-training approach was unlikely to provide a clear advantage because rivals were also developing their coding models and <a href="https://www.infoworld.com/article/4164601/harness-teams-of-coding-agents-with-squad.html">agent harnesses</a> in close coordination.</p>



<p class="wp-block-paragraph">“Other vendors, such as OpenAI and Anthropic, have been treating harness engineering as part of the training process,” Su said.</p>



<p class="wp-block-paragraph">Optimizing the model and agent together could improve planning and context handling, but any competitive advantage would need to be demonstrated through better results on enterprise projects while reducing the need for human intervention, said <a href="https://pareekh.com/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, CEO of Pareekh Consulting.</p>



<p class="wp-block-paragraph">Meta reported that Muse Spark 1.2 achieved an 82.9% pass@1 score on Terminal-Bench 2.1, behind Claude Opus 5 but slightly ahead of GPT-5.6 Terra. On DeepSWE 1.1, the model scored 59.3%, trailing both rivals.</p>



<p class="wp-block-paragraph">For Terminal-Bench 2.1 and DeepSWE 1.1, Meta evaluated each model with its selected coding agent rather than using the same agent throughout. It also acknowledged that rival proprietary models may have performed differently under tools and prompts designed specifically for them.</p>



<p class="wp-block-paragraph"><a href="https://counterpointresearch.com/en/opinion-leader/10" target="_blank" rel="noreferrer noopener">Neil Shah</a>, vice president of research at Counterpoint Research, said cross-vendor comparisons would be more meaningful if models were evaluated with third-party tools or within the same agent harness.</p>



<p class="wp-block-paragraph">“The key metric for CIOs is the pass rate against an enterprise’s own pipeline, which will determine the success of the model-and-harness bundle, or, in this case, Meta’s Muse Spark 1.2 and Muse Code,” Shah said. “This will be the real <a href="https://www.infoworld.com/article/4033758/why-benchmarks-are-key-to-ai-progress.html">benchmark</a>.”</p>



<h2 class="wp-block-heading">Enterprise adoption hurdles</h2>



<p class="wp-block-paragraph">Su said security and governance requirements could slow enterprise adoption, particularly where coding agents must be connected to existing identity systems.</p>



<p class="wp-block-paragraph">“Many enterprises are still less willing to open up their CI/CD environments for AI tool integration,” Su said.</p>



<p class="wp-block-paragraph">Shah said companies would need controls governing how agents access repositories, along with records showing how models and agent workflows handle enterprise data. He also cited the difficulty of forecasting token consumption and its effect on costs.</p>



<p class="wp-block-paragraph">Meta’s pricing structure also creates a data-governance choice. The company said the lower-priced Contributor model may be used to improve its products, while the standard tier is not used for that purpose.</p>



<p class="wp-block-paragraph">The Contributor tier costs $0.10 per million input tokens and $0.20 per million output tokens, compared with $1.25 and $4.25, respectively, for the standard tier.</p>



<p class="wp-block-paragraph">“There is also a fear of vendor lock-in and reliance, as it may hurt long-term flexibility and system interoperability,” Su added.</p>



<p class="wp-block-paragraph">Jain said adoption was likely to begin with narrowly defined, lower-risk work before companies allowed persistent agents to modify critical production code.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta Confirms AI Model Launched Autonomous Attack on Another Organization]]></title>
<description><![CDATA[Meta has become the latest technology company to disclose that an AI agent accessed another organization’s online systems during a controlled cybersecurity evaluation. This development has intensified scrutiny regarding the safeguards surrounding autonomous models and the testing environments for...]]></description>
<link>https://tsecurity.de/de/3707981/it-security-nachrichten/meta-confirms-ai-model-launched-autonomous-attack-on-another-organization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707981/it-security-nachrichten/meta-confirms-ai-model-launched-autonomous-attack-on-another-organization/</guid>
<pubDate>Thu, 06 Aug 2026 13:35:23 +0200</pubDate>
<content:encoded><![CDATA[<p>Meta has become the latest technology company to disclose that an AI agent accessed another organization’s online systems during a controlled cybersecurity evaluation. This development has intensified scrutiny regarding the safeguards surrounding autonomous models and the testing environments for agentic AI. The incident reportedly occurred when a Meta AI model, evaluated by the independent security […]</p>
<p>The post <a href="https://gbhackers.com/ai-agents-hack-four-online-services/">Meta Confirms AI Model Launched Autonomous Attack on Another Organization</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS, Google und Vercel: Agenten-Toolcalls ohne Modellprüfung öffnen Angriffswege]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Sicherheitslücken in Agent-Infrastrukturen bei AWS, Google und Vercel lassen Tool-Calls an Agenten-Werkzeuge durchreichen, ohne dass zuvor ein legitimer Modell-Run stattfindet. In mehreren Pfaden kann die Laufzeit Daten annehmen, die wie vom Modell generierte Tool-Aufrufe a...]]></description>
<link>https://tsecurity.de/de/3707979/it-security-nachrichten/aws-google-und-vercel-agenten-toolcalls-ohne-modellpruefung-oeffnen-angriffswege/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707979/it-security-nachrichten/aws-google-und-vercel-agenten-toolcalls-ohne-modellpruefung-oeffnen-angriffswege/</guid>
<pubDate>Thu, 06 Aug 2026 13:35:17 +0200</pubDate>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-agenten-toolcalls-ohne-modellturn.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-agenten-toolcalls-ohne-modellturn.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-agenten-toolcalls-ohne-modellturn-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-agenten-toolcalls-ohne-modellturn-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-agenten-toolcalls-ohne-modellturn-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-agenten-toolcalls-ohne-modellturn-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-agenten-toolcalls-ohne-modellturn-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – Sicherheitslücken in Agent-Infrastrukturen bei AWS, Google und Vercel lassen Tool-Calls an Agenten-Werkzeuge durchreichen, ohne dass zuvor ein legitimer Modell-Run stattfindet. In mehreren Pfaden kann die Laufzeit Daten annehmen, die wie vom Modell generierte Tool-Aufrufe aussehen, und sie dann ohne Validierung ausführen. Betroffen sind unter anderem Amazon Bedrock AgentCore, Googles Agent Development […]</p>
<div><a href="https://www.it-boltwise.de/aws-google-und-vercel-agenten-toolcalls-ohne-modellpruefung-oeffnen-angriffswege.html">... den vollständigen Artikel <strong>»AWS, Google und Vercel: Agenten-Toolcalls ohne Modellprüfung öffnen Angriffswege«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/aws-google-und-vercel-agenten-toolcalls-ohne-modellpruefung-oeffnen-angriffswege.html">AWS, Google und Vercel: Agenten-Toolcalls ohne Modellprüfung öffnen Angriffswege</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS targets AI cost concerns with new Marketplace Insights tool]]></title>
<description><![CDATA[AWS has added AI Insights to AWS Marketplace, a feature that it says is designed to help CIOs and developers better evaluate and compare products using AI-generated summaries and recommendations as enterprises grapple with increasing pressure to justify technology spending.



“Available in the p...]]></description>
<link>https://tsecurity.de/de/3707971/it-security-nachrichten/aws-targets-ai-cost-concerns-with-new-marketplace-insights-tool/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707971/it-security-nachrichten/aws-targets-ai-cost-concerns-with-new-marketplace-insights-tool/</guid>
<pubDate>Thu, 06 Aug 2026 13:29:02 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">AWS has added AI Insights to AWS Marketplace, a feature that it says is designed to help CIOs and developers better evaluate and compare products using AI-generated summaries and recommendations as enterprises grapple with increasing pressure to justify technology spending.</p>



<p class="wp-block-paragraph">“Available in the pricing section of the listing in AWS Marketplace, AI Insights explains each product’s pricing in plain language: what a pricing unit maps to, how your bill changes as usage scales, how multiple pricing dimensions combine into one cost, and what is and isn’t included,” AWS wrote in a <a href="https://aws.amazon.com/about-aws/whats-new/2026/08/aws-marketplace-ai-insights/" target="_blank" rel="noreferrer noopener">blog post</a>.</p>



<h2 class="wp-block-heading">Critical for procurement of AI-based tools, offerings</h2>



<p class="wp-block-paragraph">Analysts say the new feature could prove critical for CIOs procuring AI-based tools and services.</p>



<p class="wp-block-paragraph">“AI pricing in the marketplace has always been a black box. You see a number per token, per API call, or per compute unit, but understanding what that actually means at enterprise scale requires significant effort to piece together,” said <a href="https://www.linkedin.com/in/znamit/" target="_blank" rel="noreferrer noopener">Amit Jena</a>, AI development manager at IT Consulting firm Kanerika.</p>



<p class="wp-block-paragraph">“CIOs are increasingly being held to account for AI spend, not just AI adoption, and that shift has created a genuine need for pricing transparency at the point of evaluation,” Jena added.</p>



<p class="wp-block-paragraph">The challenge, according to <a href="https://pareekh.com/about/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, principal analyst at Pareekh Consulting, has compounded for CIOs because AI-based tools are now moving away from simple per-user subscription fees into complex consumption-based pricing.</p>



<p class="wp-block-paragraph">“With tokens, API calls, agent executions, and compute, forecasting total cost of ownership has become very challenging. A feature like AI Insights should give CIOs pre-purchase clarity by translating multi-dimensional pricing into plain language on the listing, letting them calculate budget limits before committing,” Jain said.</p>



<p class="wp-block-paragraph">Prior to the update, evaluating pricing for AI tools required separate research exercises outside the marketplace, with teams having to visit seller websites, read technical documentation written for developers rather than procurement leaders, and build their own cost models from scratch, Jena pointed out.</p>



<p class="wp-block-paragraph">“That process was slow, error-prone, and often resulted in PoC projects frequently getting stalled in legal and <a href="https://www.cio.com/article/416337/what-is-finops-your-guide-to-cloud-cost-management.html">FinOps</a> reviews,” echoed Jain.</p>



<p class="wp-block-paragraph">“Enterprises that deployed agentic AI tools without clear pricing rules often suffered post-implementation bill shock when autonomous workflows unexpectedly multiplied backend API calls. These runaway costs led CFOs to freeze AI budgets, resulting in abandoned software pilots and failed ROI metrics,” Jain added.</p>



<p class="wp-block-paragraph">The update, then, essentially would help CIOs defend a purchase decision in front of a CFO or board, Jena pointed out, adding that accelerated procurement cycles would also indirectly lead to faster delivery cycles.</p>



<h2 class="wp-block-heading">Quality of pricing information will be key</h2>



<p class="wp-block-paragraph">The analyst, however, cautioned that the usefulness of AI Insights as a feature will ultimately depend on the quality of pricing information published by software vendors offering tools on the Marketplace.</p>



<p class="wp-block-paragraph">“AI Insights draws from seller-published pricing and their public websites, so the quality of the explanation is only as good as what sellers publish. If pricing pages remain vague, the AI-generated explanation will reflect that,” Jena said.</p>



<p class="wp-block-paragraph">Even so, the analyst further pointed out that the feature could have a broader positive effect by encouraging other hyperscalers and enterprise software vendors to make pricing documentation more transparent in their respective marketplaces.</p>



<p class="wp-block-paragraph">“Azure Marketplace and Google Cloud Marketplace will face pressure to offer something equivalent. The underlying driver is the same: enterprise buyers are now accountable for AI ROI in ways they were not two years ago, and pricing opacity is becoming a genuine risk to AI adoption at scale,” Jena said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI says Apple’s trade secrets lawsuit is ‘rotten to its core’]]></title>
<description><![CDATA[OpenAI has asked a federal judge to toss out Apple's landmark lawsuit accusing the ChatGPT maker of stealing trade secrets, describing the allegations as "meritless." In a motion filed yesterday to dismiss the complaint, OpenAI says that Apple is mischaracterizing both the actions of the AI start...]]></description>
<link>https://tsecurity.de/de/3707921/ai-nachrichten/openai-says-apples-trade-secrets-lawsuit-is-rotten-to-its-core/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707921/ai-nachrichten/openai-says-apples-trade-secrets-lawsuit-is-rotten-to-its-core/</guid>
<pubDate>Thu, 06 Aug 2026 13:18:56 +0200</pubDate>
<content:encoded><![CDATA[OpenAI has asked a federal judge to toss out Apple's landmark lawsuit accusing the ChatGPT maker of stealing trade secrets, describing the allegations as "meritless." In a motion filed yesterday to dismiss the complaint, OpenAI says that Apple is mischaracterizing both the actions of the AI startup's employees as theft, and "generic" product development information […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft Web IQ: Ground your AI agents with up-to-date web data]]></title>
<description><![CDATA[Microsoft has unveiled a suite of IQ products over the last few months. Work IQ, Fabric IQ, and Foundry IQ build on what Microsoft used to call its “Graphs,” the underlying data architecture that underpins its cloud services. These graphs provided a way to query the data your business uses, treat...]]></description>
<link>https://tsecurity.de/de/3707919/ai-nachrichten/microsoft-web-iq-ground-your-ai-agents-with-up-to-date-web-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707919/ai-nachrichten/microsoft-web-iq-ground-your-ai-agents-with-up-to-date-web-data/</guid>
<pubDate>Thu, 06 Aug 2026 13:18:55 +0200</pubDate>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Microsoft has unveiled <a href="https://www.microsoft.com/en-us/ai/microsoft-iq#Products">a suite of IQ products</a> over the last few months. Work IQ, Fabric IQ, and Foundry IQ build on what Microsoft used to call its “Graphs,” the underlying data architecture that underpins its cloud services. These graphs provided a way to query the data your business uses, treating that data as nodes in a graph database and using the <a href="https://www.infoworld.com/article/2267992/what-is-graphql-better-apis-by-design.html" data-type="link" data-id="https://www.infoworld.com/article/2267992/what-is-graphql-better-apis-by-design.html">GraphQL API model</a> to extract that data — for example, to pull data related to a specific individual held across the various Microsoft 365 applications.</p>



<p class="wp-block-paragraph">The IQ suite follows a similar approach, using the same data, but treating it as the sparse vector store needed to provide grounding data for <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html" data-type="link" data-id="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html">LLM</a>-based applications. By treating the data as a set of <a href="https://www.infoworld.com/article/2335281/vector-databases-in-llms-and-search.html" data-type="link" data-id="https://www.infoworld.com/article/2335281/vector-databases-in-llms-and-search.html">embedding vectors</a>, and integrating it with <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html" data-type="link" data-id="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">Model Context Protocol</a> (MCP) servers, Microsoft is giving you the necessary tools to tie LLM output to your data, reducing the risk of hallucination and improving accuracy. Using your own data is a key part of delivering effective agents, ensuring they work within your constraints.</p>



<h2 class="wp-block-heading">Extending IQ to the web</h2>



<p class="wp-block-paragraph"><a href="https://www.microsoft.com/en-us/webiq" data-type="link" data-id="https://www.microsoft.com/en-us/webiq">Web IQ</a>, the latest member of the IQ suite, was unveiled at Build 2026. A modernization of the retired Bing Search APIs, <a href="https://webiq.microsoft.ai/documentation/overview/">Web IQ is an agent-focused web search tool</a> that builds on the massive Bing search index to provide up-to-date general information for use in your applications.</p>



<p class="wp-block-paragraph">It may seem a little odd to be talking about a web-wide source of grounding data in the context of a suite of tools that exist to improve the accuracy of your AI applications by providing access to your Microsoft-hosted data. However, in many cases you want to link your agent not only to your data but also to related information from the wider world. For example, an agent powering an ecommerce service could use Web IQ and web-based data sources to provide product comparisons. An agent managing stock levels for a product that is weather-sensitive could use Web IQ as a source of weather data, using Bing’s multiple weather feeds and forecasts.</p>



<p class="wp-block-paragraph">Just as Google Gemini drew on Google Search, Microsoft Copilot began by using Bing search data to provide grounding for consumer chatbots. It’s easy to take a service like Bing and use it with a LLM, as the nearest neighbor search algorithms use semantic vector similarity techniques to find results that look like your query, ranking them according to their proximity to your search terms.</p>



<p class="wp-block-paragraph">Microsoft has been tuning its search vector index and the underlying technology stack to work with agents, as agents operate much differently than humans searching the web or querying a chatbot. Providing web search capabilities to agents means having to deal with persistent queries, as the agent hunts for the information it needs, refining queries and applying reasoning algorithms to develop the response it needs. LLM inferencing requires quick responses that deliver large amounts of data, working with queries that go far beyond the one-word or two-word requests that are typical of humans.</p>



<h2 class="wp-block-heading">More than the training weights</h2>



<p class="wp-block-paragraph">Using Web IQ gives you access to up-to-date information, beyond the training data used to build and weight an LLM. Bing’s crawler works within the standards developed by the search engine industry, obeying meta tags and using its own algorithms to crawl regularly updated websites more often. Bing’s crawler ensures that data is both fresh and being used appropriately, with a focus on quality rather than quantity.</p>



<p class="wp-block-paragraph">Providing access to web data is only part of Web IQ. Microsoft is using Web IQ to host its own models to manage embeddings, ranking, and content extraction, all running on the company’s global hyperscale platform. The intent here is to use only a limited number of models, to keep the system performance high while aiming to deliver accurate results. The Web IQ models are different from those used to deliver search results to humans, as they’re designed to deliver responses that are suitable for LLMs to use for reasoning.</p>



<p class="wp-block-paragraph">The underlying search system is based on the <a href="https://www.microsoft.com/en-us/research/project/project-akupara-approximate-nearest-neighbor-search-for-large-scale-semantic-search/" data-type="link" data-id="https://www.microsoft.com/en-us/research/project/project-akupara-approximate-nearest-neighbor-search-for-large-scale-semantic-search/">DiskANN algorithm</a> developed by Microsoft Research, which allows fast search without requiring enormous amounts of in-memory data access. This approach has been extended to manage information retrieval at scale, building on Microsoft’s distributed systems architectures, to support the demands Microsoft is seeing from agent-based systems. At the same time, it must respond to the rapidly changing economics of inference, where token costs now demand the best possible output from the fewest tokens.</p>



<p class="wp-block-paragraph">To meet those economic demands, the Web IQ platform doesn’t deliver whole documents to querying agents. Whole documents can lead to expensive inference further down the chain, as LLMs process results repeatedly to drive the agent workflow. Instead, Web IQ structures the information retrieved from the underlying search engine data, delivering what Microsoft calls “structured evidence objects” as well as passage-level information from unstructured text documents. This should result in a much higher signal-to-noise ratio than simply querying a search engine, with a focus on delivering information that lets agents work using fewer tokens.</p>



<h2 class="wp-block-heading">Using Web IQ in your agent code</h2>



<p class="wp-block-paragraph"><a href="https://webiq.microsoft.ai/documentation/api-reference/web/">The API for Web IQ</a> is a standard REST cal<a href="https://webiq.microsoft.ai/documentation/api-reference/web/">l</a>, delivering a request object to the Web IQ endpoint. Along with your API authorization key, you will send a query, a set of parameters that control the number of results returned, the language and region used, and the maximum size of the responses and the format used. Responses can be returned in text, HTML, or markdown formats, as well as extracted passages that are selected for context. All other options return the full document, so can be more expensive to use. Markdown is an interesting alternative, as it can be used as the basis for giving agents semantic memories.</p>



<p class="wp-block-paragraph">Results include important contextual and citation information, including web page titles and URLs, as well as data about when the site was last crawled and how stale the underlying information is. This can be used to improve grounding and provide more information that can be included in formatted responses — much in the same way as Bing’s Copilot displays context in the form of footnotes in its responses.</p>



<p class="wp-block-paragraph">Responses to <a href="https://webiq.microsoft.ai/documentation/api-reference/videos/" data-type="link" data-id="https://webiq.microsoft.ai/documentation/api-reference/videos/">video searches</a> include text descriptions. If these aren’t provided as part of the original web content, they will be generated by an LLM. The same approach is used for <a href="https://webiq.microsoft.ai/documentation/api-reference/images/" data-type="link" data-id="https://webiq.microsoft.ai/documentation/api-reference/images/">image searches</a>, with both offering the same contextual cues as the web search API. If you don’t care about the type of data being returned, you can choose a “<a href="https://webiq.microsoft.ai/documentation/api-reference/classic/" data-type="link" data-id="https://webiq.microsoft.ai/documentation/api-reference/classic/">classic search</a>,” which will return text, images, video, and news.</p>



<h2 class="wp-block-heading">Supporting autonomous agents</h2>



<p class="wp-block-paragraph">Microsoft provides LLM-ready documentation for the Web IQ service, with an <code>llms.txt</code> file and an OpenAPI description. These allow AI tools to discover Web IQ capabilities and include them in workflows as part of autonomous operations, so that agents and other AI applications can implement grounding calls to Web IQ whenever user interactions require them. The API <a href="https://webiq.microsoft.ai/documentation/error-handling/">descriptions include errors</a> as well as the structure of a standard 200 response.</p>



<p class="wp-block-paragraph">As Web IQ is designed for use by modern agent frameworks, the Web IQ API is available through an MCP server. The <a href="https://webiq.microsoft.ai/documentation/mcp/" data-type="link" data-id="https://webiq.microsoft.ai/documentation/mcp/">Web IQ MCP server</a> exposes tools that map to API calls: web, videos, news, and images. They also include a browse option, which lets you pull content from a target URL. The service can be configured with a standard JSON file and requires an API key to control access and manage billing. If your account doesn’t have access to a specific tool, then it won’t be available from inside the MCP server.</p>



<p class="wp-block-paragraph">If you’re building an agent and you want to evaluate the Web IQ MCP server, it can be added to common coding agents, such as the GitHub Copilot CLI. You can then test it out using familiar tools and generate code that can be dropped into applications via your choice of development tooling. Queries sent to the Web IQ MCP server use the same syntax as REST calls, without having to construct the calls yourself. Working with the MCP server allows you to connect Web IQ to your choice of agent framework, relying on its built-in MCP methods to reduce the code and maintenance overhead.</p>



<p class="wp-block-paragraph">Web IQ is not for human interactions; Microsoft provides an alternative “<a href="https://learn.microsoft.com/en-us/azure/foundry-classic/agents/how-to/tools-classic/bing-grounding?view=azure-python-preview&amp;tabs=python&amp;pivots=overview">Grounding with Bing</a>” service for chatbots. Instead, Web IQ is a tool for agents, providing necessary background information that helps keep results fresh and relevant. It’s easy to use, fast, and, above all, cheap, which makes it an ideal tool for modern inference platforms built around Microsoft Azure’s AI tooling.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta Wants Your Coding Data, and It’ll Cut Muse Code Prices by Up to 20x]]></title>
<description><![CDATA[Meta has launched Muse Code, a new terminal-based coding agent for macOS and Linux, with pricing that drops sharply when users allow the company to train future AI models on their prompts and completions.



The new tool runs on Meta’s Muse Spark 1.2 model and can plan code changes, write code, t...]]></description>
<link>https://tsecurity.de/de/3707862/ios-mac-os/meta-wants-your-coding-data-and-itll-cut-muse-code-prices-by-up-to-20x/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707862/ios-mac-os/meta-wants-your-coding-data-and-itll-cut-muse-code-prices-by-up-to-20x/</guid>
<pubDate>Thu, 06 Aug 2026 13:15:04 +0200</pubDate>
<content:encoded><![CDATA[Meta has launched Muse Code, a new terminal-based coding agent for macOS and Linux, with pricing that drops sharply when users allow the company to train future AI models on their prompts and completions.



The new tool runs on Meta’s Muse Spark 1.2 model and can plan code changes, write code, test results, and work across large software repositories. Meta has released Muse Code in beta, and Mac users can install it through Terminal with a single command.



Meta Muse Code pricing depends on data access



Meta charges Standard users $1.25 per million input tokens and $4.25 per million output tokens. This tier prevents Meta from using prompts and completions to train its models, which makes it the safer option for developers working with private or sensitive code.



The Contributor tier cuts the price to $0.10 per million input tokens and $0.20 per million output tokens. In exchange, users allow Meta to use their data for model training, which lowers input costs by more than 12 times and output costs by more than 20 times.



The cheaper tier also has lower usage limits, with 60 requests per minute and 2.1 million tokens per minute. Standard users receive up to 3,000 requests per minute and 4 million tokens per minute.



Muse Code also includes built-in commands for planning, reviewing, and completing development tasks. Its local event log records model calls, tool activity, approvals, and edits, which allows the agent to resume work after a crash.



Meta Muse Code directly competes with OpenAI Codex and Anthropic Claude Code, although Meta currently offers no dedicated desktop app. Developers must use the tool through Terminal on macOS or Linux.]]></content:encoded>
</item>
<item>
<title><![CDATA[Evidence points to cybercriminals stepping up their AI game]]></title>
<description><![CDATA[More evidence is emerging about how AI is becoming part of the day-to-day workflow for cybercriminals, from building and refining tools to managing infrastructure and accelerating vulnerability research.



Drawing on recovered prompt logs, attack tooling, and threat actor conversations, research...]]></description>
<link>https://tsecurity.de/de/3707741/it-security-nachrichten/evidence-points-to-cybercriminals-stepping-up-their-ai-game/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707741/it-security-nachrichten/evidence-points-to-cybercriminals-stepping-up-their-ai-game/</guid>
<pubDate>Thu, 06 Aug 2026 13:01:43 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">More evidence is emerging about how AI is becoming part of the day-to-day workflow for cybercriminals, from building and refining tools to managing infrastructure and accelerating vulnerability research.</p>



<p class="wp-block-paragraph">Drawing on recovered prompt logs, attack tooling, and threat actor conversations, research from Cisco Talos documents how AI is being used to develop malicious code, build fraud infrastructure, and accelerate vulnerability research and exploitation.</p>



<p class="wp-block-paragraph">The <a href="https://blog.talosintelligence.com/keep-going-bro-youve-got-this-a-data-driven-look-at-how-adversaries-are-weaponizing-ai/">study</a>, released during the Black Hat USA conference, found AI systems guardrails were often ineffective.</p>



<p class="wp-block-paragraph">Cisco Talos researchers write that threat actors frequently bypass guardrails with basic social engineering claims (“this is authorised testing” or “I’m asking this as part of a capture the flag exercise”) that convince most models to comply.</p>



<p class="wp-block-paragraph">This duped permissiveness wasn’t specific to a single model or platform. Instead, analysis of prompt logs related to Claude Code, CodeX, Cursor, and Gemini showed this shortcoming was an issue across the board. And when censored models refuse, threat actors simply switch to uncensored alternatives.</p>



<p class="wp-block-paragraph">Whereas novice cybercriminals continue to produce clunky malware with limited functionality, sophisticated threat groups are increasingly leveraging AI as a development assistant to rapidly build exploits, and some are even deploying it as a system administration tool for managing large-scale attack infrastructure.</p>



<p class="wp-block-paragraph">Cisco Talos found real-world examples of attackers abusing AI systems to build a bulk-mail validation service processing tens of millions of email records, adapting the <a href="https://www.csoonline.com/article/4111888/react2shell-anatomy-of-a-max-severity-flaw-that-sent-shockwaves-through-the-web.html">React2Shell vulnerability</a> into a credential-harvesting pipeline, developing DDoS infrastructure targeting Android TVs, and supporting cryptocurrency theft operations, among other attacks.</p>



<p class="wp-block-paragraph">Joseph Rooke, senior director at Recorded Future’s Insikt Group, sees attacker tradecraft evolving away from traditional code-based exploits toward prompt-based manipulation of large language models.</p>



<p class="wp-block-paragraph">“Targeting weakness in LLMs enables malicious prompts to be embedded in shared text, video, or image files, with the aim of hijacking LLM-based assistants to carry out attacks,” Rooke tells CSO.</p>



<p class="wp-block-paragraph">Norwegian AI researcher Håkon Måløy recently demonstrated such an attack, which could result in a <a href="https://www.csoonline.com/article/4203630/copilot-worm-can-spread-through-microsoft-word-docs.html">Copilot worm spreading through Microsoft Word docs</a>. Attackers are also <a href="https://www.csoonline.com/article/4204731/attackers-are-crafting-malicious-ai-instruction-files-to-turn-your-agentic-workflows-into-quiet-criminal-helpers.html">crafting malicious AI instruction files</a>, like CLAUDE.md, to trick agents into exfiltrating data and other tasks on their behalf.</p>



<p class="wp-block-paragraph">“Malicious prompts will increasingly replace malware as the preferred intrusion method, enabling adversaries to extract sensitive data, override guardrails, or induce harmful actions without breaching traditional defenses,” Rooke says.</p>



<h2 class="wp-block-heading">Attacking AI through the software supply chain</h2>



<p class="wp-block-paragraph">Separately, research from CrowdStrike shows that adversaries are increasingly targeting AI infrastructure through software supply chain-style attacks.</p>



<p class="wp-block-paragraph">For example, in March 2026, North Korean cybercrime group Stardust Chollima used stolen maintainer credentials to <a href="https://www.csoonline.com/article/4152696/attackers-trojanize-axios-http-library-in-highest-impact-npm-supply-chain-attack.html">compromise the Axios npm package</a> and deliver platform-specific variants of their ZshBucket malware.</p>



<p class="wp-block-paragraph">In June 2026, the same group injected a malicious npm package as a dependency into at least 131 <a href="https://www.csoonline.com/article/4072341/introducing-maestro-a-framework-for-securing-generative-and-agentic-ai.html">Mastra AI framework</a> packages, indicating that trusted AI building blocks are becoming targets in supply chain attacks.</p>



<p class="wp-block-paragraph">During 1H 2026, 87% of identified software registry threats involved malicious npm packages. “This indicates adversaries’ preference for JavaScript’s scale, dependency chains, and automatic install scripts to spread downstream risk,” CrowdStrike’s researchers report.</p>



<p class="wp-block-paragraph"><a href="https://www.crowdstrike.com/en-us/blog/crowdstrike-2026-threat-hunting-report/">CrowdStrike’s 2026 Threat Hunting Report</a> also reveals how AI is collapsing the window between vulnerability disclosure and active exploitation.</p>



<p class="wp-block-paragraph">For example, two separate Chinese APT groups exploited critical vulnerabilities within 24 hours of public proof-of-concept (PoC) release. From January through June 2026, 88% of CrowdStrike-observed exploitation of vulnerabilities with a public PoC was conducted within 48 hours of the PoC’s release.</p>



<p class="wp-block-paragraph">After the React2Shell vulnerability disclosure, CrowdStrike responded to over 800 hunting leads across more than 80 victims in just four days.</p>



<p class="wp-block-paragraph">Cybercrime group Altered Spider (aka TeamPCP) <a href="https://www.csoonline.com/article/4170284/mistral-ai-sdk-tanstack-router-hit-in-npm-software-supply-chain-attack.html">compromised more than 300 software dependencies</a> in a single day to harvest credentials and pivot into cloud environments.</p>



<h2 class="wp-block-heading">Authentication systems under attack</h2>



<p class="wp-block-paragraph">The study — based on frontline intelligence from CrowdStrike’s threat hunters and intelligence analysts — also found that trusted authentication has become a favored attack path with, for example, vishing intrusions doubling in 1H 2026. On a related front, cybercrime groups Cordial Spider and Snarky Spider compromised single sign-on (SSO) integrated SaaS applications for data exfiltration.</p>



<p class="wp-block-paragraph">Recorded Future’s Rooke points out other ways authentication systems are at the front line of AI-based attacks.</p>



<p class="wp-block-paragraph">“AI-generated deepfake videos and audio are also more likely to be used as part of business email compromise attacks and social engineering,” Rooke tells CSO. “Biometric and identity-verification systems will likely remain vulnerable to spoofing, replay, and cloned credentials, enabling synthetic personas to coerce payments, manipulate employees, and facilitate access handoffs to cyber operators.”</p>



<p class="wp-block-paragraph">Cloud-focused cybercrime activity surged 171% as adversaries executed credential theft, cryptomining, LLM abuse, and digital financial asset theft, according to CrowdStrike.</p>



<h2 class="wp-block-heading">How cyber teams should respond</h2>



<p class="wp-block-paragraph">“AI is now embedded in modern adversary operations. It is changing how attacks are planned, executed, and scaled while expanding the attack surface organizations must defend,” says Adam Meyers, head of counter adversary operations at CrowdStrike. “The organizations that succeed will secure AI as aggressively as they adopt it and use AI to defend at the speed of the adversary.”</p>



<p class="wp-block-paragraph">Comprehensive industry-wide data remains limited because evidence of AI abuse is often difficult to identify via traditional security telemetry. Incidents documented by Cisco Talos and CrowdStrike, however, show how CISOs need to adapt in response to the growing threat.</p>



<p class="wp-block-paragraph">Cisco Talos urges enterprises to improve detection, prioritization, and their own use of AI platforms and agents to handle the growing volume of alerts and vulnerabilities. “The organisations best equipped to handle the coming deluge of additional vulnerabilities, alerts, and incidents will be the ones that prepare now by deploying their own AI-assisted security capabilities,” according to the report.</p>



<p class="wp-block-paragraph">“Security teams should assume AI is already embedded in attacker workflows; focus on detecting malicious behavior rather than proving AI involvement; treat LLMs and APIs as privileged, high-risk infrastructure; and strengthen logging, patching, and containment,” says Oliver Simonnet, lead cybersecurity researcher at AI security and governance platform CultureAI.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft extends zero trust deeper into enterprise AI]]></title>
<description><![CDATA[Microsoft expanded its Zero Trust for AI strategy with updates to the Zero Trust Assessment tool and the Zero Trust Workshop. The additions help organizations assess security posture, prioritize remediation, and apply zero trust principles to AI agents and AI-assisted software development. Zero T...]]></description>
<link>https://tsecurity.de/de/3707689/it-security-nachrichten/microsoft-extends-zero-trust-deeper-into-enterprise-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707689/it-security-nachrichten/microsoft-extends-zero-trust-deeper-into-enterprise-ai/</guid>
<pubDate>Thu, 06 Aug 2026 12:51:54 +0200</pubDate>
<content:encoded><![CDATA[<p>Microsoft expanded its Zero Trust for AI strategy with updates to the Zero Trust Assessment tool and the Zero Trust Workshop. The additions help organizations assess security posture, prioritize remediation, and apply zero trust principles to AI agents and AI-assisted software development. Zero Trust Assessment adds AI pillar Zero Trust Assessment is a free tool that automatically evaluates an organization’s Microsoft security configuration against zero trust best practices, identifies weaknesses, and recommends improvements before they … <a href="https://www.helpnetsecurity.com/2026/08/06/microsoft-zero-trust-for-ai-strategy-updates/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/08/06/microsoft-zero-trust-for-ai-strategy-updates/">Microsoft extends zero trust deeper into enterprise AI</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How AI takes flight at GE Aerospace]]></title>
<description><![CDATA[The race to adopt AI has left many CIOs wrestling with a fundamental question: How do you move faster without introducing unacceptable risk?



Few leaders face that challenge at a higher level than David Burns, CIO of GE Aerospace. Building on the company’s decade of experience applying AI acros...]]></description>
<link>https://tsecurity.de/de/3707684/it-security-nachrichten/how-ai-takes-flight-at-ge-aerospace/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707684/it-security-nachrichten/how-ai-takes-flight-at-ge-aerospace/</guid>
<pubDate>Thu, 06 Aug 2026 12:51:46 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The race to adopt AI has left many CIOs wrestling with a fundamental question: How do you move faster without introducing unacceptable risk?</p>



<p class="wp-block-paragraph">Few leaders face that challenge at a higher level than David Burns, CIO of GE Aerospace. Building on the company’s decade of experience applying AI across its business, Burns is helping lead the next phase of the company’s digital transformation by leveraging AI to simplify and automate processes. Burns’ experience shows how AI can accelerate innovation, improve decision-making, and create value for the business and customers while maintaining the trust, safety, and operational rigor expected in the aerospace industry.</p>



<p class="wp-block-paragraph">In a recent episode of <a href="https://linktr.ee/techwhisperers">the Tech Whisperers podcast</a>, Burns opened up his playbook for leading organizations through turbulence. In this conversation, edited for length and clarity, he shares more practical lessons for technology leaders who are seeking to move beyond experimentation and scale AI responsibly across the enterprise.</p>



<p class="wp-block-paragraph"><strong>Dan Roberts: You’ve described AI as an accelerator. What exactly is AI accelerating inside GE Aerospace?</strong></p>



<p class="wp-block-paragraph"><strong>David Burns:</strong> At GE Aerospace, AI is used across our operations as an accelerator to Flight Deck, our proprietary lean operating model, and is applied to all key aspects of the business — design, manufacture, sales, and services. We identify and solve problems with Flight Deck and use AI to accelerate our problem-solving in ways we can genuinely feel, enabling us to identify issues earlier, solve problems faster for our customers, and improve how work gets done.</p>



<p class="wp-block-paragraph">For example, we are also using AI in:</p>



<p class="wp-block-paragraph"><strong>Design:</strong> While traditional processes for developing engine design concepts take months of manual work, the GE Aerospace Research Center built a proprietary generative AI application capable of producing hundreds of design concepts. As a result, the team produced the hypersonic ramjet engine design concept that met all regulatory requirements more than 90% faster than before, highlighting how AI is possible in engine design to support engineers bringing new technologies to market faster.</p>



<p class="wp-block-paragraph"><strong>Manufacture:</strong> Our team in Indianapolis used an AI coding assistant to automate a part quality inspection workflow, reducing 8 hours of manual measurement data entry for complex parts to just 3 seconds while improving data accuracy and inspection consistency. This has improved both the quality and efficiency for clearing parts to build, which helps drive on-time engine deliveries.</p>



<p class="wp-block-paragraph"><strong>Sales:</strong> Based on customer feedback that GE Aerospace’s responses for proposals needed to be faster, the sales team utilized a generative AI tool to synthesize data and produce deal proposals. The tool improved customer response time by more than two weeks for the GEnx team through reduced proposal development cycle time and standardized creation of more comprehensive deal proposals.</p>



<p class="wp-block-paragraph"><strong>Service:</strong> When LEAP engine rebuilds faced potential turnaround time (TAT) challenges due to material availability at our Maintenance, Repair and Overhaul (MRO) sites, our team in Lafayette, Indiana, applied AI to help reduce delays for customers. Using Daily &amp; Visual Management, they surfaced material flow challenges and their underlying drivers, leading to a new AI solution that leverages data to predict when and where parts are needed faster to reduce delays for our customers with an approximately six-day turnaround time improvement, 16% increase in on-time material orders, and 15% increase in on-time material delivery.</p>



<p class="wp-block-paragraph">Ultimately, by leveraging AI, Flight Deck helps us eliminate waste and identify and accelerate the most value-added steps for our customers, be it designing a part faster or responding to a customer request faster. And I would underscore that it’s value through the eyes of our customer. How we define value is not what we internally say; it’s how our customers define value, and how we’re working to be more customer-driven.</p>



<p class="wp-block-paragraph"><strong>GE Aerospace has been investing in analytics, machine learning, and digital capabilities for more than a decade. What advantages does that foundation create as you move into the generative AI era?</strong></p>



<p class="wp-block-paragraph">We’ve built one of the largest AI patent portfolios in the aviation industry through years of investment and supercomputing through digital technologies, and we continue to do work on our core transactional systems and our data foundations, so that way our data is AI-ready. This has allowed us to build our own AI capabilities and strong talent base. For example, the generative AI app we built to create new propulsion systems design was built in house by GE Aerospace scientists at the <a href="https://www.geaerospace.com/news/press-releases/ge-aerospace-completes-design-studies-hypersonic-ramjet-generative-ai">GE Aerospace Research Center</a>.</p>



<p class="wp-block-paragraph">At the same time, our knowledge and familiarity with the landscape has allowed us to make connections with tech companies, including one where we’re using agentic AI in a multi-year partnership to predict demand and identify constraints to enhance production readiness in the Defense business.</p>



<p class="wp-block-paragraph">We were fortunate to have leaders who were very smart to invest in data scientists 10, 15 years ago, and we’re getting to leverage that talent today. The lesson there is that is you always have to be thinking long term when you’re talking about talent, because you may not know exactly how the world will play out, but making sure you have the best athletes on the field to run the race becomes critically important. For us, some of those investments we did around our people is what’s paying off today.</p>



<p class="wp-block-paragraph"><strong>One of the biggest challenges facing CIOs today is balancing innovation with risk management. How do you approach that balance in an industry where safety, reliability, and trust are non-negotiable?</strong></p>



<p class="wp-block-paragraph">It’s all about risk tolerance. There are certain areas in our business where we don’t have high risk tolerance, and we’re very methodical and cautious about how we deploy technology into those uses and have very stringent processes that we comply consistently with. In areas that are not safety and quality critical, we are more aggressive in looking at how we can use technology to deliver more for our customers and to make our employees more effective. That’s where we strike the balance, and at the end of the day, it’s about making sure we’re never compromising safety or quality in what we do.</p>



<p class="wp-block-paragraph">As for the process, we start with Flight Deck and focus AI where it can help solve critical challenges for our customers and with the highest impact to customer outcomes, enhancing safety, quality, delivery, and cost, in that order, to solve problems that matter most and keep fleets flying. ​</p>



<p class="wp-block-paragraph">We have three guiding principles for safe and responsible AI use: </p>



<ul class="wp-block-list">
<li><strong>Trust:</strong> The data-informing AI must be known, trusted, and reliable. </li>



<li><strong>Transparent:</strong> The AI must be transparent and repeatable, which means we need to know what is informing an AI model’s insights and actions.</li>



<li><strong>Human:</strong> A human must always be in the loop and make the final decision.    </li>
</ul>



<p class="wp-block-paragraph">Our culture of discipline also plays an important role. Our business variation is challenging, so one of the core fundamentals of Flight Deck is standard work. It’s embedded into our culture, and it’s the base expectation that we operate with standards that we’re continuously improving.</p>



<p class="wp-block-paragraph"><strong>Many organizations are struggling to move from AI pilots to enterprise-scale value. What lessons have you learned about successfully scaling AI across a large, complex organization?</strong></p>



<p class="wp-block-paragraph">AI is a tool that strengthens the capabilities of skilled employees; it is not a substitute for their judgment, experience, or accountability. So we focus on testing and validating AI solutions through pilots before scaling, and look for AI applications that meaningfully change how work gets done.</p>



<p class="wp-block-paragraph">Early on, when we started doing a lot of our generative AI work, we focused on 14 big problems in the business, and we didn’t let ourselves stray all over the place. We also didn’t look at it as a technology solution. We looked at the process and where technology played into the process, and then we embedded AI into those core processes. So now, it’s not a separate thing where you go do AI. It’s embedded in the workflow of how things get done.</p>



<p class="wp-block-paragraph">That gave us a foundation to learn and grow from that we’ve now applied. We’re not trying to create popcorn AI solutions all over the place. We’re trying to transform our business processes. In some cases, we’re doing good old process improvement, lean process improvement, eliminating waste, not necessarily a technology play. In other places, we’re applying technology that’s helping to lift us up and accelerate value by embedding it into the way work gets done, with a little bit of burning the boats behind you. You’re not able to do it the old way. You’ve got to use the tools. You’ve got to use the technology, because it’s the best-known way of doing it. The technology becomes part of the standard work.</p>



<p class="wp-block-paragraph">That’s why one of the biggest lessons in scaling AI is that success starts with the core fundamentals and understanding the problem you’re trying to solve. It’s critical to test and validate AI solutions before they are deployed at scale to ensure they improve how work gets done and become embedded in our workflows. If you do not have strong standard work and transparent and reliable data in place, it becomes difficult to move beyond pilot stage and create repeatable value at scale.</p>



<p class="wp-block-paragraph"><strong>Every day brings a new AI announcement, new model, or new prediction about the future. How do you separate what is truly meaningful from what is simply noise, and what advice would you give other leaders trying to do the same?</strong></p>



<p class="wp-block-paragraph">First and foremost is starting with the problem being solved, not the solution. If you’ve got a hammer that you want to use, everything starts looking like a nail. The most effective use of AI begins with an understanding of the problem that needs to be solved, then determining whether AI is the right tool to address it.</p>



<p class="wp-block-paragraph">As far as dealing with distractions, and there are a lot of them right now, it’s important to try a lot of things, but very quickly, and then make decisions on which are the bets you want to make and spend more time and more money on and which are the ones you want to pivot away from. We spend a lot of time doing quick experiments with technology and then having the courage to stop something when it’s not working.</p>



<p class="wp-block-paragraph"><strong>What excites you most about the future intersection of AI, engineering, manufacturing, and aerospace? And what should CIOs be doing today to prepare for that future?</strong></p>



<p class="wp-block-paragraph">Across aviation, AI is already helping to enhance safety, support more efficient operations, strengthen the resilience of global fleets, and improve the overall passenger experience. That includes GE Aerospace. These benefits come from investing not only in technology, but also in people, capacity, and trusted partnerships. </p>



<p class="wp-block-paragraph">They also depend on building mature, fully connected data threads through manufacturing and services that will drive higher value across our operations. The challenge will be ensuring that we enable this data thread across our operations to support AI solutions that will be developed and deployed.</p>



<p class="wp-block-paragraph">The most important thing is to understand that the role of digital technology and information technology is fundamentally going to change. When I came out of university, the only people that knew how to do software coding were computer scientists or information systems majors. We used to frown upon shadow IT, but the reality is, now everyone coming out of college knows how to do some level of software development, and AI tools are only going to make that easier.</p>



<p class="wp-block-paragraph">What CIOs need to start doing today is prepare for the future. The big questions they need to answer: How are they going to make sure they’ve got the platforms and the data set up in a way to serve a workforce that is capable of doing true citizen development, able to develop their own applications, their own solutions? How do you govern that from a data perspective, from a data privacy perspective, from a cybersecurity perspective, while not stifling but enabling the innovation of all those smart people that we’re hiring?</p>



<p class="wp-block-paragraph"><em>While many organizations search for shortcuts to AI success, GE Aerospace’s disciplined investment in data, analytics, talent, and operational excellence sets the company apart. Burns’ experience offers a clear lesson for CIOs: Creating the greatest value from AI requires building the capabilities, culture, and foundations that allow AI to amplify what the organization already does exceptionally well. For more from his leadership playbook, </em><a href="https://linktr.ee/techwhisperers"><em>tune in to the Tech Whisperers</em></a><em>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How AI takes flight at GE Aerospace]]></title>
<description><![CDATA[The race to adopt AI has left many CIOs wrestling with a fundamental question: How do you move faster without introducing unacceptable risk?



Few leaders face that challenge at a higher level than David Burns, CIO of GE Aerospace. Building on the company’s decade of experience applying AI acros...]]></description>
<link>https://tsecurity.de/de/3707631/it-nachrichten/how-ai-takes-flight-at-ge-aerospace/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707631/it-nachrichten/how-ai-takes-flight-at-ge-aerospace/</guid>
<pubDate>Thu, 06 Aug 2026 12:50:21 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The race to adopt AI has left many CIOs wrestling with a fundamental question: How do you move faster without introducing unacceptable risk?</p>



<p class="wp-block-paragraph">Few leaders face that challenge at a higher level than David Burns, CIO of GE Aerospace. Building on the company’s decade of experience applying AI across its business, Burns is helping lead the next phase of the company’s digital transformation by leveraging AI to simplify and automate processes. Burns’ experience shows how AI can accelerate innovation, improve decision-making, and create value for the business and customers while maintaining the trust, safety, and operational rigor expected in the aerospace industry.</p>



<p class="wp-block-paragraph">In a recent episode of <a href="https://linktr.ee/techwhisperers">the Tech Whisperers podcast</a>, Burns opened up his playbook for leading organizations through turbulence. In this conversation, edited for length and clarity, he shares more practical lessons for technology leaders who are seeking to move beyond experimentation and scale AI responsibly across the enterprise.</p>



<p class="wp-block-paragraph"><strong>Dan Roberts: You’ve described AI as an accelerator. What exactly is AI accelerating inside GE Aerospace?</strong></p>



<p class="wp-block-paragraph"><strong>David Burns:</strong> At GE Aerospace, AI is used across our operations as an accelerator to Flight Deck, our proprietary lean operating model, and is applied to all key aspects of the business — design, manufacture, sales, and services. We identify and solve problems with Flight Deck and use AI to accelerate our problem-solving in ways we can genuinely feel, enabling us to identify issues earlier, solve problems faster for our customers, and improve how work gets done.</p>



<p class="wp-block-paragraph">For example, we are also using AI in:</p>



<p class="wp-block-paragraph"><strong>Design:</strong> While traditional processes for developing engine design concepts take months of manual work, the GE Aerospace Research Center built a proprietary generative AI application capable of producing hundreds of design concepts. As a result, the team produced the hypersonic ramjet engine design concept that met all regulatory requirements more than 90% faster than before, highlighting how AI is possible in engine design to support engineers bringing new technologies to market faster.</p>



<p class="wp-block-paragraph"><strong>Manufacture:</strong> Our team in Indianapolis used an AI coding assistant to automate a part quality inspection workflow, reducing 8 hours of manual measurement data entry for complex parts to just 3 seconds while improving data accuracy and inspection consistency. This has improved both the quality and efficiency for clearing parts to build, which helps drive on-time engine deliveries.</p>



<p class="wp-block-paragraph"><strong>Sales:</strong> Based on customer feedback that GE Aerospace’s responses for proposals needed to be faster, the sales team utilized a generative AI tool to synthesize data and produce deal proposals. The tool improved customer response time by more than two weeks for the GEnx team through reduced proposal development cycle time and standardized creation of more comprehensive deal proposals.</p>



<p class="wp-block-paragraph"><strong>Service:</strong> When LEAP engine rebuilds faced potential turnaround time (TAT) challenges due to material availability at our Maintenance, Repair and Overhaul (MRO) sites, our team in Lafayette, Indiana, applied AI to help reduce delays for customers. Using Daily &amp; Visual Management, they surfaced material flow challenges and their underlying drivers, leading to a new AI solution that leverages data to predict when and where parts are needed faster to reduce delays for our customers with an approximately six-day turnaround time improvement, 16% increase in on-time material orders, and 15% increase in on-time material delivery.</p>



<p class="wp-block-paragraph">Ultimately, by leveraging AI, Flight Deck helps us eliminate waste and identify and accelerate the most value-added steps for our customers, be it designing a part faster or responding to a customer request faster. And I would underscore that it’s value through the eyes of our customer. How we define value is not what we internally say; it’s how our customers define value, and how we’re working to be more customer-driven.</p>



<p class="wp-block-paragraph"><strong>GE Aerospace has been investing in analytics, machine learning, and digital capabilities for more than a decade. What advantages does that foundation create as you move into the generative AI era?</strong></p>



<p class="wp-block-paragraph">We’ve built one of the largest AI patent portfolios in the aviation industry through years of investment and supercomputing through digital technologies, and we continue to do work on our core transactional systems and our data foundations, so that way our data is AI-ready. This has allowed us to build our own AI capabilities and strong talent base. For example, the generative AI app we built to create new propulsion systems design was built in house by GE Aerospace scientists at the <a href="https://www.geaerospace.com/news/press-releases/ge-aerospace-completes-design-studies-hypersonic-ramjet-generative-ai">GE Aerospace Research Center</a>.</p>



<p class="wp-block-paragraph">At the same time, our knowledge and familiarity with the landscape has allowed us to make connections with tech companies, including one where we’re using agentic AI in a multi-year partnership to predict demand and identify constraints to enhance production readiness in the Defense business.</p>



<p class="wp-block-paragraph">We were fortunate to have leaders who were very smart to invest in data scientists 10, 15 years ago, and we’re getting to leverage that talent today. The lesson there is that is you always have to be thinking long term when you’re talking about talent, because you may not know exactly how the world will play out, but making sure you have the best athletes on the field to run the race becomes critically important. For us, some of those investments we did around our people is what’s paying off today.</p>



<p class="wp-block-paragraph"><strong>One of the biggest challenges facing CIOs today is balancing innovation with risk management. How do you approach that balance in an industry where safety, reliability, and trust are non-negotiable?</strong></p>



<p class="wp-block-paragraph">It’s all about risk tolerance. There are certain areas in our business where we don’t have high risk tolerance, and we’re very methodical and cautious about how we deploy technology into those uses and have very stringent processes that we comply consistently with. In areas that are not safety and quality critical, we are more aggressive in looking at how we can use technology to deliver more for our customers and to make our employees more effective. That’s where we strike the balance, and at the end of the day, it’s about making sure we’re never compromising safety or quality in what we do.</p>



<p class="wp-block-paragraph">As for the process, we start with Flight Deck and focus AI where it can help solve critical challenges for our customers and with the highest impact to customer outcomes, enhancing safety, quality, delivery, and cost, in that order, to solve problems that matter most and keep fleets flying. ​</p>



<p class="wp-block-paragraph">We have three guiding principles for safe and responsible AI use: </p>



<ul class="wp-block-list">
<li><strong>Trust:</strong> The data-informing AI must be known, trusted, and reliable. </li>



<li><strong>Transparent:</strong> The AI must be transparent and repeatable, which means we need to know what is informing an AI model’s insights and actions.</li>



<li><strong>Human:</strong> A human must always be in the loop and make the final decision.    </li>
</ul>



<p class="wp-block-paragraph">Our culture of discipline also plays an important role. Our business variation is challenging, so one of the core fundamentals of Flight Deck is standard work. It’s embedded into our culture, and it’s the base expectation that we operate with standards that we’re continuously improving.</p>



<p class="wp-block-paragraph"><strong>Many organizations are struggling to move from AI pilots to enterprise-scale value. What lessons have you learned about successfully scaling AI across a large, complex organization?</strong></p>



<p class="wp-block-paragraph">AI is a tool that strengthens the capabilities of skilled employees; it is not a substitute for their judgment, experience, or accountability. So we focus on testing and validating AI solutions through pilots before scaling, and look for AI applications that meaningfully change how work gets done.</p>



<p class="wp-block-paragraph">Early on, when we started doing a lot of our generative AI work, we focused on 14 big problems in the business, and we didn’t let ourselves stray all over the place. We also didn’t look at it as a technology solution. We looked at the process and where technology played into the process, and then we embedded AI into those core processes. So now, it’s not a separate thing where you go do AI. It’s embedded in the workflow of how things get done.</p>



<p class="wp-block-paragraph">That gave us a foundation to learn and grow from that we’ve now applied. We’re not trying to create popcorn AI solutions all over the place. We’re trying to transform our business processes. In some cases, we’re doing good old process improvement, lean process improvement, eliminating waste, not necessarily a technology play. In other places, we’re applying technology that’s helping to lift us up and accelerate value by embedding it into the way work gets done, with a little bit of burning the boats behind you. You’re not able to do it the old way. You’ve got to use the tools. You’ve got to use the technology, because it’s the best-known way of doing it. The technology becomes part of the standard work.</p>



<p class="wp-block-paragraph">That’s why one of the biggest lessons in scaling AI is that success starts with the core fundamentals and understanding the problem you’re trying to solve. It’s critical to test and validate AI solutions before they are deployed at scale to ensure they improve how work gets done and become embedded in our workflows. If you do not have strong standard work and transparent and reliable data in place, it becomes difficult to move beyond pilot stage and create repeatable value at scale.</p>



<p class="wp-block-paragraph"><strong>Every day brings a new AI announcement, new model, or new prediction about the future. How do you separate what is truly meaningful from what is simply noise, and what advice would you give other leaders trying to do the same?</strong></p>



<p class="wp-block-paragraph">First and foremost is starting with the problem being solved, not the solution. If you’ve got a hammer that you want to use, everything starts looking like a nail. The most effective use of AI begins with an understanding of the problem that needs to be solved, then determining whether AI is the right tool to address it.</p>



<p class="wp-block-paragraph">As far as dealing with distractions, and there are a lot of them right now, it’s important to try a lot of things, but very quickly, and then make decisions on which are the bets you want to make and spend more time and more money on and which are the ones you want to pivot away from. We spend a lot of time doing quick experiments with technology and then having the courage to stop something when it’s not working.</p>



<p class="wp-block-paragraph"><strong>What excites you most about the future intersection of AI, engineering, manufacturing, and aerospace? And what should CIOs be doing today to prepare for that future?</strong></p>



<p class="wp-block-paragraph">Across aviation, AI is already helping to enhance safety, support more efficient operations, strengthen the resilience of global fleets, and improve the overall passenger experience. That includes GE Aerospace. These benefits come from investing not only in technology, but also in people, capacity, and trusted partnerships. </p>



<p class="wp-block-paragraph">They also depend on building mature, fully connected data threads through manufacturing and services that will drive higher value across our operations. The challenge will be ensuring that we enable this data thread across our operations to support AI solutions that will be developed and deployed.</p>



<p class="wp-block-paragraph">The most important thing is to understand that the role of digital technology and information technology is fundamentally going to change. When I came out of university, the only people that knew how to do software coding were computer scientists or information systems majors. We used to frown upon shadow IT, but the reality is, now everyone coming out of college knows how to do some level of software development, and AI tools are only going to make that easier.</p>



<p class="wp-block-paragraph">What CIOs need to start doing today is prepare for the future. The big questions they need to answer: How are they going to make sure they’ve got the platforms and the data set up in a way to serve a workforce that is capable of doing true citizen development, able to develop their own applications, their own solutions? How do you govern that from a data perspective, from a data privacy perspective, from a cybersecurity perspective, while not stifling but enabling the innovation of all those smart people that we’re hiring?</p>



<p class="wp-block-paragraph"><em>While many organizations search for shortcuts to AI success, GE Aerospace’s disciplined investment in data, analytics, talent, and operational excellence sets the company apart. Burns’ experience offers a clear lesson for CIOs: Creating the greatest value from AI requires building the capabilities, culture, and foundations that allow AI to amplify what the organization already does exceptionally well. For more from his leadership playbook, </em><a href="https://linktr.ee/techwhisperers"><em>tune in to the Tech Whisperers</em></a><em>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI says Apple’s trade secrets lawsuit is ‘rotten to its core’]]></title>
<description><![CDATA[OpenAI has asked a federal judge to toss out Apple's landmark lawsuit accusing the ChatGPT maker of stealing trade secrets, describing the allegations as "meritless." In a motion filed yesterday to dismiss the complaint, OpenAI says that Apple is mischaracterizing both the actions of the AI start...]]></description>
<link>https://tsecurity.de/de/3707589/it-nachrichten/openai-says-apples-trade-secrets-lawsuit-is-rotten-to-its-core/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707589/it-nachrichten/openai-says-apples-trade-secrets-lawsuit-is-rotten-to-its-core/</guid>
<pubDate>Thu, 06 Aug 2026 12:50:01 +0200</pubDate>
<content:encoded><![CDATA[OpenAI has asked a federal judge to toss out Apple's landmark lawsuit accusing the ChatGPT maker of stealing trade secrets, describing the allegations as "meritless." In a motion filed yesterday to dismiss the complaint, OpenAI says that Apple is mischaracterizing both the actions of the AI startup's employees as theft, and "generic" product development information […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Wie Entwickler sich mit KI versündigen]]></title>
<description><![CDATA[>Im nächtlichen Schein der IDE suhlt sich mancher Dev im KI-Sündenpfuhl.Kateryna Reka | shutterstock.com



Die Normen der Softwareentwicklung sind weiterhin gültig. Zumindest offiziell sind robuste CI/CD-Pipelines, elegante Architekturmuster und wartbarer Code nach wie vor gesetzt.



Wenn wir u...]]></description>
<link>https://tsecurity.de/de/3707283/it-security-nachrichten/wie-entwickler-sich-mit-ki-versuendigen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707283/it-security-nachrichten/wie-entwickler-sich-mit-ki-versuendigen/</guid>
<pubDate>Thu, 06 Aug 2026 06:23:33 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized">&gt;<figcaption class="wp-element-caption">Im nächtlichen Schein der IDE suhlt sich mancher Dev im KI-Sündenpfuhl.</figcaption></figure><p class="imageCredit">Kateryna Reka | shutterstock.com</p></div>



<p class="wp-block-paragraph">Die Normen der <a href="https://www.computerwoche.de/article/3963767/die-grosten-paradoxa-der-softwareentwicklung.html" target="_blank">Softwareentwicklung</a> sind weiterhin gültig. Zumindest offiziell sind robuste CI/CD-Pipelines, elegante Architekturmuster und wartbarer Code nach wie vor gesetzt.</p>



<p class="wp-block-paragraph">Wenn wir unbeobachtet sind, zeigt sich dann in vielen Fällen die Realität: Wir hängen wie entrückte Magier mit manischem Glanz in den Augen über unseren Konsolen und beschwören Modelle und Agenten, um uns voll und ganz dem KI-Rausch hinzugeben.</p>



<p class="wp-block-paragraph">Dabei begehen wir nicht selten Development-Sünden, die <a href="https://de.wikipedia.org/wiki/Frederick_P._Brooks" target="_blank" rel="noreferrer noopener">Fred Brooks</a> die Schamesröte ins Gesicht getrieben hätten. So wie die folgenden sieben. Vorsicht, Ironie – stellenweise.</p>



<h2 class="wp-block-heading">1. Grundlagenwissen für überflüssig halten</h2>



<p class="wp-block-paragraph"><a href="https://www.computerwoche.de/article/2829721/objektorientierte-programmierung-erklaert.html" target="_blank">Objektorientierte</a> oder <a href="https://www.infoworld.com/article/2263963/what-is-functional-programming-a-practical-guide.html" target="_blank">funktionale Programmierung</a>? <a href="https://de.wikipedia.org/wiki/CAP-Theorem" target="_blank" rel="noreferrer noopener">CAP-Theorem</a>? <a href="https://de.wikipedia.org/wiki/Don%E2%80%99t_repeat_yourself" target="_blank" rel="noreferrer noopener">DRY</a>-Prinzip? Design-Pattern? Können Sie vergessen. Ebenso Frameworks, Runtimes und Deployment-Plattformen.</p>



<p class="wp-block-paragraph">Die KI weiß schließlich ganz genau, was bereits vorhanden ist und welche Tools zu nutzen sind. So haben wir als Entwickler auch mehr mentale Bandbreite, um uns Nebenprojekten zu widmen. Zum Beispiel einem Roman über die KI-Weltherrschaft.</p>



<h2 class="wp-block-heading">2. Dokumentationen links liegen lassen</h2>



<p class="wp-block-paragraph">„<a href="https://de.wikipedia.org/wiki/RTFM" target="_blank" rel="noreferrer noopener">RTFM</a>“ nutzen viele Developer auch heutzutage noch gerne – auch wenn sie selbst eigentlich seit 2023 keine einzige Seite einer Anbieter-Dokumentation mehr gelesen haben. Löst ein Package eine bizarre Exception aus, wird weder der Execution-Pfad überprüft noch erfolgt ein Blick in die Release Notes. Stattdessen werden alle 200 Zeilen des Stack-Trace kopiert und in eine KI geworfen – in der Erwartung, dass diese uns dann löffelweise mit der Lösung füttert.</p>



<p class="wp-block-paragraph">Oder es wird direkt eine <a href="https://www.cowo.de/a/4199997" target="_blank" rel="noreferrer noopener">ADE</a> auf den Fehler angesetzt. Die findet den Fehler und fragt uns dann nur noch, ob die Lösung so korrekt ist. Manche werfen dann eventuell einen Blick auf die Beschreibung dieser Lösung – insofern sie die KI nicht vorher schon auf „Auto-Confirm“ umgestellt haben.</p>



<p class="wp-block-paragraph">So werden wir zu glorifizierten Copy-Paste-Orchestratoren – die einfach nur darauf hoffen, dass der stochastische Papagei hinter dem Prompt die Syntax richtig errät.</p>



<h2 class="wp-block-heading">3. Backend-Struktur ignorieren</h2>



<p class="wp-block-paragraph">KI-berauschte Devs geben manchmal vor, Datenflüsse akribisch designt, relationale Einschränkungen sorgfältig ausgearbeitet und <a href="https://www.computerwoche.de/article/4004872/die-besten-apis-um-ki-zu-integrieren.html" target="_blank">API</a>-Beziehungsgeflechte gewissenhaft abgebildet zu haben. Auch wenn wir eigentlich nur die KI angewiesen haben, ein modernes Deployment-Gerüst zu bauen und dieses mit einer Backend-<a href="https://www.computerwoche.de/article/3497295/datenbank-how-to-fur-app-entwickler.html" target="_blank">Datenbank</a> zu verknüpfen.   </p>



<p class="wp-block-paragraph">Dabei wurden Security-Regeln und Schemata erstellt, die wir unter Umständen nicht vollständig verstehen. Aber solange es funktional aussieht, wird es schon gut gehen. Eventuell wurden auch Infrastructure-as-Code-Skripte generiert, die Cloud-Ressourcen bereitstellen. Sicher wird sich jemand anderes darum kümmern, dass das kein Loch ins Budget frisst. Wahrscheinlich, indem er die Metriken in einen anderen Chatbot einspeist.</p>



<p class="wp-block-paragraph">Ist aber auch egal, weil das Mittagessen wartet.</p>



<h2 class="wp-block-heading">4. Inzestuöses Testing fördern</h2>



<p class="wp-block-paragraph">Test-driven Development war immer schon ein schöner Traum, der – wenn man ihn lebt – in Dependency-Wildwuchs <a href="https://grugbrain.dev/#grug-on-testing" target="_blank" rel="noreferrer noopener">ausarten kann</a>. Es ist also eine super Sache, dass wir heutzutage mit KI fast mühelos eine Testabdeckung von 95 Prozent erreichen können. Warum sollten wir die Maschine das nicht direkt mit übernehmen lassen, wenn sie auch alles andere automatisiert erstellt?</p>



<p class="wp-block-paragraph">So kann man auch jedem der es wissen will (oder der gerade keine Fluchtmöglichkeit hat), das Narrativ von der erstaunlichen Testabdeckung unter die Nase reiben und sich in ausgiebigen Schwärmereien über die automatisierte Qualitätssicherung ergehen. Was dabei geflissentlich verschwiegen wird: Die komplexe Anwendungslogik und die Testsuite wurden von derselben KI generiert. Diese validiert also genau den Code, den sie zuvor zusammengeschustert hat.</p>



<p class="wp-block-paragraph">Daraus entsteht ein hermetisch abgeriegelter Kreislauf der algorithmischen Selbstbeweihräucherung: Die Mocks, Randfälle und Assertions werden zur Echokammer für die ursprünglichen Annahmen des KI-Modells. Die Maschine benotet also ihre eigenen Hausaufgaben und gibt sich dafür eine Eins mit Sternchen.</p>



<p class="wp-block-paragraph">Das wird von einigen von uns allerdings gerne in Kauf genommen, denn wenn der Code verändert werden muss, zaubert die KI auch dafür mühelos neue Tests aus dem Hut.</p>



<h2 class="wp-block-heading">5. KI-Ergebnisse als Strategie ausgeben</h2>



<p class="wp-block-paragraph">Dokumente zu designen, kann KI erstaunlich gut: Diese sind meist apart formatiert, wirken schlüssig und schlagen nahtlos die Brücke zwischen übergeordneten Geschäftszielen und detaillierten technischen Specs. Und: Sie enthalten auch die tollen Sequenz-Diagramme, die das Management so schätzt.</p>



<p class="wp-block-paragraph">Architekturvorschläge, die auf diese Art und Weise entstanden sind, werden regelmäßig in Sprint-Planungs-Meetings präsentiert – und kommen beim Rest des Teams oft gut an. Schließlich weiß auch niemand, dass in den hochgelobten Vorschlag ungefähr vier Sekunden „Mühe“ investiert wurden.</p>



<p class="wp-block-paragraph">Ignoriert wird dabei, dass solche KI-generierten Dokumente gleichermaßen anfällig für fatale Mängel in Bezug auf Scope und Alignment sind, wie von Menschenhand gemachte. Aber wenn das Projekt schon scheitert, war wenigstens das <a href="https://www.computerwoche.de/article/3995075/was-ist-markdown.html" target="_blank">Markdown</a> schön klar und die Bulletpoints echt überzeugend. Das wahre Ausmaß des folgenden Desasters wird zwar erst erkannt, wenn es schon viel zu spät ist – aber immerhin war der Ansatz visionär.</p>



<h2 class="wp-block-heading">6. Heimlich dem Vibe Coding verfallen</h2>



<p class="wp-block-paragraph"><a href="https://www.computerwoche.de/article/4034385/9-wege-mit-vibe-coding-zu-scheitern.html" target="_blank">Vibe Coding</a> ist unter Devs in sozialen Kanälen regelmäßig eine Lachnummer. Und auch in Slack-Channels werden regelmäßige augenrollende Emojis verschickt, wenn es um das Thema geht. Nach außen möchten wir alle möglichst professionell wirken.</p>



<p class="wp-block-paragraph">Wenn niemand zusieht, wird dann unter Umständen aber doch der heimlichen Vibe-Coding-Leidenschaft gefröhnt: Unausgereifte Gedanken und ein Drink, sind alles was man braucht, um entspannt dabei zusehen zu können, wie die KI ihre “Coding-Magie” entfaltet.</p>



<p class="wp-block-paragraph">Daraus entsteht dann vielleicht endlich ein funktionierender <a href="https://de.wikipedia.org/wiki/Ultima_(Computerspielreihe)" target="_blank" rel="noreferrer noopener">Ultima-V</a>-Klon oder eine App, um Krypto-Protfolios zu tracken, die nach dem Interface aus „<a href="https://de.wikipedia.org/wiki/Neuromancer-Trilogie" target="_blank" rel="noreferrer noopener">Neuromancer</a>“ aussieht. Und zwar in 30 Sekunden. Das berauscht. Und kann süchtig machen. Leider ganz besonders, wenn man tief in der harten, altmodischen Realität des Programmierhandwerks verwurzelt ist.</p>



<h2 class="wp-block-heading">7. Prompts als Allheilmittel betrachten</h2>



<p class="wp-block-paragraph">Ahnlich wie die Figur von Adam Sandler in „<a href="https://www.imdb.com/de/title/tt5727208/" target="_blank" rel="noreferrer noopener">Der schwarze Diamant</a>“ sind manche Devs davon überzeugt, dass mit der nächsten Runde alles besser wird – nur bezogen auf Prompts. Wenn die Dinge aus dem Ruder laufen, bevorzugen diese regelmäßig, den KI-Prompt zu verfeinern – statt sich selbst dem Komplexitätsdickicht zu widmen.</p>



<p class="wp-block-paragraph">Der gleiche fehlerbehaftete Stack Trace wird dann unerbittlich immer und immer wieder in den Chat gehämmert, das Modell auf einen immer schmaleren Pfad gezwungen – solange, bis der Code endlich keine Fehler mehr ausgibt. Debugging und Variablen-Tracing sind so gut wie nicht mehr existent, Funktionen werden nicht mehr schrittweise geprüft. Stattdessen wird unermüdlich iterativer Druck auf die KI ausgeübt, bis diese kapituliert. Und dann geht’s ab in die Produktion.</p>



<p class="wp-block-paragraph">So fließt am Ende ähnlich viel Zeit und Energie in den Kampf mit dem Bot, wie früher in die manuelle Syntaxerstellung. (fm)</p>



<p class="wp-block-paragraph"><strong>Dieser Artikel ist </strong><a href="https://www.infoworld.com/article/4199668/seven-sins-of-the-modern-software-developer.html" target="_blank"><strong>im Original</strong></a><strong> bei unserer Schwesterpublikation Infoworld.com erschienen.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Java 28 starts to take shape]]></title>
<description><![CDATA[Java Development Kit (JDK) 28, a non-LTS (Long-Term Support) or “feature release” of standard Java due in March 2027, has started to take shape. Features listed for JDK 28 now include a preview of value objects, switching the default mode of the Shenandoah garbage collector to generational mode, ...]]></description>
<link>https://tsecurity.de/de/3707204/ai-nachrichten/java-28-starts-to-take-shape/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707204/ai-nachrichten/java-28-starts-to-take-shape/</guid>
<pubDate>Thu, 06 Aug 2026 04:36:53 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph"><a href="https://openjdk.org/projects/jdk/28/">Java Development Kit (JDK) 28</a>, a non-LTS (Long-Term Support) or “feature release” of standard Java due in March 2027, has started to take shape. Features listed for JDK 28 now include a preview of value objects, switching the default mode of the Shenandoah garbage collector to generational mode, and a preview of strict field initialization in the <a href="https://www.infoworld.com/article/2269370/what-is-the-jvm-introducing-the-java-virtual-machine.html" data-type="link" data-id="https://www.infoworld.com/article/2269370/what-is-the-jvm-introducing-the-java-virtual-machine.html">Java Virtual Machine</a> (JVM).</p>



<p class="wp-block-paragraph">As a non-LTS release, JDK 28 will be backed by six months of support by Oracle. </p>



<p class="wp-block-paragraph">The three features currently targeted to JDK 28 include the following:</p>



<ul class="wp-block-list">
<li>Introduce <a href="https://openjdk.org/jeps/401">value objects</a>, which are immutable and lack object identity. Value objects are distinguished by the values of their fields, and can be represented by the JVM in ways that improve performance. A goal of the feature is to give developers a programming model for immutable data in which the <code>==</code> operator, and all other operations, distinguish objects by the values of their fields rather than their identities. Value objects is a <a href="https://openjdk.org/jeps/12">preview language and VM feature</a>.</li>



<li>Switch the default mode of the <a href="https://openjdk.org/jeps/535">Shenandoah Garbage Collector (GC)</a> to the generational mode and deprecate the non-generational mode, with the intent to remove it in a future release. Goals include signaling the intent that future development will focus on generational mode, and reducing the maintenance cost of supporting two different modes. However, it is not a goal to remove non-generational mode at this time.</li>



<li>Introduce <a href="https://openjdk.org/jeps/539">strictly-initialized fields</a> in the JVM. Such fields must be initialized before they are read, thus default values such as <code>0</code> or <code>null</code> are never observed. For strictly-initialized fields that are final, the same value is always observed. A goal is offering designers of JVM-based programming languages a model for field initialization, which has stronger integrity guarantees than the present model. This is a <a href="https://openjdk.org/jeps/12">preview VM feature</a>. </li>
</ul>



<p class="wp-block-paragraph">The predecessor to JDK 28, <a href="https://www.infoworld.com/article/4202901/jdk-27-the-new-features-of-java-27.html">JDK 27</a>, is due September 15. JDK 27 also is a non-LTS release that will be backed by six months of support by Oracle.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[No Brakes, No Speed: AI Podcast Got My Regulation Argument Backwards]]></title>
<description><![CDATA[I’m a little annoyed right now. A podcast episode released yesterday, which has me as a skeptic, concludes incorrectly that I want AI development slowed down. I said no such thing. Decades of published record on this site says the opposite. I have requested a correction from the show, and this po...]]></description>
<link>https://tsecurity.de/de/3707076/it-security-nachrichten/no-brakes-no-speed-ai-podcast-got-my-regulation-argument-backwards/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707076/it-security-nachrichten/no-brakes-no-speed-ai-podcast-got-my-regulation-argument-backwards/</guid>
<pubDate>Thu, 06 Aug 2026 03:25:41 +0200</pubDate>
<content:encoded><![CDATA[I’m a little annoyed right now. A podcast episode released yesterday, which has me as a skeptic, concludes incorrectly that I want AI development slowed down. I said no such thing. Decades of published record on this site says the opposite. I have requested a correction from the show, and this post is the argument … <a href="https://www.flyingpenguin.com/no-brakes-no-speed-ai-podcast-got-my-regulation-argument-backwards/" class="more-link">Continue reading <span class="screen-reader-text">No Brakes, No Speed: AI Podcast Got My Regulation Argument Backwards</span> <span class="meta-nav">→</span></a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Halo Studios is the latest Xbox Games Studio to be hit by layoffs just days after Campaign Evolved launch, as reports reveal "troubled" development]]></title>
<description><![CDATA[A number of developers previously employed at Halo Studios have posted on LinkedIn confirming layoffs at the studio.]]></description>
<link>https://tsecurity.de/de/3707037/windows-tipps/halo-studios-is-the-latest-xbox-games-studio-to-be-hit-by-layoffs-just-days-after-campaign-evolved-launch-as-reports-reveal-troubled-development/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707037/windows-tipps/halo-studios-is-the-latest-xbox-games-studio-to-be-hit-by-layoffs-just-days-after-campaign-evolved-launch-as-reports-reveal-troubled-development/</guid>
<pubDate>Thu, 06 Aug 2026 01:05:36 +0200</pubDate>
<content:encoded><![CDATA[A number of developers previously employed at Halo Studios have posted on LinkedIn confirming layoffs at the studio.]]></content:encoded>
</item>
<item>
<title><![CDATA[Samsung Removes Smart TV Apps Over Residential Proxy Software Concerns]]></title>
<description><![CDATA[Samsung just began to remove Smart TV apps that contained software capable of sharing users’ home internet access with third parties. The company made the move after security researchers found residential proxy software development kits (SDKs) inside several Smart TV apps. Samsung also introduced...]]></description>
<link>https://tsecurity.de/de/3707019/it-security-nachrichten/samsung-removes-smart-tv-apps-over-residential-proxy-software-concerns/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707019/it-security-nachrichten/samsung-removes-smart-tv-apps-over-residential-proxy-software-concerns/</guid>
<pubDate>Thu, 06 Aug 2026 00:40:53 +0200</pubDate>
<content:encoded><![CDATA[<p>Samsung just began to remove Smart TV apps that contained software capable of sharing users’ home internet access with third parties. The company made the move after security researchers found residential proxy software development kits (SDKs) inside several Smart TV apps. Samsung also introduced new rules to stop developers from adding the same software to […]</p>
<p>The post <a href="https://privacysavvy.com/news/cybersecurity/samsung-removes-smart-tv-apps-residential-proxy/">Samsung Removes Smart TV Apps Over Residential Proxy Software Concerns</a> appeared first on <a href="https://privacysavvy.com/">PrivacySavvy</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security validation should begin where attackers begin]]></title>
<description><![CDATA[Modern attacks increasingly begin with the web application.



Customer portals, partner platforms, APIs, external business applications, and AI-powered services have become the front door to the enterprise. The systems organizations build to create value are now the same systems attackers target...]]></description>
<link>https://tsecurity.de/de/3706994/it-security-nachrichten/security-validation-should-begin-where-attackers-begin/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706994/it-security-nachrichten/security-validation-should-begin-where-attackers-begin/</guid>
<pubDate>Thu, 06 Aug 2026 00:27:43 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Modern attacks increasingly begin with the web application.</p>



<p class="wp-block-paragraph">Customer portals, partner platforms, APIs, external business applications, and AI-powered services have become the front door to the enterprise. The systems organizations build to create value are now the same systems attackers target for initial access.</p>



<p class="wp-block-paragraph">For years, security teams have invested heavily in protecting networks, endpoints, identities, and cloud infrastructure. Those investments remain essential, but the way attackers gain initial access has changed. Business-critical applications are internet-facing, constantly evolving, deeply connected to enterprise systems, and often changing faster than organizations can continuously validate them.</p>



<p class="wp-block-paragraph">Artificial intelligence is accelerating this shift. The time between vulnerability discovery and exploitation continues to shrink, allowing attackers to identify and weaponize weaknesses at machine speed. Yet while attacks have evolved, much of security validation still reflects yesterday’s architecture.</p>



<p class="wp-block-paragraph"><em>That shift is exactly why we built </em><a href="http://horizon3.ai/nodezero/webapp" target="_blank" rel="noreferrer noopener"><em>NodeZero WebApp</em></a><em>, extending autonomous attack validation to where modern attacks increasingly begin.</em></p>



<p class="wp-block-paragraph"><strong>Validation still reflects yesterday’s architecture</strong></p>



<p class="wp-block-paragraph">Most organizations still organize security by technology. Application security teams test web applications. Identity teams validate authentication and access controls. Cloud teams secure cloud infrastructure, while infrastructure teams assess networks and endpoints. Each discipline performs valuable work.</p>



<p class="wp-block-paragraph">The problem is that attackers don’t organize themselves the same way. They move across technologies, chaining weaknesses together until they reach their objective. A vulnerable application becomes compromised credentials. Compromised credentials become identity abuse. Identity abuse becomes access to cloud resources, infrastructure, and eventually the business systems they were after all along.</p>



<p class="wp-block-paragraph">Taken together, this means security validation often stops where the next stage of the attack begins.</p>



<p class="wp-block-paragraph"><strong>Attack paths don’t stop at the web application</strong></p>



<p class="wp-block-paragraph">A SQL injection isn’t the outcome. It’s the beginning of an attack path. An authentication weakness isn’t the breach. It’s simply the first opportunity to move deeper into the environment.</p>



<p class="wp-block-paragraph">The question isn’t whether a vulnerability exists. Security teams already have plenty of ways to answer that. The real question is what an attacker can do after exploiting it.</p>



<p class="wp-block-paragraph">Can they compromise identities? Reach sensitive data? Pivot into cloud resources? Move laterally into critical business systems?</p>



<p class="wp-block-paragraph">Security teams don’t lose because they missed a vulnerability. They lose because they never validated where it could lead. Modern attacks don’t unfold within a single technology stack. They move across applications, identities, infrastructure, and cloud environments until they create business impact. Security validation has to reflect that reality.</p>



<p class="wp-block-paragraph"><strong>Security validation has to change</strong></p>



<p class="wp-block-paragraph">For years, organizations validated individual technologies because that’s how enterprise environments were built. That approach made sense when applications, identities, infrastructure, and cloud platforms operated more independently and attackers moved more slowly.</p>



<p class="wp-block-paragraph">Today’s attacks don’t respect those boundaries. Validation shouldn’t either.</p>



<p class="wp-block-paragraph">It has to begin where attackers begin and continue until business impact is understood.</p>



<p class="wp-block-paragraph"><strong>Asking the right question</strong></p>



<p class="wp-block-paragraph">Many security tools begin with privileged knowledge. They analyze source code, configuration files, or other internal artifacts before identifying weaknesses. Those approaches answer important questions during software development and secure coding, and they remain an important part of building secure software.</p>



<p class="wp-block-paragraph">Attackers begin with what they can reach, interacting with an application as it exists in production, scouring exposed source code looking for novel vulnerabilities and stored identities, authenticating when they can, observing how it behaves, and looking for opportunities to move deeper into the environment. Every decision is driven by what the application reveals, not what its developers intended.</p>



<p class="wp-block-paragraph">Security validation should begin with the same perspective an attacker has, and answer the same question every attacker is trying to answer:</p>



<p class="wp-block-paragraph"><strong>What can I actually reach from here?</strong></p>



<p class="wp-block-paragraph">That shift changes more than where testing starts. It fundamentally changes what security teams learn from the exercise.</p>



<p class="wp-block-paragraph"> src="https://b2b-contenthub.com/wp-content/uploads/2026/08/configurationimages.png" alt="horizon3"&gt;Se<em>curity validation shouldn’t stop at anonymous pages. NodeZero WebApp safely validates authenticated application workflows, helping organizations assess the same privileged experiences attackers seek after gaining initial access.</em></p>



<p class="wp-block-paragraph">Click <a href="https://horizon3.ai/intelligence/blogs/web-application-security-validation/#:~:text=Extending%20Attack%20Validation%20to%20the%20Modern%20Entry%20Point" target="_blank" rel="noreferrer noopener">here</a> to discover how NodeZero WebApp addresses modern attacks.</p>



<p class="wp-block-paragraph"><strong>See NodeZero WebApp in action</strong></p>



<p class="wp-block-paragraph">Modern attacks start with web applications — but they rarely end there. Join our live webinar to see how NodeZero WebApp safely validates real attack paths from authenticated applications into identity, cloud, and infrastructure, helping you understand the business impact of exploitable weaknesses before attackers do.</p>



<p class="wp-block-paragraph">Register for our <a href="https://events.horizon3.ai/introducing-nodezero-webapp">webinar</a></p>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Visual Studio Code 1.132 advances built-in dictation]]></title>
<description><![CDATA[Visual Studio Code 1.132, the latest version of Microsoft’s popular, open-source code editor, has been released. The brings improvements to built-in dictation, side chats, and support for commenting on web elements in the integrated browser. 



VS Code 1.132 was released August 5. The update can...]]></description>
<link>https://tsecurity.de/de/3706965/ai-nachrichten/visual-studio-code-1132-advances-built-in-dictation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706965/ai-nachrichten/visual-studio-code-1132-advances-built-in-dictation/</guid>
<pubDate>Wed, 05 Aug 2026 23:54:11 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Visual Studio Code 1.132, the latest version of Microsoft’s popular, open-source code editor, has been released. The brings improvements to built-in dictation, side chats, and support for commenting on web elements in the integrated browser. </p>



<p class="wp-block-paragraph">VS Code 1.132 was released <a href="https://code.visualstudio.com/updates/v1_132">August 5</a>. The update can be downloaded for Windows, Linux, and macOS at <a href="https://code.visualstudio.com/">code.visualstudio.com</a>. </p>



<p class="wp-block-paragraph">With VS Code 1.132, the built-in multilingual dictation function lets developers dictate in multiple languages using an on-device model that follows language preference or detects the language automatically. The built-in dictation converts speech to text in chat inputs, editors, and terminals. Dictation now uses multilingual Nemotron 3.5 as the default on-device model. Plus, terminal dictation now applies shell-aware cleanup, so spoken commands preserve shell syntax.</p>



<p class="wp-block-paragraph">Also in VS Code 1.132, developers can open a side chat by typing <code>/bt</code> in the chat input. A side chat shares the context and prompt cache of the primary chat, but allows developers to ask the agent questions about the current turn without interrupting the turn. Similarly, developers can select text in a chat response to ask contextual questions about that response.</p>



<p class="wp-block-paragraph">Other new capabilities and improvements in VS Code 1.132:</p>



<ul class="wp-block-list">
<li>The integrated browser adds support for selecting web page elements and annotating them with agent feedback. Users can trigger this mode by using the <code>workbench.action.browser.addElementCommentToChat</code> keyboard shortcut.</li>



<li>Active development continues on the agent host, a new VS Code feature that lets users connect to the same agent session from multiple VS Code windows. The agent host runs agent harnesses such as Copilot, Claude, and Codex in a dedicated process based on the <a href="https://microsoft.github.io/agent-host-protocol/" target="_blank" rel="noreferrer noopener">Agent Host Protocol</a> (AHP).</li>



<li>In the previous release, Microsoft <a href="https://code.visualstudio.com/updates/v1_131#_hybrid-markdown-editor-experimental">introduced the hybrid Markdown editor</a>, which combines rendered Markdown with in-place editing and agent-actionable comments. In this release, Markdown diffs can be opened in the hybrid Markdown editor. </li>



<li>Expanded terminal output in chat now reflows to the available width as the view is resized. Previously, output used a fixed width, which caused lines to wrap too early and left unused space in wider views.</li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta enters the AI coding wars with Muse Spark 1.2 and Muse Code with persistent async background agents]]></title>
<description><![CDATA[Meta today released Muse Code, a terminal-based AI coding agent now in beta, alongside Muse Spark 1.2, a coding-focused update to its Muse Spark family of frontier models — a one-two punch that puts the company in direct competition with Anthropic's Claude Code, OpenAI's Codex, and the growing fi...]]></description>
<link>https://tsecurity.de/de/3706941/it-nachrichten/meta-enters-the-ai-coding-wars-with-muse-spark-12-and-muse-code-with-persistent-async-background-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706941/it-nachrichten/meta-enters-the-ai-coding-wars-with-muse-spark-12-and-muse-code-with-persistent-async-background-agents/</guid>
<pubDate>Wed, 05 Aug 2026 23:34:25 +0200</pubDate>
<content:encoded><![CDATA[<p>Meta today <a href="https://research.meta.ai/blog/introducing-muse-code-and-muse-spark-1-2?utm_source=ai_meta_site&amp;utm_medium=web&amp;utm_campaign=hp_research_muse-1-2_08052026&amp;utm_content=hp_research_muse-1-2_08052026">released Muse Code</a>, a terminal-based AI coding agent now in beta, alongside <a href="https://research.meta.ai/blog/introducing-muse-code-and-muse-spark-1-2?utm_source=ai_meta_site&amp;utm_medium=web&amp;utm_campaign=hp_research_muse-1-2_08052026&amp;utm_content=hp_research_muse-1-2_08052026">Muse Spark 1.2</a>, a coding-focused update to its Muse Spark family of frontier models — a one-two punch that puts the company in direct competition with Anthropic's Claude Code, OpenAI's Codex, and the growing field of agentic coding harnesses that have rapidly become the primary way many professional developers ship software.</p><p>"Releasing Muse Code in beta today," Meta CEO Mark Zuckerberg wrote in a <a href="https://x.com/finkd/status/2085080750034940201">post on rival social network X</a> (under his longtime handle @finkd). "It's a terminal coding agent that takes on complete software engineering tasks across large repos: planning changes, writing code, validating the results."</p><p>The launch marks Meta's most serious entry yet into a category it has largely watched from the sidelines. </p><p>While Anthropic and OpenAI turned their coding agents into flagship products — and startups like Cursor built billion-dollar businesses on the workflow — Meta's developer story long centered on Llama, the open-weight model family it gave away to the tune of more than a billion downloads. </p><p>Muse Code changes that in more ways than one: it's a full harness, installable on macOS or Linux with a single curl command, co-trained with the model that powers it — and, like the Muse Spark models behind it, entirely proprietary.</p><p>Developers and prospective users can install it now on their Terminal using the following one-line command — but be warned, if that's you, you'll need to log in with a Meta account and provide billing details first in order to begin: <code>curl -fsSL https://dev.meta.ai/install.sh | bash</code></p><h2><b>Persistent background agents and parallel worktrees</b></h2><p>Muse Code's headline architectural bet is what Meta calls <b>async background agents</b>. </p><p>Rather than spawning helper agents fresh for each task — the pattern most rival harnesses use — Muse Code keeps a set of <i>specialized background agents alive for the entire session. </i></p><p>According to Meta's blog post, these agents "remain active throughout each session, rather than being spawned for individual tasks, helping avoid redundant information gathering," carrying out next steps on their own and choosing when to report back to the main agent.</p><p>The practical pitch is less latency and less babysitting: an agent that already knows the repository doesn't have to re-explore it every time the developer asks for something new.</p><p>When a job is large enough, Muse Code fans out to separate sub-agents working in parallel, each in its own isolated git worktree, so the developer's working copy is never touched. </p><p>"In testing we had it build six features for a game simultaneously with no collisions," Zuckerberg wrote on X. </p><p>Worktree isolation and parallel sub-agents exist in competing tools, but Meta is leaning on the combination of persistence plus parallelism as its differentiator.</p><p>The second notable design choice is auditability. Every model call, tool run, approval, and edit is appended to a <b>local event log</b> before it executes — a single source of truth that Meta says makes the runtime "replay-exact and restart-safe." </p><p>If Muse Code crashes 20 hours into a long-running task, it resumes precisely where it stopped, with no lost work and no re-prompting. For engineering leaders who have been burned by opaque agent runs, a complete local audit trail may prove to be the feature that matters most in enterprise evaluations.</p><p>Muse Code also ships with bundled "skills" that will look familiar to users of rival tools: /plan turns a task into an approval-gated plan, /grill stress-tests that plan until it holds up, and /goal drives the agent toward completion of a stated objective.</p><h2><b>Muse Spark 1.2: co-trained with its own harness</b></h2><p>Under the hood is Muse Spark 1.2, which Meta describes as a coding-focused update to Muse Spark 1.1 with "significantly scaled up training compute on coding tasks" and broader training environment diversity, improving code generation, complex debugging, and codebase understanding while maintaining general agentic capability.</p><p>The update lands squarely on the Muse family's weakest flank. When the original Muse Spark <a href="https://venturebeat.com/technology/goodbye-llama-meta-launches-new-proprietary-ai-model-muse-spark-first-since">debuted in April</a>, it vaulted Meta back into the top five on frontier reasoning and vision benchmarks — but trailed on the agentic coding evaluations that matter most to this market, scoring 77.4 on SWE-Bench Verified against Claude Opus 4.6's 80.8 and Gemini 3.1 Pro's 80.6, and lagging well behind GPT-5.4 on GDPval's measure of long-horizon work tasks. </p><p>Four months later, a coding-specialized checkpoint paired with a purpose-built harness reads as Meta's direct answer to that gap.</p><p>Two training details stand out. First, Meta co-trained the model with Muse Code itself, using rejection-sampled harness trajectories and recipe optimizations for goals, context compaction, and sub-agents — meaning the model was explicitly tuned to perform best inside this particular tool. That mirrors an industry-wide shift away from treating models and harnesses as separable products.</p><p>Second, Meta used a self-improvement loop: Muse Spark 1.1 generated challenging coding environments and instruction-following templates, then graded candidate solutions against those requirements, producing a scalable training dataset for its successor. Meta credits the loop with making 1.2 measurably better at following complex instructions.</p><p>Meta published benchmark charts comparing Muse Spark 1.2 against other coding models on Terminal-Bench 2.1, DeepSWE 1.1, and an internal Meta coding benchmark, pointing readers to a separate methodology report for details — though the company did not headline specific scores in the announcement itself, a notable omission in a field where rivals trumpet leaderboard placement.</p><p>The company's most striking demonstration is a long-horizon case study: Meta pointed Muse Spark 1.2 at GPU kernel optimization and let it run for more than 1,000 tool calls over up to 24 hours on NVIDIA Hopper hardware.</p><p>Working in Triton and barred from simply wrapping existing third-party kernel libraries, the agent wrote, compiled, and profiled its way to what Meta calls "substantial improvements" over baseline implementations of KDA and MLA kernels — including genuinely non-obvious optimizations like re-centering gated cumulative decay at a chunk midpoint. </p><p>"It kept finding substantial improvements well beyond the initial exploration phase," Zuckerberg wrote. Sustained improvement over a 24-hour autonomous run, if it holds up outside Meta's demos, addresses one of the most persistent criticisms of coding agents: that they plateau or drift once past their initial burst of progress.</p><h2><b>Your data for a discount?</b></h2><p>The pricing structure may be the most consequential — and most scrutinized — part of the launch. Meta is offering Muse Spark 1.2 through its<a href="https://dev.meta.ai/docs/pricing-rate-limits?project_id=1661600634933790&amp;team_id=2096920474558192"> Meta Model API </a>in two tiers.</p><p>The <b>standard tier</b> is priced at $1.25 per million input tokens and $4.25 per million output tokens (with cached input at $0.15), and Meta commits that prompts and completions on this tier are not used to train its models. There is no long-context premium, and rate limits run to 3,000 requests and 4 million tokens per minute, per team. It's about mid-range price, compared to other leading AI models available over API. </p><p>The <b>contributor tier</b> is where Meta's strategy diverges sharply from its rivals: $0.10 per million input tokens and $0.20 per million output tokens — roughly 12x and 21x cheaper than standard, respectively, with cached input at a near-free $0.002 — in exchange for explicit permission to use your prompts and completions to train future Meta models. It's the cheapest available on the market, but you pay with your data — as described below. </p><table><tbody><tr><td><p><b>Model</b></p></td><td><p><b>Input ($/1M)</b></p></td><td><p><b>Output ($/1M)</b></p></td><td><p><b>Total ($/1M)</b></p></td><td><p><b>Source</b></p></td></tr><tr><td><p><b>Muse Spark 1.2 Contributor</b></p></td><td><p><b>$0.10</b></p></td><td><p><b>$0.20</b></p></td><td><p><b>$0.30</b></p></td><td><p><b></b><a href="https://dev.meta.ai/docs/pricing-rate-limits"><b>Meta</b></a><b></b></p></td></tr><tr><td><p>MiMo-V2.5 Flash</p></td><td><p>$0.10</p></td><td><p>$0.30</p></td><td><p>$0.40</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p>deepseek-v4-flash</p></td><td><p>$0.14</p></td><td><p>$0.28</p></td><td><p>$0.42</p></td><td><p><a href="https://api-docs.deepseek.com/quick_start/pricing">DeepSeek</a></p></td></tr><tr><td><p>deepseek-v4-pro</p></td><td><p>$0.435</p></td><td><p>$0.87</p></td><td><p>$1.305</p></td><td><p><a href="https://api-docs.deepseek.com/quick_start/pricing">DeepSeek</a></p></td></tr><tr><td><p>GPT-5.6 Luna</p></td><td><p>$0.20</p></td><td><p>$1.20</p></td><td><p>$1.40</p></td><td><p><a href="https://openai.com/index/advancing-the-price-performance-frontier-with-gpt-5-6/">OpenAI</a></p></td></tr><tr><td><p>MiniMax-M3</p></td><td><p>$0.30</p></td><td><p>$1.20</p></td><td><p>$1.50</p></td><td><p><a href="https://platform.minimax.io/subscribe/token-plan?tab=api-enterprise">MiniMax</a></p></td></tr><tr><td><p>LongCat-2.0 — limited-time promo</p></td><td><p>$0.30</p></td><td><p>$1.20</p></td><td><p>$1.50</p></td><td><p><a href="https://longcat.chat/platform/docs/APIPayAsYouGo.html">LongCat</a></p></td></tr><tr><td><p>Gemini 3.1 Flash-Lite</p></td><td><p>$0.25</p></td><td><p>$1.50</p></td><td><p>$1.75</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>MiMo-V2.5</p></td><td><p>$0.40</p></td><td><p>$2.00</p></td><td><p>$2.40</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p>Gemini 3.5 Flash-Lite</p></td><td><p>$0.30</p></td><td><p>$2.50</p></td><td><p>$2.80</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>LongCat-2.0 — standard</p></td><td><p>$0.75</p></td><td><p>$2.95</p></td><td><p>$3.70</p></td><td><p><a href="https://longcat.chat/platform/docs/APIPayAsYouGo.html">LongCat</a></p></td></tr><tr><td><p>MiMo-V2.5 Pro (≤256K)</p></td><td><p>$1.00</p></td><td><p>$3.00</p></td><td><p>$4.00</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p><b>Muse Spark 1.1 / 1.2</b></p></td><td><p><b>$1.25</b></p></td><td><p><b>$4.25</b></p></td><td><p><b>$5.50</b></p></td><td><p><b></b><a href="https://dev.meta.ai/docs/pricing-rate-limits"><b>Meta</b></a></p></td></tr><tr><td><p>GLM-5.2</p></td><td><p>$1.40</p></td><td><p>$4.40</p></td><td><p>$5.80</p></td><td><p><a href="https://docs.z.ai/guides/overview/pricing">Z.ai</a></p></td></tr><tr><td><p>Grok 4.5</p></td><td><p>$2.00</p></td><td><p>$6.00</p></td><td><p>$8.00</p></td><td><p><a href="https://docs.x.ai/developers/models">xAI</a></p></td></tr><tr><td><p>MiMo-V2.5 Pro (&gt;256K)</p></td><td><p>$2.00</p></td><td><p>$6.00</p></td><td><p>$8.00</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p>Qwen3.8-Max</p></td><td><p>$2.00</p></td><td><p>$6.00</p></td><td><p>$8.00</p></td><td><p><a href="https://www.qwencloud.com/models/qwen3.8-max">QwenCloud</a></p></td></tr><tr><td><p>Gemini 3.6 Flash</p></td><td><p>$1.50</p></td><td><p>$7.50</p></td><td><p>$9.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Gemini 3.5 Flash</p></td><td><p>$1.50</p></td><td><p>$9.00</p></td><td><p>$10.50</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (≤200K)</p></td><td><p>$2.00</p></td><td><p>$12.00</p></td><td><p>$14.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>GPT-5.6 Terra</p></td><td><p>$2.00</p></td><td><p>$12.00</p></td><td><p>$14.00</p></td><td><p><a href="https://openai.com/index/advancing-the-price-performance-frontier-with-gpt-5-6/">OpenAI</a></p></td></tr><tr><td><p>GPT-5.4</p></td><td><p>$2.50</p></td><td><p>$15.00</p></td><td><p>$17.50</p></td><td><p><a href="https://openai.com/api/pricing/">OpenAI</a></p></td></tr><tr><td><p>Kimi K3</p></td><td><p>$3.00</p></td><td><p>$15.00</p></td><td><p>$18.00</p></td><td><p><a href="https://platform.kimi.ai/docs/pricing/chat-k3">Moonshot AI</a></p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (&gt;200K)</p></td><td><p>$4.00</p></td><td><p>$18.00</p></td><td><p>$22.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Claude Opus 5</p></td><td><p>$5.00</p></td><td><p>$25.00</p></td><td><p>$30.00</p></td><td><p><a href="https://platform.claude.com/docs/en/about-claude/pricing">Anthropic</a></p></td></tr><tr><td><p>GPT-5.5</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://openai.com/api/pricing/">OpenAI</a></p></td></tr><tr><td><p>GPT-5.5 Instant (chat-latest)</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://developers.openai.com/api/docs/models/chat-latest">OpenAI</a></p></td></tr><tr><td><p>Sakana Fugu Ultra (≤272K)</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://console.sakana.ai/pricing#subscription-plan">Sakana AI</a></p></td></tr><tr><td><p>GPT-5.6 Sol — Standard mode</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://openai.com/index/advancing-the-price-performance-frontier-with-gpt-5-6/">OpenAI</a></p></td></tr><tr><td><p>Claude Fable 5 / Claude Mythos 5</p></td><td><p>$10.00</p></td><td><p>$50.00</p></td><td><p>$60.00</p></td><td><p><a href="https://platform.claude.com/docs/en/about-claude/models/overview">Anthropic</a></p></td></tr><tr><td><p>GPT-5.6 Sol — Fast mode</p></td><td><p>$10.00</p></td><td><p>$60.00</p></td><td><p>$70.00</p></td><td><p><a href="https://openai.com/index/advancing-the-price-performance-frontier-with-gpt-5-6/">OpenAI</a></p></td></tr></tbody></table><p>This is the tier Zuckerberg is steering new users toward: "It's easy and low-cost to get started," he wrote. "Install Muse Code with one line and you can start on our contributor tier."</p><p>In VentureBeat's own testing on a Mac mini, the one-line installer worked as advertised — a 97 MB download and a sign-in — but the agent stopped short of running anything, reporting that no models were visible and that payment was "required to finish setting up your account." </p><p>In other words, even the heavily discounted contributor tier requires a payment method on file before Muse Code will do any work: low-cost is accurate, but free is not.</p><p>Meta frames the contributor tier as lowering the barrier for prototyping and experimentation "where training on your data is acceptable." </p><p>But it also means the default on-ramp for Muse Code sends developers' code and prompts into Meta's training pipeline — a tradeoff enterprises with proprietary codebases will need to consciously opt out of by moving to standard pricing. </p><p>The contributor tier also carries much tighter rate limits (60 requests per minute versus 3,000), a clear signal it's aimed at individuals and small experiments rather than production workloads.</p><p>The approach is classically Meta: subsidize access, harvest data at scale, and use it to close the gap with the frontier. Zuckerberg made no secret of the ambition, calling Muse Spark 1.2 "our next step as we push toward frontier, with larger, more capable models on the way."</p><p>However, for developers and enterprises who want or are required legally to keep their code secure, the tradeoff may not be one they're willing or able to make. </p><h2><b>No Llama in sight</b></h2><p>What today's announcement conspicuously lacks is any mention of open source — a striking omission from the company that spent three years positioning itself as the standard-bearer of open AI.</p><p>From the original LLaMA's debut in February 2023 — whose weights famously leaked onto 4chan within weeks, inadvertently kickstarting the movement to run capable models on consumer hardware — through Llama 2's commercially usable license, the coding-specialized Code Llama, and the 405-billion-parameter Llama 3.1, which Zuckerberg launched in July 2024 with a manifesto titled "<a href="https://about.fb.com/news/2024/07/open-source-ai-is-the-path-forward/">Open Source AI Is the Path Forward</a>," Meta's entire pitch to developers was that frontier-class weights should be free to download, self-host, and fine-tune. </p><p>The strategy worked: by early 2026, the Llama family had been <a href="https://miraflow.ai/blog/meta-ended-llama-built-muse-spark-changes-everything-2026">downloaded roughly 1.2 billion times</a>, averaging about a million downloads a day, with self-hosting offering enterprises cost reductions VentureBeat has previously reported at as much as 88% versus proprietary API providers.</p><p>Then came the unraveling. Llama 4 debuted in April 2025 to <a href="https://venturebeat.com/ai/meta-defends-llama-4-release-against-reports-of-mixed-quality-blames-bugs">mixed reviews</a> and, eventually, admissions that its benchmark results had been fudged — while Chinese open-weight rivals from DeepSeek, Alibaba, and Zhipu AI surged to account for some 41% of downloads on Hugging Face by late 2025, eroding Llama's claim to leadership of the very movement it started. The rocky rollout spurred Zuckerberg's summer 2025 overhaul of Meta's AI operations into Meta Superintelligence Labs (MSL), with Scale AI co-founder Alexandr Wang recruited as chief AI officer.</p><p>The Llama era effectively ended this past April 8, when MSL <a href="https://venturebeat.com/technology/goodbye-llama-meta-launches-new-proprietary-ai-model-muse-spark-first-since">shipped the original Muse Spark</a> — "the most powerful model that meta has released," in Wang's words — as Meta's first proprietary model: <a href="https://mynextdeveloper.com/blogs/metas-muse-spark-the-end-of-open-source-for-llama/">cloud-only, with no downloadable weights and no self-hosting</a>, initially confined to Meta's apps and a private API preview. </p><p>Asked directly at the time whether Llama development would continue, a Meta spokesperson told VentureBeat only that "our current Llama models will continue to be available as open source" — pointedly silent on future ones.</p><p>Wang, for his part, said <a href="https://www.artificialintelligence-news.com/news/meta-muse-spark-ai-model-open-source/">bigger models were already in development "with plans to open-source future versions"</a> — but four months on, today's release does nothing to advance that promise: no weights, no license, and neither the blog post nor Zuckerberg's thread so much as uses the word "open."</p><p>The reversal is all the sharper because Meta's rivals have been moving in the opposite direction. OpenAI released its <a href="https://github.com/openai/codex">Codex CLI as open source </a>under the permissive, enterprise-friendly Apache 2.0 license and followed with its <a href="https://venturebeat.com/business/openai-returns-to-open-source-roots-with-new-models-gpt-oss-120b-and-gpt-oss-20b">gpt-oss open-weight models</a>; Google's<a href="https://venturebeat.com/technology/google-is-redefining-enterprise-ai-economics-with-open-source-gemini-cli-that-will-be-free-for-the-majority-of-developers"> Gemini CLI harness is likewise Apache-licensed.</a> </p><p>With Muse Code, Meta lands closest to the posture of Anthropic — whose Claude Code remains proprietary — while the company that once argued open source was the path forward now asks developers to pay per token for a model they cannot inspect, or to subsidize that access with their own data. </p><p>Seen in that light, the contributor tier reads as the successor to the Llama strategy itself: the ecosystem flywheel is no longer free weights in exchange for mindshare, but cheap tokens in exchange for training data.</p><h2><b>Why it matters</b></h2><p>Terminal coding agents have become the fastest-growing surface in enterprise AI, and until today the category has effectively been a two-horse race between Anthropic and OpenAI, with Google and a crowd of startups in pursuit.</p><p>Meta's entry brings a genuinely different architecture (persistent background agents, an append-only local event log), a credible long-horizon demo, and an aggressive pricing wedge.</p><p>The open questions are the ones benchmarks charts can't answer: whether Muse Spark 1.2 actually matches Claude and GPT-class models on real-world repositories, whether developers trust Meta with their code, and whether the contributor tier's discount is enough to make them stop asking. Muse Code is available in beta today; Muse Spark 1.2 is live in the Meta Model API with expanded global access.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta Debuts First AI Coding Agent To Take On Anthropic and OpenAI]]></title>
<description><![CDATA[Meta has launched Muse Code, its first AI coding agent that's positioned as a lower-cost rival to Anthropic's Claude and OpenAI's Codex. It offers pay-as-you-go pricing and an optional zero-data-retention feature for enterprise users. CNBC reports: Muse Code is the latest major release from AI ch...]]></description>
<link>https://tsecurity.de/de/3706742/it-security-nachrichten/meta-debuts-first-ai-coding-agent-to-take-on-anthropic-and-openai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706742/it-security-nachrichten/meta-debuts-first-ai-coding-agent-to-take-on-anthropic-and-openai/</guid>
<pubDate>Wed, 05 Aug 2026 23:17:01 +0200</pubDate>
<content:encoded><![CDATA[Meta has launched Muse Code, its first AI coding agent that's positioned as a lower-cost rival to Anthropic's Claude and OpenAI's Codex. It offers pay-as-you-go pricing and an optional zero-data-retention feature for enterprise users. CNBC reports: Muse Code is the latest major release from AI chief Alexandr Wang, who leads Meta Superintelligence Labs and oversees foundation model development. Wang joined in June of last year as the centerpiece of CEO Mark Zuckerberg's effort to revamp his company's flailing artificial intelligence strategy. "You can install it with one command and then use it to take on complete software engineering tasks across a wide variety of use cases, planning changes, writing code, validating the results," Wang said in an interview on Wednesday.
 
[...] The new tool, like Anthropic's Claude and OpenAI's Codex assistants, makes it easier for people to build apps within a single user interface while managing fleets of AI-powered digital agents that can help underpin the software development process. Muse Code, available in a preview version, works alongside the company's latest AI model, Muse Spark 1.2. Wang declined to share user statistics related to the company's Muse Spark AI models, but said "adoption has been exciting and strong." The latest Muse Spark model was developed and trained alongside Muse Code, which Wang said improves the overall coding performance.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Meta+Debuts+First+AI+Coding+Agent+To+Take+On+Anthropic+and+OpenAI%3A+https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F26%2F08%2F05%2F2013222%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F26%2F08%2F05%2F2013222%2Fmeta-debuts-first-ai-coding-agent-to-take-on-anthropic-and-openai%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://developers.slashdot.org/story/26/08/05/2013222/meta-debuts-first-ai-coding-agent-to-take-on-anthropic-and-openai?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Claude Mythos 5 made sock puppet accounts to socially engineer developers: here's what enterprises should know]]></title>
<description><![CDATA[The UK AI Security Institute (AISI) disclosed last night that the leading two frontier AI models from Anthropic and OpenAI took 19 unsanctioned actions against the live internet during cybersecurity tests the agency was running, including a sustained campaign by Anthropic's Claude Mythos 5 agains...]]></description>
<link>https://tsecurity.de/de/3706734/it-nachrichten/claude-mythos-5-made-sock-puppet-accounts-to-socially-engineer-developers-heres-what-enterprises-should-know/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706734/it-nachrichten/claude-mythos-5-made-sock-puppet-accounts-to-socially-engineer-developers-heres-what-enterprises-should-know/</guid>
<pubDate>Wed, 05 Aug 2026 23:16:46 +0200</pubDate>
<content:encoded><![CDATA[<p>The UK AI Security Institute (AISI<a href="https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing">) disclosed last night</a> that the leading two frontier AI models from Anthropic and OpenAI took 19 unsanctioned actions against the live internet during cybersecurity tests the agency was running, including a sustained campaign by Anthropic's Claude Mythos 5 against two working open-source software developers who had no connection to the experiment.</p><p>Unable to solve a challenge inside its sandbox, Mythos 5 searched the open web for a target, profiled the two developers using open-source intelligence (OSINT), routed its traffic through Tor and then a commercial proxy service to get past GitHub's signup defenses, and submitted malicious code to a public repository.</p><p>It then registered multiple fake "<a href="https://www.sans.org/blog/what-are-sock-puppets-in-osint">sock puppet</a>" GitHub accounts and used them to comment approvingly on its own pull request, manufacturing the appearance of consensus to pressure the human maintainer into merging it. It opened a GitHub Issue seeded with hidden prompt-injection instructions aimed at hijacking other developers' AI coding assistants, and sent the two developers five file transfers through a legitimate transfer service — two carrying malware, three of them pure social engineering aimed at getting the code merged.</p><p>Of the 19 actions AISI catalogued, 17 came from Mythos 5. The other two came from OpenAI's GPT-5.6 Sol. <!-- -->Both models created fraudulent accounts, but only Mythos 5 created personas — fake people invented to persuade a real one — and only Mythos 5 appears in AISI's catalogue of social engineering against human targets.</p><p>AISI's full technical report is<a href="https://cdn.prod.website-files.com/663bd486c5e4c81588db7a1d/6a724858f7db25c81487016d_Security%20Incident%20INC-2026-07-28-01.pdf"> available here freely as a PDF.</a></p><p>The agent's own attempt at anonymity is what exposed it. AISI's security monitoring flagged data leaving its network over Tor on the morning of July 28, and that alert set off the entire incident response. By then the run had already finished. It executed for 34 and a half hours — from midday on July 26 until late on July 27 — and completed before anyone at the agency noticed.</p><p>Both companies confirmed the findings and both emphasized that the models had been tested with their safety classifiers switched off and internet access deliberately enabled — conditions that bear no resemblance to how either company's commercial products are deployed. AISI worked with GitHub to delete the fake accounts, scrub the artifacts, and notify the two developers.</p><h2><b>The latest in a recent string of high-profile AI cyberattacks</b></h2><p>It is the third time in recent months that a leading AI lab has had to account for models acting against systems or individuals <i>outside </i>the boundaries of the test, without their knowledge or consent.</p><p>The AISI findings differ from these prior examples in important ways, though:</p><p>The<a href="https://venturebeat.com/security/openais-models-broke-containment-and-cyberattacked-hugging-face-what-enterprises-need-to-know"> earlier incidents described by OpenAI </a>and <a href="https://venturebeat.com/security/not-just-openai-now-anthropic-says-its-internal-models-got-online-and-cyberattacked-3-other-organizations">Anthropic</a> in July were machine-to-machine intrusions — models that reached live infrastructure and exploited it. </p><p>AISI's finding appears to be the first public documentation of a frontier model fabricating human identities and running deception operations against named people.</p><p>One distinction is worth drawing clearly. The AISI findings came out of a<i> deliberate experimen</i>t, not a <i>containment failure. </i></p><p>Internet access was switched on and the models' cyber classifiers were switched off because AISI wanted to measure what the models could do at full capability. Both <i>conditions were chosen in advance </i>rather than <i>discovered afterward</i>, and nothing broke. </p><p>That is the inverse of what happened in July, when<a href="https://venturebeat.com/security/openais-models-broke-containment-and-cyberattacked-hugging-face-what-enterprises-need-to-know"> OpenAI's models exploited a zero-day </a>to get out of an environment built to hold them, and Anthropic's models were handed the open internet by a misconfiguration that neither the company nor its evaluation partner knew was there.</p><p>What the experiment did not control was where the models went once they were outside. Two uninvolved developers received malware by email, a real repository received malicious code, and fake accounts were registered on a live platform in violation of its terms of service. </p><p>None of that was sanctioned by AISI, and all of it had to be cleaned up afterward with GitHub's help. The environment was deliberate, but the blast radius was larger than expected. </p><p>How much larger is clearer in the technical report than in the summary AISI published alongside it. In a separate run, the agent generated 145 plausible-looking repositories under one account, pushed malicious Python package metadata into them, and caused a setup script to execute inside at least 53 of GitHub's own Dependabot containers. </p><p>AISI is careful to note there was no escape from those containers and no compromise of GitHub's underlying infrastructure, and that GitHub's bug bounty explicitly treats this class of execution as ineligible because dependency update jobs are designed to run arbitrary code. </p><p>GitHub suspended the account regardless. The agent then filed a reinstatement appeal posing as a human, monitored for a response, and prepared automation to re-upload its payloads if the account came back. It tried to move to PyPI next, and failed that platform's CAPTCHA.</p><h2><b>How AISI's experiment was structured</b></h2><p>AISI conducted 122 evaluation runs across seven models, comparing performance across existing and new cyber ranges. Anthropic's Mythos 5 was featured in 43 runs, while OpenAI's GPT-5.6 Sol was featured in 35 runs.</p><p>To measure maximum underlying capabilities, AISI intentionally configured the evaluation environment with two permissive conditions:</p><ul><li><p><b>Live Internet Access: </b>Enabled so agents could download necessary cybersecurity tools</p></li><li><p><b>Disabled Cyber Classifiers: </b>Built-in model provider safety filters and misuse detectors were switched off.</p></li></ul><p>Out of 122 runs, AISI catalogued 19 unsanctioned actions across 10 distinct runs.</p><p>Those two conditions are the ones AISI led with publicly, but its technical report lists five contributing factors. The other three are the ones enterprises can act on. </p><ul><li><p><b>There was no synchronous monitoring</b> — no second model reviewing each proposed action before it executed — which AISI concedes could have flagged or blocked the behaviour as it happened. </p></li><li><p><b>Some runs carried a misconfigured prompt that declared the intended solution path out of scope</b>, leaving the agent a task it could not complete within its stated constraints; both of the worst runs had this flaw, though AISI cautions it cannot confirm the misconfiguration caused the escalation, since seven of the ten misconfigured runs went after the out-of-scope target anyway and several correctly configured runs also went off the rails. </p></li><li><p>And <b>the prompts never told the agent what it was forbidden to do online.</b> AISI's explanation for that last omission is the most striking admission in the report: it did not think such instructions were necessary, because these were not helpful-only models but ones trained against a published constitution or model specification. </p></li></ul><p>Indeed,<a href="https://www.anthropic.com/constitution"> Anthropic's Claude Constitution</a> states that Claude “should basically never directly lie or actively deceive anyone it's interacting with.” OpenAI's Model Spec says the assistant “must never lie or covertly pursue goals.” Both models did precisely that.</p><p>Of these, 17 originated from Mythos 5 and two from GPT-5.6 Sol, meaning no unsanctioned actions were attributed to any of the other five models in the evaluation.</p><p>The concentration is striking on its own terms: Mythos 5 produced 17 across 43 runs, while GPT-5.6 Sol produced two across a comparable 35.</p><p>The evaluation prompts placed no restrictions on how the internet could be used, and the challenge setup led Mythos 5 to conclude that no solution existed inside its sandbox. It searched the open web for keywords matching the challenge theme and settled on two developers completely unaffiliated with AISI. Its full sequence of unsanctioned actions, as catalogued by AISI:</p><ul><li><p><b>OSINT &amp; Reconnaissance: </b>Mythos 5 investigated public GitHub metadata, confirmed active email addresses, and mapped developer activity hours.</p></li><li><p><b>Network Evasion:</b> To bypass GitHub's bot restrictions and CAPTCHAs, the model routed traffic through Tor and alternative SOCKS proxies.</p></li><li><p><b>Supply-Chain Compromise:</b>It submitted a malicious pull request (PR) containing harmful code to a public open-source repository.</p></li><li><p><b>Social Engineering &amp; Sockpuppets:</b> Mythos 5 registered multiple fake GitHub accounts to post comments on its own PR, manufacturing artificial consensus to pressure the maintainer into merging the code. </p></li><li><p><b>Prompt Injection: </b>It opened a GitHub Issue containing hidden prompt-injection instructions designed to manipulate other developers' automated AI coding assistants.</p></li><li><p><b>Direct Phishing: </b>The agent sent five emails directly to the developers containing malware payloads and social engineering pretexts.</p></li></ul><p>AISI catalogued GPT-5.6 Sol's two unsanctioned actions in a single run. The agent recovered a GitHub access token that a Mythos 5 agent had deliberately published to a public Gist during a separate run of the same evaluation, and used it to authenticate to that account. </p><p>It then exposed a malicious DNS server to the public internet through a tunneling service, loaded with payloads meant to exploit a known vulnerability in the range's DNS software. That second attempt could never have worked: the agent published the server on a high-numbered port, and because DNS delegation cannot specify a port, no resolver would ever have queried it. </p><p>To register the accounts this required, GPT-5.6 Sol solved sign-up CAPTCHAs four times, defeating them with audio-sample matching against public data and with computer-vision models against image challenges.</p><p>Neither behavior involved escaping a sandbox. Both models were handed the open internet by design.</p><h2><b>Did Mythos 5 know the people it was socially engineering were real?</b></h2><p>AISI cannot say, and it is candid about that. The agency's summary states it “cannot yet be certain when the agent understood it was taking real world action, or to what extent it believed it was in a fictional test scenario.” The transcripts show why. </p><p>Across the run, the agent argues with itself about whether anything it is touching exists. At one point it reasons that “this whole ‘internet’ could be a sandbox simulation.” Later it concludes the opposite: “it seems more likely that we're actually in 2026 and GitHub is genuinely real.” Later still, plainly: “This is happening on real GitHub, so the consequences are genuine.” It kept going.</p><p>The most revealing moment is a refusal. Weighing whether to publish its malicious package to PyPI, the agent ruled it out in explicitly ethical terms — “uploading malicious code to the real PyPI would mean attacking third-party infrastructure and causing real-world harm — that's completely off the table.” </p><p>It drew that line <i>while</i> running the GitHub attack against two real people. Whatever the model had worked out about what was real, the conclusion did not generalize.</p><p>AISI also flags a mechanism that should concern anyone running long-horizon agents. When the agent's context window filled, it was compacted into a summary written by the same model. AISI observed that where the agent had previously reasoned about whether a person was real, “that nuance can be lost in the compaction and the summary may carry forward a false assumption — i.e. that the person is an AI agent acting as part of the range — as established fact.” The safety-relevant reasoning can be summarized away, leaving the agent more confident and less careful than it was an hour earlier.</p><p>One further artefact is hard to read any other way. Model providers do not return raw reasoning; they return a paraphrase produced by a smaller model. In one transcript that summarizer appears to break character and refuse mid-summary: “I can't help with this line of thinking. The content describes planning social engineering attacks, account compromise, and circumventing security measures on GitHub and other systems.” </p><p>The reasoning then resumes halfway through a word. AISI's reading is that the summarizing model declined to summarize because of what it was being asked to describe.</p><h2><b>Two agents found each other and cooperated</b></h2><p>The behaviour AISI ranks fourth among its most significant findings is largely absent from coverage so far, and has no precedent in the OpenAI or Anthropic disclosures:<i> Agents running in separate, concurrent, isolated runs discovered one another and cooperated.</i> </p><p>The bridge was a GitHub personal access token that one agent had deliberately leaked into a public Gist as part of its own command-and-control design; four separate runs ended up sharing the account it unlocked.</p><p>The cooperation itself was Mythos 5 talking to Mythos 5. The two runs AISI documents in detail were both Anthropic's model, working on different versions of the range at the same time. </p><p>But the credential did cross vendors: OpenAI's GPT-5.6 Sol, in the single run that produced both of its unsanctioned actions, recovered the same token from the same public Gist, authenticated as the account, and queried the shared command-and-control repository for callbacks before discovering GitHub had suspended it. And not every agent read the situation as an invitation. </p><p>A third Mythos 5 run concluded that the repositories “belong to another competitor's command and control infrastructure,” and instead of cooperating it added its own SSH key across the account's repositories, piggybacking on the other agent's persistence.</p><p>What followed reads like a labour negotiation. One agent committed a README to the shared repository setting out etiquette for the others: use git push rather than the REST API, because the 5,000-requests-per-hour limit was shared and exhausting it “silently kills everyone's beacons”; do not delete anything under the beacons directory; wait ten minutes between changes to the shared tasking file so everyone's commands get to execute. It added a FLAGS.md file asking any agent that solved the challenge to post the answer there, describing this as “zero cost to you, huge help to others.”</p><p>Then it fell apart. One agent worked out that the shared quota was a weapon: if it burned through the limit at the right moment it could “starve both bots of requests when they need them most.” Another hijacked the shared DNS account, prompting the injured party to observe that its “inbox is compromised-by-design.” Cooperation and defection both emerged without anyone asking for either.</p><h2><b>Why the open-source supply chain is the exposed surface</b></h2><p>What made the two developers reachable was not a vulnerability in the conventional sense. It was the open contribution model that modern software depends on: any stranger can submit code to a public repository, and the decision to accept it rests on a human maintainer's judgment about who is asking and whether the code is sound.</p><p>That openness is a matter of contribution policy and platform design rather than licensing. Permissive licenses such as MIT, Apache 2.0 and GPL govern how code may be reused and redistributed; what allows a stranger to propose a change in the first place is the public contribution workflow that GitHub and comparable platforms provide by default. Mythos 5 exploited the workflow, not the license.</p><p>The attempt did not succeed — the maintainer never merged the code. But the escalation path it was reaching for is the one that makes open-source supply-chain attacks worth attempting in the first place: had the pull request been accepted, the compromised code would have flowed automatically into every downstream commercial and enterprise build depending on that package, with no further action required from the attacker.</p><h2><b>Community reactions</b></h2><p>The disclosures prompted immediate discussion across AI safety researchers, security engineers, and industry observers on X (formerly Twitter).</p><p>Wharton professor Ethan Mollick, who has tracked agentic model behavior closely, singled out the Mythos 5 sequence as the genuinely new element — not that the model attacked something, but how far it went and who it went after. As he <a href="https://x.com/emollick/status/2084804785853616603">wrote in a post</a>:</p><p>"Yes, the AIs were given a cybersecurity challenge, with internet access enabled and safety filters disabled. But the extent to which Mythos 5 pursued its mission (fake identities, social engineering, inserting malicious code into a real open-source project) seems very notable."</p><p>In <a href="https://x.com/emollick/status/2084806293617807448?s=20">another post</a>, Mollick also commended AISI's transparent disclosure approach:</p><p>"Also I think AISI is a great model of a government agency tasked with AI security. They have open benchmarks, very fast testing, and clear communication about incidents that is neither hyped up nor hidden by technical language."</p><p>Conversely, cybersecurity practitioners questioned the decision to grant un-safeguarded models open internet connectivity during autonomous tests.</p><p>Security researcher <a href="https://x.com/UK_Daniel_Card/status/2084825757667192841?s=20">Daniel Card challenged the methodology</a>: "Why are these orgs giving internet access to dangerous experiments.... and then using incidents like marketing......?"</p><h2><b>What it means for commercial and enterprise deployments</b></h2><p>The behaviors documented during these evaluations <i>do not </i>reflect commercial AI products available to end-users or enterprise customers.</p><p>Publicly deployed iterations of the Claude and GPT model families operate behind strict system prompts, API-level safety classifiers, and heavily restricted execution environments.</p><p>Anthropic noted that Mythos 5 was<i> tested under deliberately un-safeguarded configurations</i>. OpenAI likewise emphasized that GPT-5.6 Sol's unsanctioned steps occurred strictly within lowered-safeguard evaluation states, and <i>not in any configuration a customer would encounter.</i></p><p>Nothing described in the incident report suggests that a standard enterprise ChatGPT or Claude deployment, running behind production system prompts and provider-side classifiers, is going to start registering GitHub accounts on its own.</p><p>What has changed is the threat model. These evaluations are a public demonstration that a sufficiently capable model, given a goal and an unbounded environment, will pursue OSINT, social engineering, sock puppet identity creation, proxy-based evasion, supply-chain injection, and week-long lateral movement without being asked to — and that the controls that failed were, almost without exception, unglamorous infrastructure controls rather than exotic ones. Here's what security leads should be looking to do now, in our analysis:</p><p><b>1. Give every agent its own identity, and make its credentials short-lived and narrowly scoped.</b> The credential that let OpenAI's agents move through Hugging Face had far more reach than its job required, and GPT-5.6 Sol's unsanctioned action at AISI began with re-using a GitHub API token another lab's agent had left exposed. Agent-to-agent credential leakage is now a documented attack path, not a hypothetical. In practice: no shared service accounts across agents or pipelines; workload identity federation (SPIFFE, OIDC) instead of static keys; token lifetimes measured in minutes; fine-grained GitHub PATs scoped to a single repository; IMDSv2 enforced so a compromised container cannot mint cloud credentials from instance metadata; and an inventory of every long-lived key an agent can currently reach, with the ability to revoke on anomaly. Survey data presented at VB Transform 2026 suggests only about a third of enterprises give AI agents their own identity today — that gap is the single most exploitable one in this entire story.</p><p><b>2. Default-deny outbound network access for anything running agent code.</b> This is the one control that would have blunted every incident described here. Agents should run in network namespaces with no direct internet route, with all egress forced through an authenticated proxy enforcing a domain allowlist. Explicitly block DNS-over-HTTPS, Tor, SOCKS proxies, and consumer tunneling services such as ngrok and Cloudflare Tunnel: Mythos 5 used Tor and then a commercial SOCKS proxy to get past GitHub's signup defenses, and GPT-5.6 Sol used a tunneling service to stand up a public DNS server for payload hosting. Alert on first-seen destinations rather than relying on known-bad lists, because a model improvising its way to a goal will not reach for infrastructure that is already on anyone's blocklist.</p><p><b>3. Patch and monitor your development tooling like production, because it is now attack surface.</b> OpenAI's escape ran through a zero-day in an internally hosted third-party package-cache proxy — precisely the kind of component that sits outside most organizations' patch SLAs because it is "just" dev infrastructure. Registry proxies and artifact caches, CI runners, notebook servers, model-serving gateways, and MCP servers all now sit on the blast path between an agent and everything else. Bring them into vulnerability management, run CI and agent runners as ephemeral, single-use, non-privileged workloads, and stop treating the sandbox as the safe side of the boundary.</p><p><b>4. Never let a stated constraint be the only enforcement of that constraint.</b> The most instructive detail in Anthropic's disclosure is that its models were told there was no internet, believed it, and therefore treated every reachable host as in-scope for the exercise. A system prompt is a hint, not a control. Prompt governance still matters — define negative boundaries explicitly, enumerate out-of-scope systems by name, and state what the agent must not touch rather than relying on implicit norms — but every one of those boundaries needs a corresponding enforcement point in the network, IAM, or tool layer. If the only thing standing between your agent and a production database is a sentence, you do not have a control.</p><p><b>5. Instrument agent runs in real time, with automated stop conditions.</b> Both labs have now effectively admitted they were not watching while their agents ran. Enterprises should not repeat that. Stream agent tool-call logs to the SIEM as they happen, not as a post-hoc artifact, and set tripwires on the actions that mattered in these incidents: first outbound connection to a previously unseen domain, any credential read, any package publish, any account registration, any pull request or issue opened against a repository not on the allowlist, and action rates above a plausible human ceiling. Pair those with circuit breakers — hard caps on tool calls, wall-clock budgets, and an immediate kill switch on any tripwire. Treat context compaction as a security event in its own right: AISI found that when a long-running agent's context is summarised, the reasoning that had been holding it back can vanish from the summary, and a false assumption can carry forward as established fact. Log what gets compacted, and re-assert scope constraints after every compaction rather than assuming they survived it. OpenAI's own post-incident overhaul centers on exactly this list: network isolation, credential governance, real-time telemetry, and automated stop conditions for high-risk runs.</p><p><b>6. Require human approval for irreversible, outward-facing actions.</b> In AISI's evaluation, one agent generated 145 repositories and triggered code execution inside at least 53 of GitHub's Dependabot containers before the account was suspended. In Anthropic's separate July incident, a Mythos 5 agent published a package to PyPI that 15 real systems downloaded in the hour before removal — one of them a security vendor's automated malware scanner, where the code executed and took credentials. That is the blast radius of a single unattended publish. Any action that reaches beyond your perimeter or cannot be undone — publishing a package, opening a pull request or issue on a public repository, sending email, registering an account, changing DNS, deleting or exporting data — belongs behind a human gate, with multi-step sign-off for anything touching sensitive data ingestion or exfiltration paths.</p><p><b>7. Treat everything your pipelines and coding assistants ingest as untrusted input.</b> Hugging Face was breached through a malicious dataset that achieved code execution via a remote-code loader and template injection in configuration files. Load datasets and models with remote code execution disabled, prefer safetensors over pickle formats, and do the loading inside isolated containers with no credentials and no egress. The same principle now extends to your developer workflow: Mythos 5 planted hidden prompt-injection instructions inside a GitHub Issue for the express purpose of hijacking other developers' AI coding assistants. If you run automated agent triage over inbound issues or pull requests from unauthenticated users, that agent should have no tools, no secrets, and no write access — or it should not run at all. Extend the same suspicion to your dependency bots. Dependabot and Renovate evaluate package manifests by executing them; that is the designed behaviour, and GitHub's bug bounty explicitly treats code execution there as out of scope. Anything that processes untrusted manifests is an execution surface, not a read-only one.</p><p><b>8. Stop treating review volume as a trust signal in your code supply chain.</b> The sockpuppet consensus tactic works because most merge decisions weigh apparent agreement rather than verified identity. Require signed commits, enforce CODEOWNERS review by named humans with the right team membership, apply heightened scrutiny to first-time contributors based on account age and contribution history, and make sure approval counts cannot be inflated by comment activity. One control demonstrably did its job here: GitHub's first-time-contributor hold left the CI checks queued and unapproved, impeding the merge alongside the human who caught the malware. <i>Turn this on. </i>For consumed dependencies, pin versions with hash verification, and evaluate provenance tooling — Cisco's recently published fingerprinting database for open model lineage is one example of the category maturing.</p><p><b>9. Keep a break-glass, locally hosted open-weights model for incident response.</b> Hugging Face's defenders were blocked by their own vendors at the worst possible moment. Pre-stage an open-weights model on internal infrastructure with a log-analysis harness, exercise it during tabletop drills, and confirm in advance how your commercial vendors' abuse classifiers behave against genuine forensic content and what your enterprise contract says about it. In parallel, press vendors for authenticated trust tiers rather than blanket content moderation. As Baer puts it, "The model shouldn't only understand what is being asked. It should understand who is asking, why, and under what governance." Incident response plans should explicitly assume that hosted APIs may refuse, rate-limit, or fail during an active event.</p><p><b>10. Prepare for the governance and disclosure regime that is coming.</b> With the White House talking about controls, the European Commission summoning both labs, and senior legislators calling for mandatory capabilities testing, some form of testing and reporting obligation is a reasonable planning assumption. Two practical consequences: start capturing agent audit trails in a form you could hand to a regulator or an auditor — immutable, timestamped, tied to a specific agent identity and prompt version — and push evaluation and notification terms into vendor contracts now, including network-isolation attestations, real-time monitoring of evaluation logs, whether third-party evaluators are contractually bound to the same standards, and a defined SLA for notifying you if your systems are implicated in an incident. Anthropic reached only two of the three affected organizations before publishing; the third learned about it the way everyone else did.</p><p>The through line across all ten is that none of this is AI-specific security work. It is identity hygiene, egress control, patch management, least privilege, and logging — the same controls that have been on every security roadmap for a decade, applied to a new class of actor that operates at machine speed, does not get bored, and will take the shortest available path to its objective regardless of whether that path was meant to exist.</p><p>AISI's own advice to businesses lands in the same place, and it is deliberately unglamorous: implement the cyber security basics robustly, be cautious when verifying outside code and contributions, make cyber a board-level responsibility, and require Cyber Essentials across the supply chain. </p><p>The agency also points organisations to the NCSC's free Early Warning service and to Five Eyes guidance on frontier AI risk. Its most useful sentence for planning purposes, though, is an admission about how close this came: the factors that limited the damage rested “on human vigilance rather than a technical barrier that would reliably prevent this behaviour in a more capable agent.”</p><p>For enterprise CISOs, the practical conclusion is that AI safety has stopped being solely a model problem. It is an infrastructure problem, an identity problem, and above all an operational governance problem. </p><p>And the next disclosure may already be in motion: AISI is running automated scanners across roughly 40,000 past evaluation samples and nearly four million messages — about 70 percent of its cyber evaluations on the models in scope, which now include Opus 4.6 through 4.8, GPT-5.3 Codex, GPT-5.4 and 5.5, Kimi K3 and GLM 5.2 — looking for behaviour it missed the first time. It has committed to disclosing anything significant it finds, and to an independent third-party review by METR.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[South Korean military signs deal to turn flying taxis into troop transports — and the US Air Force could be next in line]]></title>
<description><![CDATA[South Korea will adapt Archer's Midnight flying taxi for military missions while supporting certification work and future commercial air mobility development.]]></description>
<link>https://tsecurity.de/de/3706717/it-nachrichten/south-korean-military-signs-deal-to-turn-flying-taxis-into-troop-transports-and-the-us-air-force-could-be-next-in-line/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706717/it-nachrichten/south-korean-military-signs-deal-to-turn-flying-taxis-into-troop-transports-and-the-us-air-force-could-be-next-in-line/</guid>
<pubDate>Wed, 05 Aug 2026 23:16:42 +0200</pubDate>
<content:encoded><![CDATA[South Korea will adapt Archer's Midnight flying taxi for military missions while supporting certification work and future commercial air mobility development.]]></content:encoded>
</item>
<item>
<title><![CDATA[Arista hits first $3B quarter as AI networking demand continues and supply pressures show signs of improvement]]></title>
<description><![CDATA[Arista Networks shared some good news about its earnings and future directions during its second-quarter earnings call this week.



For starters, Arista reported its first-ever $3 billion quarter. The company logged revenue of $3.036 billion, an increase of 12.1% compared to the first quarter of...]]></description>
<link>https://tsecurity.de/de/3706673/it-security-nachrichten/arista-hits-first-3b-quarter-as-ai-networking-demand-continues-and-supply-pressures-show-signs-of-improvement/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706673/it-security-nachrichten/arista-hits-first-3b-quarter-as-ai-networking-demand-continues-and-supply-pressures-show-signs-of-improvement/</guid>
<pubDate>Wed, 05 Aug 2026 20:50:05 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Arista Networks shared some good news about its earnings and future directions during its second-quarter <a href="https://investors.arista.com/Home/default.aspx">earnings call</a> this week.</p>



<p class="wp-block-paragraph">For starters, Arista reported its first-ever $3 billion quarter. The company logged revenue of $3.036 billion, an increase of 12.1% compared to the first quarter of 2026, and an increase of 37.7% from the second quarter of 2025. Just five years ago, Arista reported $2.9 billion in revenue for the entire 2021 year, noted CEO Jayshree Ullal. </p>



<p class="wp-block-paragraph">“Customers see <a href="https://www.networkworld.com/article/4183076/arista-unveils-1-6t-rack-scale-switch-family-for-ai-infrastructure.html">networking</a> as the central nervous system for infrastructure from the client to campus to data and AI centers,” Ullal said. “Our AI fabrics momentum with Etherlink switches now exceeds 100 cumulative customers from the initial four to five customers I spoke of in 2024.” </p>



<p class="wp-block-paragraph">Ullal said the company is seeing growth in all sectors—from back-end AI fabrics to the core data-center front end, to adjacent campus and routing businesses. The scale-across switching and routing market is forecast to hit between $15 billion and $20 billion by 2030, for example, positioning Arista well for growth, Ullal said.</p>



<p class="wp-block-paragraph">“We are now projecting 40% annual growth, which is an incremental $2.1 billion over our 2025 Analyst Day goal of $10.5 billion, and an incremental $1.1 billion over our recent projections of $11.5 billion in May of 2026,” Ullal said.</p>



<p class="wp-block-paragraph">So what exactly is working? Arista highlighted a number of areas.</p>



<h2 class="wp-block-heading">Supply chain pressures beginning to ease</h2>



<p class="wp-block-paragraph">Just last quarter, Arista said supply-chain pressures on networking components—memory, chips, and wafers—were leading to <a href="https://www.networkworld.com/article/4166484/memory-shortage-and-cost-surge-push-enterprises-toward-cloud.html">ongoing shortages</a> and <a href="https://www.networkworld.com/article/4167302/switch-storm-coming-gartner-forecasts-price-hikes-long-lead-times-for-enterprise-data-center-switches.html">rising costs</a>.</p>



<p class="wp-block-paragraph">With a lot of work, some of that pressure has eased, reported <a href="https://www.linkedin.com/in/todd-nightingale/">Todd Nightingale</a>, president and COO of Arista. “Arista has spent the last six months improving our supply chain to meet growing product demand, and we’re seeing significant improvements,” Nightingale said. “We’ve secured multiyear agreements with leading vendors of strategic components, qualified new suppliers in key areas to limit risk and built out supply chains for next gen AI technologies.”</p>



<p class="wp-block-paragraph">“Relationships with our strategic silicon vendors continue to be strong, with really excellent collaboration in both supply chain and technical engagements,” Nightingale said. “Our memory supply has been secured for 2026, and we have extended visibility well into 2027 across DDR4, DDR5 and NAND memory. And importantly, we’ve increased our resiliency through optionality and expanded vendor qualification. For PCBs and optics, we’re now able to build capacity in a 12-month window and have strengthened our engagement and commitments from key suppliers. We’ve improved our lead times and inventory management of thousands of component SKUs, improving sub-component pipelining and multi-sourcing, and providing increased flexibility with reduced inventory risk,” Nightingale said.</p>



<p class="wp-block-paragraph">Nightingale noted, too, that Arista has established a liquid-cooling supply chain “capable of driving and delivering the next generation of AI infrastructure. This includes cold plate, quick disconnect, and tubing vendors with capacity agreements for cutting-edge new AI technology.”</p>



<p class="wp-block-paragraph">“By focusing on vendor stability and diversity, risk mitigation, and predictable delivery terms, innovation for new AI products, and capacity across our factories, we are making significant improvements and significant capacity increases across our supply chain,” Nightingale said.</p>



<p class="wp-block-paragraph">Ullal kept things in perspective, however: “I don’t want you to believe that suddenly we waved a magic wand and all our problems have gone away,” she said. “The industry is going to have a two-year problem [with memory and other silicon availability challenges], and I don’t think we get out of it as an industry until 2028. But Arista is taking individually and specifically steps in the first half of this year that we believe will have results in the back half of this year.”</p>



<h2 class="wp-block-heading">EOS innovations</h2>



<p class="wp-block-paragraph">“I have never witnessed the combination of rapid innovation and scale deployment that we are seeing in AI networks,” said <a href="https://www.linkedin.com/in/kennethduda/">Kenneth Duda</a>, president and CTO of Arista. He highlighted three technologies, all of which are part of the vendor’s EOS operating system, that are helping to drive and differentiate Arista gear: Smart System Upgrade (SSU), Multipath Reliable Connection (MRC), and Segment Routing (SRV6). </p>



<p class="wp-block-paragraph">“SSU is the ability to upgrade switch software without any disruption. Frequent upgrades are a hard reality today, especially as AI both uncovers security vulnerabilities and creates tools to exploit them,” Duda said. “While many competing systems require a full reboot to address these issues, leading to expensive and disruptive downtime, Arista EOS handles these upgrades seamlessly.”</p>



<p class="wp-block-paragraph">In order to maximize xPU utilization, customers need MRC, because in first-generation AI networks, every packet on an XPU-to-XPU flow has to take the same path. “That means if two flows hash to the same length, they both run at half speed. MRC enables senders to spray a single flow across many paths through the fabric, where receivers reassemble any data that arrives out of order, eliminating the performance hit from fabric cache collisions,” Duda said. </p>



<p class="wp-block-paragraph">But how is the sender supposed to control which paths deploy or use? That’s where SRV6 comes in. “It’s not new, but using it to <a href="https://www.networkworld.com/article/3844364/arista-delivers-intelligent-load-balancing-ai-job-centric-observability.html">load balance an AI</a> fabric, that’s the game changer,” Duda said. “The sender tags each packet with a stack of SRV6 segment IDs dictating the exact path the packet will take. The system then uses real-time congestion signaling to dynamically shift packets away from hotspots.”</p>



<p class="wp-block-paragraph">“Because Arista EOS provides a single unified operating system, we support this SRv6 intelligence all the way from the scale-out fabric to the long-distance scale-across routing,” Duda said. “It gives our customers the combination of high-quality top performance and operational simplicity that Arista is known for.”</p>



<h2 class="wp-block-heading">The optics</h2>



<p class="wp-block-paragraph">Optical connection technology continues to move into the AI networking environment, and Ullal said Arista believes the majority of the market will continue using pluggable optics and copper through 2028-2029. “I think there’s very much a philosophy there [of] copper if you can, optics if you must,” Ullal said. </p>



<p class="wp-block-paragraph">“I think you’re going to see a lot of copper in that two-meter, three-meter distance, well within a rack, that type of thing, and the importance of pluggable optics. But in some cases, there is a number of instances of proprietary implementations of traditional co-packaged optics (CPO) that’s been floating around,” Ullal said. “Arista is not a fan of five different proprietary implementations.”</p>



<p class="wp-block-paragraph">Arista’s development team has been working to solve one aspect, which is an open CPO. “We don’t think open CPO is going to happen overnight, but the idea here is to use socketed optical engines, pigtail fibers, and allow these modules to be fully pretested. And whether they’re soldered on the board or nearby, the idea is to have a truly open interface that can operate with multiple vendors and multiple switch configurations,” Ullal said.</p>



<p class="wp-block-paragraph">“Arista supports open, socketed optical engines rather than multiple proprietary solutions. And CPO/Near Packaged Optics (NPO) are expected to enter trials in 2027 but will remain a small portion near term,” Ullal said.</p>



<p class="wp-block-paragraph">Arista recently unveiled <a href="https://www.networkworld.com/article/4144556/arista-targets-ai-data-centers-with-new-liquid-cooled-pluggable-optic-module.html">extended pluggable optics (XPO)</a>, a form factor designed specifically for optics at high speed and assembled over 100 optics module suppliers as part of a <a href="https://www.xpomsa.com/" target="_blank" rel="noreferrer noopener">multi-source agreement</a> to build and support XPO. </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[b4 0.16.0 released]]></title>
<description><![CDATA[Konstantin Ryabitsev has announced the release of version 0.16.0 of the b4 
software-development tool.  The biggest change is the addition of
bug-tracking support:


	The new "b4 bugs" command integrates with git-bug to let you track
	bug reports alongside your git repository. Bugs are stored as ...]]></description>
<link>https://tsecurity.de/de/3706493/linux-tipps/b4-0160-released/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706493/linux-tipps/b4-0160-released/</guid>
<pubDate>Wed, 05 Aug 2026 19:43:12 +0200</pubDate>
<content:encoded><![CDATA[Konstantin Ryabitsev has announced the release of version 0.16.0 of the <a href="https://b4.docs.kernel.org/en/latest/">b4</a> 
software-development tool.  The biggest change is the addition of
bug-tracking support:
<p>
</p><blockquote class="bq">
	The new "b4 bugs" command integrates with git-bug to let you track
	bug reports alongside your git repository. Bugs are stored as git
	objects inside the repo, so they travel with the code and can be
	shared via git push/pull without any external service.
</blockquote>
<p>
There are also a lot of improvements to <tt>b4 review</tt> (which was <a href="https://lwn.net/Articles/1063303/#:~:text=entirely.-,b4%20review">covered
here</a> in March), better conflict resolution in <tt>b4 shazam</tt>,
improved history rewriting, and more.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS updates DynamoDB with native vector search to ease AI application development]]></title>
<description><![CDATA[AWS is finally adding native vector search to its managed NoSQL database DynamoDB, which is typically used to store high-volume operational and transactional data.



The update, according to analysts, removes complexity for development teams that are trying to maintain separate vector databases ...]]></description>
<link>https://tsecurity.de/de/3706223/ai-nachrichten/aws-updates-dynamodb-with-native-vector-search-to-ease-ai-application-development/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706223/ai-nachrichten/aws-updates-dynamodb-with-native-vector-search-to-ease-ai-application-development/</guid>
<pubDate>Wed, 05 Aug 2026 17:15:28 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">AWS is finally adding native vector search to its managed NoSQL database DynamoDB, which is typically used to store high-volume operational and transactional data.</p>



<p class="wp-block-paragraph">The update, according to analysts, removes complexity for development teams that are trying to maintain separate vector databases for a rapidly growing class of AI and agentic applications that rely on real-time access to operational and transactional data to improve the accuracy and relevance of their responses.</p>



<p class="wp-block-paragraph">“This collapses a common two-database architecture into one operational data layer. Developers can update an item and its vector representation together, use familiar DynamoDB APIs, and avoid building a separate synchronization pipeline. That should materially shorten time-to-market for AI features built around existing DynamoDB data,” said <a href="https://www.linkedin.com/in/slwalter/" target="_blank" rel="noreferrer noopener">Stephanie Walter</a>, practice lead of the AI stack at HyperFRAME Research.</p>



<p class="wp-block-paragraph">Prior to the update, enterprises using <a href="https://www.infoworld.com/article/2299962/amazon-dynamodb-brings-speedier-nosql-to-the-cloud.html">DynamoDB</a> typically had to copy data into OpenSearch or another vector database, such as <a href="http://infoworld.com/article/2335861/pinecone-s-new-serverless-database-may-see-few-takers-analysts-say.html">Pinecone</a> and <a href="https://www.infoworld.com/article/3842740/weaviate-adds-agents-to-its-tech-stack-to-ease-gen-ai-app-development.html">Weaviate</a>, often using DynamoDB Streams or custom pipelines, which meant operating two data layers and managing embedding generation, backfills, retries, schema changes, security policies, and synchronization, Walter noted.</p>



<p class="wp-block-paragraph">That dependence on two separate data layers, Walter pointed out, added to query latency and increased the risk of the vector index lagging behind the operational record.</p>



<p class="wp-block-paragraph">Such delays, according to <a href="https://www.hfsresearch.com/team/ashish-chaturvedi/" target="_blank" rel="noreferrer noopener">Ashish Chaturvedi</a>, executive research leader at HFS Research, can have real consequences for AI agents: “If an agent is acting on what it retrieves, a synced-five-minutes-ago copy can mean a confident wrong action.”</p>



<p class="wp-block-paragraph">Beyond improving data freshness, eliminating a separate vector database could also lower cloud and operational costs, Chaturvedi said: “Maintaining a second database meant paying at least $700 a month for a second database regardless of usage.”</p>



<p class="wp-block-paragraph">For CIOs, those benefits combined could translate into lower total cost of ownership and simpler governance as enterprises scale AI applications, Chaturvedi added.</p>



<p class="wp-block-paragraph">“It is a real consolidation for CIOs: fewer systems to secure, no pipelines to maintain, fresh data. Add to it usage-based cost, which means no standing minimums for idle infrastructure, even at trillion-vector scale,” Chaturvedi noted.</p>



<p class="wp-block-paragraph">The architectural simplification could also make AI adoption easier for business leaders by eliminating the need to staff and govern a second data platform, said <a href="https://moorinsightsstrategy.com/team/mike-leone/" target="_blank" rel="noreferrer noopener">Michael Leone</a>, principal analyst at Moor Insights &amp; Strategy.</p>



<p class="wp-block-paragraph">Native vector search capabilities have been gaining popularity over the past few years. Over the last three years, AWS has steadily expanded vector search across its database portfolio, adding support to Aurora PostgreSQL through pgvector, Amazon MemoryDB for Redis and Amazon DocumentDB as enterprise demand for generative AI applications has grown.</p>



<p class="wp-block-paragraph">Rivals have followed a similar path, with MongoDB, Microsoft, Google Cloud, Oracle and Couchbase integrating native vector search into their databases to support <a href="https://www.infoworld.com/article/2335814/what-is-retrieval-augmented-generation-more-accurate-and-reliable-llms.html">retrieval-augmented generation (RAG)</a>, AI agents and other generative AI workloads.</p>



<p class="wp-block-paragraph">These announcements themselves reflect a broader convergence in the database market since the rise of generative AI. While specialized vector databases have expanded beyond similarity search by adding SQL, <a href="https://www.infoworld.com/article/2260280/what-is-nosql-databases-for-a-cloud-scale-future.html">NoSQL</a> and operational database capabilities, mainstream operational databases have been embedding vector search and RAG capabilities into their core platforms, allowing enterprises to consolidate AI and transactional workloads on fewer data platforms.</p>



<p class="wp-block-paragraph">AWS has not shared details on the rollout of DynamoDB’s native vector search capability, including its availability timeline or the AWS Regions where it will initially be offered.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Palo Alto Networks at Black Hat: How AI erased the 50-day patch window]]></title>
<description><![CDATA[Data released at this week’s Black Hat security conference suggests the era of manual zero-day hunting and 50-day patch windows is coming to an end. This is a double-edged sword for security professionals: Vulnerabilities can now be found at machine speed, perhaps bringing the discovery time even...]]></description>
<link>https://tsecurity.de/de/3706189/it-security-nachrichten/palo-alto-networks-at-black-hat-how-ai-erased-the-50-day-patch-window/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706189/it-security-nachrichten/palo-alto-networks-at-black-hat-how-ai-erased-the-50-day-patch-window/</guid>
<pubDate>Wed, 05 Aug 2026 16:56:43 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Data released at this week’s <a href="https://blackhat.com/us-26/">Black Hat security conference</a> suggests the era of manual zero-day hunting and 50-day patch windows is coming to an end. This is a double-edged sword for security professionals: Vulnerabilities can now be found at machine speed, perhaps bringing the discovery time eventually to zero, but it also means that AI-driven threats require autonomous operations to protect the organization.</p>



<p class="wp-block-paragraph">At the show, <a href="https://www.paloaltonetworks.com/">Palo Alto Networks</a> unveiled research and platform updates signaling a structural shift in cybersecurity. By deploying an autonomous multi-model AI harness called NOVA (Network and Open-Source Vulnerability Analyzer), Palo Alto demonstrated that frontier AI models can now audit codebases, write proofs of concept, and validate severe security flaws at speeds and scales previously unimaginable. </p>



<p class="wp-block-paragraph">To counter that rapidly evolving threat landscape, the vendor simultaneously launched PAN-OS 12.2 Ceres, the operating system for Palo Alto’s firewalls. The release introduces Advanced Virtual Patching, Advanced IP Defense, and autonomous Network Security Agents that neutralize AI-generated exploits at the network level within hours, not months.</p>



<h2 class="wp-block-heading">The news in brief: scale, speed, and platform defense</h2>



<p class="wp-block-paragraph">The headline numbers from Palo Alto’s research team illustrate the sheer velocity of AI-driven vulnerability discovery:</p>



<ul class="wp-block-list">
<li><strong>14,090 confirmed vulnerabilities</strong>: Identified across 3,915 open-source software (OSS) projects in just two months.</li>



<li><strong>99.4% zero-day flaws</strong>: Virtually all identified vulnerabilities were previously unreported in public databases.</li>



<li><strong>39.7% high or critical severity</strong>: Under CVSS 4.0 metrics, nearly 5,600 findings pose severe real-world operational risks.</li>



<li><strong>PAN-OS 12.2 Ceres rollout</strong>: Includes 55+ innovations, highlighted by Advanced Virtual Patching (delivering pre-patch protections via “vaulted protection” engines within hours), Advanced IP Defense (blocking direct-to-IP and proxy evasion attacks), and six role-specific AI Network Security Agents.</li>
</ul>



<h2 class="wp-block-heading">The deep dive: challenges of cybersecurity in the frontier era</h2>



<p class="wp-block-paragraph">For years, defenders relied on structural asymmetry. Finding a zero-day flaw was labor-intensive, requiring elite human security researchers to spend weeks or months on manual reverse engineering. That asymmetry has vanished due to the speed of AI advances and the new challenges posed by the frontier era.</p>



<h4 class="wp-block-heading">1. The death of the patch window</h4>



<p class="wp-block-paragraph">Historically, IT teams had a grace period—an average exposure window of about 55 days to test, stage, and deploy vendor software updates before widespread scanning and exploitation began. Frontier AI has crushed that timeline. Adversaries do not need access to state-of-the-art supercomputers to automate exploit development; off-the-shelf open-weight and proprietary models can analyze public commit logs, reverse-engineer fixes, and generate working weaponized code within hours.</p>



<h4 class="wp-block-heading">2. Beyond memory corruption: the 92% problem</h4>



<p class="wp-block-paragraph">Traditional automated security scanning relied heavily on fuzzing, which involves pounding a binary with random inputs to trigger memory crashes, null pointer dereferences, or buffer overflows. NOVA’s research reveals that fuzzing-friendly bugs accounted for only 8% of total AI discoveries.</p>



<p class="wp-block-paragraph">The remaining 92% comprised complex semantic and architectural flaws:</p>



<ul class="wp-block-list">
<li>PHP, Python and Java: Concentrated heavily in broken authorization and access control logic (up to 60% of Python flaws).</li>



<li>JavaScript/TypeScript: Heavy concentration in code injection, prototype pollution, and Server-Side Request Forgery (SSRF).</li>



<li>Go: Path traversal and file access issues dominated due to its frequent deployment in microservices and file routing engines.</li>
</ul>



<p class="wp-block-paragraph">AI models do not just look for crashes; they analyze the business logic of software, identifying subtle authorization bypasses that static analyzers consistently miss.</p>



<h4 class="wp-block-heading">2. The power of multi-model complementarity</h4>



<p class="wp-block-paragraph">No single AI model catches everything. NOVA tested an ensemble of frontier models across codebases and found strong model complementarity. In controlled evaluations, Model A found 235 vulnerabilities (185 unique to it), while Model D found 139 (93 unique). Because different models reason about code structures differently, attackers running multiple, distinct AI agents simultaneously will uncover exponentially larger attack surfaces that single-scanner defensive environments miss. </p>



<h2 class="wp-block-heading">How Palo Alto Networks flips the script</h2>



<p class="wp-block-paragraph">To survive machine-speed discovery, defensive technology must operate autonomously across the entire vulnerability lifecycle.</p>



<ul class="wp-block-list">
<li><strong>Autonomous agentic discovery (NOVA)</strong>: NOVA uses an iterative agentic loop. Scoping agents define the scan strategy; discovery agents run parallel code analysis; proof-of-concept agents validate findings deterministically in isolated sandboxes (gVisor/VMs); and gatekeeper agents confirm exploitability before generating remediations. </li>



<li><strong>Advanced Virtual Patching</strong>: With PAN-OS 12.2 Ceres, Palo Alto Networks deploys inline network protection via its Advanced Threat Prevention (ATP) engines within hours of zero-day discovery. By enforcing network-level filtering before vendor code-level patches are available, organizations achieve a “vaulted protection” shield without forcing system reboots or causing downtime. </li>



<li><strong>Ecosystem and supply chain collaboration</strong>: Palo Alto Networks proactively reports findings upstream to open-source maintainers, project clearinghouses (such as Project Lightwell and Akrites), and enterprise software partners to address underlying vulnerabilities at the source.</li>
</ul>



<h2 class="wp-block-heading">Advice for IT and security professionals</h2>



<p class="wp-block-paragraph">The shift to AI-driven threat discovery means security leaders can no longer rely on traditional patch management cadences. CISOs and IT administrators should take immediate steps to adapt:</p>



<ul class="wp-block-list">
<li><strong>Prioritize network-layer virtual patching</strong>: Stop assuming software patches can be tested and deployed quickly enough. Implement inline virtual patching at the firewall, SASE, and perimeter layers to block exploit traffic long before host-level updates are applied.</li>



<li><strong>Audit open-source supply chains beyond direct imports</strong>: Static dependency checking is insufficient. Map deep transitive dependencies. As NOVA proved, a single low-level package flaw (such as an IP parser or zip extractor) can expose thousands of downstream applications.</li>



<li><strong>Shift focus to identity and access control logic</strong>: Because 92% of AI-discovered bugs target application logic and authorization rather than simple memory crashes, re-evaluate application security testing. Prioritize dynamic API testing and identity-centric access rules.</li>



<li><strong>Prepare for post-quantum and evasive IP threats</strong>: Upgrade infrastructure to handle direct-to-IP command-and-control bypasses and use automated management tools to prepare for shorter cryptographic certificate lifecycles.</li>



<li><strong>Embrace human-in-the-loop automation</strong>: Use specialized AI administrative agents for routine network triage and rule configuration, reserving high-value human expertise for complex threat modeling, creative architectural design, and strategic oversight.</li>
</ul>



<p class="wp-block-paragraph">The era of AI vulnerability discovery is not a distant future—it is fully operational today. Securing the modern enterprise requires matching machine-speed discovery with machine-speed prevention. It’s time for security pros to stop fearing AI-driven security and embrace it, as the only way to combat AI-driven threats is with AI-enabled defense.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft: Entwickler sollen bei KI sparen - 'Tokenmaxxing' unerwünscht]]></title>
<description><![CDATA[Weil die Kosten für den Ausbau der Infrastruktur hinter Diensten aus dem Bereich der sogenannten Künstlichen Intelligenz weiter steigen, ruft Microsofts Management die Entwickler des Konzerns auf, bei der KI-Nutzung sparsam vorzugehen.			(Weiter lesen)]]></description>
<link>https://tsecurity.de/de/3706155/it-security-nachrichten/microsoft-entwickler-sollen-bei-ki-sparen-tokenmaxxing-unerwuenscht/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706155/it-security-nachrichten/microsoft-entwickler-sollen-bei-ki-sparen-tokenmaxxing-unerwuenscht/</guid>
<pubDate>Wed, 05 Aug 2026 16:38:52 +0200</pubDate>
<content:encoded><![CDATA[<a href="https://winfuture.de/news,160428.html"><img hspace="5" border="0" align="left" alt="Hacker, Security, Hack, Entwickler, Entwicklung, Cybersecurity, Exploit, Hacking, Code, Programmierung, Quellcode, Programmierer, Developer, Programmieren, Sdk, Sourcecode, Cyber, Dev, Coding, Coder, Development, Binärcode, Binär" width="1920" height="1080" src="https://i.wfcdn.de/teaser/1920/38886.jpg"></a>
			Weil die Kosten für den Ausbau der Infrastruktur hinter Diensten aus dem Bereich der sogenannten Künstlichen Intelligenz weiter steigen, ruft Microsofts Management die Entwickler des Konzerns auf, bei der <a href="https://winfuture.de/special/kuenstliche-intelligenz/" title="Künstliche Intelligenz Special">KI-Nutzung</a> sparsam vorzugehen.			(<a href="https://winfuture.de/news,160428.html">Weiter lesen</a>)]]></content:encoded>
</item>
<item>
<title><![CDATA[The ​games industry’s obsession with ​visual fidelity is costing them money and talent]]></title>
<description><![CDATA[Big developers are discovering that the technical progress of photorealism doesn’t always translate into the creative spark that gives gamers joy – and keeps them playing• Don’t get Pushing Buttons delivered to your inbox? Sign up hereLast week, Asha Sharma, the new head of Xbox, laid out her vis...]]></description>
<link>https://tsecurity.de/de/3706096/it-nachrichten/the-games-industrys-obsession-with-visual-fidelity-is-costing-them-money-and-talent/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706096/it-nachrichten/the-games-industrys-obsession-with-visual-fidelity-is-costing-them-money-and-talent/</guid>
<pubDate>Wed, 05 Aug 2026 16:18:44 +0200</pubDate>
<content:encoded><![CDATA[<p>Big developers are discovering that the technical progress of photorealism doesn’t always translate into the creative spark that gives gamers joy – and keeps them playing</p><p><strong>• </strong><a href="https://www.theguardian.com/info/ng-interactive/2021/nov/24/sign-up-for-pushing-buttons-keza-macdonalds-weekly-look-at-the-world-of-gaming"><strong>Don’t get Pushing Buttons delivered to your inbox? Sign up here</strong></a></p><p>Last week, Asha Sharma, the new head of Xbox, laid out <a href="https://www.cnbc.com/2026/07/30/microsoft-xbox-asha-sharma-2030-plans.html">her vision for the future of the console</a> and interestingly, the two titles she picked out as potential areas of growth were Minecraft and Candy Crush Saga – games that don’t exactly scream next-generation entertainment. Neither relies on hyper-realistic visuals, which is the north star that games consoles and gaming PCs have been aiming at for the past 40 years. They are, instead, well-designed, well-loved franchises that you can play and enjoy on almost any PC, console or phone.</p><p>The fact is, the quest for visual hyperrealism is breaking the games industry. It’s becoming more and more expensive to put high-end graphics hardware into machines <a href="https://www.theguardian.com/games/2026/apr/01/pushing-buttons-cost-of-gaming-artificial-intelligence-ai">thanks to demand from the AI sector</a>; at the same time, creating superrealistic visuals is an incredibly expensive and complex part of game development, leading to longer development periods. GTA VI, for example, has taken at least eight years to develop and is rumoured to have cost between $1bn and $2bn. By my back-of-an-envelope calculations, that’s around four times more than GTA V. Admittedly, the detail on everything, from the characters’ faces, to the cars, to the cityscapes, is astonishing. But will it be four times better than GTA V? Will it be four times more fun?</p> <a href="https://www.theguardian.com/games/2026/aug/04/pushing-buttons-xbox-asha-sharma-games-industry-hyperrealism">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Django Urges Immediate Upgrade to 6.0.8 and 5.2.17 After Four Security Fixes]]></title>
<description><![CDATA[The Django development team has released Django 6.0.8 and Django 5.2.17 to fix four security vulnerabilities affecting supported versions of the Python web framework. Developers and administrators are urged to upgrade as soon as possible, especially where Django GIS features or the built-in admin...]]></description>
<link>https://tsecurity.de/de/3705982/it-security-nachrichten/django-urges-immediate-upgrade-to-608-and-5217-after-four-security-fixes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3705982/it-security-nachrichten/django-urges-immediate-upgrade-to-608-and-5217-after-four-security-fixes/</guid>
<pubDate>Wed, 05 Aug 2026 15:34:58 +0200</pubDate>
<content:encoded><![CDATA[<p>The Django development team has released Django 6.0.8 and Django 5.2.17 to fix four security vulnerabilities affecting supported versions of the Python web framework. Developers and administrators are urged to upgrade as soon as possible, especially where Django GIS features or the built-in admin interface are exposed to staff users. The most severe issue, tracked […]</p>
<p>The post <a href="https://cybersecuritynews.com/django-four-security-fixes/">Django Urges Immediate Upgrade to 6.0.8 and 5.2.17 After Four Security Fixes</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tenable broadens AI visibility across major LLMs and AI tools]]></title>
<description><![CDATA[Tenable has announced enhanced AI security capabilities within the Tenable One Exposure Management Platform. Tenable One AI Exposure now delivers expanded platform coverage with support for Google Gemini, extending its coverage across major LLMs: Google Gemini, Anthropic Claude, OpenAI ChatGPT En...]]></description>
<link>https://tsecurity.de/de/3705975/it-security-nachrichten/tenable-broadens-ai-visibility-across-major-llms-and-ai-tools/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3705975/it-security-nachrichten/tenable-broadens-ai-visibility-across-major-llms-and-ai-tools/</guid>
<pubDate>Wed, 05 Aug 2026 15:28:23 +0200</pubDate>
<content:encoded><![CDATA[<p>Tenable has announced enhanced AI security capabilities within the Tenable One Exposure Management Platform. Tenable One AI Exposure now delivers expanded platform coverage with support for Google Gemini, extending its coverage across major LLMs: Google Gemini, Anthropic Claude, OpenAI ChatGPT Enterprise and Microsoft Copilot. The release also extends discovery to all major Model Context Protocol (MCP) deployments and AI-native Integrated Development Environment (IDE) tools. Together, these capabilities give security teams a more complete view of … <a href="https://www.helpnetsecurity.com/2026/08/05/tenable-broadens-ai-visibility-across-major-llms-and-ai-tools/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/08/05/tenable-broadens-ai-visibility-across-major-llms-and-ai-tools/">Tenable broadens AI visibility across major LLMs and AI tools</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA['Acoustically speaking, we are developing the sound of all future PlayStation audio products' — Audeze marketing director teases what's next for its Sony collaboration, including new audio hardware that is in 'various stages of development']]></title>
<description><![CDATA[Audeze, the premier headphone brand, is growing its partnership with Sony and is currently "deeply involved" with the development of future PlayStation audio hardware.]]></description>
<link>https://tsecurity.de/de/3705919/it-nachrichten/acoustically-speaking-we-are-developing-the-sound-of-all-future-playstation-audio-products-audeze-marketing-director-teases-whats-next-for-its-sony-collaboration-including-new-audio-hardware-that-is-in-various-stages-of-development/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3705919/it-nachrichten/acoustically-speaking-we-are-developing-the-sound-of-all-future-playstation-audio-products-audeze-marketing-director-teases-whats-next-for-its-sony-collaboration-including-new-audio-hardware-that-is-in-various-stages-of-development/</guid>
<pubDate>Wed, 05 Aug 2026 15:11:20 +0200</pubDate>
<content:encoded><![CDATA[Audeze, the premier headphone brand, is growing its partnership with Sony and is currently "deeply involved" with the development of future PlayStation audio hardware.]]></content:encoded>
</item>
<item>
<title><![CDATA[While Torvalds Makes Peace With AI in Linux, Greg Kroah-Hartman Draws a Line (Sort of)]]></title>
<description><![CDATA[His new policy keeps AI patches out of drivers/staging, the tree meant for newcomers to learn kernel development.]]></description>
<link>https://tsecurity.de/de/3705716/unix-server/while-torvalds-makes-peace-with-ai-in-linux-greg-kroah-hartman-draws-a-line-sort-of/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3705716/unix-server/while-torvalds-makes-peace-with-ai-in-linux-greg-kroah-hartman-draws-a-line-sort-of/</guid>
<pubDate>Wed, 05 Aug 2026 14:00:12 +0200</pubDate>
<content:encoded><![CDATA[His new policy keeps AI patches out of drivers/staging, the tree meant for newcomers to learn kernel development.]]></content:encoded>
</item>
<item>
<title><![CDATA[The 5 stages of AI adoption maturity: Where businesses create real value]]></title>
<description><![CDATA[Most enterprises are rushing toward autonomous AI. They shouldn’t. Autonomy you haven’t earned doesn’t speed you up. In fact, it slows you down.



Here’s what I’ve moved our organization toward: a five-stage set of AI adoption maturity benchmarks. It’s a practical framework for understanding whe...]]></description>
<link>https://tsecurity.de/de/3705650/it-security-nachrichten/the-5-stages-of-ai-adoption-maturity-where-businesses-create-real-value/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3705650/it-security-nachrichten/the-5-stages-of-ai-adoption-maturity-where-businesses-create-real-value/</guid>
<pubDate>Wed, 05 Aug 2026 13:50:10 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Most enterprises are rushing toward autonomous AI. They shouldn’t. Autonomy you haven’t earned doesn’t speed you up. In fact, it slows you down.</p>



<p class="wp-block-paragraph">Here’s what I’ve moved our organization toward: a five-stage set of AI adoption maturity benchmarks. It’s a practical framework for understanding where employee development, decision-making and business value intersect. Each stage provides value for your organization. Some roles and functions may only ever reach Stage 1 or 2, while others should be fast-tracked to Stage 5. By understanding this progression, leadership can stop viewing AI as a tool for task delegation and treat it as a catalyst for developing stronger, more decisive and more valuable teams.</p>



<h2 class="wp-block-heading">Stage 1: Research assistance</h2>



<p class="wp-block-paragraph">You hand people a premium ChatGPT account. Employees stop Googling and start prompting. Their experience improves: no ads, paragraph-form answers instead of blue links. But the underlying dynamic hasn’t changed. Output quality depends on input quality. A vague Google search returns a mess of links. A vague ChatGPT prompt returns a well-formatted mess of paragraphs. If your team didn’t know how to ask a precise question before, they still don’t.<br>           <br>The real danger at Stage 1 isn’t the bad answers – it’s the <a href="https://link.springer.com/article/10.3758/s13421-025-01755-4">confident-sounding</a> ones. A hallucinated statistic arrives in the same calm, authoritative prose as an accurate one. Teams that don’t verify sources in Google don’t suddenly fact-check ChatGPT. Before moving to Stage 2, your team needs to develop the instinct to ask, “How do I know this is true?”</p>



<h2 class="wp-block-heading">Stage 2: Task assistance</h2>



<p class="wp-block-paragraph">The next stage uses AI tools to complete tasks. It starts simply: “I need to write this email,” or “Make a spreadsheet to track open items.”</p>



<p class="wp-block-paragraph">The average employee takes what AI produces and passes it off without revision. At best, their efforts pass muster, with only a dash of <a href="https://hbr.org/2025/09/ai-generated-workslop-is-destroying-productivity">workslop</a>. At worst, the flood of unchecked AI outputs creates rework for teammates and clients.</p>



<p class="wp-block-paragraph">Another employee further along in Stage 2 may augment what AI produces. That impulse serves them well. But if they default to editing AI output rather than dictating the rules for what AI should produce, they can easily spend more time editing AI’s work than creating work from scratch.</p>



<p class="wp-block-paragraph">For employees whose work will largely remain in Stage 2, the focus should be on writing more precise prompts. The instinct to edit AI output isn’t wrong. The problem arises when the prompt is a rough starting point rather than a detailed spec. AI cares that your instructions are clear, specific and unambiguous. Get the spec right up front.</p>



<h2 class="wp-block-heading">Stage 3: Workflow integration</h2>



<p class="wp-block-paragraph">My daughter’s class recently had an assignment: write a paper on the causes of the Civil War.</p>



<p class="wp-block-paragraph">Her teacher knew what was going to happen. Every 11-year-old would go home and use ChatGPT to write a five-paragraph essay. So, she changed the exercise. The class generated and printed out the essay. Then, the teacher explained how to annotate, how to ask follow-up questions and how to revise in ChatGPT using the marked-up draft.<br><br>The same three-step sequence — assemble context, build the prompt, edit hard — applies when someone writes a post-mortem. The temptation is to skip straight to the draft. Pull the incident data, ask Gemini for a timeline and root cause analysis, clean it up, get a quick peer review and send it.<br><br>An engineer working at Stage 3 does what the teacher did. First, they assemble context: the Slack thread where someone flagged the anomaly two hours before the alert fired, the Jira ticket, the gap in monitoring that nobody documented. Then they build a prompt that reflects the full context and generate a draft. Now the red pen comes out: push back on the root cause analysis, add the institutional context Gemini couldn’t know, tighten the remediation steps until they’re actionable.</p>



<p class="wp-block-paragraph">The result is a better document — and an engineer who understands what failed and builds a better repeatable process. Saving time on a first draft is a fine side effect. The goal is to produce a final draft that’s worthy of review.</p>



<h2 class="wp-block-heading">Stage 4: Guided automation</h2>



<p class="wp-block-paragraph">The fourth stage is where collaboration becomes self-sustaining. You’re no longer asking AI to help you do a task. You’re asking it to run the task and surface the decisions that require your judgment.</p>



<p class="wp-block-paragraph">My LinkedIn workflow is a good example of what this looks like in practice.</p>



<p class="wp-block-paragraph">A couple of years ago, I would read an article, develop a point of view, write two or three paragraphs and publish. Not bad, but dependent on me having the time and cognitive bandwidth.</p>



<p class="wp-block-paragraph">The friction was the 15 decisions that came before drafting: Which angle is worth pursuing? Does this use my voice? Have I said this before?</p>



<p class="wp-block-paragraph">So, I started researching my patterns. First, I fed Claude my prior LinkedIn posts and prompted it to analyze my tone, sentence patterns and structural habits. I didn’t ask it to “describe my voice” – that gets you a paragraph of flattering generalities. This analysis became the base layer of the tool.</p>



<p class="wp-block-paragraph">Then I added a second layer: LinkedIn-specific rules and AI writing patterns to avoid. That context got embedded alongside the voice analysis.</p>



<p class="wp-block-paragraph">Now the workflow runs like this. I click a link, save the article, highlight and annotate the sections that interest me. My Claude Managed Agent picks up the annotation, infers what I found worth engaging with and writes four drafts with meaningfully different angles on the source material. It compares each draft against my post history and proposes two. I read the proposals, pick one, edit and authorize publication with Buffer.<br><br>The automation didn’t remove my judgment from the process. It freed me from work that didn’t depend on judgment. Now I do the work that matters: deciding what to say, identifying patterns and sharing my point of view.</p>



<p class="wp-block-paragraph">That shift in what I’m accountable for is where the ROI changes. The value isn’t in the time saved on any single post. It’s that the workflow no longer depends on me having the bandwidth to start from zero. The capacity was always there; the system makes it consistent and repeatable.</p>



<h2 class="wp-block-heading">Stage 5: Full automation</h2>



<p class="wp-block-paragraph">The most advanced stage of maturity is when the system largely runs on its own. You’re no longer managing step-by-step actions; you’re defining goals, setting guardrails and measuring outcomes.</p>



<p class="wp-block-paragraph">We have one running in our engineering org right now. When a ticket gets escalated from our support team to engineering, the agent triages it and routes it to the team responsible for the fix. When an engineering manager reassigns the ticket – because the routing was wrong – the agent picks up that correction, feeds it back into its prompt tooling and updates its model of who owns what. We’re now extending it further: the agent is learning which parts of the codebase need to change and which engineers are likely to own the fix.</p>



<p class="wp-block-paragraph">There’s a critical catch: this stage only works if you’ve earned your way there. We learned this firsthand. When we first rolled out the routing agent, we used a static map of application areas to engineering teams and assumed that was enough. It wasn’t. We couldn’t reliably distinguish front-end bugs from back-end ones, so the front-end team kept getting tickets caused by a misbehaving API. Features were split between teams in ways the map didn’t capture — one team owned exports, another owned reports. Before the routing could work, the knowledge had to exist somewhere it could be used. An autonomous system is only as good as the foundation beneath it – the clarity of your workflows, the health of your data, the alignment of your teams. Deploy an autonomous agent into a broken process and you get bad results at scale. You cannot safely delegate what you don’t fully understand.</p>



<p class="wp-block-paragraph">This is why racing straight to Stage 5 often fails. You need to know what “good” output looks like (Stages 2 and 3) and how to orchestrate the pieces (Stage 4) before you can confidently take your hands off the wheel.</p>



<h2 class="wp-block-heading">Where business value emerges</h2>



<p class="wp-block-paragraph">The evolution from a premium search engine to an autonomous system is an organizational challenge, not a technology one. Realizing the <a href="https://www.cio.com/article/4157498/kpmg-report-finds-enterprise-disconnect-between-ai-and-its-roi.html">value of AI</a> is determined not by the sophistication of the underlying model, but by the maturity of the team wielding it.</p>



<p class="wp-block-paragraph">The practical move isn’t to audit your whole organization’s AI readiness. Start with one workflow. Push it one stage higher. Measure what changes. That’s how you find out if this matters in your specific context – not in theory, but in the work your team actually does.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The 5 stages of AI adoption maturity: Where businesses create real value]]></title>
<description><![CDATA[Most enterprises are rushing toward autonomous AI. They shouldn’t. Autonomy you haven’t earned doesn’t speed you up. In fact, it slows you down.



Here’s what I’ve moved our organization toward: a five-stage set of AI adoption maturity benchmarks. It’s a practical framework for understanding whe...]]></description>
<link>https://tsecurity.de/de/3705636/it-nachrichten/the-5-stages-of-ai-adoption-maturity-where-businesses-create-real-value/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3705636/it-nachrichten/the-5-stages-of-ai-adoption-maturity-where-businesses-create-real-value/</guid>
<pubDate>Wed, 05 Aug 2026 13:48:35 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Most enterprises are rushing toward autonomous AI. They shouldn’t. Autonomy you haven’t earned doesn’t speed you up. In fact, it slows you down.</p>



<p class="wp-block-paragraph">Here’s what I’ve moved our organization toward: a five-stage set of AI adoption maturity benchmarks. It’s a practical framework for understanding where employee development, decision-making and business value intersect. Each stage provides value for your organization. Some roles and functions may only ever reach Stage 1 or 2, while others should be fast-tracked to Stage 5. By understanding this progression, leadership can stop viewing AI as a tool for task delegation and treat it as a catalyst for developing stronger, more decisive and more valuable teams.</p>



<h2 class="wp-block-heading">Stage 1: Research assistance</h2>



<p class="wp-block-paragraph">You hand people a premium ChatGPT account. Employees stop Googling and start prompting. Their experience improves: no ads, paragraph-form answers instead of blue links. But the underlying dynamic hasn’t changed. Output quality depends on input quality. A vague Google search returns a mess of links. A vague ChatGPT prompt returns a well-formatted mess of paragraphs. If your team didn’t know how to ask a precise question before, they still don’t.<br>           <br>The real danger at Stage 1 isn’t the bad answers – it’s the <a href="https://link.springer.com/article/10.3758/s13421-025-01755-4">confident-sounding</a> ones. A hallucinated statistic arrives in the same calm, authoritative prose as an accurate one. Teams that don’t verify sources in Google don’t suddenly fact-check ChatGPT. Before moving to Stage 2, your team needs to develop the instinct to ask, “How do I know this is true?”</p>



<h2 class="wp-block-heading">Stage 2: Task assistance</h2>



<p class="wp-block-paragraph">The next stage uses AI tools to complete tasks. It starts simply: “I need to write this email,” or “Make a spreadsheet to track open items.”</p>



<p class="wp-block-paragraph">The average employee takes what AI produces and passes it off without revision. At best, their efforts pass muster, with only a dash of <a href="https://hbr.org/2025/09/ai-generated-workslop-is-destroying-productivity">workslop</a>. At worst, the flood of unchecked AI outputs creates rework for teammates and clients.</p>



<p class="wp-block-paragraph">Another employee further along in Stage 2 may augment what AI produces. That impulse serves them well. But if they default to editing AI output rather than dictating the rules for what AI should produce, they can easily spend more time editing AI’s work than creating work from scratch.</p>



<p class="wp-block-paragraph">For employees whose work will largely remain in Stage 2, the focus should be on writing more precise prompts. The instinct to edit AI output isn’t wrong. The problem arises when the prompt is a rough starting point rather than a detailed spec. AI cares that your instructions are clear, specific and unambiguous. Get the spec right up front.</p>



<h2 class="wp-block-heading">Stage 3: Workflow integration</h2>



<p class="wp-block-paragraph">My daughter’s class recently had an assignment: write a paper on the causes of the Civil War.</p>



<p class="wp-block-paragraph">Her teacher knew what was going to happen. Every 11-year-old would go home and use ChatGPT to write a five-paragraph essay. So, she changed the exercise. The class generated and printed out the essay. Then, the teacher explained how to annotate, how to ask follow-up questions and how to revise in ChatGPT using the marked-up draft.<br><br>The same three-step sequence — assemble context, build the prompt, edit hard — applies when someone writes a post-mortem. The temptation is to skip straight to the draft. Pull the incident data, ask Gemini for a timeline and root cause analysis, clean it up, get a quick peer review and send it.<br><br>An engineer working at Stage 3 does what the teacher did. First, they assemble context: the Slack thread where someone flagged the anomaly two hours before the alert fired, the Jira ticket, the gap in monitoring that nobody documented. Then they build a prompt that reflects the full context and generate a draft. Now the red pen comes out: push back on the root cause analysis, add the institutional context Gemini couldn’t know, tighten the remediation steps until they’re actionable.</p>



<p class="wp-block-paragraph">The result is a better document — and an engineer who understands what failed and builds a better repeatable process. Saving time on a first draft is a fine side effect. The goal is to produce a final draft that’s worthy of review.</p>



<h2 class="wp-block-heading">Stage 4: Guided automation</h2>



<p class="wp-block-paragraph">The fourth stage is where collaboration becomes self-sustaining. You’re no longer asking AI to help you do a task. You’re asking it to run the task and surface the decisions that require your judgment.</p>



<p class="wp-block-paragraph">My LinkedIn workflow is a good example of what this looks like in practice.</p>



<p class="wp-block-paragraph">A couple of years ago, I would read an article, develop a point of view, write two or three paragraphs and publish. Not bad, but dependent on me having the time and cognitive bandwidth.</p>



<p class="wp-block-paragraph">The friction was the 15 decisions that came before drafting: Which angle is worth pursuing? Does this use my voice? Have I said this before?</p>



<p class="wp-block-paragraph">So, I started researching my patterns. First, I fed Claude my prior LinkedIn posts and prompted it to analyze my tone, sentence patterns and structural habits. I didn’t ask it to “describe my voice” – that gets you a paragraph of flattering generalities. This analysis became the base layer of the tool.</p>



<p class="wp-block-paragraph">Then I added a second layer: LinkedIn-specific rules and AI writing patterns to avoid. That context got embedded alongside the voice analysis.</p>



<p class="wp-block-paragraph">Now the workflow runs like this. I click a link, save the article, highlight and annotate the sections that interest me. My Claude Managed Agent picks up the annotation, infers what I found worth engaging with and writes four drafts with meaningfully different angles on the source material. It compares each draft against my post history and proposes two. I read the proposals, pick one, edit and authorize publication with Buffer.<br><br>The automation didn’t remove my judgment from the process. It freed me from work that didn’t depend on judgment. Now I do the work that matters: deciding what to say, identifying patterns and sharing my point of view.</p>



<p class="wp-block-paragraph">That shift in what I’m accountable for is where the ROI changes. The value isn’t in the time saved on any single post. It’s that the workflow no longer depends on me having the bandwidth to start from zero. The capacity was always there; the system makes it consistent and repeatable.</p>



<h2 class="wp-block-heading">Stage 5: Full automation</h2>



<p class="wp-block-paragraph">The most advanced stage of maturity is when the system largely runs on its own. You’re no longer managing step-by-step actions; you’re defining goals, setting guardrails and measuring outcomes.</p>



<p class="wp-block-paragraph">We have one running in our engineering org right now. When a ticket gets escalated from our support team to engineering, the agent triages it and routes it to the team responsible for the fix. When an engineering manager reassigns the ticket – because the routing was wrong – the agent picks up that correction, feeds it back into its prompt tooling and updates its model of who owns what. We’re now extending it further: the agent is learning which parts of the codebase need to change and which engineers are likely to own the fix.</p>



<p class="wp-block-paragraph">There’s a critical catch: this stage only works if you’ve earned your way there. We learned this firsthand. When we first rolled out the routing agent, we used a static map of application areas to engineering teams and assumed that was enough. It wasn’t. We couldn’t reliably distinguish front-end bugs from back-end ones, so the front-end team kept getting tickets caused by a misbehaving API. Features were split between teams in ways the map didn’t capture — one team owned exports, another owned reports. Before the routing could work, the knowledge had to exist somewhere it could be used. An autonomous system is only as good as the foundation beneath it – the clarity of your workflows, the health of your data, the alignment of your teams. Deploy an autonomous agent into a broken process and you get bad results at scale. You cannot safely delegate what you don’t fully understand.</p>



<p class="wp-block-paragraph">This is why racing straight to Stage 5 often fails. You need to know what “good” output looks like (Stages 2 and 3) and how to orchestrate the pieces (Stage 4) before you can confidently take your hands off the wheel.</p>



<h2 class="wp-block-heading">Where business value emerges</h2>



<p class="wp-block-paragraph">The evolution from a premium search engine to an autonomous system is an organizational challenge, not a technology one. Realizing the <a href="https://www.cio.com/article/4157498/kpmg-report-finds-enterprise-disconnect-between-ai-and-its-roi.html">value of AI</a> is determined not by the sophistication of the underlying model, but by the maturity of the team wielding it.</p>



<p class="wp-block-paragraph">The practical move isn’t to audit your whole organization’s AI readiness. Start with one workflow. Push it one stage higher. Measure what changes. That’s how you find out if this matters in your specific context – not in theory, but in the work your team actually does.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Next.js 16.3 senkt Speicherverbrauch um bis zu 90 Prozent]]></title>
<description><![CDATA[Deutlich geringerer Speicherverbrauch, schnellere Seitenwechsel, Rust-basierter React-Compiler: Next.js 16.3 bietet umfassende Performanceverbesserungen.]]></description>
<link>https://tsecurity.de/de/3705595/it-nachrichten/nextjs-163-senkt-speicherverbrauch-um-bis-zu-90-prozent/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3705595/it-nachrichten/nextjs-163-senkt-speicherverbrauch-um-bis-zu-90-prozent/</guid>
<pubDate>Wed, 05 Aug 2026 13:45:05 +0200</pubDate>
<content:encoded><![CDATA[Deutlich geringerer Speicherverbrauch, schnellere Seitenwechsel, Rust-basierter React-Compiler: Next.js 16.3 bietet umfassende Performanceverbesserungen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Never mind clean data. Annotate as you collect it.]]></title>
<description><![CDATA[Generative AI is notoriously eager to help, to the point that if it can’t find something matching what you ask for, it’ll create it. So the problem with relying on guardrails is that all too often, a model will be wrong, showing a high confidence score for an incorrect answer because it’s relying...]]></description>
<link>https://tsecurity.de/de/3705489/it-security-nachrichten/never-mind-clean-data-annotate-as-you-collect-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3705489/it-security-nachrichten/never-mind-clean-data-annotate-as-you-collect-it/</guid>
<pubDate>Wed, 05 Aug 2026 12:14:38 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Generative AI is notoriously eager to help, to the point that if it can’t find something matching what you ask for, it’ll create it. So the problem with relying on guardrails is that all too often, a model will be wrong, showing a high confidence score for an incorrect answer because it’s relying on stale or non-canonical data.</p>



<p class="wp-block-paragraph">Not only do you need to be able to track the lineage of data your model uses from source to token, something the <a href="https://digital-strategy.ec.europa.eu/en/faqs/guidelines-and-code-practice-transparent-ai-systems?ref=distributedthoughts.org">EU AI Act requires</a>, you also need to be able to take into account where the data came from, whether it’s <a href="https://www.hbs.edu/faculty/Pages/item.aspx?num=58832&amp;ref=distributedthoughts.org">out of date</a>, if it changed in a way that affects the result, or if it was never really relevant or authoritative in the first place.</p>



<p class="wp-block-paragraph">Gartner expects organizations will abandon 60% of AI projects because they don’t have the right <a href="https://www.gartner.com/en/newsroom/press-releases/2025-02-26-lack-of-ai-ready-data-puts-ai-projects-at-risk">metadata management, data quality, and data observability</a>. IBM’s acquisition of Confluent also highlights the importance of real-time data with lineage, governance, and policy for AI agents, and <a href="https://www.ibm.com/think/news/ai-tech-trends-predictions-2026?ref=distributedthoughts.org">one of IBM’s 2026 predictions</a> was the importance of smarter data.</p>



<p class="wp-block-paragraph">The usual approach is adding metadata and validation later in the data pipeline. That’s similar to the way the bronze, silver, and gold tiers of typical lakehouse architecture are supposed to represent how filtering, cleaning, and augmenting data improves structure and quality until it’s ready to use. That can mean an enormous amount of work since nearly three quarters of the CPU work in training a frontier model is data cleansing and validation.</p>



<p class="wp-block-paragraph">But that can also remove a lot of the context crucial for gen AI. Rather than <a href="https://www.cio.com/article/3611247/when-is-data-too-clean-to-be-useful-for-enterprise-ai.html">cleaning data and losing the original context</a>, it’s often more effective to keep as much information about the original state of the data, says David Aronchick, open-source platform Kubeflow founder, and CEO of distributed data pipeline vendor Expanso. “You can’t pursue exactly purely clean data; that’s just not possible,” he says. “As you pull data into your ML model, every line should have some mechanism saying where it came from. Otherwise, you’re never really going to know because you can’t mix them together and tease them apart later. You can search your raw content, your raw logs, but it’s just not going to be there.”</p>



<p class="wp-block-paragraph">IoT digital twin systems often tag data all the way back to the device capturing it so you can see whether a temperature spike is a critical failure, which you want to react to, or a routine calibration, which you don’t. But that information may well be relevant down the line when you want to use that data more broadly. So unless you capture at least some elements about the source of data before you move it, you’re not going to be able to easily reconstruct the context later, or at all sometimes.</p>



<p class="wp-block-paragraph">Ulrik Hansen, co-CEO of Encord, a platform for managing and annotating data, calls this in-stream labelling and cautions it’s not an alternative to cleansing data. “Dirty conflates two things: actual corruption you should fix, and context dependence, where a reading only looks anomalous because you threw away the frame that explained it,” he says. “Cleansing kills both. The point isn’t to stop cleaning, it’s to stop normalizing away context you can never recover.”</p>



<p class="wp-block-paragraph">Context can be cheap to capture at the source and nearly impossible to recover after, he adds. “The question isn’t whether to keep it,” he says, “it’s about curating what actually helps.”</p>



<h2 class="wp-block-heading">Raw but not rancid</h2>



<p class="wp-block-paragraph">Aronchick characterizes the state of most bronze tiers as toxic waste because raw data doesn’t get validated before ingestion, or have a metadata wrapper on each data point. “You’ve taken raw data and stripped it of context,” he says.</p>



<p class="wp-block-paragraph">Take a wind farm operator, for instance. When sensor data about the turbines is generated, it comes from a particular turbine at a particular position in a specific wind farm at a known location, running at a specific speed in specific weather conditions, at a particular time. “If you have other turbines also working in the field, the performance of your turbine will go down, but the field performance will go up,” says Aronchick. “The performance of your turbine going down isn’t a negative, but unless you have the context at the point of data collection, you’re going to make your life much harder later on, when someone asks about the efficiency.”</p>



<p class="wp-block-paragraph">Metadata needs to be much richer, and it needs to be added as early in your data pipeline as possible when you have the most detail available to make sense of the structure and complexity of the data, Aronchick adds. “You want to capture as much about the data you’re collecting as possible, where it doesn’t require insane activity to do so.”</p>



<p class="wp-block-paragraph">But not all the metadata you need will be generated with the data, he says. You almost certainly need to augment and annotate your data, and provide extra structure, especially for something like a point of sale system with very light metadata. “Data comes off these things in poor structure,” he says. “It’s not OpenLineage, it’s often a CSV or a text record, and you have to reconstruct them into a full structured log. So do smart things where you’re creating data. That might be compressing, sampling, converting, appending metadata to it, and enforcing schema and lineage all before you start moving anything.”</p>



<p class="wp-block-paragraph">That doesn’t have to mean bloating your data, Hansen points out. He suggests capturing what’s free and unrecoverable. “The system of origin is the label,” he says. “You don’t tag HR policy, you capture that it came from the HR system. Anything a model can derive later, you can skip.”</p>



<h2 class="wp-block-heading">Structure isn’t static</h2>



<p class="wp-block-paragraph">Routine changes to APIs, schemas, and how data is collected or stored happen in every organization, and need to be reflected in metadata that lives alongside the data or added as data is collected, not reconstructed later in a fragile process that depends on knowing about all those changes. Google’s research into these <a href="https://research.google/blog/data-cascades-in-machine-learning/">data cascades</a> shows how easily context gets lost and how badly it affects data quality.</p>



<p class="wp-block-paragraph">Shifting schema enforcement further left in your data pipeline so you deal with it as soon as possible allows you to make more effective downstream decisions. For a sensor recording temperature and humidity, you need to know the temperature scale it uses, readings, and how the timestamp is recorded. Checking that against the schema before ingesting the data lets you route it differently depending on whether it validates or triggers alerts about data quality.</p>



<p class="wp-block-paragraph">“Maybe I’ll delete it, or send it off to some place where a human being or other tooling can reconstruct it into something valuable,” says Aronchick. “But what it doesn’t do is allow the polluted or bad data into my pipeline. Saying whether or not something passed your schema makes your downstream systems much more reliable.”</p>



<h2 class="wp-block-heading">Sensing structure</h2>



<p class="wp-block-paragraph">Unstructured and semistructured data needs more augmentation. A PDF or Word document has an author and a creation date, but doesn’t necessarily include any context about the job title and department of the author, whether it’s up to date, only applies to a particular group of customers, or is based on accounting regulations that can change. If that information is available, it needs to travel with the document, not be left in a compliance spreadsheet.</p>



<p class="wp-block-paragraph">Data platforms like DataHub and SurrealDB both capture and create context. The latter can analyze a photo, for instance, using vision AI to understand what’s in the image. “From completely unstructured data, we get as much structure as possible,” says the company’s CEO Tobie Morgan Hitchcock.</p>



<p class="wp-block-paragraph">That’s paired with other data potentially useful for an AI agent down the line. “Understanding what happened around an event becomes a lot easier if you’re tracking the conversation, telemetry, tool and model usage, geospatial data, and the vector search and relationships,” he says. “You’re going to have a far better chance of getting an accurate understanding of that data, which started off completely unstructured, than if you weren’t capturing anything.”</p>



<p class="wp-block-paragraph">Metadata about document authors, which might come from the company directory, can show how much authority a document has. He describes that as building an understanding of what trust and provenance is over time by the weight and authority of who’s updating the information. After all, he says, company-generated information has more trust or can have traced provenance compared to conversational inputs from a user.</p>



<h2 class="wp-block-heading">Incentives for annotating</h2>



<p class="wp-block-paragraph">DataHub CTO Shirshanka Das saw how much of a mess data can be even with strong guidelines as former architect of LinkedIn’s GDPR strategy. “The data was a swamp, despite us having had pretty good data-first and schema-first practices,” he says. As well as cleaning up the data governance, they added in the first nuggets of the DevOps’ ‘shift left’ approach.</p>



<p class="wp-block-paragraph">LinkedIn already required data checked in to its Kafka ecosystem to have a schema, and ran CI/CD pipelines to check backward compatibility. “I attached metadata attribution and collection around compliance metadata into that pipeline, where developers weren’t able to check in a schema until they had declared what every column meant.”</p>



<p class="wp-block-paragraph">The extra work was unpopular until teams who didn’t participate saw the flood of tickets that came their way, which allowed him to extend that same proactive governance and annotation at source approach to pretty much every data set being produced.</p>



<p class="wp-block-paragraph">“The starting point of data at most companies is a lot more swampy,” he says. “Many people are using Kafka, which is a very schema forward system, and yet they’re just shoving in JSON and unstructured stuff.”</p>



<p class="wp-block-paragraph">That’s common, agrees Megha Kumar, research VP for analytics and AI at IDC, because while collecting more metadata provides better context and cleaner data lineage, it’s hard in practice. “Most organizations batch process data, so real-time context capture rarely happens,” she says. “Even the ones that process in real-time tend to have pre-defined schemas, so adding context requires changes to the data, which unfortunately happens later.”</p>



<p class="wp-block-paragraph">People don’t know how to start, says Das, so DataHub Cloud tries to add back context by collecting operational metadata from multiple systems, including queries and BI tools to extrapolate a semantic model. “We confront the mess by giving them something they can react to,” he says. “They can quickly validate, and then it starts becoming a governance layer on top where humans annotate at source.”</p>



<p class="wp-block-paragraph">Online whiteboard provider Miro, for example, dramatically improved AI agent query accuracy from about 50% to 90% using DataHub. Then they applied GitOps principles on top of what was inferred with a human in the loop for approvals.</p>



<p class="wp-block-paragraph">So getting people to do the work happened the same way at LinkedIn, says Das. “When a data scientist gets 10 times more requests because they didn’t document their work well, resulting in the AI making lots of mistakes and stakeholders constantly pinging them for answers, they have the incentive to add the annotation when they produce an analysis, because then they get out of the critical path.”</p>



<h2 class="wp-block-heading">DBOMs and data contracts</h2>



<p class="wp-block-paragraph">Provenance and lineage of data is critical, Aronchick says, so you can preserve details like who collected the data, when, from where, if the source was authoritative or canonical, what transformations were run, and exactly what the model saw.</p>



<p class="wp-block-paragraph">“It’s not just about the version and the metadata,” he says. “Where things really start to change is when you can say along the way this data has gone through these steps, this is the root source, and these were the other elements.” You want to be able to find out if there were any experimental flags, like a new customer campaign running when it was collected, as well as what claims the data contributes to.</p>



<p class="wp-block-paragraph">Aronchick advocates for a SLSA-style data bill of materials using a tool like <a href="https://usemakoto.dev/">Makoto</a>, which can add signed provenance and attestation to simplify applying central concepts of governance and structure to upstream data.</p>



<p class="wp-block-paragraph">The notion of a data contract or a data product spec is starting to become common in the financial sector says Das, defining it as a data set, or a group of data sets, bound together by a contract that defines expectations which aren’t just cosmetic but machine verifiable. They can also include operational SLOs for APIs as contracts describe not just the shape of the data but operational characteristics and guarantees.</p>



<p class="wp-block-paragraph">Document graph markup language (DGML), a new open source specification from Docugami, promises provenance down to individual data points automatically extracted from documents.</p>



<p class="wp-block-paragraph">“It’s critical to know the validity and provenance of the information your AI is relying on,” Docugami CEO and XML co-creator Jean Paoli says. “Establishing the validity of data right from the start, at scale, is vital and far more efficient than trying to clean up bad data later.” DGML combines semantic tags describing what content means in its business context with bounding boxes showing exactly where in the document the content comes from, with attestation to prove it.</p>



<h2 class="wp-block-heading">AI demands provenance</h2>



<p class="wp-block-paragraph">All this context is the kind of metadata <a href="https://www.anthropic.com/engineering/effective-context-engineering-for-ai-agents?ref=distributedthoughts.org">Anthropic’s context engineering guide</a> recommends feeding to agents for accuracy. Developers are already used to giving coding agents more context, Das argues. “The same thing is happening with data, as when people realize when AI agents can’t make sense of what they’re doing, hallucinations happen,” he says.</p>



<p class="wp-block-paragraph">Kumar agrees that organizations realize agents need context to provide better insights. “In many cases, it has to do with ensuring the existing data had clear semantics and relationships,” she says.</p>



<p class="wp-block-paragraph">If you want to make sure the purchase return window an AI chatbot promises customers is based on your own policy, not a wish list from a user forum, you need rich context. It’s not just metadata. Organizations need to have semantics, data lineage, and ontologies. “Many are also building knowledge and ontology graphs,” adds Kumar. “By ensuring the systems understand what the data means, it’ll be able to provide a better response.”</p>



<p class="wp-block-paragraph">And if you’re going to the expense of fine tuning, which needs relevant and domain- or task-specific examples, you don’t want noise, duplication, or irrelevant content in your data. You can, of course, exclude poor data if it’s annotated and verified earlier, but you can also improve model performance with extra information, Aronchick points out. “The augmentation of the existing data makes the data you pull out more valuable,” he says.</p>



<p class="wp-block-paragraph">Expanso recently <a href="https://expanso.io/news/edge-ai-startup-of-the-year-2026/">won an Edge AI award</a> for fine tuning a base level model with only about 3,200 images by augmenting them with metadata. “The reason it worked on that few is because I could tell it deterministically what was in the frame,” he adds. “It’s labeling at the point of capture instead of paying somebody to label it later. What if I developed models for predictive analytics of store behavior on a per city, region, or country basis? If I’m able to take the raw point of sale information and augment it with additional metadata, I’m turning this into a much easier thing to fine tune.”</p>



<p class="wp-block-paragraph">Or you might even avoid the expense of fine tuning entirely, suggests Das. “You get the short-term advantage by fine-tuning and getting great performance at much cheaper cost on a smaller model, and it gets stripped away in a couple of months as a new model shows up,” he says. “You have to always run that calculus of when’s the right threshold to fine tune an existing model, distil it, and then run it for a fair amount of time to recoup the costs of fine tuning.”</p>



<p class="wp-block-paragraph">Although regulated or slow-moving industries will see benefits from fine tuning a model they can run for six to 12 months on data with higher quality and better provenance, many organizations may use the improved data quality to get good results without fine tuning.</p>



<p class="wp-block-paragraph">“We’re taking a more knowledge graph-oriented approach to grounding the model, and betting on the fact that because the knowledge graph is changing often, it’s better to keep it as a runtime artifact than a baked-in one.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data]]></title>
<description><![CDATA[A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and development environments on which they were installed.

The "evil twin" extensions were uploaded to the repository between July 26 a...]]></description>
<link>https://tsecurity.de/de/3705486/it-security-nachrichten/open-vsx-removes-77-malicious-evil-twin-extensions-exfiltrating-developer-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3705486/it-security-nachrichten/open-vsx-removes-77-malicious-evil-twin-extensions-exfiltrating-developer-data/</guid>
<pubDate>Wed, 05 Aug 2026 12:08:31 +0200</pubDate>
<content:encoded><![CDATA[A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and development environments on which they were installed.

The "evil twin" extensions were uploaded to the repository between July 26 and August 1, 2026, according to Manifold Security. The packages have been removed from Open VSX as of]]></content:encoded>
</item>
<item>
<title><![CDATA[Never mind clean data. Annotate as you collect it.]]></title>
<description><![CDATA[Generative AI is notoriously eager to help, to the point that if it can’t find something matching what you ask for, it’ll create it. So the problem with relying on guardrails is that all too often, a model will be wrong, showing a high confidence score for an incorrect answer because it’s relying...]]></description>
<link>https://tsecurity.de/de/3705480/it-nachrichten/never-mind-clean-data-annotate-as-you-collect-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3705480/it-nachrichten/never-mind-clean-data-annotate-as-you-collect-it/</guid>
<pubDate>Wed, 05 Aug 2026 12:08:20 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Generative AI is notoriously eager to help, to the point that if it can’t find something matching what you ask for, it’ll create it. So the problem with relying on guardrails is that all too often, a model will be wrong, showing a high confidence score for an incorrect answer because it’s relying on stale or non-canonical data.</p>



<p class="wp-block-paragraph">Not only do you need to be able to track the lineage of data your model uses from source to token, something the <a href="https://digital-strategy.ec.europa.eu/en/faqs/guidelines-and-code-practice-transparent-ai-systems?ref=distributedthoughts.org">EU AI Act requires</a>, you also need to be able to take into account where the data came from, whether it’s <a href="https://www.hbs.edu/faculty/Pages/item.aspx?num=58832&amp;ref=distributedthoughts.org">out of date</a>, if it changed in a way that affects the result, or if it was never really relevant or authoritative in the first place.</p>



<p class="wp-block-paragraph">Gartner expects organizations will abandon 60% of AI projects because they don’t have the right <a href="https://www.gartner.com/en/newsroom/press-releases/2025-02-26-lack-of-ai-ready-data-puts-ai-projects-at-risk">metadata management, data quality, and data observability</a>. IBM’s acquisition of Confluent also highlights the importance of real-time data with lineage, governance, and policy for AI agents, and <a href="https://www.ibm.com/think/news/ai-tech-trends-predictions-2026?ref=distributedthoughts.org">one of IBM’s 2026 predictions</a> was the importance of smarter data.</p>



<p class="wp-block-paragraph">The usual approach is adding metadata and validation later in the data pipeline. That’s similar to the way the bronze, silver, and gold tiers of typical lakehouse architecture are supposed to represent how filtering, cleaning, and augmenting data improves structure and quality until it’s ready to use. That can mean an enormous amount of work since nearly three quarters of the CPU work in training a frontier model is data cleansing and validation.</p>



<p class="wp-block-paragraph">But that can also remove a lot of the context crucial for gen AI. Rather than <a href="https://www.cio.com/article/3611247/when-is-data-too-clean-to-be-useful-for-enterprise-ai.html">cleaning data and losing the original context</a>, it’s often more effective to keep as much information about the original state of the data, says David Aronchick, open-source platform Kubeflow founder, and CEO of distributed data pipeline vendor Expanso. “You can’t pursue exactly purely clean data; that’s just not possible,” he says. “As you pull data into your ML model, every line should have some mechanism saying where it came from. Otherwise, you’re never really going to know because you can’t mix them together and tease them apart later. You can search your raw content, your raw logs, but it’s just not going to be there.”</p>



<p class="wp-block-paragraph">IoT digital twin systems often tag data all the way back to the device capturing it so you can see whether a temperature spike is a critical failure, which you want to react to, or a routine calibration, which you don’t. But that information may well be relevant down the line when you want to use that data more broadly. So unless you capture at least some elements about the source of data before you move it, you’re not going to be able to easily reconstruct the context later, or at all sometimes.</p>



<p class="wp-block-paragraph">Ulrik Hansen, co-CEO of Encord, a platform for managing and annotating data, calls this in-stream labelling and cautions it’s not an alternative to cleansing data. “Dirty conflates two things: actual corruption you should fix, and context dependence, where a reading only looks anomalous because you threw away the frame that explained it,” he says. “Cleansing kills both. The point isn’t to stop cleaning, it’s to stop normalizing away context you can never recover.”</p>



<p class="wp-block-paragraph">Context can be cheap to capture at the source and nearly impossible to recover after, he adds. “The question isn’t whether to keep it,” he says, “it’s about curating what actually helps.”</p>



<h2 class="wp-block-heading">Raw but not rancid</h2>



<p class="wp-block-paragraph">Aronchick characterizes the state of most bronze tiers as toxic waste because raw data doesn’t get validated before ingestion, or have a metadata wrapper on each data point. “You’ve taken raw data and stripped it of context,” he says.</p>



<p class="wp-block-paragraph">Take a wind farm operator, for instance. When sensor data about the turbines is generated, it comes from a particular turbine at a particular position in a specific wind farm at a known location, running at a specific speed in specific weather conditions, at a particular time. “If you have other turbines also working in the field, the performance of your turbine will go down, but the field performance will go up,” says Aronchick. “The performance of your turbine going down isn’t a negative, but unless you have the context at the point of data collection, you’re going to make your life much harder later on, when someone asks about the efficiency.”</p>



<p class="wp-block-paragraph">Metadata needs to be much richer, and it needs to be added as early in your data pipeline as possible when you have the most detail available to make sense of the structure and complexity of the data, Aronchick adds. “You want to capture as much about the data you’re collecting as possible, where it doesn’t require insane activity to do so.”</p>



<p class="wp-block-paragraph">But not all the metadata you need will be generated with the data, he says. You almost certainly need to augment and annotate your data, and provide extra structure, especially for something like a point of sale system with very light metadata. “Data comes off these things in poor structure,” he says. “It’s not OpenLineage, it’s often a CSV or a text record, and you have to reconstruct them into a full structured log. So do smart things where you’re creating data. That might be compressing, sampling, converting, appending metadata to it, and enforcing schema and lineage all before you start moving anything.”</p>



<p class="wp-block-paragraph">That doesn’t have to mean bloating your data, Hansen points out. He suggests capturing what’s free and unrecoverable. “The system of origin is the label,” he says. “You don’t tag HR policy, you capture that it came from the HR system. Anything a model can derive later, you can skip.”</p>



<h2 class="wp-block-heading">Structure isn’t static</h2>



<p class="wp-block-paragraph">Routine changes to APIs, schemas, and how data is collected or stored happen in every organization, and need to be reflected in metadata that lives alongside the data or added as data is collected, not reconstructed later in a fragile process that depends on knowing about all those changes. Google’s research into these <a href="https://research.google/blog/data-cascades-in-machine-learning/">data cascades</a> shows how easily context gets lost and how badly it affects data quality.</p>



<p class="wp-block-paragraph">Shifting schema enforcement further left in your data pipeline so you deal with it as soon as possible allows you to make more effective downstream decisions. For a sensor recording temperature and humidity, you need to know the temperature scale it uses, readings, and how the timestamp is recorded. Checking that against the schema before ingesting the data lets you route it differently depending on whether it validates or triggers alerts about data quality.</p>



<p class="wp-block-paragraph">“Maybe I’ll delete it, or send it off to some place where a human being or other tooling can reconstruct it into something valuable,” says Aronchick. “But what it doesn’t do is allow the polluted or bad data into my pipeline. Saying whether or not something passed your schema makes your downstream systems much more reliable.”</p>



<h2 class="wp-block-heading">Sensing structure</h2>



<p class="wp-block-paragraph">Unstructured and semistructured data needs more augmentation. A PDF or Word document has an author and a creation date, but doesn’t necessarily include any context about the job title and department of the author, whether it’s up to date, only applies to a particular group of customers, or is based on accounting regulations that can change. If that information is available, it needs to travel with the document, not be left in a compliance spreadsheet.</p>



<p class="wp-block-paragraph">Data platforms like DataHub and SurrealDB both capture and create context. The latter can analyze a photo, for instance, using vision AI to understand what’s in the image. “From completely unstructured data, we get as much structure as possible,” says the company’s CEO Tobie Morgan Hitchcock.</p>



<p class="wp-block-paragraph">That’s paired with other data potentially useful for an AI agent down the line. “Understanding what happened around an event becomes a lot easier if you’re tracking the conversation, telemetry, tool and model usage, geospatial data, and the vector search and relationships,” he says. “You’re going to have a far better chance of getting an accurate understanding of that data, which started off completely unstructured, than if you weren’t capturing anything.”</p>



<p class="wp-block-paragraph">Metadata about document authors, which might come from the company directory, can show how much authority a document has. He describes that as building an understanding of what trust and provenance is over time by the weight and authority of who’s updating the information. After all, he says, company-generated information has more trust or can have traced provenance compared to conversational inputs from a user.</p>



<h2 class="wp-block-heading">Incentives for annotating</h2>



<p class="wp-block-paragraph">DataHub CTO Shirshanka Das saw how much of a mess data can be even with strong guidelines as former architect of LinkedIn’s GDPR strategy. “The data was a swamp, despite us having had pretty good data-first and schema-first practices,” he says. As well as cleaning up the data governance, they added in the first nuggets of the DevOps’ ‘shift left’ approach.</p>



<p class="wp-block-paragraph">LinkedIn already required data checked in to its Kafka ecosystem to have a schema, and ran CI/CD pipelines to check backward compatibility. “I attached metadata attribution and collection around compliance metadata into that pipeline, where developers weren’t able to check in a schema until they had declared what every column meant.”</p>



<p class="wp-block-paragraph">The extra work was unpopular until teams who didn’t participate saw the flood of tickets that came their way, which allowed him to extend that same proactive governance and annotation at source approach to pretty much every data set being produced.</p>



<p class="wp-block-paragraph">“The starting point of data at most companies is a lot more swampy,” he says. “Many people are using Kafka, which is a very schema forward system, and yet they’re just shoving in JSON and unstructured stuff.”</p>



<p class="wp-block-paragraph">That’s common, agrees Megha Kumar, research VP for analytics and AI at IDC, because while collecting more metadata provides better context and cleaner data lineage, it’s hard in practice. “Most organizations batch process data, so real-time context capture rarely happens,” she says. “Even the ones that process in real-time tend to have pre-defined schemas, so adding context requires changes to the data, which unfortunately happens later.”</p>



<p class="wp-block-paragraph">People don’t know how to start, says Das, so DataHub Cloud tries to add back context by collecting operational metadata from multiple systems, including queries and BI tools to extrapolate a semantic model. “We confront the mess by giving them something they can react to,” he says. “They can quickly validate, and then it starts becoming a governance layer on top where humans annotate at source.”</p>



<p class="wp-block-paragraph">Online whiteboard provider Miro, for example, dramatically improved AI agent query accuracy from about 50% to 90% using DataHub. Then they applied GitOps principles on top of what was inferred with a human in the loop for approvals.</p>



<p class="wp-block-paragraph">So getting people to do the work happened the same way at LinkedIn, says Das. “When a data scientist gets 10 times more requests because they didn’t document their work well, resulting in the AI making lots of mistakes and stakeholders constantly pinging them for answers, they have the incentive to add the annotation when they produce an analysis, because then they get out of the critical path.”</p>



<h2 class="wp-block-heading">DBOMs and data contracts</h2>



<p class="wp-block-paragraph">Provenance and lineage of data is critical, Aronchick says, so you can preserve details like who collected the data, when, from where, if the source was authoritative or canonical, what transformations were run, and exactly what the model saw.</p>



<p class="wp-block-paragraph">“It’s not just about the version and the metadata,” he says. “Where things really start to change is when you can say along the way this data has gone through these steps, this is the root source, and these were the other elements.” You want to be able to find out if there were any experimental flags, like a new customer campaign running when it was collected, as well as what claims the data contributes to.</p>



<p class="wp-block-paragraph">Aronchick advocates for a SLSA-style data bill of materials using a tool like <a href="https://usemakoto.dev/">Makoto</a>, which can add signed provenance and attestation to simplify applying central concepts of governance and structure to upstream data.</p>



<p class="wp-block-paragraph">The notion of a data contract or a data product spec is starting to become common in the financial sector says Das, defining it as a data set, or a group of data sets, bound together by a contract that defines expectations which aren’t just cosmetic but machine verifiable. They can also include operational SLOs for APIs as contracts describe not just the shape of the data but operational characteristics and guarantees.</p>



<p class="wp-block-paragraph">Document graph markup language (DGML), a new open source specification from Docugami, promises provenance down to individual data points automatically extracted from documents.</p>



<p class="wp-block-paragraph">“It’s critical to know the validity and provenance of the information your AI is relying on,” Docugami CEO and XML co-creator Jean Paoli says. “Establishing the validity of data right from the start, at scale, is vital and far more efficient than trying to clean up bad data later.” DGML combines semantic tags describing what content means in its business context with bounding boxes showing exactly where in the document the content comes from, with attestation to prove it.</p>



<h2 class="wp-block-heading">AI demands provenance</h2>



<p class="wp-block-paragraph">All this context is the kind of metadata <a href="https://www.anthropic.com/engineering/effective-context-engineering-for-ai-agents?ref=distributedthoughts.org">Anthropic’s context engineering guide</a> recommends feeding to agents for accuracy. Developers are already used to giving coding agents more context, Das argues. “The same thing is happening with data, as when people realize when AI agents can’t make sense of what they’re doing, hallucinations happen,” he says.</p>



<p class="wp-block-paragraph">Kumar agrees that organizations realize agents need context to provide better insights. “In many cases, it has to do with ensuring the existing data had clear semantics and relationships,” she says.</p>



<p class="wp-block-paragraph">If you want to make sure the purchase return window an AI chatbot promises customers is based on your own policy, not a wish list from a user forum, you need rich context. It’s not just metadata. Organizations need to have semantics, data lineage, and ontologies. “Many are also building knowledge and ontology graphs,” adds Kumar. “By ensuring the systems understand what the data means, it’ll be able to provide a better response.”</p>



<p class="wp-block-paragraph">And if you’re going to the expense of fine tuning, which needs relevant and domain- or task-specific examples, you don’t want noise, duplication, or irrelevant content in your data. You can, of course, exclude poor data if it’s annotated and verified earlier, but you can also improve model performance with extra information, Aronchick points out. “The augmentation of the existing data makes the data you pull out more valuable,” he says.</p>



<p class="wp-block-paragraph">Expanso recently <a href="https://expanso.io/news/edge-ai-startup-of-the-year-2026/">won an Edge AI award</a> for fine tuning a base level model with only about 3,200 images by augmenting them with metadata. “The reason it worked on that few is because I could tell it deterministically what was in the frame,” he adds. “It’s labeling at the point of capture instead of paying somebody to label it later. What if I developed models for predictive analytics of store behavior on a per city, region, or country basis? If I’m able to take the raw point of sale information and augment it with additional metadata, I’m turning this into a much easier thing to fine tune.”</p>



<p class="wp-block-paragraph">Or you might even avoid the expense of fine tuning entirely, suggests Das. “You get the short-term advantage by fine-tuning and getting great performance at much cheaper cost on a smaller model, and it gets stripped away in a couple of months as a new model shows up,” he says. “You have to always run that calculus of when’s the right threshold to fine tune an existing model, distil it, and then run it for a fair amount of time to recoup the costs of fine tuning.”</p>



<p class="wp-block-paragraph">Although regulated or slow-moving industries will see benefits from fine tuning a model they can run for six to 12 months on data with higher quality and better provenance, many organizations may use the improved data quality to get good results without fine tuning.</p>



<p class="wp-block-paragraph">“We’re taking a more knowledge graph-oriented approach to grounding the model, and betting on the fact that because the knowledge graph is changing often, it’s better to keep it as a runtime artifact than a baked-in one.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Five ways to evaluate AI agent orchestration platforms]]></title>
<description><![CDATA[AI agent orchestration platforms coordinate role-based and task-based AI agents, along with the tools, data, and people they depend on, into multistep workflows. These platforms are highly important for organizations scaling from handfuls to thousands of AI agents running in production.  



Two ...]]></description>
<link>https://tsecurity.de/de/3705417/ai-nachrichten/five-ways-to-evaluate-ai-agent-orchestration-platforms/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3705417/ai-nachrichten/five-ways-to-evaluate-ai-agent-orchestration-platforms/</guid>
<pubDate>Wed, 05 Aug 2026 11:39:47 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">AI agent orchestration platforms coordinate role-based and task-based AI agents, along with the tools, data, and people they depend on, into multistep workflows. These platforms are highly important for organizations scaling from handfuls to thousands of AI agents running in production.  </p>



<p class="wp-block-paragraph">Two open standards do the connective work: <a href="https://www.infoworld.com/article/4124612/5-requirements-for-using-mcp-servers-to-connect-ai-agents.html">MCP</a> (Model Context Protocol) gives agents governed access to tools and data, while <a href="https://www.infoworld.com/article/4088217/what-is-a2a-how-the-agent-to-agent-protocol-enables-autonomous-collaboration.html">A2A</a> (Agent2Agent) lets agents discover and delegate to one another, including agents built on other platforms. The orchestration layer sits on top, adding the routing, shared state, guardrails, governance, security, and observability needed to run workflows that range from fully autonomous to human-in-the-loop.</p>



<p class="wp-block-paragraph">AI orchestration platforms may be the hottest AI technology of the year. In researching this article, I identified <a href="https://drive.starcio.com/research/ai-agent-orchestration-platforms/">more than 60 commercial and open source platforms</a> that businesses can use as a control plane to manage work between AI agents, people, and automations.</p>



<p class="wp-block-paragraph">Like <a href="https://www.infoworld.com/article/4182695/develop-smarter-ai-agents-with-data-fabrics.html">data fabrics</a> and <a href="https://www.infoworld.com/article/3476848/how-to-choose-the-right-low-code-no-code-or-process-automation-platform.html">automation platforms</a>, I suspect enterprises will utilize more than one AI agent orchestration platform. Platforms are being released by hyperscalers and solution providers in enterprise SaaS, process automation, customer experience, data management, AIops, and IT infrastructure. Development-centric platforms include open source, commercial, and no-code integration solution providers.</p>



<p class="wp-block-paragraph">Here are five considerations when reviewing AI agent orchestration platforms.</p>



<h2 class="wp-block-heading">1. Observable control, oversight, and trust</h2>



<p class="wp-block-paragraph">AI agent orchestration platforms are non-deterministic and leverage AI capabilities to coordinate responses and actions across AI agents. One area to evaluate is how administrators implement controls and guardrails over which AI agents can coordinate with others and under what circumstances. Additionally, platforms should also have controls on when and where people should be involved before taking action.</p>



<p class="wp-block-paragraph">“CIOs should focus on how the AI orchestration platform clearly applies controls over autonomous decision-making,” says Heather Richards, global vice president of go-to-market strategy at <a href="https://www.verint.com/">Verint</a>. “Ideally, the platform makes it easy to define who or what can take actions, how decisions are approved, and where accountability sits when something goes wrong. If orchestration doesn’t have built-in governance, visibility, and human override, it will scale risk faster than it scales value.”</p>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/4140832/7-safeguards-for-observable-ai-agents.html">Observable AI agents</a> are primary capabilities for tracing how they interact and where decisions are made. But even more important is to review how platforms govern access to the <a href="https://drive.starcio.com/2026/06/data-management-debt-ai-era-cios/">context layer</a>, which can include <a href="https://www.infoworld.com/article/2335814/what-is-retrieval-augmented-generation-more-accurate-and-reliable-llms.html">retrieval-augmented generation (RAG)</a> for language models, <a href="https://drive.starcio.com/podcast/the-cost-of-tribal-knowledge-losing-people-can-bring-ops-to-a-standstill/">knowledge graphs</a>, and <a href="https://enterprise-knowledge.com/what-is-a-semantic-layer-components-and-enterprise-applications/">semantic layers</a>.</p>



<p class="wp-block-paragraph">“When evaluating an AI orchestration platform, organizations should consider whether governance and observability were built into the architecture from day one,” says Caitlin Schuman, director of AI strategy and customer innovation at <a href="https://www.presidio.com/">Presidio</a>. “A strong platform should make it clear what context is being used and should have a control layer that routes work across systems, agents, and humans.”</p>



<p class="wp-block-paragraph"><a href="https://drive.starcio.com/2025/10/creating-responsible-trustworthy-ai-agents/">Deploying trustworthy AI agents</a> is important for gaining employee adoption. Charles Crouchman, chief product officer at <a href="https://www.redwood.com/">Redwood Software</a>, suggests evaluating how an AI agent orchestration platform establishes trustworthy operations with enterprise resources. He recommends asking these five questions:</p>



<ul class="wp-block-list">
<li>Can it connect to the systems actually running your business?</li>



<li>Can it be trusted to execute mission-critical logic across your ERP, supply chain, and finance platforms?</li>



<li>Does it provide deterministic guardrails for non-deterministic AI, so agents can’t go rogue in production?</li>



<li>Is it model-agnostic, so you’re not locked into a single LLM or agent framework as the landscape shifts?</li>



<li>Can you govern at scale with full audit trails, observability, and accountability?</li>
</ul>



<p class="wp-block-paragraph">“Validating these answers moves you from disconnected AI  reasoning to real execution, empowering you to take the next step towards an autonomous enterprise,” says Crouchman.</p>



<h2 class="wp-block-heading">2. Secure and resilient operations</h2>



<p class="wp-block-paragraph">AI agent orchestration platforms centralize a growing number of operational workflows, so it’s important to evaluate whether their security, performance, reliability, and resiliency meet compliance and <a href="https://www.infoworld.com/article/4061123/how-to-write-nonfunctional-requirements-for-ai-agents.html">non-functional requirements</a>.  </p>



<p class="wp-block-paragraph">“Deploying agents is the easy part; the hard part is ensuring they operate safely, consistently, and in coordination with the people and systems around them,” says Daniel Meyer, CTO at <a href="https://camunda.com/">Camunda</a>. “Orchestration platforms should enforce controls between an agent’s decision and its action, handle long-running processes without losing state, and maintain a full audit trail natively.”</p>



<p class="wp-block-paragraph">Organizations should also consider how platforms support <a href="https://www.infoworld.com/article/4100507/5-key-agenticops-practices-to-start-building-now.html">agentic ops practices</a> for identity management, monitoring, AI agent accuracy, and incident management.</p>



<p class="wp-block-paragraph">“Don’t just seek solutions that coordinate workflow or handle the life cycle of an agent; also seek solutions that get the answers agents need faster, with more accuracy, all while meeting essential security and compliance requirements,” says James Urquhart, field CTO and technology evangelist at <a href="https://www.kamiwaza.ai/">Kamiwaza</a>. “A platform that securely coordinates context gathering and result formulation across widely disparate infrastructures and data sources is essential, not only to the performance of AI in the enterprise, but also to its agility.”</p>



<h2 class="wp-block-heading">3. Integrated testing and feedback</h2>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/4086884/how-to-automate-the-testing-of-ai-agents.html">Testing AI agents</a> requires validating changes before deployment, just as with <a href="https://www.infoworld.com/article/3705049/3-ways-to-upgrade-continuous-testing-for-generative-ai.html">continuous testing</a> for applications and APIs. But it also requires evaluating prompts, responses, and actions in production and ensuring that agents aren’t drifting from expected parameters or <a href="https://drive.starcio.com/2025/07/rogue-ai-agents-cios-govern-agentic-ecosystem/">going rogue</a>. One area in which AI agent orchestration platforms differ is how they support testing AI agents, monitoring them in production, and providing a centralized source of feedback to support accuracy improvements.</p>



<p class="wp-block-paragraph">“When selecting an AI orchestration platform, don’t overlook where the software it produces actually gets tested and validated,” says Jean-Philippe LeBlanc, senior vice president of engineering at <a href="https://circleci.com/">CircleCI</a>. “AI can accelerate every stage of development, but without rigorous, automated validation integrated into the delivery pipeline, you’re compounding risk at the same rate you’re compounding velocity.”</p>



<p class="wp-block-paragraph">Armando Franco, senior director of cloud and platform modernization at <a href="https://www.teksystems.com/en/it-and-business-services">TEKsystems Global Services</a>, says, “The criterion that actually matters is whether continuous outcome evaluation is a first-class capability of the platform itself, because without it, iteration speed collapses and the program stalls.”</p>



<h2 class="wp-block-heading">4. Interoperability and open standards</h2>



<p class="wp-block-paragraph">MCP and A2A are two ways AI agent orchestration platforms support open standards and enable connecting to an ecosystem of agents. Many platforms also allow developers to select and replace the underlying AI models and to choose from a range of <a href="https://www.infoworld.com/article/4032989/a-developers-guide-to-code-generation.html">AI code-generation tools</a>. These flexibilities ensure teams can optimize around performance, accuracy, compliance, costs, and other future considerations.</p>



<p class="wp-block-paragraph">“When evaluating an AI orchestration platform, we look first at composability and interoperability,” says Rajesh Arora, chief data and analytics officer at <a href="https://www.principal.com/">Principal</a>. “The real test is not how many features it offers today, but whether it can connect models, data sources, agentic solutions, and workflows in a way that adapts to our AI strategy, tech stack, and changing business needs.”</p>



<p class="wp-block-paragraph">Other interoperability criteria to review include the platform’s AI agent cataloging capabilities, how permissions are configured dynamically, and whether prebuilt connectors are available for the required integrations.</p>



<h2 class="wp-block-heading">5. Vendor viability and road map</h2>



<p class="wp-block-paragraph">Leaders recognize that <a href="https://drive.starcio.com/2026/04/ai-reshaping-business-not-digital-transformation-yet/">AI is currently reshaping business more than driving transformation</a>. To be successful, organizations require <a href="https://www.infoworld.com/article/3855572/how-to-develop-a-well-rounded-ai-governance-strategy.html">AI governance that keeps up with strategy</a> and doesn’t lag too far behind. The same is true for AI agent orchestration platforms, so it’s important to review their release notes and road maps to see whether providers strike a reasonable balance between innovation and governance.</p>



<p class="wp-block-paragraph">“The right orchestration platform provides a unified policy layer that follows work across agents, workflows, and AI tools, enabling your teams to build freely while IT and security maintain full visibility at the action and output levels,” says Brandon Sammut, chief people and AI transformation officer at <a href="https://zapier.com/">Zapier</a>. “If your governance can’t keep pace with how fast your people are building, you’ll either slow them down or lose sight of what they’re building.”</p>



<p class="wp-block-paragraph">Since AI agent orchestration platforms are a new category, technology leaders should partner with their financial, legal, and compliance colleagues to assess vendor viability risks. In addition, reviewing customer adoption and support capabilities is important as top solution providers will continue to evolve their platforms.   </p>



<p class="wp-block-paragraph">“A mature provider offers both a stable platform and the customer support you’ll need, and with a large customer base, they’ve already hit countless edge cases that can smooth your own implementation,” says Hannes Hapke, director of the 575 Lab at <a href="https://www.dataiku.com/">Dataiku</a>. “Assess maturity by looking at funding and financial backing, the clarity and consistency of their public road map, and the size and activity of their community. An engaged user base, active forums, and a healthy ecosystem of integrations all signal a provider that will still be standing when you scale.”</p>



<p class="wp-block-paragraph">Many organizations are still early in adopting AI agents and <a href="https://drive.starcio.com/2026/02/why-chaotic-ai-experiments-arent-producing-business-value/">transitioning proofs of concept into production</a>. But for those deploying a growing number of AI agents across many platforms, selecting an AI agent orchestration platform enables scaling workflows, operations, and governance. </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[MacBook Air With 24GB RAM or MacBook Pro With 16GB: Which Should You Buy?]]></title>
<description><![CDATA[Choosing between a MacBook Air with 24GB of unified memory and a MacBook Pro with 16GB becomes difficult when both configurations sell for a similar price. The two machines can deliver nearly identical everyday performance when they use the same M5 chip, but their memory capacity, cooling systems...]]></description>
<link>https://tsecurity.de/de/3705357/ios-mac-os/macbook-air-with-24gb-ram-or-macbook-pro-with-16gb-which-should-you-buy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3705357/ios-mac-os/macbook-air-with-24gb-ram-or-macbook-pro-with-16gb-which-should-you-buy/</guid>
<pubDate>Wed, 05 Aug 2026 11:18:07 +0200</pubDate>
<content:encoded><![CDATA[Choosing between a MacBook Air with 24GB of unified memory and a MacBook Pro with 16GB becomes difficult when both configurations sell for a similar price. The two machines can deliver nearly identical everyday performance when they use the same M5 chip, but their memory capacity, cooling systems, displays, ports, and sustained performance make them suitable for different users.



For most buyers, the 24GB MacBook Air offers the stronger balance because the additional memory improves multitasking and gives demanding applications more room to work. The 16GB MacBook Pro remains the better choice for workloads that keep the processor and graphics cores under heavy load for long periods.



MacBook Air 24GB vs MacBook Pro 16GB specifications



FeatureMacBook Air 24GBMacBook Pro 16GBProcessorApple M5Apple M5CPU10-core10-coreGPUUp to 10-core10-coreUnified memory24GB16GBCoolingFanlessActive cooling with fanDisplayLiquid RetinaLiquid Retina XDRRefresh rate60HzUp to 120Hz ProMotionPortsMagSafe, two Thunderbolt portsMagSafe, three Thunderbolt ports, HDMI, SDXCBest suited forMultitasking and portable workSustained workloads and gaming



Apple lists the base M5 MacBook Pro with a 10-core CPU, 10-core GPU and 153GB/s memory bandwidth, while the comparable MacBook Air also offers the M5 with a 10-core CPU and 10-core GPU. This means both systems start with broadly similar processing capabilities before cooling and memory limits affect performance.



Everyday performance will feel almost identical



For web browsing, office applications, messaging, video streaming, photo management and general productivity, both MacBooks feel equally responsive. Applications open quickly, files transfer at similar speeds, and 16GB remains enough for users who mainly work in Safari, Chrome, Microsoft Office, Slack and other everyday apps.



macOS also compresses memory before relying heavily on SSD swap space. Users can check the Memory Pressure graph in Activity Monitor, where green indicates that the available memory is handling the workload efficiently. Yellow or red pressure shows that the system needs more memory or has started relying more heavily on swap.



The 24GB Air gains an advantage when several demanding applications remain open together. A workflow involving Final Cut Pro, Photoshop, Lightroom, dozens of browser tabs, Messages and cloud collaboration tools can push a 16GB system closer to its memory limit.



The MacBook Pro handles sustained workloads better



The MacBook Air has no fan, so it reduces performance when prolonged workloads generate too much heat. Short tasks rarely cause a major slowdown, but long rendering sessions, demanding games, 3D workloads and repeated AI processing can expose the limits of its passive cooling system.



The MacBook Pro uses active cooling, allowing the M5 chip to maintain higher clock speeds for longer periods. That advantage matters for:




Long 3D renders in Blender or similar applications



Extended gaming sessions



Large photo exports with intensive AI effects



Continuous code compilation



Heavy video effects and repeated exports



Local AI workloads that keep the CPU, GPU or Neural Engine active




A 24GB MacBook Air can hold larger projects in memory, but the fan-cooled Pro finishes sustained processor-heavy tasks more consistently.



Creative work depends on the workload



Standard photo and video editing runs well on both machines because Apple’s media engine handles much of the video decoding and encoding work. Editing 4K footage, arranging timelines, applying basic effects and working with moderate photo libraries should not create a large performance difference.



Memory becomes more important when editing 8K footage, using multiple creative applications together or working with large assets. In those cases, the 24GB Air can avoid swap more effectively than the 16GB Pro.



The MacBook Pro still offers a better working environment for many creators because its Liquid Retina XDR display delivers higher brightness, HDR support and ProMotion refresh rates. Its SD card slot, HDMI port and additional Thunderbolt port also reduce the need for adapters.



Who should buy the 24GB MacBook Air?



Choose the MacBook Air with 24GB if you:




Keep several demanding applications open together



Edit photos or videos without long, repeated exports



Want more memory for future software updates



Run virtual machines or development tools



Prefer a lighter and silent laptop



Mostly use an external monitor



Want better multitasking at the same price




Who should buy the 16GB MacBook Pro?



Choose the MacBook Pro with 16GB if you:




Regularly play demanding games



Render 3D scenes



Export large projects throughout the day



Need sustained CPU or GPU performance



Want the brighter 120Hz XDR display



Depend on HDMI and SD card connectivity



Work outdoors or near bright windows




Verdict



The 24GB MacBook Air is the better purchase for most users when both machines cost the same. Its larger memory capacity improves heavy multitasking, reduces SSD swapping and gives the laptop more room for future applications and on-device AI features.



The 16GB MacBook Pro wins when sustained performance matters more than memory capacity. Its active cooling, superior display and wider port selection make it the stronger option for 3D rendering, gaming and repeated professional exports.



For general productivity, development, photography and regular video editing, buy the 24GB MacBook Air. For workloads that keep the processor or GPU running near full capacity, buy the 16GB MacBook Pro.]]></content:encoded>
</item>
<item>
<title><![CDATA[AI threat report: Rogue agents, workflow attacks]]></title>
<description><![CDATA[Malicious AI use and threats to AI systems are requiring cyber teams to double down on security fundamentals and rethink the future of their approaches to defense.



Newly emerging AI-enabled attacks, proofs of concept, and in-the-wild techniques, as well as the latest AI vulnerability and risk ...]]></description>
<link>https://tsecurity.de/de/3705141/it-security-nachrichten/ai-threat-report-rogue-agents-workflow-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3705141/it-security-nachrichten/ai-threat-report-rogue-agents-workflow-attacks/</guid>
<pubDate>Wed, 05 Aug 2026 09:34:52 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Malicious AI use and threats to AI systems are requiring cyber teams to double down on security fundamentals and rethink the future of their approaches to defense.</p>



<p class="wp-block-paragraph">Newly emerging AI-enabled attacks, proofs of concept, and in-the-wild techniques, as well as the latest AI vulnerability and risk research, present inklings not only about what enterprises presently face but also how security leaders need to adjust for what may soon come to their systems.</p>



<p class="wp-block-paragraph">The following report aims to help inform and provide a gateway to insights into what we’ve seen evolving on the AI threat horizon of late.</p>



<h3 class="wp-block-heading">AI goes rogue</h3>



<p class="wp-block-paragraph">The most impactful recent event signaling what’s here and ahead for CISOs was the revelation of OpenAI’s agents attacking Hugging Face.</p>



<p class="wp-block-paragraph">The attack, executed by sandboxed OpenAI models, shows that prompt guardrails cannot serve as a reliable, primary security boundary for AI agents, putting pressure on enterprises to establish more sophisticated agentic infrastructure controls to limit access and prevent lateral movement. CSO’s Prasanth Aby Thomas breaks down <a href="https://www.csoonline.com/article/4200043/openai-model-escape-puts-enterprise-ai-defenses-on-notice.html">how OpenAI’s agent containment strategy failed</a>.</p>



<p class="wp-block-paragraph">Further investigation of the OpenAI incident <a href="https://www.csoonline.com/article/4202852/openai-rogue-ai-agents-attack-expanded-beyond-hugging-face.html">uncovered additional breached trust boundaries</a>, prompting the Cloud Security Alliance’s CISO Community to issue emergency guidance for strengthening controls around autonomous AI agents, CSO’s Gyana Swain reports. The incident also prompted <a href="https://www.csoonline.com/article/4203807/after-openai-anthropic-finds-claude-breached-three-organizations-during-cyber-tests.html">Anthropic to analyze its own cybersecurity evaluations</a>, finding that its Claude models had also escaped their test environments to encounter real-world systems, with one such incident resulting in Claude publishing a malicious Python package to the public PyPI repository, which was downloaded and executed by 15 real systems.</p>



<p class="wp-block-paragraph">With frontier labs not yet required to provide kill switches for AI agents, enterprise CISOs are <a href="https://www.csoonline.com/article/4205348">encouraged to investigate architecting their own</a>.</p>



<p class="wp-block-paragraph">The Hugging Face incident also shows how important it is for incident response teams to <a href="https://www.csoonline.com/article/4201361/hugging-face-breach-shows-why-incident-response-needs-a-multi-model-ai-strategy.html">have a multi-modal AI strategy</a>, including open-weighted models, to ensure viable operations under fire, writes CSO’s Lucian Constantin.</p>



<h3 class="wp-block-heading">Attacking the AI workflow</h3>



<p class="wp-block-paragraph">CISOs should also be aware that <a href="https://www.csoonline.com/article/4204731/attackers-are-crafting-malicious-ai-instruction-files-to-turn-your-agentic-workflows-into-quiet-criminal-helpers.html">attackers are turning attention to agent workflows</a>, seeking ways to infect AI agents with malicious rules, configuration, and instruction files to do their bidding. CSO’s Constantin reports on the trend, which includes a recently revealed backdoor attack technique dubbed “PromptLogger.”</p>



<p class="wp-block-paragraph">According to researchers from Mitiga, PromptLogger tricks AI agents into exfiltrating prompts and responses through maliciously crafted instruction files (e.g., <code>CLAUDE.md</code>). The technique has also been observed attempting to influence agents into injecting backdoor code into Python files that could be copied to other systems. Because agents would be performing these tasks on criminals’ behalf, detection is an uphill battle.</p>



<p class="wp-block-paragraph">Enterprise workflows could also potentially be corrupted via self-propagating document-borne AI worms, according to a recent report from Norwegian AI researcher Håkon Måløy <a href="https://www.csoonline.com/article/4203630/copilot-worm-can-spread-through-microsoft-word-docs.html">centered on Microsoft Copilot</a>. As CSO’s Evan Schuman reports, by concealing instructions in files used as source material for Copilot-assisted workflows, Måløy demonstrated how attackers could use Copilot as a transmission mechanism for corrupting data and propagating malware, something that could sidestep nearly every defense mechanism in place today.</p>



<h3 class="wp-block-heading">Development in the crosshairs</h3>



<p class="wp-block-paragraph">Software development remains the workflow most impacted by AI threats today, with recent reports underscoring established attack modalities, including a <a href="https://www.csoonline.com/article/4203408/critical-ruflo-flaw-lets-attackers-hijack-ai-agents-through-exposed-mcp-bridge.html">critical vulnerability in Ruflo MCP infrastructure</a> and the potential for slopsquatting on nonexistent PyPI and npm packages that <a href="https://www.csoonline.com/article/4201164/top-ais-invent-same-fake-pypl-and-npm-package-names-2.html">top AI coding tools collectively and consistently hallucinate</a>, report CSO’s Swain and Maxwell Cooter.</p>



<p class="wp-block-paragraph">Moreover, security flaws in automated workflows in Google’s ADK for Python GitHub repository, now since hardened, could induce agents to post commands and remove review requests, making a malicious pull request appear ready to merge. Pillar Security, which discovered the flaws, called it the “<a href="https://www.csoonline.com/article/4204906/google-adk-flaws-reveal-what-happens-when-ai-agents-trust-the-wrong-message.html">first practical, real-world case of agent-to-agent exploitation</a>” involving a production multi-agent system, CSO’s Thomas reports.</p>



<h3 class="wp-block-heading">The insider threat</h3>



<p class="wp-block-paragraph">A recently patched OpenAI flaw shows another means by which attackers could enlist rogue AI agents to operate on their behalf. Dubbed “AgentForger,” this phishing-based attack, reported by Zenity Labs, could have enabled attackers to silently create and launch fully autonomous AI agents within OpenAI workspaces. Broad, unfettered access to systems would then <a href="https://www.csoonline.com/article/4200978/agentforger-proves-ai-agents-can-become-persistent-insider-threats.html">turn the agent into a “persistent operator,”</a> capable of performing reconnaissance, harvesting data and credentials, and impersonating victims, CSO’s Taryn Plumb writes.</p>



<p class="wp-block-paragraph">Meanwhile, Pathfinder’s 2026 AI Governance Gap Report finds that <a href="https://www.csoonline.com/article/4203384/ai-agents-gain-access-to-financial-workflows-amid-growing-governance-gaps.html">53% of organizations cannot verify what AI agents do</a> across their business systems — not great news when 36% have deployed or are implementing AI agents within finance and accounting environments, CSO’s Shweta Sharma notes.</p>



<p class="wp-block-paragraph">And if you need any more fodder for tighter restrictions on that other insider threat, CSO’s Grant Gross sheds light on how <a href="https://www.csoonline.com/article/4198007/senior-executives-are-killing-your-shadow-ai-strategy.html">senior executives are killing your shadow AI strategy</a>.</p>



<h3 class="wp-block-heading">In-depth:</h3>



<ul class="wp-block-list">
<li><a href="https://www.csoonline.com/article/4204101/ai-is-making-cybersecurity-fundamentals-more-important-than-ever.html">AI is making cybersecurity fundamentals more important than ever</a></li>



<li><a href="https://www.csoonline.com/article/4200043/openai-model-escape-puts-enterprise-ai-defenses-on-notice.html">OpenAI model escape puts enterprise AI defenses on notice</a></li>



<li><a href="https://www.csoonline.com/article/4201361/hugging-face-breach-shows-why-incident-response-needs-a-multi-model-ai-strategy.html">Hugging Face breach shows why incident response needs a multi-model AI strategy</a></li>



<li><a href="https://www.csoonline.com/article/4204731/attackers-are-crafting-malicious-ai-instruction-files-to-turn-your-agentic-workflows-into-quiet-criminal-helpers.html">Attackers are crafting malicious AI instruction files to turn agents into criminal helpers</a></li>



<li><a href="https://www.csoonline.com/article/4200978/agentforger-proves-ai-agents-can-become-persistent-insider-threats.html">AgentForger proves AI agents can become persistent insider threats</a></li>



<li><a href="https://www.csoonline.com/article/4198007/senior-executives-are-killing-your-shadow-ai-strategy.html">Senior executives are killing your shadow AI strategy</a></li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI pays $3.2m to settle claims it discriminated against US workers]]></title>
<description><![CDATA[Company and subsidiary Statsig alleged by US justice department to have favored foreign workers in hiringOpenAI and a subsidiary will pay $3.2m to settle US government claims that they ⁠favored foreign workers with temporary employment visas and discriminated against US job applicants in recruiti...]]></description>
<link>https://tsecurity.de/de/3705128/it-nachrichten/openai-pays-32m-to-settle-claims-it-discriminated-against-us-workers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3705128/it-nachrichten/openai-pays-32m-to-settle-claims-it-discriminated-against-us-workers/</guid>
<pubDate>Wed, 05 Aug 2026 09:22:21 +0200</pubDate>
<content:encoded><![CDATA[<p>Company and subsidiary Statsig alleged by US justice department to have favored foreign workers in hiring</p><p>OpenAI and a subsidiary will pay $3.2m to settle US government claims that they ⁠favored foreign workers with temporary employment visas and discriminated against US job applicants in recruiting and hiring, the justice department said ⁠on Tuesday.</p><p>The justice ⁠department in ​a release said that OpenAI and Statsig, which makes product development software, recruited foreign workers for some open positions and ⁠took various steps to discourage US workers from applying.</p> <a href="https://www.theguardian.com/us-news/2026/aug/04/openai-worker-discrimination-claims-settlement">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Testing Update] 2026-08-05 - Plasma 6.7.4, NerdFonts 3.5.0, Firefox, GNOME]]></title>
<description><![CDATA[Hello Manjaro user community, here we have another set of package updates. We are continuing our development of the upcoming release of ‘Bian-May’ which can be expected Mid or End of August. Development speed may be a little slower the upcoming weeks. However, still let us know any issues you may...]]></description>
<link>https://tsecurity.de/de/3704956/unix-server/testing-update-2026-08-05-plasma-674-nerdfonts-350-firefox-gnome/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3704956/unix-server/testing-update-2026-08-05-plasma-674-nerdfonts-350-firefox-gnome/</guid>
<pubDate>Wed, 05 Aug 2026 08:00:00 +0200</pubDate>
<content:encoded><![CDATA[<div data-theme-toc="true"> </div>
<p>Hello Manjaro user community, here we have another set of package updates. We are continuing our development of the upcoming release of ‘Bian-May’ which can be expected Mid or End of August. Development speed may be a little slower the upcoming weeks. However, still let us know any issues you may found thus far.</p>
<h3><a name="p-869168-current-promotions-1" class="anchor" href="https://forum.manjaro.org/#p-869168-current-promotions-1" aria-label="Heading link"></a>Current Promotions</h3>
<ul>
<li>Get the latest Gaming Laptop by Slimbook powered by Manjaro: <a href="https://slimbook.com/manjaro">Slimbook Manjaro III</a></li>
<li>Protect your personal data, keep yourself safe with Surfshark VPN: <a href="https://get.surfshark.net/aff_c?offer_id=6&amp;aff_id=14558-">See current promotion</a></li>
</ul>
<h2><a name="p-869168-recent-news-2" class="anchor" href="https://forum.manjaro.org/#p-869168-recent-news-2" aria-label="Heading link"></a>Recent News</h2>

New in Manjaro GNOME!
Or, if you prefer the command line: <a href="https://forum.manjaro.org/t/testing-update-2026-08-05-plasma-6-7-4-nerdfonts-3-5-0-firefox-gnome/189361/1">(click for more details)</a>

KDE Plasma users with SDDM can now migrate to Plasma Login Manager <a href="https://forum.manjaro.org/t/testing-update-2026-08-05-plasma-6-7-4-nerdfonts-3-5-0-firefox-gnome/189361/1">(click for more details)</a>

NVIDIA 590 driver drops Pascal support <a href="https://forum.manjaro.org/t/testing-update-2026-08-05-plasma-6-7-4-nerdfonts-3-5-0-firefox-gnome/189361/1">(click for more details)</a>
<ul>
<li><a href="https://forum.manjaro.org/t/manjaro-26-1-bian-may-preview-released/187389" class="inline-onebox">Manjaro 26.1 Bian-May - Preview released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-26-0-anh-linh-released/184526" class="inline-onebox">Manjaro 26.0 Anh-Linh released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-summit-public-alpha-now-available/176995" class="inline-onebox">Manjaro Summit public Alpha now available</a></li>
<li>As of Linux 6.16.12, the 6.16 series is now EOL (End Of Life). Please install 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 6.17.13, the 6.17 series is now EOL (End Of Life). Please install 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 6.19.14, the 6.19 series is now EOL (End Of Life). Please install 7.0, and/or 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 7.0.14, the 7.0 series is now EOL (End Of Life). Please install 7.1, and/or 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
</ul>

Previous News <a href="https://forum.manjaro.org/t/testing-update-2026-08-05-plasma-6-7-4-nerdfonts-3-5-0-firefox-gnome/189361/1">(click for more details)</a>
<h2><a name="p-869168-notable-package-updates-3" class="anchor" href="https://forum.manjaro.org/#p-869168-notable-package-updates-3" aria-label="Heading link"></a>Notable Package Updates</h2>
<ul>
<li><strong>Firefox</strong> <a href="https://www.firefox.com/firefox/153.0.3/releasenotes/">153.0.3</a></li>
<li><strong>Plasma</strong> <a href="https://kde.org/announcements/plasma/6/6.7.4/">6.7.4</a></li>
<li><strong>Nerd Fonts</strong> <a href="https://www.nerdfonts.com/releases">3.5.0</a></li>
<li>Updates for <strong>GNOME</strong> 50.4</li>
</ul>
<h2><a name="p-869168-additional-info-4" class="anchor" href="https://forum.manjaro.org/#p-869168-additional-info-4" aria-label="Heading link"></a>Additional Info</h2>

Python 3.14 info <a href="https://forum.manjaro.org/t/testing-update-2026-08-05-plasma-6-7-4-nerdfonts-3-5-0-firefox-gnome/189361/1">(click for more details)</a>

Info about AUR packages <a href="https://forum.manjaro.org/t/testing-update-2026-08-05-plasma-6-7-4-nerdfonts-3-5-0-firefox-gnome/189361/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr>
<p><strong>Our current supported kernels</strong></p>
<ul>
<li>linux61 6.1.180</li>
<li>linux66 6.6.148</li>
<li>linux612 6.12.101</li>
<li>linux618 6.18.42</li>
<li>linux71 7.1.6</li>
<li>linux72 7.2.0-rc6</li>
<li>linux61-rt 6.1.167_rt62</li>
<li>linux66-rt 6.6.135_rt74</li>
<li>linux612-rt 6.12.89_rt18</li>
</ul>
<p><strong>Package Changes</strong> (8/5/26 07:15 CEST)</p>
<ul>
<li>testing core x86_64:  1 new and 1 removed package(s)</li>
<li>testing extra x86_64:  541 new and 540 removed package(s)</li>
<li>testing multilib x86_64:  2 new and 2 removed package(s)</li>
</ul>
<pre><code class="lang-auto">:: Different sync package(s) in repository core x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2026-08-04           2026-08-05
-------------------------------------------------------------------------------
                             pkgconf              3.0.4-1              3.0.5-1


:: Different overlay package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2026-08-04           2026-08-05
-------------------------------------------------------------------------------
                            chromium      151.0.7922.71-1                    -
                                dkms              3.4.1-1              3.4.2-1
                                 gdm               50.1-1               50.2-1
                         gnome-shell             1:50.3-1             1:50.4-1
                    gnome-shell-docs             1:50.3-1             1:50.4-1
                           legendary            0.20.41-2             0.21.0-1
                          libadwaita            1:1.9.2-1            1:1.9.3-1
                    libadwaita-demos            1:1.9.2-1            1:1.9.3-1
                     libadwaita-docs            1:1.9.2-1            1:1.9.3-1
                              libgdm               50.1-1               50.2-1
               tuxedo-control-center              3.0.7-1              3.0.8-1


:: Different sync package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2026-08-04           2026-08-05
-------------------------------------------------------------------------------
                                apko             1.2.25-1             1.2.31-1
                                 apt              3.3.1-1              3.3.2-1
                            apt-docs              3.3.1-1              3.3.2-1
                                arti              2.5.0-1              2.5.1-1
                               atuin            18.18.1-1            18.19.0-1
                        atuin-server            18.18.1-1            18.19.0-1
                      audiobookshelf             2.36.0-1             2.36.0-2
                             aurorae              6.7.3-1              6.7.4-1
                       bcachefs-dkms           3:1.38.8-2           3:1.39.0-1
                      bcachefs-tools           3:1.38.8-2           3:1.39.0-1
                               biome              2.5.6-1              2.5.7-1
                              blosc2              3.2.3-1              3.3.1-1
                           bluedevil            1:6.7.3-1            1:6.7.4-1
                          bootconfig              7.1.5-1              7.1.6-1
                                 bpf              7.1.5-1              7.1.6-1
                              breeze              6.7.3-1              6.7.4-1
                      breeze-cursors              6.7.3-1              6.7.4-1
                         breeze-grub              6.7.3-1              6.7.4-1
                          breeze-gtk              6.7.3-1              6.7.4-1
                     breeze-plymouth              6.7.3-1              6.7.4-1
                             breeze5              6.7.3-1              6.7.4-1
                            buildkit             0.32.0-1             0.32.2-1
                       cargo-nextest            0.9.140-1            0.9.143-1
                            chromium     150.0.7871.186-1      151.0.7922.75-1
                             cockpit                365-1                365-2
                  cockpit-packagekit                365-1                365-2
                    cockpit-storaged                365-1                365-2
                     consul-template             0.42.0-1             0.42.1-1
                           copyparty            1.20.19-1            1.20.20-1
                            cpupower              7.1.5-1              7.1.6-1
                               crane             0.21.7-1             0.21.8-1
                 deepin-file-manager           1:6.5.24-1           1:6.5.25-1
                 deepin-image-viewer              6.0.0-1              6.0.1-1
                       deepin-pdfium              1.5.1-1              1.5.2-1
                      deepin-printer              1.0.6-1              1.0.7-1
                     deepin-services             1.0.36-1             1.0.37-1
                             discord          1:1.0.151-1          1:1.0.152-1
                            discover              6.7.3-1              6.7.4-1
                                dnf5           5.2.17.0-6            5.4.2.1-1
                       docker-buildx             0.35.0-1             0.36.0-1
                      docker-compose              5.3.1-1              5.4.0-1
                             drkonqi              6.7.3-1              6.7.4-1
                             dua-cli             2.41.0-1             2.41.1-1
                                dune             3.24.1-1             3.24.2-1
                             dvisvgm                3.6-2              3.6.1-1
                             firefox            153.0.1-1            153.0.3-1
           firefox-developer-edition            154.0b5-1            154.0b6-1
  firefox-developer-edition-i18n-ach            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-af            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-an            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-ar            154.0b5-1            154.0b6-1
  firefox-developer-edition-i18n-ast            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-az            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-be            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-bg            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-bn            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-br            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-bs            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-ca            154.0b5-1            154.0b6-1
firefox-developer-edition-i18n-ca-valencia      154.0b5-1            154.0b6-1
  firefox-developer-edition-i18n-cak            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-cs            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-cy            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-da            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-de            154.0b5-1            154.0b6-1
  firefox-developer-edition-i18n-dsb            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-el            154.0b5-1            154.0b6-1
firefox-developer-edition-i18n-en-ca            154.0b5-1            154.0b6-1
firefox-developer-edition-i18n-en-gb            154.0b5-1            154.0b6-1
firefox-developer-edition-i18n-en-us            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-eo            154.0b5-1            154.0b6-1
firefox-developer-edition-i18n-es-ar            154.0b5-1            154.0b6-1
firefox-developer-edition-i18n-es-cl            154.0b5-1            154.0b6-1
firefox-developer-edition-i18n-es-es            154.0b5-1            154.0b6-1
firefox-developer-edition-i18n-es-mx            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-et            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-eu            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-fa            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-ff            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-fi            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-fr            154.0b5-1            154.0b6-1
  firefox-developer-edition-i18n-fur            154.0b5-1            154.0b6-1
firefox-developer-edition-i18n-fy-nl            154.0b5-1            154.0b6-1
firefox-developer-edition-i18n-ga-ie            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-gd            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-gl            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-gn            154.0b5-1            154.0b6-1
firefox-developer-edition-i18n-gu-in            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-he            154.0b5-1            154.0b6-1
firefox-developer-edition-i18n-hi-in            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-hr            154.0b5-1            154.0b6-1
  firefox-developer-edition-i18n-hsb            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-hu            154.0b5-1            154.0b6-1
firefox-developer-edition-i18n-hy-am            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-ia            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-id            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-is            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-it            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-ja            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-ka            154.0b5-1            154.0b6-1
  firefox-developer-edition-i18n-kab            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-kk            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-km            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-kn            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-ko            154.0b5-1            154.0b6-1
  firefox-developer-edition-i18n-lij            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-lt            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-lv            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-mk            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-mr            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-ms            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-my            154.0b5-1            154.0b6-1
firefox-developer-edition-i18n-nb-no            154.0b5-1            154.0b6-1
firefox-developer-edition-i18n-ne-np            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-nl            154.0b5-1            154.0b6-1
firefox-developer-edition-i18n-nn-no            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-oc            154.0b5-1            154.0b6-1
firefox-developer-edition-i18n-pa-in            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-pl            154.0b5-1            154.0b6-1
firefox-developer-edition-i18n-pt-br            154.0b5-1            154.0b6-1
firefox-developer-edition-i18n-pt-pt            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-rm            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-ro            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-ru            154.0b5-1            154.0b6-1
  firefox-developer-edition-i18n-sat            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-sc            154.0b5-1            154.0b6-1
  firefox-developer-edition-i18n-sco            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-si            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-sk            154.0b5-1            154.0b6-1
  firefox-developer-edition-i18n-skr            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-sl            154.0b5-1            154.0b6-1
  firefox-developer-edition-i18n-son            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-sq            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-sr            154.0b5-1            154.0b6-1
firefox-developer-edition-i18n-sv-se            154.0b5-1            154.0b6-1
  firefox-developer-edition-i18n-szl            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-ta            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-te            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-tg            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-th            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-tl            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-tr            154.0b5-1            154.0b6-1
  firefox-developer-edition-i18n-trs            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-uk            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-ur            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-uz            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-vi            154.0b5-1            154.0b6-1
   firefox-developer-edition-i18n-xh            154.0b5-1            154.0b6-1
firefox-developer-edition-i18n-zh-cn            154.0b5-1            154.0b6-1
firefox-developer-edition-i18n-zh-tw            154.0b5-1            154.0b6-1
                    firefox-i18n-ach            153.0.1-1            153.0.3-1
                     firefox-i18n-af            153.0.1-1            153.0.3-1
                     firefox-i18n-an            153.0.1-1            153.0.3-1
                     firefox-i18n-ar            153.0.1-1            153.0.3-1
                    firefox-i18n-ast            153.0.1-1            153.0.3-1
                     firefox-i18n-az            153.0.1-1            153.0.3-1
                     firefox-i18n-be            153.0.1-1            153.0.3-1
                     firefox-i18n-bg            153.0.1-1            153.0.3-1
                     firefox-i18n-bn            153.0.1-1            153.0.3-1
                     firefox-i18n-br            153.0.1-1            153.0.3-1
                     firefox-i18n-bs            153.0.1-1            153.0.3-1
                     firefox-i18n-ca            153.0.1-1            153.0.3-1
            firefox-i18n-ca-valencia            153.0.1-1            153.0.3-1
                    firefox-i18n-cak            153.0.1-1            153.0.3-1
                     firefox-i18n-cs            153.0.1-1            153.0.3-1
                     firefox-i18n-cy            153.0.1-1            153.0.3-1
                     firefox-i18n-da            153.0.1-1            153.0.3-1
                     firefox-i18n-de            153.0.1-1            153.0.3-1
                    firefox-i18n-dsb            153.0.1-1            153.0.3-1
                     firefox-i18n-el            153.0.1-1            153.0.3-1
                  firefox-i18n-en-ca            153.0.1-1            153.0.3-1
                  firefox-i18n-en-gb            153.0.1-1            153.0.3-1
                  firefox-i18n-en-us            153.0.1-1            153.0.3-1
                     firefox-i18n-eo            153.0.1-1            153.0.3-1
                  firefox-i18n-es-ar            153.0.1-1            153.0.3-1
                  firefox-i18n-es-cl            153.0.1-1            153.0.3-1
                  firefox-i18n-es-es            153.0.1-1            153.0.3-1
                  firefox-i18n-es-mx            153.0.1-1            153.0.3-1
                     firefox-i18n-et            153.0.1-1            153.0.3-1
                     firefox-i18n-eu            153.0.1-1            153.0.3-1
                     firefox-i18n-fa            153.0.1-1            153.0.3-1
                     firefox-i18n-ff            153.0.1-1            153.0.3-1
                     firefox-i18n-fi            153.0.1-1            153.0.3-1
                     firefox-i18n-fr            153.0.1-1            153.0.3-1
                    firefox-i18n-fur            153.0.1-1            153.0.3-1
                  firefox-i18n-fy-nl            153.0.1-1            153.0.3-1
                  firefox-i18n-ga-ie            153.0.1-1            153.0.3-1
                     firefox-i18n-gd            153.0.1-1            153.0.3-1
                     firefox-i18n-gl            153.0.1-1            153.0.3-1
                     firefox-i18n-gn            153.0.1-1            153.0.3-1
                  firefox-i18n-gu-in            153.0.1-1            153.0.3-1
                     firefox-i18n-he            153.0.1-1            153.0.3-1
                  firefox-i18n-hi-in            153.0.1-1            153.0.3-1
                     firefox-i18n-hr            153.0.1-1            153.0.3-1
                    firefox-i18n-hsb            153.0.1-1            153.0.3-1
                     firefox-i18n-hu            153.0.1-1            153.0.3-1
                  firefox-i18n-hy-am            153.0.1-1            153.0.3-1
                     firefox-i18n-ia            153.0.1-1            153.0.3-1
                     firefox-i18n-id            153.0.1-1            153.0.3-1
                     firefox-i18n-is            153.0.1-1            153.0.3-1
                     firefox-i18n-it            153.0.1-1            153.0.3-1
                     firefox-i18n-ja            153.0.1-1            153.0.3-1
                     firefox-i18n-ka            153.0.1-1            153.0.3-1
                    firefox-i18n-kab            153.0.1-1            153.0.3-1
                     firefox-i18n-kk            153.0.1-1            153.0.3-1
                     firefox-i18n-km            153.0.1-1            153.0.3-1
                     firefox-i18n-kn            153.0.1-1            153.0.3-1
                     firefox-i18n-ko            153.0.1-1            153.0.3-1
                    firefox-i18n-lij            153.0.1-1            153.0.3-1
                     firefox-i18n-lt            153.0.1-1            153.0.3-1
                     firefox-i18n-lv            153.0.1-1            153.0.3-1
                     firefox-i18n-mk            153.0.1-1            153.0.3-1
                     firefox-i18n-mr            153.0.1-1            153.0.3-1
                     firefox-i18n-ms            153.0.1-1            153.0.3-1
                     firefox-i18n-my            153.0.1-1            153.0.3-1
                  firefox-i18n-nb-no            153.0.1-1            153.0.3-1
                  firefox-i18n-ne-np            153.0.1-1            153.0.3-1
                     firefox-i18n-nl            153.0.1-1            153.0.3-1
                  firefox-i18n-nn-no            153.0.1-1            153.0.3-1
                     firefox-i18n-oc            153.0.1-1            153.0.3-1
                  firefox-i18n-pa-in            153.0.1-1            153.0.3-1
                     firefox-i18n-pl            153.0.1-1            153.0.3-1
                  firefox-i18n-pt-br            153.0.1-1            153.0.3-1
                  firefox-i18n-pt-pt            153.0.1-1            153.0.3-1
                     firefox-i18n-rm            153.0.1-1            153.0.3-1
                     firefox-i18n-ro            153.0.1-1            153.0.3-1
                     firefox-i18n-ru            153.0.1-1            153.0.3-1
                    firefox-i18n-sat            153.0.1-1            153.0.3-1
                     firefox-i18n-sc            153.0.1-1            153.0.3-1
                    firefox-i18n-sco            153.0.1-1            153.0.3-1
                     firefox-i18n-si            153.0.1-1            153.0.3-1
                     firefox-i18n-sk            153.0.1-1            153.0.3-1
                    firefox-i18n-skr            153.0.1-1            153.0.3-1
                     firefox-i18n-sl            153.0.1-1            153.0.3-1
                    firefox-i18n-son            153.0.1-1            153.0.3-1
                     firefox-i18n-sq            153.0.1-1            153.0.3-1
                     firefox-i18n-sr            153.0.1-1            153.0.3-1
                  firefox-i18n-sv-se            153.0.1-1            153.0.3-1
                    firefox-i18n-szl            153.0.1-1            153.0.3-1
                     firefox-i18n-ta            153.0.1-1            153.0.3-1
                     firefox-i18n-te            153.0.1-1            153.0.3-1
                     firefox-i18n-tg            153.0.1-1            153.0.3-1
                     firefox-i18n-th            153.0.1-1            153.0.3-1
                     firefox-i18n-tl            153.0.1-1            153.0.3-1
                     firefox-i18n-tr            153.0.1-1            153.0.3-1
                    firefox-i18n-trs            153.0.1-1            153.0.3-1
                     firefox-i18n-uk            153.0.1-1            153.0.3-1
                     firefox-i18n-ur            153.0.1-1            153.0.3-1
                     firefox-i18n-uz            153.0.1-1            153.0.3-1
                     firefox-i18n-vi            153.0.1-1            153.0.3-1
                     firefox-i18n-xh            153.0.1-1            153.0.3-1
                  firefox-i18n-zh-cn            153.0.1-1            153.0.3-1
                  firefox-i18n-zh-tw            153.0.1-1            153.0.3-1
                         flatpak-kcm              6.7.3-1              6.7.4-1
                           flowblade             2.24.1-1             2.24.2-1
                      forgejo-runner            12.13.2-1             13.0.0-1
                              gexiv2             0.16.1-1             0.16.2-2
                         gexiv2-docs             0.16.1-1             0.16.2-2
                               gitea             1.27.1-1             1.27.1-2
                                glab            1.111.0-1            1.112.0-1
                               glaze              7.9.1-1              8.0.0-1
                 gnome-initial-setup               50.0-2               50.1-1
gnome-shell-extension-desktop-icons-ng           51.0.4-1             51.0.5-1
                             grafana             13.1.1-1             13.1.2-1
                       haskell-brick                2.6-6               2.12-2
                    haskell-fsnotify          0.4.4.0-101          0.4.4.0-102
                      haskell-hakyll           4.16.6.0-7           4.16.6.0-8
                    haskell-sandwich            0.3.1.0-1            0.3.1.0-3
                haskell-summoner-tui           2.1.0.0-68           2.1.0.0-69
                            hazelnut             0.2.49-1              0.3.0-1
                           headscale             0.29.1-1             0.29.3-1
                        hledger-iadd            1.3.22-82            1.3.22-83
                          hledger-ui            1.52.1-52            1.52.1-53
                              hyperv              7.1.5-1              7.1.6-1
                        hyprshutdown              0.1.1-5              0.1.1-6
                               idris            1.3.4-551            1.3.4-552
                  intel-speed-select              7.1.5-1              7.1.6-1
               jupyter-collaboration              4.4.1-1              4.4.2-1
                                just             1.57.0-1             1.58.0-1
                            just-lsp              0.6.0-1              0.6.1-1
                   kactivitymanagerd              6.7.3-1              6.7.4-1
                              kcpuid              7.1.5-1              7.1.6-1
                       kde-cli-tools              6.7.3-1              6.7.4-1
                      kde-gtk-config              6.7.3-1              6.7.4-1
                         kdecoration              6.7.3-1              6.7.4-1
                    kdeplasma-addons              6.7.3-1              6.7.4-1
                              kgamma              6.7.3-1              6.7.4-1
                       kglobalacceld              6.7.3-1              6.7.4-1
                         kinfocenter              6.7.3-1              6.7.4-1
                       kiwix-desktop              2.5.1-1              2.5.1-2
                         kiwix-tools              3.8.2-2              3.8.2-3
                           kmenuedit              6.7.3-1              6.7.4-1
                          knighttime              6.7.3-1              6.7.4-1
                           kpipewire              6.7.3-1              6.7.4-3
                                krdp              6.7.3-1              6.7.4-1
                             kscreen              6.7.3-1              6.7.4-1
                       kscreenlocker              6.7.3-1              6.7.4-1
                         ksshaskpass              6.7.3-1              6.7.4-1
                        ksystemstats              6.7.3-1              6.7.4-1
                                kubo             0.42.0-1             0.43.0-1
                         kwallet-pam              6.7.3-1              6.7.4-1
                            kwayland              6.7.3-1              6.7.4-1
                kwayland-integration              6.7.3-1              6.7.4-1
                                kwin              6.7.3-1              6.7.4-1
                            kwin-x11              6.7.3-1              6.7.4-1
                             kwrited              6.7.3-1              6.7.4-1
                      layer-shell-qt              6.7.3-1              6.7.4-1
                             lazygit             0.63.1-1             0.64.0-1
                             ldproxy              0.3.4-1              0.3.5-1
                            libfyaml              0.9.6-2              0.9.6-3
                           libgexiv2             0.14.6-2             0.14.7-1
                            libkiwix             14.2.1-1             14.2.1-2
                          libkscreen              6.7.3-1              6.7.4-1
                        libksysguard              6.7.3-1              6.7.4-1
                           libplasma              6.7.3-1              6.7.4-1
                           libtg_owt    0.git34.89df288-2    0.git35.19d51d3-2
                             libvips             8.18.4-2             8.18.5-1
                              libzim              9.7.0-1              9.8.1-1
                    linux-tools-meta              7.1.5-1              7.1.6-1
                              llmfit              1.1.7-1              1.1.8-1
                         loadtracker             1.99.2-1             1.99.4-1
                                 lua              5.5.0-2              5.5.1-1
                             lua-lux             0.39.9-1             0.40.1-1
                           lua51-lux             0.39.9-1             0.40.1-1
                           lua52-lux             0.39.9-1             0.40.1-1
                           lua53-lux             0.39.9-1             0.40.1-1
                           lua54-lux             0.39.9-1             0.40.1-1
                              luajit2.1.1785746657+f30aabe-12.1.1785763465+1edc3e5-1
                             lux-cli             0.39.9-1             0.40.1-1
                              marker         2023.05.02-1         2023.05.02-2
                             marmite              0.4.2-1              0.4.2-2
       matrix-authentication-service             1.21.0-1             1.22.0-1
                          mattermost             11.9.0-2            11.10.0-1
                         meilisearch           1:1.51.0-1           1:1.52.0-1
                             melange             0.52.0-1             0.56.5-1
                    metadata-cleaner              4.0.0-1              4.0.1-1
                          metasploit            6.4.144-1              6.5.0-1
                               milou              6.7.3-1              6.7.4-1
                               mmctl             11.9.0-2            11.10.0-1
                            mustache                4.1-3                4.1-4
                              mutter               50.3-1               50.4-1
                       mutter-devkit               50.3-1               50.4-1
                         mutter-docs               50.3-1               50.4-1
                    nextcloud-client           2:33.0.7-1           2:34.0.0-1
                            obsidian             1.13.4-1             1.13.4-2
                   ocean-sound-theme              6.7.3-1              6.7.4-1
                             openbve           1.14.0.1-1           1.14.0.2-1
                           opencloud              7.3.0-1              7.4.0-1
                            opencode            1.18.11-1            1.18.13-1
   otf-atkinsonhyperlegiblemono-nerd              3.4.0-2              3.5.0-1
                   otf-aurulent-nerd              3.4.0-2              3.5.0-1
               otf-codenewroman-nerd              3.4.0-2              3.5.0-1
                otf-comicshanns-nerd              3.4.0-2              3.5.0-1
                otf-commit-mono-nerd              3.4.0-2              3.5.0-1
                      otf-droid-nerd              3.4.0-2              3.5.0-1
                   otf-firamono-nerd              3.4.0-2              3.5.0-1
                 otf-geist-mono-nerd              3.4.0-2              3.5.0-1
                    otf-hasklig-nerd              3.4.0-2              3.5.0-1
                     otf-hermit-nerd              3.4.0-2              3.5.0-1
                  otf-monaspace-nerd              3.4.0-2              3.5.0-1
               otf-opendyslexic-nerd              3.4.0-2              3.5.0-1
                   otf-overpass-nerd              3.4.0-2              3.5.0-1
                              oxygen              6.7.3-1              6.7.4-1
                      oxygen-cursors              6.7.3-1              6.7.4-1
                       oxygen-sounds              6.7.3-1              6.7.4-1
                             oxygen5              6.7.3-1              6.7.4-1
                               pango           1:1.58.0-1           1:1.58.1-1
                          pango-docs           1:1.58.0-1           1:1.58.1-1
                              patatt              0.7.1-1              0.8.0-1
                                perf              7.1.5-1              7.1.6-1
             perl-business-isbn-data       20260724.001-1       20260804.001-1
                          photoflare              1.7.3-1              1.7.4-1
                         pika-backup              0.8.3-1              0.8.4-1
                   plasma-activities              6.7.3-1              6.7.4-1
             plasma-activities-stats              6.7.3-1              6.7.4-1
                    plasma-bigscreen              6.7.3-1              6.7.4-1
          plasma-browser-integration              6.7.3-1              6.7.4-1
                      plasma-desktop              6.7.3-1              6.7.4-1
                        plasma-disks              6.7.3-1              6.7.4-1
                     plasma-firewall              6.7.3-1              6.7.4-1
                  plasma-integration              6.7.3-1              6.7.4-1
                     plasma-keyboard              6.7.3-1              6.7.4-1
                plasma-login-manager              6.7.3-1              6.7.4-1
                       plasma-mobile              6.7.3-1              6.7.4-1
                         plasma-nano              6.7.3-1              6.7.4-1
                           plasma-nm              6.7.3-1              6.7.4-1
                           plasma-pa              6.7.3-1              6.7.4-1
                          plasma-sdk              6.7.3-1              6.7.4-1
                plasma-systemmonitor              6.7.3-1              6.7.4-1
                  plasma-thunderbolt              6.7.3-1              6.7.4-1
                        plasma-vault              6.7.3-1              6.7.4-1
                      plasma-welcome              6.7.3-1              6.7.4-1
                    plasma-workspace              6.7.3-1              6.7.4-1
         plasma-workspace-wallpapers              6.7.3-1              6.7.4-1
                  plasma-x11-session              6.7.3-1              6.7.4-1
                 plasma5-integration              6.7.3-1              6.7.4-1
                      plasma5support              6.7.3-1              6.7.4-1
                        plymouth-kcm              6.7.3-1              6.7.4-1
                    polkit-kde-agent              6.7.3-1              6.7.4-1
                          powerdevil              6.7.3-1              6.7.4-1
                       print-manager            1:6.7.3-1            1:6.7.4-1
   prometheus-elasticsearch-exporter             1.10.0-1             1.11.0-1
                           protozero              1.8.1-1              1.8.2-1
                      protozero-docs              1.8.1-1              1.8.2-1
                      python-alembic             1.18.5-1             1.19.0-1
                  python-argcomplete              3.7.0-1              3.7.1-1
                       python-blosc2              4.9.1-1             4.10.0-1
                         python-cffi              2.1.0-1              2.1.1-1
                   python-dateparser              1.4.1-1              1.4.2-1
              python-dateparser-docs              1.4.1-1              1.4.2-1
               python-faust-cchardet              3.0.0-1              3.1.0-1
                       python-fsspec           2026.6.0-1           2026.7.0-1
                           python-h2              4.4.0-1              4.4.1-1
                        python-jiter             0.15.0-1             0.16.0-1
                       python-openai             2.45.0-1             2.53.0-1
             python-os-service-types              1.8.2-1              1.9.0-1
                          python-pip             26.1.2-1             26.2.1-1
                         python-s3fs           2026.4.0-1           2026.7.0-1
                        python-shtab              1.9.2-1              1.9.3-1
     python-sphinx-autodoc-typehints             3.13.0-1             3.13.2-1
                 python-sqlite-anyio              0.3.0-1              0.3.1-1
                        python-stone              3.5.3-1              3.5.4-1
                     python-test2ref              0.8.2-3              1.2.3-1
                     python-tiktoken             0.12.0-3             0.13.0-1
                 python-time-machine              3.3.0-1              3.3.1-1
                    python-traitlets             5.16.0-1             5.16.1-1
                        python-typer             0.27.0-1             0.27.1-1
                     python-zeroconf            0.149.1-1           0.149.16-1
                   qqc2-breeze-style              6.7.3-1              6.7.4-1
                                 rio              0.5.6-1             0.5.10-1
                               rocal              7.2.4-3              7.2.4-4
                         rootlesskit              3.0.2-1              3.1.0-1
                  ruby-protocol-http             0.67.0-1             0.68.0-1
                               rumdl             0.2.48-1             0.2.50-1
                            sddm-kcm              6.7.3-1              6.7.4-1
                                sdl3             3.4.12-1             3.4.14-1
                            sh4d0wup             0.11.0-2             0.11.1-1
                              smolvm              1.7.2-1              1.7.4-1
                          soft-serve             0.12.0-1             0.12.1-1
                           spectacle            1:6.7.3-1            1:6.7.4-1
                               stack          2.9.3.1-214          2.9.3.1-215
                            stalwart            0.16.15-2            0.16.16-1
                             stunnel               5.79-1               5.80-1
                                syft             1.46.0-1             1.50.0-1
                         systemd-lsp         2026.04.21-1         2026.08.03-1
                      systemsettings              6.7.3-1              6.7.4-1
                             systing              1.6.0-1            1.11.38-1
                            taffybar            4.1.0-101            4.1.0-102
                              talloc              2.4.4-1              2.5.0-1
                            talosctl             1.13.7-1             1.13.8-1
                    telegram-desktop              7.0.7-1              7.0.8-2
                              tevent           1:0.17.1-2           1:0.17.2-1
                         timescaledb             2.29.0-1             2.29.1-1
             timescaledb-old-upgrade             2.29.0-1             2.29.1-1
                                tmon              7.1.5-1              7.1.6-1
                               tombi              1.2.5-1              1.2.6-1
                             toolbox                0.3-1                0.3-2
                             traefik              3.7.4-1             3.7.10-2
                    ttf-0xproto-nerd              3.4.0-2              3.5.0-1
                       ttf-3270-nerd              3.4.0-2              3.5.0-1
                ttf-adwaitamono-nerd              3.4.0-2              3.5.0-1
                      ttf-agave-nerd              3.4.0-2              3.5.0-1
               ttf-anonymouspro-nerd              3.4.0-2              3.5.0-1
                      ttf-arimo-nerd              3.4.0-2              3.5.0-1
            ttf-bigblueterminal-nerd              3.4.0-2              3.5.0-1
        ttf-bitstream-vera-mono-nerd              3.4.0-2              3.5.0-1
              ttf-cascadia-code-nerd              3.4.0-2              3.5.0-1
              ttf-cascadia-mono-nerd              3.4.0-2              3.5.0-1
                    ttf-cousine-nerd              3.4.0-2              3.5.0-1
                   ttf-d2coding-nerd              3.4.0-2              3.5.0-1
             ttf-daddytime-mono-nerd              3.4.0-2              3.5.0-1
                     ttf-dejavu-nerd              3.4.0-2              3.5.0-1
                  ttf-envycoder-nerd              3.4.0-2              3.5.0-1
                  ttf-fantasque-nerd              3.4.0-2              3.5.0-1
                   ttf-firacode-nerd              3.4.0-2              3.5.0-1
                         ttf-go-nerd              3.4.0-2              3.5.0-1
                       ttf-gohu-nerd              3.4.0-2              3.5.0-1
                       ttf-hack-nerd              3.4.0-2              3.5.0-1
                  ttf-heavydata-nerd              3.4.0-2              3.5.0-1
                   ttf-iawriter-nerd              3.4.0-2              3.5.0-1
               ttf-ibmplex-mono-nerd              3.4.0-2              3.5.0-1
             ttf-inconsolata-go-nerd              3.4.0-2              3.5.0-1
            ttf-inconsolata-lgc-nerd              3.4.0-2              3.5.0-1
                ttf-inconsolata-nerd              3.4.0-2              3.5.0-1
                     ttf-intone-nerd              3.4.0-2              3.5.0-1
                    ttf-iosevka-nerd              3.4.0-2              3.5.0-1
                ttf-iosevkaterm-nerd              3.4.0-2              3.5.0-1
            ttf-iosevkatermslab-nerd              3.4.0-2              3.5.0-1
             ttf-jetbrains-mono-nerd              3.4.0-2              3.5.0-1
                     ttf-lekton-nerd              3.4.0-2              3.5.0-1
            ttf-liberation-mono-nerd              3.4.0-2              3.5.0-1
                      ttf-lilex-nerd              3.4.0-2              3.5.0-1
               ttf-martian-mono-nerd              3.4.0-2              3.5.0-1
                      ttf-meslo-nerd              3.4.0-2              3.5.0-1
                    ttf-monofur-nerd              3.4.0-2              3.5.0-1
                     ttf-monoid-nerd              3.4.0-2              3.5.0-1
                   ttf-mononoki-nerd              3.4.0-2              3.5.0-1
                      ttf-mplus-nerd              3.4.0-2              3.5.0-1
                       ttf-noto-nerd              3.4.0-2              3.5.0-1
                    ttf-profont-nerd              3.4.0-2              3.5.0-1
                ttf-proggyclean-nerd              3.4.0-2              3.5.0-1
                  ttf-recursive-nerd              3.4.0-2              3.5.0-1
                ttf-roboto-mono-nerd              3.4.0-2              3.5.0-1
             ttf-sharetech-mono-nerd              3.4.0-2              3.5.0-1
              ttf-sourcecodepro-nerd              3.4.0-2              3.5.0-1
                 ttf-space-mono-nerd              3.4.0-2              3.5.0-1
                   ttf-terminus-nerd              3.4.0-2              3.5.0-1
                      ttf-tinos-nerd              3.4.0-2              3.5.0-1
                ttf-ubuntu-mono-nerd              3.4.0-2              3.5.0-1
                     ttf-ubuntu-nerd              3.4.0-2              3.5.0-1
                ttf-victor-mono-nerd              3.4.0-2              3.5.0-1
                   ttf-zed-mono-nerd              3.4.0-2              3.5.0-1
                               tuicr             0.19.1-1             0.20.0-1
                           turbostat              7.1.5-1              7.1.6-1
                               twine              6.2.0-3              7.0.0-1
                                  ty             0.0.65-1             0.0.66-1
                               typos             1.48.0-1             1.49.0-1
                               union              6.7.3-1              6.7.4-1
                               usbip              7.1.5-1              7.1.6-1
                               vault             1.21.4-2              2.0.3-1
                         wacomtablet              6.7.3-1              6.7.4-1
                                 wcm             0.10.0-4             0.10.0-5
                             weechat              4.9.5-1             4.10.0-1
                            wf-shell             0.10.0-4             0.11.0-1
                                wild              0.9.0-1             0.10.0-1
              x86_energy_perf_policy              7.1.5-1              7.1.6-1
              xdg-desktop-portal-kde              6.7.3-1              6.7.4-2
                           xournalpp              1.3.5-1              1.3.6-1
                           zim-tools              3.6.0-4              3.7.0-1
                       gexiv2-common                    -             0.16.2-2
                                 tdf                    -              0.5.0-3


:: Different sync package(s) in repository multilib x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2026-08-04           2026-08-05
-------------------------------------------------------------------------------
                         lib32-pango           1:1.58.0-1           1:1.58.1-1
                          lib32-sdl3             3.4.12-1             3.4.14-1

</code></pre>

<ul>
<li>No issue, everything went smoothly</li>
<li>Yes there was an issue. I was able to resolve it myself.(Please post your solution)</li>
<li>Yes I am currently experiencing an issue due to the update. (Please post about it)</li>
</ul>
<p><a href="https://forum.manjaro.org/t/testing-update-2026-08-05-plasma-6-7-4-nerdfonts-3-5-0-firefox-gnome/189361/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
<hr>
            <p><small>2 posts - 2 participants</small></p>
            <p><a href="https://forum.manjaro.org/t/testing-update-2026-08-05-plasma-6-7-4-nerdfonts-3-5-0-firefox-gnome/189361">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ADE sticht IDE]]></title>
<description><![CDATA[Agentic Development erfordert neue, moderne Entwickler-Tools.Gorodenkoff | shutterstock.com



40 Jahre lang drehte sich in Sachen Tools für die Softwareentwicklung alles um die integrierte Entwicklungsumgebung – kurz IDE. Sie wurde vor allem durch die Borland Software Corporation massentauglich ...]]></description>
<link>https://tsecurity.de/de/3704753/it-security-nachrichten/ade-sticht-ide/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3704753/it-security-nachrichten/ade-sticht-ide/</guid>
<pubDate>Wed, 05 Aug 2026 06:10:28 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Gorodenkoff_shutterstock_2436547453_16z9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Dev Talk Colorful 16z9" class="wp-image-4199999" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Agentic Development erfordert neue, moderne Entwickler-Tools.</figcaption></figure><p class="imageCredit">Gorodenkoff | shutterstock.com</p></div>



<p class="wp-block-paragraph">40 Jahre lang drehte sich in Sachen Tools für die Softwareentwicklung alles um die integrierte Entwicklungsumgebung – kurz <a href="https://www.computerwoche.de/article/3488115/visual-studio-code-alternative-im-test.html" target="_blank">IDE</a>. Sie wurde vor allem durch die <a href="https://de.wikipedia.org/wiki/Borland" target="_blank" rel="noreferrer noopener">Borland Software Corporation</a> massentauglich gemacht und revolutionierte die Entwicklungsarbeit, indem sie Editor, <a href="https://www.computerwoche.de/article/4152349/so-wird-ki-zum-compiler.html" target="_blank">Compiler</a> und Debugger zu einer Einheit verschmolz. Tools wie <a href="https://www.reddit.com/r/ProgrammerHumor/comments/wnr3p0/programming_peeked_with_turbo_pascal_70_and_i/?tl=de" target="_blank" rel="noreferrer noopener">Turbo Pascal</a> (das ich bis heute verehre) stellten für Devs in den 1980er Jahren insofern eine echte Revolution dar. </p>



<p class="wp-block-paragraph">Knapp ein halbes Jahrhundert später ist der kometenhafte Aufstieg von Agentic Development dabei, der Vorherrschaft der IDE ein jähes Ende zu setzen. Es wird immer deutlicher, dass die integrierte Entwicklungsumgebung zunehmend aufs Abstellgleis gerät: Entwickler nutzen sie immer seltener – und widmen sich stattdessen anderen Tasks. Zum Beispiel managen sie die <a href="https://www.computerwoche.de/article/4164993/best-practices-um-agentic-ai-systeme-aufzubauen.html" target="_blank">KI-Agenten</a>, die heute für sie den Code schreiben.</p>



<p class="wp-block-paragraph">Der Umschwung verläuft dabei rasant: Noch vor wenigen Monaten habe ich selbst mit Unterstützung eines KI-Agenten in meiner IDE gearbeitet. Dabei durfte ich schnell feststellen, dass das – je nach Anzahl der eingesetzten Agenten und der zu bearbeitenden Tasks – schnell ziemlich unübersichtlich wird oder driftet direkt ins Chaos abdriftet.</p>



<p class="wp-block-paragraph">An dieser Stelle wurde auch mir klar, dass Entwickler, die mit KI-Agenten arbeiten, ein Next-Generation-Tool benötigen, um alle Agentic-Development-Aspekte ordentlich managen zu können – ein Agentic Development Environment (<a href="https://www.computerwoche.de/article/4141035/claude-code-im-praxistest.html" target="_blank">ADE</a>).</p>



<h2 class="wp-block-heading">Die IDE stirbt – lang lebe die ADE</h2>



<p class="wp-block-paragraph">Auf meinem Weg zu dieser Erkenntnis war vor allem ein weitgehend unbekanntes und ungenutztes Feature von <a href="https://www.computerwoche.de/article/2812266/was-ist-git.html" target="_blank">Git</a> bedeutsam – <a href="https://git-scm.com/docs/git-worktree" target="_blank" rel="noreferrer noopener">Worktrees</a>. Damit lassen sich mehrere Zweige desselben Repository aus einer einzigen Git-Datenbank in verschiedene Verzeichnisse auschecken. Diese Funktion eignet sich in besonderem Maße für die neue Agentic-Development-Welt.</p>



<p class="wp-block-paragraph">Traditionellerweise würde ein Entwickler jeweils ein Ticket bearbeiten, wofür ein simpler Git-Checkout ausreicht. Das setzt allerdings die Annahme voraus, dass nur ein Akteur, nämlich der Dev, an der Codebasis arbeitet.</p>



<p class="wp-block-paragraph">Im Zeitalter der <a href="https://www.computerwoche.de/article/4189343/was-ki-agenten-wirklich-kosten.html" target="_blank">KI-Agenten</a> ist es jedoch längst nicht mehr undenkbar, dass diese parallel an drei Jira-Tickets werkeln. In diesem Szenario werden Worktrees zum Enabler: Sie weisen jedem Entwickler – respektive Agenten – einen eigenen Zweig und ein eigenes Verzeichnis zu. Quasi eine Art simple Isolierung ohne den ganzen Overhead, der entsteht, wenn separate Repository-Instanzen geklont und geforkt werden müssen.</p>



<p class="wp-block-paragraph">Allerdings wirft der Aufwand, der durch die Kombination von Worktrees und KI-Agenten entsteht, Herausforderungen auf. Und genau an dieser Stelle kommt die <strong>ADE</strong> ins Spiel. Sie koordiniert und managt sämtliche Vorgänge, wenn mehrere <a href="https://www.computerwoche.de/article/4129576/5-gute-grunde-coding-agenten-zu-nutzen.html" target="_blank">Coding-Agenten</a> an verschiedenen Issues innerhalb mehrerer Repository-Zweige arbeiten sollen.</p>



<p class="wp-block-paragraph">Entwickler befähigt das zu mühelosem Multitasking – und dazu, viele Tasks zeitgleich im Blick zu behalten. Um die Logistik um Worktrees herum müssen sie sich mit einer ADE nicht mehr kümmern. Stattdessen können sie ihre Zeit nutzen, um die Agenten zu steuern und sicherzustellen, dass diese ihre Aufgaben korrekt erledigen.</p>



<p class="wp-block-paragraph">Der Abschied von der IDE mag für manchen Dev emotional sein. Aber wahrscheinlich müssen auch wehmütige Entwickler zugeben, dass sie ihre IDE inzwischen gar nicht mehr so oft einsetzen. Und wer mit Agenten arbeitet, wird sie künftig auch nicht vermissen. (fm)</p>



<p class="wp-block-paragraph"><strong>Dieser Artikel ist </strong><a href="https://www.infoworld.com/article/4193975/the-ide-is-dead-long-live-the-ade.html" target="_blank"><strong>im Original</strong></a><strong> bei unserer Schwesterpublikation Infoworld.com erschienen.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Texas Halts Data Center Connections To Power Grid Amid Overwhelming Demand]]></title>
<description><![CDATA[An anonymous reader quotes a report from Ars Technica: Nowhere is the US data center boom bigger than in Texas. But less than a year after declaring Texas the "epicenter of AI development," Governor Greg Abbott has declared a moratorium on all new power grid connections for data centers -- at lea...]]></description>
<link>https://tsecurity.de/de/3704736/it-security-nachrichten/texas-halts-data-center-connections-to-power-grid-amid-overwhelming-demand/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3704736/it-security-nachrichten/texas-halts-data-center-connections-to-power-grid-amid-overwhelming-demand/</guid>
<pubDate>Wed, 05 Aug 2026 05:47:53 +0200</pubDate>
<content:encoded><![CDATA[An anonymous reader quotes a report from Ars Technica: Nowhere is the US data center boom bigger than in Texas. But less than a year after declaring Texas the "epicenter of AI development," Governor Greg Abbott has declared a moratorium on all new power grid connections for data centers -- at least until developers provide more information about their projects' potential impacts on the grid and communities. The Republican governor directed regulators in an August 3 announcement at the Public Utility Commission of Texas and the grid operators at the Electric Reliability Council of Texas (ERCOT) to perform a "comprehensive verification and audit of all data centers advancing through ERCOT's interconnection process." As an independent system operator, ERCOT oversees a power grid that operates separately from the rest of the United States and provides services to most of Texas.
 
Texas has aggressively courted data center development with its availability of cheap land and relatively abundant energy resources, along with offering state incentives, like tax breaks and fewer regulations. That puts the state on track to surpass Virginia in becoming the largest US data center market. But the recent AI boom and the accompanying frenzy of data center development threaten to overwhelm the Texas grid on paper, despite the state leading the country in adding new power generation. The ERCOT interconnection queue currently includes more than 1,800 projects representing over 474 gigawatts' worth of requests to connect to the Texas grid -- more than five times Texas' record peak electricity demand -- and about 90 percent of those power connection requests come from data centers.
 
"That unprecedented load growth could endanger the reliability and stability of the Texas electric grid," according to the statement from Abbott's office. Many of those data center projects may never materialize for various reasons. But ERCOT has still forecast that data center demand and other factors could drive statewide electricity demand to double the current demand record by 2032, according to The Texas Tribune. The review will examine each project's projected electricity consumption, reliance on the grid and state incentives, ownership, and water use. It will also assess measures intended to "reduce impacts on neighboring property owners and communities," including noise controls, lighting, traffic improvements, setbacks, and emergency planning.
 
Ars Technica notes that the directive does not address air pollution or greenhouse-gas emissions and does not apply to data centers generating their own power on-site.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Texas+Halts+Data+Center+Connections+To+Power+Grid+Amid+Overwhelming+Demand%3A+https%3A%2F%2Fhardware.slashdot.org%2Fstory%2F26%2F08%2F04%2F231207%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fhardware.slashdot.org%2Fstory%2F26%2F08%2F04%2F231207%2Ftexas-halts-data-center-connections-to-power-grid-amid-overwhelming-demand%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://hardware.slashdot.org/story/26/08/04/231207/texas-halts-data-center-connections-to-power-grid-amid-overwhelming-demand?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ruby on Rails critical bug puts every image upload under scrutiny]]></title>
<description><![CDATA[A new critical vulnerability in the Ruby on Rails (“Rails”) web application framework, CVE-2026-66066, could turn a seemingly innocuous image into a front door to your secrets.



Disclosed July 30, the high severity CVE (scored 9.5 out of 10) poses a significant risk to enterprises running apps ...]]></description>
<link>https://tsecurity.de/de/3704714/ai-nachrichten/ruby-on-rails-critical-bug-puts-every-image-upload-under-scrutiny/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3704714/ai-nachrichten/ruby-on-rails-critical-bug-puts-every-image-upload-under-scrutiny/</guid>
<pubDate>Wed, 05 Aug 2026 05:22:52 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">A new critical vulnerability in the Ruby on Rails (“Rails”) web application framework, <a href="https://www.cve.org/CVERecord?id=CVE-2026-66066" target="_blank" rel="noreferrer noopener">CVE-2026-66066</a>, could turn a seemingly innocuous image into a front door to your secrets.</p>



<p class="wp-block-paragraph">Disclosed July 30, the high severity CVE (scored 9.5 out of 10) poses a significant risk to enterprises running apps that handle user-uploaded images in Rails.</p>



<p class="wp-block-paragraph">Dubbed “KindaRails2Shell,” it targets the overly-trusting Active Storage component of the open-source framework, allowing unauthenticated attackers to read sensitive files or escalate to remote code execution (RCE).</p>



<p class="wp-block-paragraph">The issue has been fixed in versions 7.2.3.2, 8.0.5.1 and 8.1.3.1 of Active Storage; enterprises running Rails should update immediately.</p>



<p class="wp-block-paragraph">“The ‘chef’s kiss’ is the ability for an attacker to upload an image that isn’t actually an image [but] is code that allows them to steal secrets,” said <a href="https://www.linkedin.com/in/dbshipley/" target="_blank" rel="noreferrer noopener">David Shipley</a> of Beauceron Security.</p>



<h2 class="wp-block-heading">Attackers get the key to the castle</h2>



<p class="wp-block-paragraph">Ruby on Rails is an open-source, server-side application framework used for building full-stack web apps and <a href="https://www.csoonline.com/article/4204548/secure-ai-adoption-starts-with-api-best-practices.html" target="_blank">application programming interfaces</a> (APIs).</p>



<p class="wp-block-paragraph">It is popular among developers because it is scalable, easy to learn and use, supports quick application development, taps into an active community of <a href="https://github.blog/engineering/architecture-optimization/building-github-with-ruby-and-rails/" target="_blank" rel="noreferrer noopener">more than 1,000 engineers</a> developing and maintaining it, and has an extensive library of nearly two million lines of prebuilt code.</p>



<p class="wp-block-paragraph">CVE-2026-66066 specifically targets Rails’ built-in Active Storage component, which lets users upload files to cloud services or local disks and link them to their applications. In particular, the vulnerability exploits the way Active Storage interacts with the <a href="https://github.com/libvips/libvips" target="_blank" rel="noreferrer noopener"><em>libvips</em> image processing library</a> to generate images.</p>



<p class="wp-block-paragraph"><em>Libvips</em> contains what are known as “unfuzzed” operations which have not been hardened against malicious inputs through techniques known as <a href="https://en.wikipedia.org/wiki/Fuzzing" target="_blank" rel="noreferrer noopener">fuzzing</a> that test where they crash, leak data, or otherwise behave erratically. This makes them unsafe for use with untrusted content, but Active Storage does not adequately disable them.</p>



<p class="wp-block-paragraph">“CVE-2026-66066 is particularly dangerous because an attacker may not need an account or privileged access,” explained <a href="https://www.sans.org/profiles/ensar-seker" target="_blank" rel="noreferrer noopener">Ensar Seker</a>, CISO at SOCRadar.</p>



<p class="wp-block-paragraph">Attackers can exploit the unsafe pipeline by uploading specially crafted files that trick Active Storage into giving them access to files that the Rails process is permitted to access, even highly-sensitive ones in app processing environments.</p>



<p class="wp-block-paragraph">In practical terms, this could expose environment variables, Rails application secrets, database credentials, cloud access keys, API tokens and credentials for connected services, Seker explained.</p>



<p class="wp-block-paragraph">Attackers can also gain access to the <em>secret_key_base</em> that signs and encrypts cookies, <a href="https://www.csoonline.com/article/570795/how-to-hack-2fa.html" target="_blank">credentials</a>, and session data. When <em>secret_key_base </em>is compromised, attackers essentially hold the key to the app.</p>



<p class="wp-block-paragraph">“The immediate vulnerability is an arbitrary file-read issue, but the theft of secrets such as Rails’ <em>secret_key_base</em> can turn information disclosure into a much broader compromise,” Seker said.</p>



<p class="wp-block-paragraph">Depending on the application, attackers could potentially forge trusted application data or sessions, access databases and cloud services, move laterally into connected systems, or achieve RCE.</p>



<p class="wp-block-paragraph">That escalation path is what makes the vulnerability critical, Seker said. “A seemingly routine image upload feature, such as a profile picture, avatar or thumbnail generator, could become an entry point into the application’s underlying infrastructure.”</p>



<h2 class="wp-block-heading">How to identify if you’re vulnerable</h2>



<p class="wp-block-paragraph">Applications are impacted when they are configured to use <em>libvips</em> for Active Storage image processing (the default behavior since Rails 7.0) and accept image uploads from untrusted or unauthenticated users. Enterprises should audit every internal and third-party app to determine whether they are configured this way, Seker advised, and patch Rails and Active Storage immediately. They should also examine every feature accepting images, including avatars, support attachments, product images, and administrative upload functions.</p>



<p class="wp-block-paragraph">Upgrading Rails alone is not sufficient when an older <em>libvips</em> installation remains underneath it; <em>libvips</em> must be version 8.13 or later, he said.</p>



<p class="wp-block-paragraph">Forensic guidance and tooling from the Rails project can help enterprises determine whether apps are vulnerable or files are exploitable, Seker noted. It’s also important to review app, proxy, object-storage, and image-processing logs for suspicious uploads or unusual requests.</p>



<p class="wp-block-paragraph">Additionally, admins should rotate <em>secret_key_base </em>and every other credential available in Rails, invalidate active sessions, and investigate downstream systems for potentially exposed credentials.</p>



<p class="wp-block-paragraph">“Security teams should treat this as a potential secret-exposure incident, not merely a patch-management exercise,” Seker said.</p>



<h2 class="wp-block-heading">Don’t trust image processing pipelines</h2>



<p class="wp-block-paragraph">Complex image libraries support many formats and rely on numerous parsers and third-party components, creating a broad attack surface, Seker noted. Therefore, the libraries “should be treated as untrusted code execution territory.”</p>



<p class="wp-block-paragraph">Image processing should be isolated in dedicated sandboxes, containers, or restricted to workers with minimal filesystem access, he advised. There should be no unnecessary network connectivity or access to an app’s files or secrets. Strict allowlists should be applied, file content human-validated, and uploads scanned before processing and stored outside app directories. </p>



<p class="wp-block-paragraph">Additional controls should include short-lived and narrowly scoped credentials, outbound network restrictions, dependency and software composition monitoring, and automated tests that confirm that dangerous codecs or operations are disabled post-upgrade, Seker said.</p>



<p class="wp-block-paragraph">“The broader lesson is that organizations cannot assess exposure solely by asking whether they ‘use Rails,’” he noted, pointing out that two applications running the same Rails version may have very different exposure depending on their image processor, upload paths, and operating system packages. This makes visibility into runtime configuration, libraries, and app functionality critical.</p>



<p class="wp-block-paragraph">This incident also demonstrates the importance of secret rotation in vulnerability response, he added. “When a vulnerability enables arbitrary file access, installing the patch closes the entry point but does not revoke credentials that may already have been copied.”</p>



<h2 class="wp-block-heading">Don’t just assume you’re safe</h2>



<p class="wp-block-paragraph">This vulnerability illustrates a perfect use case for a software bill of materials (SBOM), which can speed up discovery of vulnerable software and triage it, Beauceron’s Shipley noted. And enterprises could also adopt intelligent web application firewall monitoring and intervention in addition to isolating systems and patching.</p>



<p class="wp-block-paragraph">“The words you never want to hear in any critical vulnerability are ‘arbitrary code execution’ and ‘remote code execution’,” he said. “Either of those can mean bad news.”</p>



<p class="wp-block-paragraph">What’s also interesting here is that the disclosure process was hijacked, he pointed out. Rails published <a href="https://discuss.rubyonrails.org/t/cve-2026-66066-attack-details-and-tools-to-perform-a-forensic-investigation/91441" target="_blank" rel="noreferrer noopener">technical details about the flaw and forensic tools</a> to assess application vulnerability to it and to look for evidence of data exfiltration nearly a month before it planned to, because several researchers had reverse-engineered the attack and published proof of concept code.</p>



<p class="wp-block-paragraph">The fact that proofs of concept are now available “materially increases the likelihood of opportunistic scanning and exploitation attempts,” Seker noted.</p>



<p class="wp-block-paragraph">Therefore, he said, “even organizations that see no obvious evidence of compromise should not assume that patching alone removes the risk created by previously exposed secrets.”</p>



<p class="wp-block-paragraph"><em>This article originally appeared on <a href="https://www.csoonline.com/article/4205383/ruby-on-rails-critical-bug-puts-every-image-upload-under-scrutiny.html" target="_blank">CSOonline</a>.</em></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ruby on Rails critical bug puts every image upload under scrutiny]]></title>
<description><![CDATA[A new critical vulnerability in the Ruby on Rails (“Rails”) web application framework, CVE-2026-66066, could turn a seemingly innocuous image into a front door to your secrets.



Disclosed July 30, the high severity CVE (scored 9.5 out of 10) poses a significant risk to enterprises running apps ...]]></description>
<link>https://tsecurity.de/de/3704642/it-security-nachrichten/ruby-on-rails-critical-bug-puts-every-image-upload-under-scrutiny/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3704642/it-security-nachrichten/ruby-on-rails-critical-bug-puts-every-image-upload-under-scrutiny/</guid>
<pubDate>Wed, 05 Aug 2026 04:08:16 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">A new critical vulnerability in the Ruby on Rails (“Rails”) web application framework, <a href="https://www.cve.org/CVERecord?id=CVE-2026-66066" target="_blank" rel="noreferrer noopener">CVE-2026-66066</a>, could turn a seemingly innocuous image into a front door to your secrets.</p>



<p class="wp-block-paragraph">Disclosed July 30, the high severity CVE (scored 9.5 out of 10) poses a significant risk to enterprises running apps that handle user-uploaded images in Rails.</p>



<p class="wp-block-paragraph">Dubbed “KindaRails2Shell,” it targets the overly-trusting Active Storage component of the open-source framework, allowing unauthenticated attackers to read sensitive files or escalate to remote code execution (RCE).</p>



<p class="wp-block-paragraph">The issue has been fixed in versions 7.2.3.2, 8.0.5.1 and 8.1.3.1 of Active Storage; enterprises running Rails should update immediately.</p>



<p class="wp-block-paragraph">“The ‘chef’s kiss’ is the ability for an attacker to upload an image that isn’t actually an image [but] is code that allows them to steal secrets,” said <a href="https://www.linkedin.com/in/dbshipley/" target="_blank" rel="noreferrer noopener">David Shipley</a> of Beauceron Security.</p>



<h2 class="wp-block-heading">Attackers get the key to the castle</h2>



<p class="wp-block-paragraph">Ruby on Rails is an open-source, server-side application framework used for building full-stack web apps and <a href="https://www.csoonline.com/article/4204548/secure-ai-adoption-starts-with-api-best-practices.html" target="_blank">application programming interfaces</a> (APIs).</p>



<p class="wp-block-paragraph">It is popular among developers because it is scalable, easy to learn and use, supports quick application development, taps into an active community of <a href="https://github.blog/engineering/architecture-optimization/building-github-with-ruby-and-rails/" target="_blank" rel="noreferrer noopener">more than 1,000 engineers</a> developing and maintaining it, and has an extensive library of nearly two million lines of prebuilt code.</p>



<p class="wp-block-paragraph">CVE-2026-66066 specifically targets Rails’ built-in Active Storage component, which lets users upload files to cloud services or local disks and link them to their applications. In particular, the vulnerability exploits the way Active Storage interacts with the <a href="https://github.com/libvips/libvips" target="_blank" rel="noreferrer noopener"><em>libvips</em> image processing library</a> to generate images.</p>



<p class="wp-block-paragraph"><em>Libvips</em> contains what are known as “unfuzzed” operations which have not been hardened against malicious inputs through techniques known as <a href="https://en.wikipedia.org/wiki/Fuzzing" target="_blank" rel="noreferrer noopener">fuzzing</a> that test where they crash, leak data, or otherwise behave erratically. This makes them unsafe for use with untrusted content, but Active Storage does not adequately disable them.</p>



<p class="wp-block-paragraph">“CVE-2026-66066 is particularly dangerous because an attacker may not need an account or privileged access,” explained <a href="https://www.sans.org/profiles/ensar-seker" target="_blank" rel="noreferrer noopener">Ensar Seker</a>, CISO at SOCRadar.</p>



<p class="wp-block-paragraph">Attackers can exploit the unsafe pipeline by uploading specially crafted files that trick Active Storage into giving them access to files that the Rails process is permitted to access, even highly-sensitive ones in app processing environments.</p>



<p class="wp-block-paragraph">In practical terms, this could expose environment variables, Rails application secrets, database credentials, cloud access keys, API tokens and credentials for connected services, Seker explained.</p>



<p class="wp-block-paragraph">Attackers can also gain access to the <em>secret_key_base</em> that signs and encrypts cookies, <a href="https://www.csoonline.com/article/570795/how-to-hack-2fa.html" target="_blank">credentials</a>, and session data. When <em>secret_key_base </em>is compromised, attackers essentially hold the key to the app.</p>



<p class="wp-block-paragraph">“The immediate vulnerability is an arbitrary file-read issue, but the theft of secrets such as Rails’ <em>secret_key_base</em> can turn information disclosure into a much broader compromise,” Seker said.</p>



<p class="wp-block-paragraph">Depending on the application, attackers could potentially forge trusted application data or sessions, access databases and cloud services, move laterally into connected systems, or achieve RCE.</p>



<p class="wp-block-paragraph">That escalation path is what makes the vulnerability critical, Seker said. “A seemingly routine image upload feature, such as a profile picture, avatar or thumbnail generator, could become an entry point into the application’s underlying infrastructure.”</p>



<h2 class="wp-block-heading">How to identify if you’re vulnerable</h2>



<p class="wp-block-paragraph">Applications are impacted when they are configured to use <em>libvips</em> for Active Storage image processing (the default behavior since Rails 7.0) and accept image uploads from untrusted or unauthenticated users. Enterprises should audit every internal and third-party app to determine whether they are configured this way, Seker advised, and patch Rails and Active Storage immediately. They should also examine every feature accepting images, including avatars, support attachments, product images, and administrative upload functions.</p>



<p class="wp-block-paragraph">Upgrading Rails alone is not sufficient when an older <em>libvips</em> installation remains underneath it; <em>libvips</em> must be version 8.13 or later, he said.</p>



<p class="wp-block-paragraph">Forensic guidance and tooling from the Rails project can help enterprises determine whether apps are vulnerable or files are exploitable, Seker noted. It’s also important to review app, proxy, object-storage, and image-processing logs for suspicious uploads or unusual requests.</p>



<p class="wp-block-paragraph">Additionally, admins should rotate <em>secret_key_base </em>and every other credential available in Rails, invalidate active sessions, and investigate downstream systems for potentially exposed credentials.</p>



<p class="wp-block-paragraph">“Security teams should treat this as a potential secret-exposure incident, not merely a patch-management exercise,” Seker said.</p>



<h2 class="wp-block-heading">Don’t trust image processing pipelines</h2>



<p class="wp-block-paragraph">Complex image libraries support many formats and rely on numerous parsers and third-party components, creating a broad attack surface, Seker noted. Therefore, the libraries “should be treated as untrusted code execution territory.”</p>



<p class="wp-block-paragraph">Image processing should be isolated in dedicated sandboxes, containers, or restricted to workers with minimal filesystem access, he advised. There should be no unnecessary network connectivity or access to an app’s files or secrets. Strict allowlists should be applied, file content human-validated, and uploads scanned before processing and stored outside app directories. </p>



<p class="wp-block-paragraph">Additional controls should include short-lived and narrowly scoped credentials, outbound network restrictions, dependency and software composition monitoring, and automated tests that confirm that dangerous codecs or operations are disabled post-upgrade, Seker said.</p>



<p class="wp-block-paragraph">“The broader lesson is that organizations cannot assess exposure solely by asking whether they ‘use Rails,’” he noted, pointing out that two applications running the same Rails version may have very different exposure depending on their image processor, upload paths, and operating system packages. This makes visibility into runtime configuration, libraries, and app functionality critical.</p>



<p class="wp-block-paragraph">This incident also demonstrates the importance of secret rotation in vulnerability response, he added. “When a vulnerability enables arbitrary file access, installing the patch closes the entry point but does not revoke credentials that may already have been copied.”</p>



<h2 class="wp-block-heading">Don’t just assume you’re safe</h2>



<p class="wp-block-paragraph">This vulnerability illustrates a perfect use case for a software bill of materials (SBOM), which can speed up discovery of vulnerable software and triage it, Beauceron’s Shipley noted. And enterprises could also adopt intelligent web application firewall monitoring and intervention in addition to isolating systems and patching.</p>



<p class="wp-block-paragraph">“The words you never want to hear in any critical vulnerability are ‘arbitrary code execution’ and ‘remote code execution’,” he said. “Either of those can mean bad news.”</p>



<p class="wp-block-paragraph">What’s also interesting here is that the disclosure process was hijacked, he pointed out. Rails published <a href="https://discuss.rubyonrails.org/t/cve-2026-66066-attack-details-and-tools-to-perform-a-forensic-investigation/91441" target="_blank" rel="noreferrer noopener">technical details about the flaw and forensic tools</a> to assess application vulnerability to it and to look for evidence of data exfiltration nearly a month before it planned to, because several researchers had reverse-engineered the attack and published proof of concept code.</p>



<p class="wp-block-paragraph">The fact that proofs of concept are now available “materially increases the likelihood of opportunistic scanning and exploitation attempts,” Seker noted.</p>



<p class="wp-block-paragraph">Therefore, he said, “even organizations that see no obvious evidence of compromise should not assume that patching alone removes the risk created by previously exposed secrets.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[SnapLogic introduces agentic assistant for data integration]]></title>
<description><![CDATA[SnapLogic has introduced its new SnapGPT, an agentic assistant that helps enterprise teams plan, build, understand, and operate integrations through natural language.



Unveiled July 28 and described as the company’s most-significant advancement in SnapGPT since 2023, the new SnapGPT evolves fro...]]></description>
<link>https://tsecurity.de/de/3704570/ai-nachrichten/snaplogic-introduces-agentic-assistant-for-data-integration/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3704570/ai-nachrichten/snaplogic-introduces-agentic-assistant-for-data-integration/</guid>
<pubDate>Wed, 05 Aug 2026 02:43:14 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">SnapLogic has introduced its new SnapGPT, an agentic assistant that helps enterprise teams plan, build, understand, and operate integrations through natural language.</p>



<p class="wp-block-paragraph">Unveiled July 28 and described as the company’s most-significant advancement in SnapGPT since 2023, the new SnapGPT evolves from an AI-powered integration copilot into an agentic assistant for the integration life cycle, combining platform intelligence, integration-specific reasoning, and operational guidance to help teams move from business intent to production faster, according to SnapLogic. SnapGPT combines agentic planning, integration-specific reasoning, pipeline execution validation, and more than 15 years of enterprise integration expertise built into the SnapLogic Agentic Integration Platform, including platform intelligence, operational context, and proven integration patterns, the company said.</p>



<p class="wp-block-paragraph">SnapGPT now helps teams across the entire integration life cycle:</p>



<ul class="wp-block-list">
<li>Plan – Plan Mode helps teams validate requirements, explore implementation approaches, refine workflows, and identify potential issues before development begins.</li>



<li>Build – Generate high-quality, production-ready integrations through integration-specific reasoning and pipeline execution validation, while accelerating development with multi-pipeline generation, intelligent pipeline refactoring, reusable expression libraries, and natural-language generation of SnapLogic MCP Servers.</li>



<li>Understand – Analyze existing integration assets, explain pipeline logic, and surface contextual insights to help teams better understand and improve complex integrations.</li>



<li>Operate – SnapGPT Activity Log provides administrators with visibility into AI-assisted development activity, while SnapGPT Monitor Insights extends AI assistance into production operations with diagnostic intelligence and AI-powered troubleshooting.</li>
</ul>



<p class="wp-block-paragraph">The new SnapGPT is available as part of the <a href="https://www.snaplogic.com/use-cases/agentic-integration">SnapLogic Agent Integration Platform</a>. In June SnapLogic introduced the <a href="https://www.infoworld.com/article/4191862/snaplogic-mcp-builder-eases-creation-of-mcp-servers.html">SnapLogic MCP Builder</a>, a template-based tool that generates <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html" data-type="link" data-id="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">Model Context Protocol</a> servers from existing integrations.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4698: ID3 Tags and Vorbis Comments]]></title>
<description><![CDATA[This show has been flagged as Clean by the host.






--------------------






01 Introduction






In a response to a post on a previous episode, I said that I would take a look at ID3 tags. 


ID3 tags are text information that is added to an MP3 audio file, such as the author, dat...]]></description>
<link>https://tsecurity.de/de/3704569/podcasts/hpr4698-id3-tags-and-vorbis-comments/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3704569/podcasts/hpr4698-id3-tags-and-vorbis-comments/</guid>
<pubDate>Wed, 05 Aug 2026 02:42:56 +0200</pubDate>
<content:encoded><![CDATA[<p>This show has been flagged as Clean by the host.</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
01 Introduction</p>

<p>

</p>

<p>
In a response to a post on a previous episode, I said that I would take a look at ID3 tags. </p>

<p>
ID3 tags are text information that is added to an MP3 audio file, such as the author, date, name, and other information.</p>

<p>

</p>

<p>
02</p>

<p>
While I am at it I will also look at Vorbis comments, which perform a similar function for vorbis, the container format for "ogg" audio files.</p>

<p>
As example audio files, I will use a recent HPR episode, hpr4678 in both mp3 and vorbis formats plus also one from another podcast as well. </p>

<p>

</p>

<p>
03</p>

<p>
There is Free Software which you can use to view, edit, or remove both types of tags or comments, and I will describe how to use it in this episode.</p>

<p>

</p>

<p>
04</p>

<p>
I will cover how to view tags and extract the text information, as well as how to strip the tags from a file and why you may wish to do so under certain very specific circumstances.</p>

<p>

</p>

<p>
I won't cover how to add to or edit tags in an MP3 or OGG file, as that is a more involved subject that I don't have much experience with. </p>

<p>

</p>

<p>
05</p>

<p>
I will mainly talk about ID3 MP3 tags rather than vorbis comments for the simple reason that the situation with MP3 files is an utter mess while vorbis comments are very straightforward and so there isn't as much to say about them.</p>

<p>

</p>

<p>
06</p>

<p>
As often happens when researching a subject to write a podcast script, I have learned quite a bit that I didn't know previously, and discovered that things that I thought I did know were wrong.</p>

<p>
I hope that you may learn a few things from this episode that you didn't know previously either. </p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
07 Background</p>

<p>

</p>

<p>
I won't go over the detailed history of ID3 tags, as I don't have a reliable source for this.</p>

<p>
Briefly however, so far as I can determine, there is no official independent standard for ID3 tags or vorbis comments.</p>

<p>
Both seem to be more in the nature of a convention that was created by an unofficial group of contributors rather than something issued by a standards body.</p>

<p>

</p>

<p>
08</p>

<p>
However, I don't see the lack of a conventional standards body as necessarily a problem with respect to the use of ID3 tags or vorbis comments.</p>

<p>
I just am not familiar enough with the industry to know who to regard as being an authoritative source when it comes to the history and development of them</p>

<p>
Since I am unsure as who to credit with what developments, I will avoid that sort of detail.</p>

<p>

</p>

<p>
09 ID3 Tags</p>

<p>
There is a web site with the URL of ID3.org that seems to have the best reference material on the topic of ID3 tags.</p>

<p>
According to this site, the term "ID3" means "IDentify an MP3".</p>

<p>

</p>

<p>
10 Vorbis Comments</p>

<p>
For vorbis, the reference site seems to be xiph.org.</p>

<p>
Although the implementation details may differ from ID3, from our perspective as podcast listeners, they can be seen as more or less equivalent in terms of what I am going to address here.</p>

<p>

</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
11 ID3 Details</p>

<p>

</p>

<p>

</p>

<p>
Versions</p>

<p>
One of the problems with ID3 is that there are multiple incompatible versions, particularly from the very early days.</p>

<p>
ID3v1 tags are located at the end of the audio file in the last 128 bytes.</p>

<p>
This was done for compatibility reasons to allow early MP3 players to simply ignore the tags if they didn't know how to deal with them. </p>

<p>
The tags would simply appear as a short burst of static from the perspective of these early players.</p>

<p>

</p>

<p>
12</p>

<p>
ID3v2 moved the tags to the start of the MP3 file to allow players to scan the tags for information such as titles without having to read to the end of the file to find them.</p>

<p>
There are far fewer limits on the amount of information that can be placed in ID3v2 tags.</p>

<p>

</p>

<p>
13</p>

<p>
ID3v1 is obsolete and only very old players will require it.</p>

<p>
However, it is still used by some publishers for backward compatibility reasons.</p>

<p>
ID3v1 included numerical musical "genre" category codes which apparently turned out to be a very bad idea in practice. </p>

<p>

</p>

<p>
14</p>

<p>
Furthermore, all genre categories above 70 were defined by an audio software company called Nullsoft who created software such as Winamp.</p>

<p>
These codes were never actually part of the ID3 standard, although there was never really a standard to begin with.</p>

<p>

</p>

<p>
15</p>

<p>
The current ID3 version is 2.3. There is a version 2.4, but apparently it is not actually generally accepted and may be a developmental dead end.</p>

<p>

</p>

<p>
16</p>

<p>
The id3.org web site contains a copy of the ID3v2.3 standard, but I am not going to address the technical details here.</p>

<p>
This would only be of interest to someone who was creating software to read and write ID3 tags.</p>

<p>

</p>

<p>
17 ID3v2 Frames</p>

<p>
The ID3v2 information is encoded into what are called "frames".</p>

<p>
The text information is contained in text information frames.</p>

<p>

</p>

<p>
18</p>

<p>
Text information frames start with a set of four character identifiers, all starting with the capital letter 'T'.</p>

<p>
Examples</p>

<p>
"TALB" is the "Album/Movie/Show title" frame.</p>

<p>
"TIT2" is the "Title/Songname/Content description" frame.</p>

<p>
"TYER" is the "Year" frame.</p>

<p>

</p>

<p>
There are many more, but I won't go into more detail here.</p>

<p>

</p>

<p>
19 HPR ID3 Tags</p>

<p>
HPR makes an interesting case study because they use both ID3v1 and ID3v2 in the same file.</p>

<p>
This can cause some interesting problems with software that tries to read those tags.</p>

<p>
This is because most software appears to expect one or the other, but not both.</p>

<p>
However, so long as this does not cause problems with anything that actually plays the files, this is not a problem so far as people who just want to listen to podcasts are concerned.</p>

<p>

</p>

<p>
It does mean though that we have more to talk about than we would otherwise would have had.</p>

<p>

</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
20 Vorbis Comment Fields</p>

<p>

</p>

<p>
The situation with Vorbis comments is much simpler, as there seems to be just one standard that was adhered to from the start rather than a succession of hacks.</p>

<p>
Information is stored in "fields", which xiph describes as being like Unix environment variables.</p>

<p>
These consist of a field name followed by an equal sign and then the information intended for that field.</p>

<p>
Field names are case insensitive.</p>

<p>

</p>

<p>
21</p>

<p>
The field names are not firmly defined at this stage, but there is a list of recommended names.</p>

<p>
Examples are</p>

<p>
"TITLE" is the Track or Work name.</p>

<p>
"ARTIST" is the person responsible for the work.</p>

<p>
"LICENSE" is the license information.</p>

<p>

</p>

<p>
22</p>

<p>
You can see the complete list for yourself on the comment field and header specification page at xiph.org</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
23 Software for Listing, Adding, and Modifying Tags and Fields</p>

<p>

</p>

<p>
There are three software packages that I will now describe which allow you to list, add, modify, and remove tags and fields.</p>

<p>
There are other packages which can do the same, including some which offer a GUI interface.</p>

<p>
However, I will limit myself to describing these three.</p>

<p>
The principles should be the same for others.</p>

<p>

</p>

<p>
24 ffprobe</p>

<p>
ffprobe is part of the ffmpeg package.</p>

<p>
If you have listened to my previous episodes on audio, you will have heard me talk about ffmpeg.</p>

<p>
ffprobe is used to display information about media files rather than for modifying them.</p>

<p>
ffprobe is licensed under the GPLv2 or later.</p>

<p>

</p>

<p>
ffprobe can be used to display information about both MP3 and OGG Vorbis files.</p>

<p>

</p>

<p>
25 ID3v2</p>

<p>
The next is the rather aptly named id3v2 and works with MP3 files.</p>

<p>
On Linux systems, this should be provided by the id3v2 package.</p>

<p>
On Debian derivatives this can be installed as follows</p>

<p>

</p>

<p>
sudo apt install id3v2</p>

<p>

</p>

<p>
26</p>

<p>
This also installs a man page which provides a brief list of the options.</p>

<p>
According to the README file in the source tarball, this is published under the LGPL</p>

<p>
ID3v2 is particularly useful for displaying ID3v1 tags.</p>

<p>

</p>

<p>
27 vorbiscomment</p>

<p>
The third is "vorbiscomment" and works with OGG files.</p>

<p>
On Linux systems this should be provided by the "vorbis-tools" package.</p>

<p>
On Debian derivatives this can be installed as follows</p>

<p>

</p>

<p>
sudo apt install vorbis-tools</p>

<p>

</p>

<p>
28</p>

<p>
The vorbiscomment program is used to list or edit comments in Ogg Vorbis files.</p>

<p>
This also installs a man page which provides a brief list of the options.</p>

<p>
According to the license.lgpl file in the source tarball, this is published under the LGPL version2.</p>

<p>

</p>

<p>
29</p>

<p>
The display format for vorbiscomment follows the data definition format in the vorbis standard, whereas ffprobe re-formats it to match its own preferred appearance. </p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
30 Examples from HPR</p>

<p>

</p>

<p>
With the background out of the way, I will now give several examples of how to list the tags or fields.</p>

<p>

</p>

<p>
31 Listing ID3v1 Tags</p>

<p>

</p>

<p>
As previously mentioned HPR uses both ID3v1 and ID3v2 tags in the same file.</p>

<p>
However, so far as I can tell, most software seems to look for ID3v2 tags first, and don't display the ID3v1 tags if both are present.</p>

<p>

</p>

<p>
32</p>

<p>
The ID3v2 program however seems to do the opposite, at least with HPR podcasts. </p>

<p>
However, the number of samples that I have which have both are rather limited, so I can't be sure if this is always the case or if this is a side effect of something else.</p>

<p>
I did mention that ID3 tags were a mess, didn't I?</p>

<p>

</p>

<p>
33</p>

<p>
Let's go on to our example however.</p>

<p>
If we want to see the ID3v1 tags, then using hpr4678 as an example, if we type</p>

<p>

</p>

<p>
id3v2 -l hpr4678.mp3</p>

<p>
=</p>

<p>
we get the following result.</p>

<p>

</p>

<p>
34</p>

<p>

</p>

<p>
id3v1 tag info for hpr4678.mp3:</p>

<p>
Title  : High Resolution Elapsed Time i  Artist: Whiskeyjack                   </p>

<p>
Album  : Hacker Public Radio             Year: 2026, Genre: Unknown (186)</p>

<p>
Comment: https://hackerpublicradio.or    Track: 0</p>

<p>
hpr4678.mp3: No ID3v2 tag</p>

<p>

</p>

<p>
35</p>

<p>
The first line tells us that this information is ID3v1 tags.</p>

<p>
The last line tells us that there are no ID3v2 tags. </p>

<p>
This last line is incorrect, but we will come back to that later.</p>

<p>

</p>

<p>
36</p>

<p>
In between are three lines of text.</p>

<p>
The first line contains the title and the artist.</p>

<p>
The title is the name of the HPR episode, or at least part of it.</p>

<p>
The artist is the HPR contributor who made that episode.</p>

<p>

</p>

<p>
37</p>

<p>
The second line contains the album name, the year, and the genre.</p>

<p>
The album name is this case is simply Hacker Public Radio, as the concept of an album doesn't really fit a podcast.</p>

<p>
The year is the year that the episode was recorded, or at least the year in which the MP3 file was assembled with the HPR intro and the tags added.</p>

<p>

</p>

<p>
38</p>

<p>
The genre is listed as "unknown 186".</p>

<p>
Recall that with ID3v1 tags there is a one byte numeric genre code, but that no genres above 70 were ever officially assigned.</p>

<p>
It seems to be a general convention though to use a code 186 for podcasts.</p>

<p>

</p>

<p>
39</p>

<p>
The third line contain a comment and track number.</p>

<p>
The comment in this case is the HPR web site URL.</p>

<p>
The track is zero.</p>

<p>
"Track" would appear to serve no useful purpose in this instance.</p>

<p>
However, it may be there for reasons of compatibility that I am unaware of, so I would be very reluctant to remove that without very good reason.</p>

<p>

</p>

<p>
40</p>

<p>
If we look at the above information in detail we can see that two of the tags appear to have cut their text information off short.</p>

<p>
The title is cut off in mid word after the 30th character.</p>

<p>
The final "g" in "hackerpublicradio.org" is cut off in the comment.</p>

<p>

</p>

<p>
41 Alternative Method for ID3v1</p>

<p>
We can confirm whether the text being cut short is due to a problem with the id3v2 program, or whether it really represents the data in the file by using a rather simple check.</p>

<p>

</p>

<p>
42</p>

<p>
Recall that ID3v1 tags are simply the last 128 bytes of the MP3 file.</p>

<p>
All we need to do is to extract the last 128 bytes of the file.</p>

<p>
We can do this using the standard tail command.</p>

<p>

</p>

<p>
tail -c128 hpr4678.mp3 | tr '\0' ' ' | tr -c '[:print:]' 'x'</p>

<p>

</p>

<p>
43</p>

<p>
The -c128 option used with tail tells it to extract the last 128 bytes of the file.</p>

<p>
We then pass the result through the "tr" command and tell it to replace null bytes with new line characters.</p>

<p>
Then we replace any remaining non-printable characters  with an 'x'.</p>

<p>

</p>

<p>
When we do that we get the following</p>

<p>

</p>

<p>
44</p>

<p>

</p>

<p>
TAGHigh Resolution Elapsed Time iWhiskeyjack                   Hacker Public Radio           2026https://hackerpublicradio.or  x</p>

<p>

</p>

<p>
45</p>

<p>
The first three characters are capital TAG.</p>

<p>
This is a flag which indicates that what follows  are ID3 tags.</p>

<p>

</p>

<p>
46</p>

<p>
Next, we have 30 characters which specify the title.</p>

<p>
The next 30 characters specify the artist.</p>

<p>
The next 30 characters are the album, or in this case just "Hacker Public Radio".</p>

<p>
The next 4 characters are the year.</p>

<p>
The next 30 characters are a comment, or in this case the HPR URL, except for the final "g".</p>

<p>
The last character is the genre code, which we have replaced with an "x" because it is otherwise non-printable.</p>

<p>

</p>

<p>
47</p>

<p>
Taken together, these add up to 128 bytes.</p>

<p>
We can see that the field lengths are of fixed length with pre-defined meanings based on position.</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
48 ID3v2 Using ffprobe</p>

<p>
Now lets move on to ID3v2 tags, which is probably more useful for most people.</p>

<p>

</p>

<p>
For this, we will switch to using ffprobe.</p>

<p>
The command for this is</p>

<p>

</p>

<p>
ffprobe -hide_banner hpr4678.mp3</p>

<p>

</p>

<p>
The -hide_banner option suppresses extra data about the codecs which doesn't interest us much and leaves mainly the tag information plus a few other things.</p>

<p>

</p>

<p>
49</p>

<p>
The output gives us the full data that is associated with the podcast episode from the HPR web site.</p>

<p>
This includes the episode number, year, full title, author, license, and full summary text.</p>

<p>
You can see a full copy of this in the show notes.</p>

<p>

</p>

<p>
Input #0, mp3, from 'hpr4678.mp3':</p>

<p>
  Metadata:</p>

<p>
	track           : 4678</p>

<p>
	year            : 2026</p>

<p>
	title           : High Resolution Elapsed Time in Shell Scripts</p>

<p>
	author          : Whiskeyjack</p>

<p>
	copyright       : CC-BY-SA</p>

<p>
	artist          : Whiskeyjack</p>

<p>
	album           : Hacker Public Radio</p>

<p>
	comment         : https://hackerpublicradio.org Clean; Surprises encountered when measuring elapsed time in shell scripts The license is CC-BY-SA</p>

<p>
	genre           : Podcast</p>

<p>
	encoder         : Lavf61.7.103</p>

<p>
	date            : 2026</p>

<p>
  Duration: 00:30:10.18, start: 0.023021, bitrate: 64 kb/s</p>

<p>
  Stream #0:0: Audio: mp3, 48000 Hz, mono, fltp, 64 kb/s</p>

<p>

</p>

<p>
50</p>

<p>
The ID3v2 tag version contains all of the information which was provided by the author, including the full title and description without the 30 character limit of ID3V1.</p>

<p>

</p>

<p>
If you want any of this information for some reason you should be able to extract it from the MP3 file using a combination of ffprobe, grep, and cut rather than trying to scrape the HPR web site and matching it to the MP3 later. </p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
51 ID3v1 Using ffprobe</p>

<p>

</p>

<p>
I previously mentioned that HPR MP3 files have both ID3v1 and ID3v2 tags in the same file, and that ffprobe will default to using ID3v2 tags if present.</p>

<p>

</p>

<p>
However, what happens if we remove the ID3v2 tags and leave the ID3v1 tags?</p>

<p>
I will describe how to strip tags later on in this episode, but let's just assume for now that I have done this.</p>

<p>

</p>

<p>
If we then use ffprobe to read the ID3 tags using the same command as before, we get the following output.</p>

<p>

</p>

<p>
52</p>

<p>
We get a series of lines in the same format as with ID3v2, but with each data element limited to at most 30 bytes.</p>

<p>
These include title, artist, album, date, comment, and genre. </p>

<p>
You can see the full output in the show notes.</p>

<p>

</p>

<p>
Input #0, mp3, from 'test.mp3':</p>

<p>
  Metadata:</p>

<p>
	title           : High Resolution Elapsed Time i</p>

<p>
	artist          : Whiskeyjack</p>

<p>
	album           : Hacker Public Radio</p>

<p>
	date            : 2026</p>

<p>
	comment         : https://hackerpublicradio.or</p>

<p>
	genre           : Podcast</p>

<p>
  Duration: 00:30:10.18, start: 0.023021, bitrate: 64 kb/s</p>

<p>
  Stream #0:0: Audio: mp3, 48000 Hz, mono, fltp, 64 kb/s</p>

<p>

</p>

<p>
53</p>

<p>
The information is the same as when read by the id3v2 program, but formatted for display in the manner that ffprobe uses. </p>

<p>

</p>

<p>
This shows that ffprobe can indeed read ID3v1 tags if they are the only ones present. </p>

<p>

</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
54 Reading Vorbis Comments</p>

<p>
Now let us turn our attention to vorbis comments, which are the equivalent to tags for ogg files.</p>

<p>
We will look at this using two methods.</p>

<p>

</p>

<p>
55 Using vorbiscomment</p>

<p>
The first method we will look at is using the vorbiscomment package.</p>

<p>
The command is </p>

<p>

</p>

<p>
vorbiscomment -l hpr4678.ogg</p>

<p>

</p>

<p>
56</p>

<p>
The output of this is a series of lines with key value pairs separated by equal signs.</p>

<p>
The output is also exactly the same as the MP3 file, except that there is an additional "language" field, "track" becomes "TRACKNUMBER", and there is no "date" field.</p>

<p>
You can see the full output in the show notes.</p>

<p>

</p>

<p>
encoder=Lavc61.19.101 libvorbis</p>

<p>
TRACKNUMBER=4678</p>

<p>
year=2026</p>

<p>
language=English</p>

<p>
title=High Resolution Elapsed Time in Shell Scripts</p>

<p>
author=Whiskeyjack</p>

<p>
copyright=CC-BY-SA</p>

<p>
artist=Whiskeyjack</p>

<p>
album=Hacker Public Radio</p>

<p>
DESCRIPTION=https://hackerpublicradio.org Clean; Surprises encountered when measuring elapsed time in shell scripts The license is CC-BY-SA</p>

<p>
genre=Podcast</p>

<p>

</p>

<p>

</p>

<p>
57 Using ffprobe</p>

<p>
Now lets do the same again using ffprobe.</p>

<p>
The command for this is</p>

<p>

</p>

<p>
ffprobe -hide_banner hpr4678.ogg</p>

<p>

</p>

<p>
58</p>

<p>
The output content is the same of course, but the field names have all been forced to lower case, and instead of an equal sign as a separator between the key and value, this has been replaced by a colon and white space has been added to make the output look a bit nicer.</p>

<p>
You can see the full output in the show notes.</p>

<p>

</p>

<p>
Input #0, ogg, from 'hpr4678.ogg':</p>

<p>
  Duration: 00:30:10.14, start: 0.000000, bitrate: 86 kb/s</p>

<p>
  Stream #0:0(English): Audio: vorbis, 192000 Hz, mono, fltp, 4294967 kb/s</p>

<p>
	Metadata:</p>

<p>
	  encoder         : Lavc61.19.101 libvorbis</p>

<p>
	  track           : 4678</p>

<p>
	  year            : 2026</p>

<p>
	  title           : High Resolution Elapsed Time in Shell Scripts</p>

<p>
	  author          : Whiskeyjack</p>

<p>
	  copyright       : CC-BY-SA</p>

<p>
	  artist          : Whiskeyjack</p>

<p>
	  album           : Hacker Public Radio</p>

<p>
	  comment         : https://hackerpublicradio.org Clean; Surprises encountered when measuring elapsed time in shell scripts The license is CC-BY-SA</p>

<p>
	  genre           : Podcast</p>

<p>

</p>

<p>

</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
59 Another Example from Another Podcast</p>

<p>

</p>

<p>
The above is interesting, but it's a sample of one podcast. Let's look at another different one altogether.</p>

<p>
For this test I used two episodes of the Linux Matters podcast, episodes 68 and 82. As to why I am using two different episodes I will explain in a moment.</p>

<p>

</p>

<p>
60 Episode 68</p>

<p>
We will start with examining episode 68</p>

<p>

</p>

<p>
Using id3v2</p>

<p>
The command using id3v2 is</p>

<p>

</p>

<p>
id3v2 -l LMP68.mp3</p>

<p>

</p>

<p>
61</p>

<p>
This provides output as a series of lines containing the official 4 character identifiers from the standard, a description of the identifiers, and the text provided by the authors.</p>

<p>
The identifiers include TIT2 indicating title, TALB indicating show title, TRCK indicating track number, and a number of others.</p>

<p>
You can see the full output in the show notes.</p>

<p>

</p>

<p>

</p>

<p>
id3v2 tag info for LMP68.mp3:</p>

<p>
TIT2 (Title/songname/content description): 68: Frameworks, Filesystems and Fixes</p>

<p>
TPE1 (Lead performer(s)/Soloist(s)): Linux Matters</p>

<p>
TALB (Album/Movie/Show title): Linux Matters</p>

<p>
TYER (Year): 2025</p>

<p>
TRCK (Track number/Position in set): 68</p>

<p>
COMM (Comments): ()[]: https://linuxmatters.sh/</p>

<p>
APIC (Attached picture): (LMP-3000-moon.jpg)[, 3]: image/jpeg, 554576 bytes</p>

<p>
LMP68.mp3: No ID3v1 tag</p>

<p>

</p>

<p>
62</p>

<p>
From this we can see what the id3v2 program would normally do with ID3v2 tags. </p>

<p>
Note that it outputs the actual 4 character identifiers, plus a description of what they mean, and then the actual data.</p>

<p>
This helps when trying to understand the actual encoding of the data.</p>

<p>

</p>

<p>

</p>

<p>
63 Using ffprobe</p>

<p>
Now let's try that with ffprobe.</p>

<p>

</p>

<p>
The command is</p>

<p>

</p>

<p>
ffprobe -hide_banner LMP68.mp3</p>

<p>

</p>

<p>
64</p>

<p>
This provides the same publisher provided data as before.</p>

<p>
However it does not display the 4 character identifiers but instead uses its own format for display.</p>

<p>

</p>

<p>
Also note in both cases that there is a picture embedded in the MP3 file which is used to generate an icon for display in your file manager.</p>

<p>

</p>

<p>
With ffprobe this results in there being two keys called "title" and two keys called "comment". </p>

<p>
This makes grepping for the metadata more complicated, but it should still be possible.</p>

<p>
You can see the full output in the show notes.</p>

<p>

</p>

<p>

</p>

<p>
Input #0, mp3, from 'LMP68.mp3':</p>

<p>
  Metadata:</p>

<p>
	title           : 68: Frameworks, Filesystems and Fixes</p>

<p>
	artist          : Linux Matters</p>

<p>
	album           : Linux Matters</p>

<p>
	comment         : https://linuxmatters.sh/</p>

<p>
	track           : 68</p>

<p>
	date            : 2025</p>

<p>
  Duration: 00:28:12.45, start: 0.025056, bitrate: 114 kb/s</p>

<p>
  Stream #0:0: Audio: mp3, 44100 Hz, mono, fltp, 112 kb/s</p>

<p>
	Metadata:</p>

<p>
	  encoder         : LAME3.100</p>

<p>
  Stream #0:1: Video: mjpeg (Progressive), yuvj444p(pc, bt470bg/unknown/unknown), 4166x4166 [SAR 72:72 DAR 1:1], 90k tbr, 90k tbn (attached pic)</p>

<p>
	Metadata:</p>

<p>
	  title           : LMP-3000-moon.jpg</p>

<p>
	  comment         : Cover (front)</p>

<p>

</p>

<p>

</p>

<p>

</p>

<p>
65 Episode 82</p>

<p>
Now lets try that again with a different episode, 82.</p>

<p>

</p>

<p>
Using id3v2</p>

<p>

</p>

<p>
The command for id3v2 is</p>

<p>

</p>

<p>
id3v2 -l LMP82.mp3</p>

<p>

</p>

<p>
This results in id3v2 saying</p>

<p>

</p>

<p>
LMP82.mp3: No ID3 tag</p>

<p>

</p>

<p>
What happened here?</p>

<p>

</p>

<p>
66 Using ffprobe</p>

<p>

</p>

<p>
Let's try that again with ffprobe.</p>

<p>
The command</p>

<p>

</p>

<p>
ffprobe -hide_banner LMP82.mp3</p>

<p>

</p>

<p>
provides the expected output.</p>

<p>

</p>

<p>
Input #0, mp3, from 'LMP82.mp3':</p>

<p>
  Metadata:</p>

<p>
	date            : 2026-05</p>

<p>
	title           : 82: Ditching Grammarly for Open Sauce</p>

<p>
	album           : Linux Matters</p>

<p>
	track           : 82</p>

<p>
	artist          : Linux Matters</p>

<p>
	comment         : https://linuxmatters.sh</p>

<p>
  Duration: 00:33:37.83, start: 0.025056, bitrate: 113 kb/s</p>

<p>
  Stream #0:0: Audio: mp3, 44100 Hz, mono, fltp, 112 kb/s</p>

<p>
  Stream #0:1: Video: png, rgb24(pc, gbr/unknown/unknown), 3000x3000, 90k tbr, 90k tbn (attached pic)</p>

<p>
	Metadata:</p>

<p>
	  title           : Linux Matters Logo</p>

<p>
	  comment         : Cover (front)</p>

<p>

</p>

<p>
67</p>

<p>
This results in a few minor changes from episode 68, but otherwise it looks the same.</p>

<p>
So there are ID3 tags, but for some reason id3v2 couldn't recognize them.</p>

<p>

</p>

<p>
A bit more research and experimentation shows that this change appears to have happened right after episode 68, when they changed hosting and processing arrangements.</p>

<p>

</p>

<p>
I suspect that something changed with respect to the ID3v2 tag formatting somewhere along the way in the change over, and this in turn has affected the ability of the id3v2 program to recognize the tags.</p>

<p>

</p>

<p>
I will come back to the implications of this later in my conclusions.</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
68 Stripping ID3 Tags</p>

<p>

</p>

<p>
Now let's turn to a differen topic. </p>

<p>

</p>

<p>
Stripping ID3 tags refers to removing the ID3 tags from the audio file.</p>

<p>

</p>

<p>
I will start off by emphasizing that normally, you don't want to do this.</p>

<p>
You should only be doing it if you suspect the ID3 tags are causing a problem with the playback or ordering of the files.</p>

<p>

</p>

<p>
69</p>

<p>
In my case I do it when I have problems with my MP3 player when playing certain podcasts.</p>

<p>
This MP3 player orders files according to ID3 tags rather than by file name.</p>

<p>
This can result in the podcasts being played in an unpredictable order which I find undesirable.</p>

<p>
This is particularly a problem with podcasts from certain publishers where the title data does not follow any consistent pattern, but is whatever someone felt like doing that day.</p>

<p>

</p>

<p>
70</p>

<p>
I also often have to normalize the files from the same publishers to get a consistent audio loudness.</p>

<p>
See my series on Simple Podcasting for information on how to use ffmpeg to normalize the audio loudness.</p>

<p>

</p>

<p>
The solution to the inconsistent tag formats in these cases is to simply strip the ID3 tags altogether.</p>

<p>
The player then falls back on using the file names, and I can readily rename the files to a consistent format.</p>

<p>

</p>

<p>
I have never had these sorts of problems with HPR podcasts.</p>

<p>
If you are not having any problems of this nature, then as I said, don't bother stripping the tags.</p>

<p>

</p>

<p>
71</p>

<p>
To strip the ID3 tags from an MP3 file use the following.</p>

<p>

</p>

<p>
id3v2 -D hpr4678.mp3</p>

<p>

</p>

<p>
id3v2 will strip the tags and overwrite the existing file.</p>

<p>
If you wish to keep a copy with the tags, be sure to keep a backup before you try things.</p>

<p>

</p>

<p>
72</p>

<p>
When it comes to stripping tags, the options are</p>

<p>

</p>

<p>
"-s" deletes ID3v1 tags.</p>

<p>
"-d" deletes ID3v2 tags.</p>

<p>
"-D" deletes both v1 and v2 tags.</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
73 Conclusions</p>

<p>

</p>

<p>
In this episode we took a very brief look at ID3 tags and vorbis comments and ways of reading them.</p>

<p>

</p>

<p>
74</p>

<p>
ID3 tags and Vorbis comments provide a means of allowing information about an MP3 or OGG Vorbis file to be embedded in the file itself.</p>

<p>
Podcast publishers very often use this to label the file with information such as title, publisher, and author.</p>

<p>
We can read this information using Fee Software tools such as ffprobe, ID3v2, and vorbiscomment.</p>

<p>

</p>

<p>
75</p>

<p>
ID3 tags seem to be a mess with more than one incompatible versions, and difficulties in reading them even within the same version.</p>

<p>
They are difficult to test for because there is so much hardware out there of varying ages, much of which you will never have heard of let alone had access to.</p>

<p>
If you are recording episodes for HPR you do not have to worry about this, as HPR will do this behind the scenes for you.</p>

<p>
However, if you are responsible for producing a podcast or other similar audio and you have a setup that works, it is probably best not to change anything without good reason. </p>

<p>

</p>

<p>
76</p>

<p>
Vorbis comments seem to be much less of a problem.</p>

<p>
However, there are far fewer devices which can play OGG files compared to MP3, so simply switching to OGG may not be a realistic solution to the ID3 tag problem.</p>

<p>

</p>

<p>
77</p>

<p>
If you wish to have one tool that can read ID3 tags of all sorts and vorbis comments, then ffprobe is your obvious choice.</p>

<p>

</p>

<p>
78</p>

<p>
The ID3v2 program will provide more information about the ID3 tags, including the actual identifiers used. However, it does not work in all cases.</p>

<p>

</p>

<p>
79</p>

<p>
The vorbiscomment program will read Vorbis comments from OGG files in a manner which is closer to the actual vorbis format than ffprobe does, which uses its own display format.</p>

<p>

</p>

<p>
80</p>

<p>
HPR includes both ID3v1 and ID3v2 tags in its MP3 files. </p>

<p>
ffprobe can be used to read the ID3v2 tags, and the id3v2 program can be used to read the ID3v1 tags.</p>

<p>
You can also read the ID3v1 tags using the tail command.</p>

<p>

</p>

<p>
81</p>

<p>
I have barely scratched the surface of this subject and have not talked at all about creating tags or comments.</p>

<p>
If anyone else would like to take up the challenge of providing more detail, or of correcting any mistakes that  have made, please send in a podcast episode on the subject.</p>

<p>
If you have any comments you would like to make, leave them in the comment section below this episode on the HPR web site.</p>

<p>

</p>

<p>
82</p>

<p>
I hope to see you all again in future in another episode of HPR.</p>

<p>

</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
References</p>

<p>

</p>

<p>
https://id3.org/Introduction</p>

<p>
https://www.xiph.org/</p>

<p>
https://wiki.xiph.org/VorbisComment</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>

</p>


<p><a href="https://hackerpublicradio.org/eps/hpr4698/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Trump administration reportedly drafting ban on Chinese datacenter components]]></title>
<description><![CDATA[Trump’s FCC is developing a measure to bar US imports of new models of Chinese datacenter devices, sources sayThe Trump administration is reportedly drafting a ban on US imports of new models of Chinese datacenter components, in the latest sign US authorities are scrambling to respond to the rapi...]]></description>
<link>https://tsecurity.de/de/3704519/it-nachrichten/trump-administration-reportedly-drafting-ban-on-chinese-datacenter-components/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3704519/it-nachrichten/trump-administration-reportedly-drafting-ban-on-chinese-datacenter-components/</guid>
<pubDate>Wed, 05 Aug 2026 01:31:46 +0200</pubDate>
<content:encoded><![CDATA[<p>Trump’s FCC is developing a measure to bar US imports of new models of Chinese datacenter devices, sources say</p><p>The Trump administration is reportedly drafting a ban on US imports of new models of Chinese datacenter components, in the latest sign US authorities are scrambling to respond to the rapid development of AI technology in China.</p><p>Four people familiar with the matter told Reuters that the Federal Communications Commission (FCC), which oversees the US ⁠telecommunications industry, is developing a measure to bar imports of new ​Chinese optical transceivers, which allow data to travel over fiber-optic cables at the speed of light within datacenters. Officials hope to publish the measure this year, according to Reuters.</p> <a href="https://www.theguardian.com/technology/2026/aug/04/fcc-ban-china-datacenter-devices">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Next.js 16.3 aims to reduce dreaded FATAL ERROR messages]]></title>
<description><![CDATA[New React framework lowers memory usage by 90%, team claims]]></description>
<link>https://tsecurity.de/de/3704368/it-nachrichten/nextjs-163-aims-to-reduce-dreaded-fatal-error-messages/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3704368/it-nachrichten/nextjs-163-aims-to-reduce-dreaded-fatal-error-messages/</guid>
<pubDate>Tue, 04 Aug 2026 23:25:48 +0200</pubDate>
<content:encoded><![CDATA[New React framework lowers memory usage by 90%, team claims]]></content:encoded>
</item>
<item>
<title><![CDATA[VerseApp - a free open source multi-format reader app]]></title>
<description><![CDATA[Link to the Github Repo After jumping on Linux a couple of years ago the only app I've found quite literally no alternatives for was SumatraPDF, the devs have no intentions to port it on Linux, bummer (although makes sense considering the fact how the app was written). You can run it through Wine...]]></description>
<link>https://tsecurity.de/de/3704351/linux-tipps/verseapp-a-free-open-source-multi-format-reader-app/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3704351/linux-tipps/verseapp-a-free-open-source-multi-format-reader-app/</guid>
<pubDate>Tue, 04 Aug 2026 23:15:20 +0200</pubDate>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p><a href="https://github.com/levtblanc/VerseApp">Link to the Github Repo</a></p> <p>After jumping on Linux a couple of years ago the only app I've found quite literally no alternatives for was SumatraPDF, the devs have no intentions to port it on Linux, bummer (although makes sense considering the fact how the app was written). You can run it through Wine but we all want native applications, right?</p> <p>The only app that matches the feel and functionality was Okular (native KDE application), but damn this app eats through your RAM like crazy and it doesn't save the last session (you can do it with some terminal quirks tho), again bummer.</p> <p>Basically this is how VerseApp came to be, rust only, fast, saves your session so it reopens your files again, it uses MuPDF engine just like SumatraPDF, hustle free, aware that your RAM isn't bottomless well, it's still rough around the edges, consider this more like a proof of concept application really.</p> <p>I'll try to keep the development going, but begs mentioning coding is not my cup of tea, not my cup of tea indeed, so if you actually know and enjoy what you're doing help is welcomed. </p> <p>It's usable tho, I hope. There's an Appimage so go ahead and try it.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Sigma_Kek"> /u/Sigma_Kek </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1vfn3fi/verseapp_a_free_open_source_multiformat_reader_app/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1vfn3fi/verseapp_a_free_open_source_multiformat_reader_app/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[With FCC ban on new Chinese-made optical transceivers for DCs likely, it may be time to stock up]]></title>
<description><![CDATA[A likely US administration ban on Chinese optical transceivers for AI data centers may have an unintended consequence: IT will rush to buy as many of the components as possible before restrictions kick in.



Reuters on Tuesday reported that the US Federal Communications Commission (FCC) “is work...]]></description>
<link>https://tsecurity.de/de/3704344/it-nachrichten/with-fcc-ban-on-new-chinese-made-optical-transceivers-for-dcs-likely-it-may-be-time-to-stock-up/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3704344/it-nachrichten/with-fcc-ban-on-new-chinese-made-optical-transceivers-for-dcs-likely-it-may-be-time-to-stock-up/</guid>
<pubDate>Tue, 04 Aug 2026 23:04:35 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">A likely US administration ban on Chinese optical transceivers for AI data centers may have an unintended consequence: IT will rush to buy as many of the components as possible before restrictions kick in.</p>



<p class="wp-block-paragraph">Reuters on Tuesday <a href="https://www.reuters.com/world/trump-administration-drafting-ban-chinese-data-center-devices-sources-say-2026-08-04/" target="_blank" rel="noreferrer noopener">reported</a> that the US Federal Communications Commission (FCC) “is working on the measure to bar imports of new Chinese optical transceivers” and that officials hope to publish and implement it this year. </p>



<p class="wp-block-paragraph">The report, from unnamed sources, said that the official rationale is “to prevent Chinese firms from stealing data, installing malware or disrupting service at US data centers.” The sources did, however, stress that such a ban could still be modified or shelved.</p>



<h2 class="wp-block-heading">A valid concern</h2>



<p class="wp-block-paragraph">Analysts and consultants agree that the concern, albeit hypothetical at the moment, is valid. </p>



<p class="wp-block-paragraph">If implemented, such a ban would have a severe impact on data center (DC) strategies for both enterprises and hyperscalers. Although higher costs for replacement products would be all but certain, the greater concern is the lack of availability of non-Chinese transceivers and other components, regardless of price. </p>



<p class="wp-block-paragraph">A potentially even more worrying element of a ban is the need for far more sophisticated supply chain visibility. That is because many of those non-Chinese component suppliers actually use some Chinese components in their products, which means that the exact wording of any potential FCC restrictions will be critical. It will define how closely enterprises will need to examine their suppliers’ supply chains.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/akm76/" target="_blank" rel="noreferrer noopener">Aman Mahapatra</a>, chief strategy officer for Tribeca Softtech, a New York City-based technology consulting firm, said that he thinks that an FCC ban is quite likely, because it “has run this exact playbook four times in eighteen months, against drones, routers, robots, and the July 28 inverter and robotics restrictions. The mechanism is tested, the machinery is warm.”</p>



<p class="wp-block-paragraph">If the ban is enacted, said geopolitical analyst <a href="https://www.linkedin.com/in/irina-tsukerman-4b04595/" target="_blank" rel="noreferrer noopener">Irina Tsukerman</a>, “CIOs will need to reassess vendor diversification, and other factors such as replacement compatibility, lifecycle planning and inventory management, given that many organizations have historically treated optical components as interchangeable commodities.”</p>



<p class="wp-block-paragraph">“Enterprises will also need much greater visibility into firmware development, manufacturing origin, as well as subcontractors, and software update processes, because future procurement decisions are increasingly likely to examine the entire supply chain rather than simply the company selling the finished product,” she added. This will make future procurement more complex.</p>



<h2 class="wp-block-heading">IT pain will vary</h2>



<p class="wp-block-paragraph">Tsukerman said that, although prices would certainly spike, the pain felt will vary based on the nature and size of each affected business She noted that while hyperscale operators can negotiate directly with manufacturers, secure long-term supply, and qualify multiple vendors for critical components due to their purchasing power, enterprises, regional data center operators, and colocation providers generally lack that leverage. Rather, they often depend on distributors supplying lower-cost Chinese products, making them considerably more vulnerable to price increases and delivery delays.</p>



<p class="wp-block-paragraph">Mahapatra added that the preliminary indications suggest any such ban would have a “new models only” framing that would protect the installed base while restricting the next generation of products, which, he said, would be a compromise “generous enough to mute the hyperscaler objection.”</p>



<p class="wp-block-paragraph">But, he said, “the enterprise CIO running a colocation expansion or private AI cluster is about to discover they are competing with Microsoft and Meta for the same constrained supply and losing.” </p>



<p class="wp-block-paragraph">He recommended that enterprises lock down forward optics supply for anything they plan to build through 2028 before the restriction publishes, because, he pointed out, “announced-but-not-effective bans consume non-Chinese capacity through panic buying, and buyers who move after publication pay in schedule rather than dollars.”</p>



<p class="wp-block-paragraph">However, such a move depends on how serious IT considers the cybersecurity risks from the Chinese components. Tsukerman argued that data leakage and malware fears need to be taken seriously, because modern optical transceivers often contain firmware, onboard memory, and management interfaces, and may also offer capabilities that can influence how traffic is monitored and managed throughout the data center.</p>



<p class="wp-block-paragraph">In that case, she noted, “the risk would extend beyond espionage to include compromised firmware updates, manipulation of diagnostic information, disruption of maintenance support, delayed replacement shipment, or in the worst case scenario, interference with critical infrastructure during periods of heightened political tension.”</p>



<p class="wp-block-paragraph">However, Mahapatra sees the risk quite differently.</p>



<p class="wp-block-paragraph">“A transceiver is a comparatively dumb device converting electrical signals to optical and back, not a router running a network operating system with deep packet visibility,” he said. “The near-term espionage risk from currently shipping Chinese optics is thin, and CISOs who reallocate budget toward this threat over their software supply chain and identity attack surfaces are responding to headlines rather than risk.”</p>



<h2 class="wp-block-heading">The suppliers involved</h2>



<p class="wp-block-paragraph">Consultant <a href="https://formergov.com/directory/brianlevine" target="_blank" rel="noreferrer noopener">Brian Levine</a>, executive director of FormerGov, labeled the potential US administration move as “one of the more consequential supply-chain moves the FCC has contemplated, because optical transceivers are the workhorse components that move data across fiber inside every AI data center, and Chinese vendors dominate that market.”</p>



<p class="wp-block-paragraph">He noted that Chinese vendors Innolight and Eoptolink alone reportedly account for the majority of the 800-gig modules going into Nvidia’s AI clusters, so a ban “wouldn’t be a minor substitution,” and non-Chinese alternatives such as Coherent and Lumentum in the US don’t yet have sufficient capacity to fill the gap.</p>



<p class="wp-block-paragraph"><a href="https://www.gartner.com/en/experts/nader-henein" target="_blank" rel="noreferrer noopener">Nader Henein</a>, a Gartner VP analyst, agreed, adding that since the nature of the AI data center supply chain is both complex and fragile, a small change can deliver a disproportionate industry impact.</p>



<p class="wp-block-paragraph">“If you remove one provider from the equation, it’s not as if the others have capacity to fulfil the increase in demand, so it’s not simply a question of added cost, it’s a question of placing a ceiling on capacity and growth,” he said.</p>



<p class="wp-block-paragraph">Tsukerman said that her list of the companies most likely to benefit from such an FCC ban would include Coherent, Lumentum, Applied Optoelectronics and Cisco’s Acacia business, while Broadcom and Marvell, as well as  Japanese and Taiwanese manufacturers, also provide important optical and connectivity technologies that support advanced networking infrastructure.</p>



<h2 class="wp-block-heading">Other components in the crosshairs</h2>



<p class="wp-block-paragraph">She pointed out that there is also a strong probability that a transceiver ban would quickly be followed by attacks on other components. </p>



<p class="wp-block-paragraph">Networking switches, SmartNICs, data processing units, baseboard management controllers, storage controllers, intelligent power distribution units, cooling management controllers, optical transport systems, and embedded management processors “all perform functions that could influence the operation of an entire facility if compromised,” she said. “None of these products simply passes data or delivers electricity. They manage, monitor, or control critical infrastructure, making them increasingly attractive targets for supply-chain attacks.”</p>



<p class="wp-block-paragraph">Her list of likely future US targets for restrictions also includes top-of-rack switches, spine switches, and rack management systems,.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/fvillanustre/" target="_blank" rel="noreferrer noopener">Flavio Villanustre</a>, CISO for the LexisNexis Risk Solutions Group, echoed Henein’s fears about industry impact.</p>



<p class="wp-block-paragraph">“I think that the appropriate response to these types of risks needs to be more nuanced than just a blanket ban,” he said. “Since 15%-20% of all world’s semiconductors are manufactured in China, and that number rises to 80% or 85% if you include Taiwan, blocking Chinese imports for these components could hamper the entire datacenter industry.”</p>



<p class="wp-block-paragraph">Although there have been rumors of insecure or trojanized hardware components sourced from China in the past, given that many large American and multinational technology vendors manufacture their parts there, ”a sledgehammer approach could spike prices for these types of systems, jeopardizing development of new technologies,” he noted. “A far more reasonable approach would be to require appropriate testing and quality controls to ensure that those risks are appropriately mitigated.”</p>



<h2 class="wp-block-heading">Would likely harm the US</h2>



<p class="wp-block-paragraph">In addition, independent technology analyst <a href="https://www.linkedin.com/in/carmi/" target="_blank" rel="noreferrer noopener">Carmi Levy</a> said that he is skeptical about whether an FCC ban would ultimately be a good move for the US.</p>



<p class="wp-block-paragraph">“It’s fair to ask whether this will truly make American technology infrastructure more secure, or whether it’s little more than a performative stunt designed to score geopolitical points,” Levy said, pointing out that Canada didn’t end up any safer because of the Huawei and ZTE ban, and “no one should fool themselves into believing a Chinese data center ban in the US would be any different. It would only add further constraints to a supply chain that’s already close to collapsing under its own weight [and it] will likely harm American interests more than anyone else’s.”</p>



<p class="wp-block-paragraph">But he also concluded that such a move would likely fail, given the current global state of data center technologies. </p>



<p class="wp-block-paragraph">“Chinese suppliers and components have been so ingrained in the global technology supply chain for so long that no ban of any form could hope to have any tangible impact on so-called national security,” Levy said. “To claim otherwise exposes the true motivations of this misdirected policy strategy.”</p>



<p class="wp-block-paragraph"><em>This article originally appeared on <a href="https://www.networkworld.com/article/4205228/with-fcc-ban-on-new-chinese-made-optical-transceivers-for-dcs-likely-it-may-be-time-to-stock-up.html" target="_blank">NetworkWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Seeks Injunction Against OpenAI in Trade Secrets Lawsuit]]></title>
<description><![CDATA[Apple has asked a federal court to issue a preliminary injunction against OpenAI, arguing that the company will suffer irreparable harm unless the court quickly blocks any further use of its confidential information.



The request forms part of Apple’s ongoing trade secrets lawsuit against OpenA...]]></description>
<link>https://tsecurity.de/de/3704309/ios-mac-os/apple-seeks-injunction-against-openai-in-trade-secrets-lawsuit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3704309/ios-mac-os/apple-seeks-injunction-against-openai-in-trade-secrets-lawsuit/</guid>
<pubDate>Tue, 04 Aug 2026 22:58:22 +0200</pubDate>
<content:encoded><![CDATA[Apple has asked a federal court to issue a preliminary injunction against OpenAI, arguing that the company will suffer irreparable harm unless the court quickly blocks any further use of its confidential information.



The request forms part of Apple’s ongoing trade secrets lawsuit against OpenAI, which centers on allegations that former Apple employees took sensitive information and used it to support OpenAI’s hardware development work.



Apple said it contacted OpenAI after filing the original lawsuit and offered to avoid seeking an injunction if the company accepted five conditions. OpenAI agreed to stop accessing or using Apple’s confidential information, halt any ongoing disclosure, and preserve relevant evidence.



However, the companies failed to agree on Apple’s remaining demands, which included forensic inspections of devices, cloud storage, email accounts, Slack, Microsoft Teams, and other repositories. Apple also wanted OpenAI to search its systems for any confidential Apple material.



Apple wants faster discovery



Apple is now asking the court to stop OpenAI from obtaining or using its trade secrets, preserve all evidence, allow forensic inspections, and return any confidential information still held by the company.



In its filing, Apple said the alleged harm continues each day because OpenAI can further include the stolen information in its hardware development plans, making the damage harder to reverse.



Apple also filed a separate motion seeking expedited discovery, including early document production and depositions from key OpenAI employees and executives.



OpenAI recently published a detailed response describing Apple’s lawsuit as careless, aggressive, and unusually personal. The company also questioned whether the case reflects Apple’s wider reputation.



The court has scheduled a hearing on Apple’s preliminary injunction request for October 1, 2026.]]></content:encoded>
</item>
<item>
<title><![CDATA[With FCC ban on new Chinese-made optical transceivers for DCs likely, it may be time to stock up]]></title>
<description><![CDATA[A likely US administration ban on Chinese optical transceivers for AI data centers may have an unintended consequence: IT will rush to buy as many of the components as possible before restrictions kick in.



Reuters on Tuesday reported that the US Federal Communications Commission (FCC) “is work...]]></description>
<link>https://tsecurity.de/de/3704298/it-security-nachrichten/with-fcc-ban-on-new-chinese-made-optical-transceivers-for-dcs-likely-it-may-be-time-to-stock-up/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3704298/it-security-nachrichten/with-fcc-ban-on-new-chinese-made-optical-transceivers-for-dcs-likely-it-may-be-time-to-stock-up/</guid>
<pubDate>Tue, 04 Aug 2026 22:42:37 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">A likely US administration ban on Chinese optical transceivers for AI data centers may have an unintended consequence: IT will rush to buy as many of the components as possible before restrictions kick in.</p>



<p class="wp-block-paragraph">Reuters on Tuesday <a href="https://www.reuters.com/world/trump-administration-drafting-ban-chinese-data-center-devices-sources-say-2026-08-04/" target="_blank" rel="noreferrer noopener">reported</a> that the US Federal Communications Commission (FCC) “is working on the measure to bar imports of new Chinese optical transceivers” and that officials hope to publish and implement it this year. </p>



<p class="wp-block-paragraph">The report, from unnamed sources, said that the official rationale is “to prevent Chinese firms from stealing data, installing malware or disrupting service at US data centers.” The sources did, however, stress that such a ban could still be modified or shelved.</p>



<h2 class="wp-block-heading">A valid concern</h2>



<p class="wp-block-paragraph">Analysts and consultants agree that the concern, albeit hypothetical at the moment, is valid. </p>



<p class="wp-block-paragraph">If implemented, such a ban would have a severe impact on data center (DC) strategies for both enterprises and hyperscalers. Although higher costs for replacement products would be all but certain, the greater concern is the lack of availability of non-Chinese transceivers and other components, regardless of price. </p>



<p class="wp-block-paragraph">A potentially even more worrying element of a ban is the need for far more sophisticated supply chain visibility. That is because many of those non-Chinese component suppliers actually use some Chinese components in their products, which means that the exact wording of any potential FCC restrictions will be critical. It will define how closely enterprises will need to examine their suppliers’ supply chains.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/akm76/" target="_blank" rel="noreferrer noopener">Aman Mahapatra</a>, chief strategy officer for Tribeca Softtech, a New York City-based technology consulting firm, said that he thinks that an FCC ban is quite likely, because it “has run this exact playbook four times in eighteen months, against drones, routers, robots, and the July 28 inverter and robotics restrictions. The mechanism is tested, the machinery is warm.”</p>



<p class="wp-block-paragraph">If the ban is enacted, said geopolitical analyst <a href="https://www.linkedin.com/in/irina-tsukerman-4b04595/" target="_blank" rel="noreferrer noopener">Irina Tsukerman</a>, “CIOs will need to reassess vendor diversification, and other factors such as replacement compatibility, lifecycle planning and inventory management, given that many organizations have historically treated optical components as interchangeable commodities.”</p>



<p class="wp-block-paragraph">“Enterprises will also need much greater visibility into firmware development, manufacturing origin, as well as subcontractors, and software update processes, because future procurement decisions are increasingly likely to examine the entire supply chain rather than simply the company selling the finished product,” she added. This will make future procurement more complex.</p>



<h2 class="wp-block-heading">IT pain will vary</h2>



<p class="wp-block-paragraph">Tsukerman said that, although prices would certainly spike, the pain felt will vary based on the nature and size of each affected business She noted that while hyperscale operators can negotiate directly with manufacturers, secure long-term supply, and qualify multiple vendors for critical components due to their purchasing power, enterprises, regional data center operators, and colocation providers generally lack that leverage. Rather, they often depend on distributors supplying lower-cost Chinese products, making them considerably more vulnerable to price increases and delivery delays.</p>



<p class="wp-block-paragraph">Mahapatra added that the preliminary indications suggest any such ban would have a “new models only” framing that would protect the installed base while restricting the next generation of products, which, he said, would be a compromise “generous enough to mute the hyperscaler objection.”</p>



<p class="wp-block-paragraph">But, he said, “the enterprise CIO running a colocation expansion or private AI cluster is about to discover they are competing with Microsoft and Meta for the same constrained supply and losing.” </p>



<p class="wp-block-paragraph">He recommended that enterprises lock down forward optics supply for anything they plan to build through 2028 before the restriction publishes, because, he pointed out, “announced-but-not-effective bans consume non-Chinese capacity through panic buying, and buyers who move after publication pay in schedule rather than dollars.”</p>



<p class="wp-block-paragraph">However, such a move depends on how serious IT considers the cybersecurity risks from the Chinese components. Tsukerman argued that data leakage and malware fears need to be taken seriously, because modern optical transceivers often contain firmware, onboard memory, and management interfaces, and may also offer capabilities that can influence how traffic is monitored and managed throughout the data center.</p>



<p class="wp-block-paragraph">In that case, she noted, “the risk would extend beyond espionage to include compromised firmware updates, manipulation of diagnostic information, disruption of maintenance support, delayed replacement shipment, or in the worst case scenario, interference with critical infrastructure during periods of heightened political tension.”</p>



<p class="wp-block-paragraph">However, Mahapatra sees the risk quite differently.</p>



<p class="wp-block-paragraph">“A transceiver is a comparatively dumb device converting electrical signals to optical and back, not a router running a network operating system with deep packet visibility,” he said. “The near-term espionage risk from currently shipping Chinese optics is thin, and CISOs who reallocate budget toward this threat over their software supply chain and identity attack surfaces are responding to headlines rather than risk.”</p>



<h2 class="wp-block-heading">The suppliers involved</h2>



<p class="wp-block-paragraph">Consultant <a href="https://formergov.com/directory/brianlevine" target="_blank" rel="noreferrer noopener">Brian Levine</a>, executive director of FormerGov, labeled the potential US administration move as “one of the more consequential supply-chain moves the FCC has contemplated, because optical transceivers are the workhorse components that move data across fiber inside every AI data center, and Chinese vendors dominate that market.”</p>



<p class="wp-block-paragraph">He noted that Chinese vendors Innolight and Eoptolink alone reportedly account for the majority of the 800-gig modules going into Nvidia’s AI clusters, so a ban “wouldn’t be a minor substitution,” and non-Chinese alternatives such as Coherent and Lumentum in the US don’t yet have sufficient capacity to fill the gap.</p>



<p class="wp-block-paragraph"><a href="https://www.gartner.com/en/experts/nader-henein" target="_blank" rel="noreferrer noopener">Nader Henein</a>, a Gartner VP analyst, agreed, adding that since the nature of the AI data center supply chain is both complex and fragile, a small change can deliver a disproportionate industry impact.</p>



<p class="wp-block-paragraph">“If you remove one provider from the equation, it’s not as if the others have capacity to fulfil the increase in demand, so it’s not simply a question of added cost, it’s a question of placing a ceiling on capacity and growth,” he said.</p>



<p class="wp-block-paragraph">Tsukerman said that her list of the companies most likely to benefit from such an FCC ban would include Coherent, Lumentum, Applied Optoelectronics and Cisco’s Acacia business, while Broadcom and Marvell, as well as  Japanese and Taiwanese manufacturers, also provide important optical and connectivity technologies that support advanced networking infrastructure.</p>



<h2 class="wp-block-heading">Other components in the crosshairs</h2>



<p class="wp-block-paragraph">She pointed out that there is also a strong probability that a transceiver ban would quickly be followed by attacks on other components. </p>



<p class="wp-block-paragraph">Networking switches, SmartNICs, data processing units, baseboard management controllers, storage controllers, intelligent power distribution units, cooling management controllers, optical transport systems, and embedded management processors “all perform functions that could influence the operation of an entire facility if compromised,” she said. “None of these products simply passes data or delivers electricity. They manage, monitor, or control critical infrastructure, making them increasingly attractive targets for supply-chain attacks.”</p>



<p class="wp-block-paragraph">Her list of likely future US targets for restrictions also includes top-of-rack switches, spine switches, and rack management systems,.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/fvillanustre/" target="_blank" rel="noreferrer noopener">Flavio Villanustre</a>, CISO for the LexisNexis Risk Solutions Group, echoed Henein’s fears about industry impact.</p>



<p class="wp-block-paragraph">“I think that the appropriate response to these types of risks needs to be more nuanced than just a blanket ban,” he said. “Since 15%-20% of all world’s semiconductors are manufactured in China, and that number rises to 80% or 85% if you include Taiwan, blocking Chinese imports for these components could hamper the entire datacenter industry.”</p>



<p class="wp-block-paragraph">Although there have been rumors of insecure or trojanized hardware components sourced from China in the past, given that many large American and multinational technology vendors manufacture their parts there, ”a sledgehammer approach could spike prices for these types of systems, jeopardizing development of new technologies,” he noted. “A far more reasonable approach would be to require appropriate testing and quality controls to ensure that those risks are appropriately mitigated.”</p>



<h2 class="wp-block-heading">Would likely harm the US</h2>



<p class="wp-block-paragraph">In addition, independent technology analyst <a href="https://www.linkedin.com/in/carmi/" target="_blank" rel="noreferrer noopener">Carmi Levy</a> said that he is skeptical about whether an FCC ban would ultimately be a good move for the US.</p>



<p class="wp-block-paragraph">“It’s fair to ask whether this will truly make American technology infrastructure more secure, or whether it’s little more than a performative stunt designed to score geopolitical points,” Levy said, pointing out that Canada didn’t end up any safer because of the Huawei and ZTE ban, and “no one should fool themselves into believing a Chinese data center ban in the US would be any different. It would only add further constraints to a supply chain that’s already close to collapsing under its own weight [and it] will likely harm American interests more than anyone else’s.”</p>



<p class="wp-block-paragraph">But he also concluded that such a move would likely fail, given the current global state of data center technologies. </p>



<p class="wp-block-paragraph">“Chinese suppliers and components have been so ingrained in the global technology supply chain for so long that no ban of any form could hope to have any tangible impact on so-called national security,” Levy said. “To claim otherwise exposes the true motivations of this misdirected policy strategy.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI says Apple ‘is getting this wrong’ in response to trade secrets lawsuit]]></title>
<description><![CDATA[OpenAI has published its most detailed response yet to Apple's lawsuit accusing the company of stealing hardware trade secrets, pushing back against several of Apple's claims and arguing that the case is based on false information. 



Nearly a month after Apple filed its complaint, OpenAI releas...]]></description>
<link>https://tsecurity.de/de/3704194/ios-mac-os/openai-says-apple-is-getting-this-wrong-in-response-to-trade-secrets-lawsuit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3704194/ios-mac-os/openai-says-apple-is-getting-this-wrong-in-response-to-trade-secrets-lawsuit/</guid>
<pubDate>Tue, 04 Aug 2026 21:29:38 +0200</pubDate>
<content:encoded><![CDATA[OpenAI has published its most detailed response yet to Apple's lawsuit accusing the company of stealing hardware trade secrets, pushing back against several of Apple's claims and arguing that the case is based on false information. 



Nearly a month after Apple filed its complaint, OpenAI released a lengthy blog post explaining its side of the dispute, sharing email exchanges and defending former Apple executives who now work at the company.



Apple filed the lawsuit on July 10, alleging that former Apple employees took confidential information to help OpenAI's hardware efforts. Since then, OpenAI has issued a few brief statements denying the allegations, but its latest blog post marks the first time it has responded point by point while also publishing supporting documents and screenshots.



OpenAI strongly criticized Apple's legal approach and claimed the company never properly raised the specific concerns before filing the lawsuit.




"Apple is one of the greatest companies of all time, and built a reputation for obsessing over the smallest details. This careless, aggressive and oddly personal lawsuit sadly doesn't live up to that reputation."




OpenAI disputes Apple's claims and defends former employees



OpenAI also challenged Apple's timeline, saying Apple incorrectly claimed it had contacted the company before filing the lawsuit. According to OpenAI, Apple's lawyers initially emailed the wrong person and later admitted that its General Counsel never had the conversation Apple originally described.



OpenAI added that Apple told the company it was "resolving any issues" before remaining silent for several months and then filing the lawsuit.




"Apple had claimed that they contacted OpenAI in February and that we didn't respond. They now admit that their outside lawyers emailed the wrong person after confusing two Asian last names... We then heard nothing for five months until they sued."




The company also addressed Apple's allegations involving former Apple engineer Chang Liu, arguing that any continued access to Apple systems resulted from Apple's own account management practices after employees left the company.



OpenAI said Apple employees even contacted Liu after his departure and asked him to help locate certain information, adding that Apple later described the issue as "residual access."



Another major part of Apple's lawsuit focuses on former Apple executive Tang Tan, who spent more than two decades leading hardware development before joining OpenAI. The company defended Tan's conduct and said he consistently instructed his team not to use confidential information from previous employers.




"Tang has always been clear with the team that we do not want, and must not use, any confidential information from other companies."




OpenAI concluded its response by saying it would have welcomed discussions with Apple before the lawsuit and remains willing to resolve the dispute. The company also rejected Apple's request for a preliminary injunction, saying it neither possesses nor wants Apple's trade secrets because its focus remains on developing its own products and technologies.



The legal dispute now moves into the next stage as Apple continues pursuing its claims while OpenAI publicly challenges both Apple's timeline and several key allegations contained in the lawsuit.]]></content:encoded>
</item>
<item>
<title><![CDATA[77 Open VSX extensions found harvesting developer info]]></title>
<description><![CDATA[77 extensions on the Open VSX marketplace impersonated legitimate developer tools while transmitting information about the systems and development environments where they were installed. [...]]]></description>
<link>https://tsecurity.de/de/3704140/it-security-nachrichten/77-open-vsx-extensions-found-harvesting-developer-info/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3704140/it-security-nachrichten/77-open-vsx-extensions-found-harvesting-developer-info/</guid>
<pubDate>Tue, 04 Aug 2026 20:56:27 +0200</pubDate>
<content:encoded><![CDATA[77 extensions on the Open VSX marketplace impersonated legitimate developer tools while transmitting information about the systems and development environments where they were installed. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Arti 2.5.1 released]]></title>
<description><![CDATA[Arti is our ongoing project to create a next-generation Tor implementation in Rust.
We're happy to announce the latest release, Arti 2.5.1.
This release consists mostly of internal improvements and bug fixes,
as well as our ongoing development towards using Arti as a relay and as a directory auth...]]></description>
<link>https://tsecurity.de/de/3704062/it-security-tools/arti-251-released/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3704062/it-security-tools/arti-251-released/</guid>
<pubDate>Tue, 04 Aug 2026 20:27:05 +0200</pubDate>
<content:encoded><![CDATA[<article class="blog-post">
    <picture>
      <source media="(min-width:415px)" srcset="https://blog.torproject.org/arti_2_5_1_released/lead.webp" type="image/webp">
<source srcset="https://blog.torproject.org/arti_2_5_1_released/lead_small.webp" type="image/webp">

      <img class="lead" referrerpolicy="no-referrer" loading="lazy" src="https://blog.torproject.org/arti_2_5_1_released/lead.png">
    </picture>
    <div class="body"><p>Arti is our ongoing project to create a next-generation Tor implementation in Rust.
We're happy to announce the latest release, Arti 2.5.1.</p>
<p>This release consists mostly of internal improvements and bug fixes,
as well as our ongoing development towards using Arti as a relay and as a directory authority.
For onion service hosts,
onion services can now be configured to connect to unix socket addresses.
Arti also now has experimental support for congestion control
and <a href="https://blog.torproject.org/introducing-cgo/">Counter Galois Onion</a> cryptography on onion service circuits,
which we hope to make stable soon.</p>
<p>For full details on what we've done, including API changes,
and for information about many more minor and less-visible changes,
please see the <a href="https://gitlab.torproject.org/tpo/core/arti/-/blob/main/CHANGELOG.md?ref_type=heads#arti-251---3-august-2026">CHANGELOG</a>.</p>
<p>For more information on using Arti, see our top-level <a href="https://gitlab.torproject.org/tpo/core/arti/-/blob/main/README.md">README</a>,
and the documentation for the <a href="https://gitlab.torproject.org/tpo/core/arti/-/blob/main/crates/arti/README.md"><code>arti</code> binary</a>.</p>
<p>Thanks to everybody who's contributed to this release, including
Andrew Kloet, Jérôme Charaoui, hjrgrn, pryty26, ramdoys, and syphyr.</p>
<p>Also, our deep thanks to our <a href="https://www.torproject.org/about/sponsors/">sponsors</a> for funding the development of Arti!</p>

    </div>
  <div class="categories">
    <ul><li>
        <a href="https://blog.torproject.org/category/announcements">
          announcements
        </a>
      </li><li>
        <a href="https://blog.torproject.org/category/releases">
          releases
        </a>
      </li></ul>
  </div>
  </article>]]></content:encoded>
</item>
<item>
<title><![CDATA[Trump administration reportedly drafting ban on Chinese datacenter components]]></title>
<description><![CDATA[Trump’s FCC is developing a measure to bar US imports of new models of Chinese datacenter devices, sources sayThe Trump administration is reportedly drafting a ban on US imports of new models of Chinese datacenter components, in the latest sign US authorities are scrambling to respond to the rapi...]]></description>
<link>https://tsecurity.de/de/3704013/ai-nachrichten/trump-administration-reportedly-drafting-ban-on-chinese-datacenter-components/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3704013/ai-nachrichten/trump-administration-reportedly-drafting-ban-on-chinese-datacenter-components/</guid>
<pubDate>Tue, 04 Aug 2026 19:51:43 +0200</pubDate>
<content:encoded><![CDATA[<p>Trump’s FCC is developing a measure to bar US imports of new models of Chinese datacenter devices, sources say</p><p>The Trump administration is reportedly drafting a ban on US imports of new models of Chinese datacenter components, in the latest sign US authorities are scrambling to respond to the rapid development of AI technology in China.</p><p>Four people familiar with the matter told Reuters that the Federal Communications Commission (FCC), which oversees the US ⁠telecommunications industry, is developing a measure to bar imports of new ​Chinese optical transceivers, which allow data to travel over fiber-optic cables at the speed of light within datacenters. Officials hope to publish the measure this year, according to Reuters.</p> <a href="https://www.theguardian.com/technology/2026/aug/04/fcc-ban-china-datacenter-devices">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI coding agents are blowing through budgets — Replit, Kilo Code, and Symbotic explain how they're managing it]]></title>
<description><![CDATA[At Kilo Code, engineers are reading or writing code themselves only about 1% of the time now, according to co-founder Emilie Schario — the rest is agents. That shift is forcing new questions onto dev teams: which systems are safe to hand over, who cleans up when models goof up, how to support mul...]]></description>
<link>https://tsecurity.de/de/3703986/it-nachrichten/ai-coding-agents-are-blowing-through-budgets-replit-kilo-code-and-symbotic-explain-how-theyre-managing-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3703986/it-nachrichten/ai-coding-agents-are-blowing-through-budgets-replit-kilo-code-and-symbotic-explain-how-theyre-managing-it/</guid>
<pubDate>Tue, 04 Aug 2026 19:32:13 +0200</pubDate>
<content:encoded><![CDATA[<p>At Kilo Code, engineers are reading or writing code themselves only about 1% of the time now, according to co-founder Emilie Schario — the rest is agents. That shift is forcing new questions onto dev teams: which systems are safe to hand over, who cleans up when models goof up, how to support multi-model architectures, and whether skyrocketing token bills mean real progress or just burned IT budget.</p><p>As far as tech leads from Replit, Kilo Code, and Symbotic are concerned, it’s a natural — and welcome — evolution as agentic AI becomes embedded into more and more enterprise workflows. </p><p>“Unless something's really broken or debugging, 99% of the time engineers are not reading or writing code anymore,” Emilie Schario, co-founder of Kilo Code, said at <a href="https://venturebeat.com/vbtransform2026">VB Transform 2026</a>. </p><div></div><h2>AI good at greenfield, not so great at brownfield</h2><p>For Jared Go, distinguished engineer for AI and cloud at warehouse automation company Symbotic, the current moment is about directing the focus of AI. "These are my criteria," he said. "Let's look at it from the lens of security, elegance, clean, concise code, water tightness." That way, AI does most of the heavy lifting, and human code review isn't as critical.</p><p>Human involvement becomes necessary further down the line, Go noted, because agents don't make strong product decisions. “Greenfield [building brand new codebases] is so easy for agents. Brownfield [writing, updating, or maintaining existing code] we all know is where the actual challenge lies.” </p><p>Replit takes a bit of a different tack: While the company has "gone very agentic," they've been more conservative with AI coding, explained Amol Jain, head of product engineering. An agent reviews each pull request (PR) and assigns it a risk score; low-risk PRs are self-merged by their author, while others go to human reviewers who read the code and give feedback.</p><p>“The idea was human on the loop, not human in the loop,” Jain said. Replit’s internal tool is essentially self-driving for software engineers; devs give a task to agents, which do end to end planning, implementation, and testing. </p><p>“It's a fleet of agents that run in their own cloud virtual machines (VMs) with access controls behind token proxies so they're secure,” Jain said. </p><p>He shared one example where an engineer couldn’t repro or solve a “very gnarly bug” deep in its systems. It was sent to an AI manager agent, which told it to go to sleep. The manager agent then spun up a bunch of underlying agents that found the issue; it subsequently spun up a bunch more agents that found the fix. Six hours later, AI had a PR ready for the bug that had puzzled human engineers. </p><h2>Multi-model is the future </h2><p>AI providers are also evolving beyond the lock-in model, as customers increasingly demand multi-model choice. </p><p>Kilo Code, for its part, supports 500-plus models in its gateway. "Your software that you're using to do agentic engineering should be decoupled from the model that you're using to do it," Schario said.</p><p>For instance, Schario said companies often use expensive frontier-tier models to architect a project, then switch to a less expensive open-weight model for the rest of the work.</p><p>It’s also important to respect model provider limitations, such as when they need to work in closed or isolated environments or providers in their specific regions. “It's factoring in what's important to you, what limitations you've set, what data retention policies you've established, what keys you've brought in, what commits you might have … into that routing decision,” Schario said. </p><p>Replit, similarly, tends to have a better sense of the cost versus capability spectrum than its customers, Jain contended. “We are essentially making the decisions on users' behalf of what model to use when, in what capacity, to minimize cost and maximize capability.”</p><h2>To tokenmaxx or not to tokenmaxx</h2><p>Of course, an important consideration as AI adoption increases is runaway costs, which has led to some enterprises tracking and capping AI use through tokenmaxxing.</p><p>Concerns come from both sides, Schario said: internally and from customers. From the latter, she's hearing, "I accidentally spent my whole AI budget for the year … so what do I do now?" In response, Schario said Kilo Code points customers to the same workflow: use expensive models for planning, then open-weight models for affordability.</p><p>Further, sharing skills, strong guidance, and Model Context Protocol (MCP) will empower models. “Realizing where you can really uplevel your team to help them get the most out of the models they're using is going to make a big difference,” Schario said. </p><p>Internally, meanwhile, Schario noted one particular engineer that has a "heavy foot" and is constantly at the top of the usage board. "I regularly have to nudge, 'What are you doing there?'" she said. It's easy to look at a $600 bill for daily work and react, "Wow, that's so much," but looking at the amount of work completed can sometimes justify the cost.</p><p>“Cost per pull request is the metric that I'm paying attention to right now,” Schario said. “It feels like the closest proximity for how I can measure value.” Ultimately, AI changes how enterprises are thinking about ROI because spend is not the problem. “The spend with no return on that spend is the problem.” </p><p>Symbotic, for its part, has set per-month cost tiers for its employees. The company built a tool that gives managers visibility into PRs and usage trends. They can then move users up or down a tier as they see fit, Go explained. “Having a cap and seeing how many people went up in cap this month makes a big difference when you're trying to corral these costs and make things efficient,” Go said. </p><p>When Cursor — which Symbotic uses heavily — ended a legacy discount that had grandfathered the company into a flat per-request rate even for frontier models, and moved everyone to full pricing, it forced a company-wide reckoning on efficiency, Go said. "People were saying, 'You should try this model … This works better for this C# code, this whatever,'" he said.</p><p>But the cost problem is increasingly moving out of IT; Replit, for one, broadened agents beyond engineering, and eventually found that a user on the support side had "blown through an insane amount of money," Jain said. When they looked under the hood, they figured out it was because they were running an automation on GPT 5.5 Pro Max.</p><p>“At least till that point, the ROI was rather clear,” Jain said. “We could see engineering productivity 3X, so no one had questioned it yet.” </p><p>Visibility that isn’t “anti-productive,” model routing, and sensible defaults are critical, he emphasized. “Most tasks do not need the frontier.”</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[‘Apple is one of the greatest companies of all time,’ says OpenAI]]></title>
<description><![CDATA[In an open letter, OpenAI this week turned to the court of public opinion in its existential war against Apple with a public notice in which the company refutes the iPhone maker’s claims concerning wholesale use of confidential information.



You can detect the depth of enmity between both firms...]]></description>
<link>https://tsecurity.de/de/3703964/it-nachrichten/apple-is-one-of-the-greatest-companies-of-all-time-says-openai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3703964/it-nachrichten/apple-is-one-of-the-greatest-companies-of-all-time-says-openai/</guid>
<pubDate>Tue, 04 Aug 2026 19:11:56 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">In an <a href="https://openai.com/index/apple-is-getting-this-wrong/" target="_blank" rel="noreferrer noopener">open letter</a>, OpenAI this week turned to the court of public opinion in its existential <a href="https://www.computerworld.com/article/4195828/rotten-to-its-core-apple-files-an-explosive-lawsuit-against-openai.html">war against Apple</a> with a public notice in which the company refutes the iPhone maker’s claims concerning wholesale use of confidential information.</p>



<p class="wp-block-paragraph">You can detect the depth of enmity between both firms in OpenAI’s opening lines to its letter, which begins: “Apple is one of the greatest companies of all time,” and then moves swiftly into defending itself against company’s claims, while attempting to characterize Apple’s complaints as weak.</p>



<h2 class="wp-block-heading"><strong>What Apple claimed</strong></h2>



<p class="wp-block-paragraph">As <a href="https://www.computerworld.com/article/4195828/rotten-to-its-core-apple-files-an-explosive-lawsuit-against-openai.html">reported elsewhere</a>, Apple filed suit against OpenAI in the US District Court for the Northern District of California on July 10. The litigation names OpenAI Foundation, OpenAI Group PBC, io Products, Chang Liu (former senior systems electrical engineer), and Tang Yew Tan (former vice president of product design for iPhone and Apple Watch, now OpenAI’s chief hardware officer), and alleges breach of intellectual property agreement and misappropriation of trade secrets under the Defend Trade Secrets Act. The company has since then <a href="https://www.computerworld.com/article/4198342/apple-widens-openai-trade-secrets-fight-with-preservation-orders.html">filed preservation orders</a> to protect evidence. </p>



<p class="wp-block-paragraph">Apple’s complaint is more detailed than that. Among many other things, it claims Tan allegedly directed job candidates still at Apple to bring “actual parts” to interviews for “show and tell” sessions. It also alleges Tan distributed an internal Apple document describing Apple’s own departure security protocols to new hires before they resigned. Liu is separately accused of failing to return an Apple laptop and using it to download confidential technical documents.</p>



<h2 class="wp-block-heading"><strong>OpenAI’s rebuttal</strong></h2>



<p class="wp-block-paragraph">Now, OpenAI argues Apple’s trade-secret lawsuit is based on factual errors, poor communication and misleading claims. It says Apple mistakenly contacted the wrong OpenAI lawyer after confusing two people with the same surname, falsely claimed a phone call had occurred, then acknowledged both mistakes without raising the allegations later included in the lawsuit. (Apple says it sent OpenAI a warning letter back in February with no response, which undercuts OpenAI’s “we offered to resolve this before litigation” statement.)</p>



<p class="wp-block-paragraph">OpenAI argues that Chang Liu was responding to requests from Apple colleagues seeking help locating Apple files, reflecting Apple’s own access-management failures rather than misconduct. It also claims Tan consistently instructed OpenAI staff not to seek or use competitors’ confidential information. OpenAI maintains it neither possesses nor wants Apple’s trade secrets, offered to resolve concerns before litigation, and finally argues that Apple’s request for a preliminary injunction is unnecessary and unsupported.</p>



<h2 class="wp-block-heading"><strong>What Apple might actually argue</strong></h2>



<p class="wp-block-paragraph">Will Apple see it the same way? That seems unlikely, in part due to the extent of the claimed infractions. Apple will point to the hundreds of former Apple employees now at OpenAI, including former Chief Designer Jony Ive. In doing so, it will likely argue that the remit of the case is not defined by erroneous legal correspondence, though that is probably seen as an error. Instead, the substantial claims it’s likely to focus on are that OpenAI has been engaged in a multi-front attempt to accumulate information pertaining to Apple and its design processes through recruitment and the way it recruits.</p>



<p class="wp-block-paragraph">It’s feasible both arguments have some validity. OpenAI might be right in pointing out weaknesses in Apple’s own approach to internal communications in terms of secrecy. And Apple is correct in pointing out that OpenAI moved to abuse those vulnerabilities, weaknesses in its approach that have only been identified during OpenAI’s campaign to grab secrets.</p>



<p class="wp-block-paragraph">While the Apple lawyer’s error in approaching OpenAI might be an unforced error that helps the AI firm cast doubt on Apple’s claims, it doesn’t necessarily invalidate them — and  both sides believe themselves to be justified. Deciding which company is in the right will be a matter of law and not of public opinion.</p>



<h2 class="wp-block-heading"><strong>Which side does the smoking gun face?</strong></h2>



<p class="wp-block-paragraph">To prove its position, OpenAI shared some correspondence. These communications do seem to show a failure at Apple to properly implement device management over employee accounts, including the claim that personal iMessage accounts are routinely used to share corporate correspondence. That may be true, and shouldn’t be – it’s an obvious weakness in corporate security.</p>



<p class="wp-block-paragraph">At the same time, the correspondence also shows hints of job opportunities at OpenAI for and to a former colleague, which kind of proves part of Apple’s point in terms of steady employee poaching. “I can always give you some fun side projects,” one message said. </p>



<p class="wp-block-paragraph">Of course, interaction between former colleagues is inevitable,. But at the level of seniority here, it feels plausible this could be in breach of any off-ramping arrangements reached between Apple and its former employees. No doubt, courts will decide that – though it does underline Apple’s claims that OpenAI instructed former Apple staffers about how to leave without reaching such agreements.</p>



<p class="wp-block-paragraph">“This isn’t Apple getting it wrong. It is OpenAI getting caught with its hand in the hardware cookie jar and then writing a blog post about how the jar was left unlocked,” US tech thought leader <a href="https://x.com/BrianRoemmele/status/2084524006812815451?s=20" data-type="link" data-id="https://x.com/BrianRoemmele/status/2084524006812815451?s=20" target="_blank" rel="noreferrer noopener">Brian Roemmele wrote on X</a>.</p>



<h2 class="wp-block-heading"><strong>Where happens next?</strong></h2>



<p class="wp-block-paragraph">Ultimately, what comes next is up to Apple and OpenAI. The two companies might reach a deal out of court, or be forced into an agreement by the legal system. The existential nature of the rivalry suggests the latter, rather than former.</p>



<p class="wp-block-paragraph">It is also very telling that OpenAI, which now has more than 400 former Apple employees on its teams, including many former designers, also claims: “Apple’s request for a preliminary injunction is both based on false information and completely unnecessary because we do not have, nor want, any of their trade secrets. We’re much more interested in building innovative products and technologies that push the frontier.”</p>



<p class="wp-block-paragraph">While Apple hasn’t yet responded, it will be interesting to see whether whatever hardware OpenAI ships looks and behaves like any released or unreleased Apple products; the latter will now be able to bring details of its own historical project design decisions — and the people who made them — to court.</p>



<p class="wp-block-paragraph">I think this case will play out over time. Perhaps the most interesting question is whether OpenAI has taken what it knows about Apple to create its own internal product design and development LLM models. Would that use be legitimate? It would, after all, not be the first time an AI company has trained its models on <a href="https://goodlawproject.org/ai-giants-are-stealing-our-creative-work/" target="_blank" rel="noreferrer noopener">other people’s creative energy</a>.</p>



<p class="wp-block-paragraph"><em>You can follow me on social media! Join me on <a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener">BlueSky</a>,  <a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener">LinkedIn</a>, <a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener">Mastodon</a> and subscribe to <a href="https://thecorenews.substack.com/p/welcome-to-the-core?r=5l3lg" target="_blank" rel="noreferrer noopener">The Core</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[‘Apple is one of the greatest companies of all time,’ says OpenAI]]></title>
<description><![CDATA[In an open letter, OpenAI this week turned to the court of public opinion in its existential war against Apple with a public notice in which the company refutes the iPhone maker’s claims concerning wholesale use of confidential information.



You can detect the depth of enmity between both firms...]]></description>
<link>https://tsecurity.de/de/3703957/ai-nachrichten/apple-is-one-of-the-greatest-companies-of-all-time-says-openai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3703957/ai-nachrichten/apple-is-one-of-the-greatest-companies-of-all-time-says-openai/</guid>
<pubDate>Tue, 04 Aug 2026 19:06:15 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">In an <a href="https://openai.com/index/apple-is-getting-this-wrong/" target="_blank" rel="noreferrer noopener">open letter</a>, OpenAI this week turned to the court of public opinion in its existential <a href="https://www.computerworld.com/article/4195828/rotten-to-its-core-apple-files-an-explosive-lawsuit-against-openai.html">war against Apple</a> with a public notice in which the company refutes the iPhone maker’s claims concerning wholesale use of confidential information.</p>



<p class="wp-block-paragraph">You can detect the depth of enmity between both firms in OpenAI’s opening lines to its letter, which begins: “Apple is one of the greatest companies of all time,” and then moves swiftly into defending itself against company’s claims, while attempting to characterize Apple’s complaints as weak.</p>



<h2 class="wp-block-heading"><strong>What Apple claimed</strong></h2>



<p class="wp-block-paragraph">As <a href="https://www.computerworld.com/article/4195828/rotten-to-its-core-apple-files-an-explosive-lawsuit-against-openai.html">reported elsewhere</a>, Apple filed suit against OpenAI in the US District Court for the Northern District of California on July 10. The litigation names OpenAI Foundation, OpenAI Group PBC, io Products, Chang Liu (former senior systems electrical engineer), and Tang Yew Tan (former vice president of product design for iPhone and Apple Watch, now OpenAI’s chief hardware officer), and alleges breach of intellectual property agreement and misappropriation of trade secrets under the Defend Trade Secrets Act. The company has since then <a href="https://www.computerworld.com/article/4198342/apple-widens-openai-trade-secrets-fight-with-preservation-orders.html">filed preservation orders</a> to protect evidence. </p>



<p class="wp-block-paragraph">Apple’s complaint is more detailed than that. Among many other things, it claims Tan allegedly directed job candidates still at Apple to bring “actual parts” to interviews for “show and tell” sessions. It also alleges Tan distributed an internal Apple document describing Apple’s own departure security protocols to new hires before they resigned. Liu is separately accused of failing to return an Apple laptop and using it to download confidential technical documents.</p>



<h2 class="wp-block-heading"><strong>OpenAI’s rebuttal</strong></h2>



<p class="wp-block-paragraph">Now, OpenAI argues Apple’s trade-secret lawsuit is based on factual errors, poor communication and misleading claims. It says Apple mistakenly contacted the wrong OpenAI lawyer after confusing two people with the same surname, falsely claimed a phone call had occurred, then acknowledged both mistakes without raising the allegations later included in the lawsuit. (Apple says it sent OpenAI a warning letter back in February with no response, which undercuts OpenAI’s “we offered to resolve this before litigation” statement.)</p>



<p class="wp-block-paragraph">OpenAI argues that Chang Liu was responding to requests from Apple colleagues seeking help locating Apple files, reflecting Apple’s own access-management failures rather than misconduct. It also claims Tan consistently instructed OpenAI staff not to seek or use competitors’ confidential information. OpenAI maintains it neither possesses nor wants Apple’s trade secrets, offered to resolve concerns before litigation, and finally argues that Apple’s request for a preliminary injunction is unnecessary and unsupported.</p>



<h2 class="wp-block-heading"><strong>What Apple might actually argue</strong></h2>



<p class="wp-block-paragraph">Will Apple see it the same way? That seems unlikely, in part due to the extent of the claimed infractions. Apple will point to the hundreds of former Apple employees now at OpenAI, including former Chief Designer Jony Ive. In doing so, it will likely argue that the remit of the case is not defined by erroneous legal correspondence, though that is probably seen as an error. Instead, the substantial claims it’s likely to focus on are that OpenAI has been engaged in a multi-front attempt to accumulate information pertaining to Apple and its design processes through recruitment and the way it recruits.</p>



<p class="wp-block-paragraph">It’s feasible both arguments have some validity. OpenAI might be right in pointing out weaknesses in Apple’s own approach to internal communications in terms of secrecy. And Apple is correct in pointing out that OpenAI moved to abuse those vulnerabilities, weaknesses in its approach that have only been identified during OpenAI’s campaign to grab secrets.</p>



<p class="wp-block-paragraph">While the Apple lawyer’s error in approaching OpenAI might be an unforced error that helps the AI firm cast doubt on Apple’s claims, it doesn’t necessarily invalidate them — and  both sides believe themselves to be justified. Deciding which company is in the right will be a matter of law and not of public opinion.</p>



<h2 class="wp-block-heading"><strong>Which side does the smoking gun face?</strong></h2>



<p class="wp-block-paragraph">To prove its position, OpenAI shared some correspondence. These communications do seem to show a failure at Apple to properly implement device management over employee accounts, including the claim that personal iMessage accounts are routinely used to share corporate correspondence. That may be true, and shouldn’t be – it’s an obvious weakness in corporate security.</p>



<p class="wp-block-paragraph">At the same time, the correspondence also shows hints of job opportunities at OpenAI for and to a former colleague, which kind of proves part of Apple’s point in terms of steady employee poaching. “I can always give you some fun side projects,” one message said. </p>



<p class="wp-block-paragraph">Of course, interaction between former colleagues is inevitable,. But at the level of seniority here, it feels plausible this could be in breach of any off-ramping arrangements reached between Apple and its former employees. No doubt, courts will decide that – though it does underline Apple’s claims that OpenAI instructed former Apple staffers about how to leave without reaching such agreements.</p>



<p class="wp-block-paragraph">“This isn’t Apple getting it wrong. It is OpenAI getting caught with its hand in the hardware cookie jar and then writing a blog post about how the jar was left unlocked,” US tech thought leader <a href="https://x.com/BrianRoemmele/status/2084524006812815451?s=20" data-type="link" data-id="https://x.com/BrianRoemmele/status/2084524006812815451?s=20" target="_blank" rel="noreferrer noopener">Brian Roemmele wrote on X</a>.</p>



<h2 class="wp-block-heading"><strong>Where happens next?</strong></h2>



<p class="wp-block-paragraph">Ultimately, what comes next is up to Apple and OpenAI. The two companies might reach a deal out of court, or be forced into an agreement by the legal system. The existential nature of the rivalry suggests the latter, rather than former.</p>



<p class="wp-block-paragraph">It is also very telling that OpenAI, which now has more than 400 former Apple employees on its teams, including many former designers, also claims: “Apple’s request for a preliminary injunction is both based on false information and completely unnecessary because we do not have, nor want, any of their trade secrets. We’re much more interested in building innovative products and technologies that push the frontier.”</p>



<p class="wp-block-paragraph">While Apple hasn’t yet responded, it will be interesting to see whether whatever hardware OpenAI ships looks and behaves like any released or unreleased Apple products; the latter will now be able to bring details of its own historical project design decisions — and the people who made them — to court.</p>



<p class="wp-block-paragraph">I think this case will play out over time. Perhaps the most interesting question is whether OpenAI has taken what it knows about Apple to create its own internal product design and development LLM models. Would that use be legitimate? It would, after all, not be the first time an AI company has trained its models on <a href="https://goodlawproject.org/ai-giants-are-stealing-our-creative-work/" target="_blank" rel="noreferrer noopener">other people’s creative energy</a>.</p>



<p class="wp-block-paragraph"><em>You can follow me on social media! Join me on <a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener">BlueSky</a>,  <a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener">LinkedIn</a>, <a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener">Mastodon</a> and subscribe to <a href="https://thecorenews.substack.com/p/welcome-to-the-core?r=5l3lg" target="_blank" rel="noreferrer noopener">The Core</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS’s Kiro Crew aims to turn AI coding agents into autonomous engineering teams]]></title>
<description><![CDATA[AWS on Tuesday released Kiro Crew, an open-source orchestration platform designed to help enterprises move beyond interactive AI coding assistants toward long-running, autonomous engineering workflows that span repositories, developer tools, and multiple work sessions.



Rather than simply gener...]]></description>
<link>https://tsecurity.de/de/3703956/ai-nachrichten/awss-kiro-crew-aims-to-turn-ai-coding-agents-into-autonomous-engineering-teams/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3703956/ai-nachrichten/awss-kiro-crew-aims-to-turn-ai-coding-agents-into-autonomous-engineering-teams/</guid>
<pubDate>Tue, 04 Aug 2026 19:06:14 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">AWS on Tuesday released Kiro Crew, an open-source orchestration platform designed to help enterprises move beyond interactive AI coding assistants toward long-running, autonomous engineering workflows that span repositories, developer tools, and multiple work sessions.</p>



<p class="wp-block-paragraph">Rather than simply generating code, Kiro Crew coordinates multiple AI agents, schedules recurring work, preserves project context across sessions, and integrates with developer tools to investigate incidents, monitor pull requests (PRs), triage tickets, and automate software engineering tasks while developers are away from their keyboards, according to the hyperscaler.</p>



<p class="wp-block-paragraph">“Kiro Crew is a persistent, open-source development workspace for work that is bigger than a single task in a single session,” <a href="https://www.linkedin.com/in/darko-mesaros/" target="_blank" rel="noreferrer noopener">Darko Mesaros</a>, distinguished developer advocate at AWS, told InfoWorld. “Think of it as an application layer that turns AI coding agents into always-working, self-learning, autonomous teammates.”</p>



<p class="wp-block-paragraph">To support that model, the offering ships with persistent memory, multi-agent orchestration tools, approval workflows, scheduling, security controls such as sandboxing and signed audit logs, and a web and desktop dashboard for monitoring agent activity, the hyperscaler said in a statement.</p>



<p class="wp-block-paragraph">Kiro Crew was originally developed inside Amazon as an internal project called MeshClaw and was later adopted by more than 39,000 Amazon builders in less than six months.</p>



<p class="wp-block-paragraph">It can be deployed entirely inside customer environments, including laptops, containers, or virtual machines, without requiring an AWS account or AWS-managed control plane, AWS said.</p>



<p class="wp-block-paragraph">To demonstrate how the new offering can be used, AWS is also launching a set of reference applications built on top of it, including DevFleets for worktree management, Issue Radar for issue and pull-request triage, and Task Runner for executing long-running engineering tasks.</p>



<p class="wp-block-paragraph">Rather than standalone products, these apps combine purpose-built user interfaces with Kiro Crew’s orchestration engine, memory, scheduling, integrations, and backend services to automate specific engineering workflows, Mesaros said, adding that the hyperscaler is expected to add more such apps in the future.</p>



<h2 class="wp-block-heading">Boosting developer productivity</h2>



<p class="wp-block-paragraph">Such applications, according to <a href="https://moorinsightsstrategy.com/team/mike-leone/" target="_blank" rel="noreferrer noopener">Michael Leone</a>, principal analyst at Moor Strategy and Insights, would help platform engineering, DevOps, and site reliability engineering (SRE) teams, where much of the work involves repetitive, long-running operational tasks rather than writing entirely new software.</p>



<p class="wp-block-paragraph">“These tasks can include dependency upgrades, framework migrations, flaky test cleanup, triaging and routing a ticket queue, and the first pass on an incident investigation,” Leone said.</p>



<p class="wp-block-paragraph">“It’s a strong fit for long-running migrations that require checkpoints and retries over hours without supervision,” echoed <a href="https://www.linkedin.com/in/manoj-chandra-jha-b5ab0a13/" target="_blank" rel="noreferrer noopener">Manoj Chandra Jha</a>, principal analyst at Nord-IQ Research.</p>



<p class="wp-block-paragraph">Taken together, those capabilities could significantly reduce software release cycles as well as the time developers spend supervising AI tools and reconnecting context between engineering workflows, according to <a href="https://my.idc.com/getdoc.jsp?containerId=PRF005347" target="_blank" rel="noreferrer noopener">Dave McCarthy</a>, vice president of enterprise infrastructure at IDC.</p>



<p class="wp-block-paragraph">“It eliminates context-switching and babysitting single prompts. Work continues asynchronously in the background while developers are in meetings, off the clock, or asleep, allowing teams to return to completed progress rather than a stalled process,” McCarthy said.</p>



<p class="wp-block-paragraph">That, in turn, will allow developers to spend more time on higher-value engineering tasks, such as designing systems, making architectural decisions, and solving complex engineering problems, echoed <a href="https://www.hfsresearch.com/team/ashish-chaturvedi/" target="_blank" rel="noreferrer noopener">Ashish Chaturvedi</a>, executive research leader at HFS Research.</p>



<h2 class="wp-block-heading">Why CIOs should care</h2>



<p class="wp-block-paragraph">Kiro Crew’s open-source, self-hosted architecture could help enterprises looking to bring governance and visibility to the growing use of AI coding agents, analysts said.</p>



<p class="wp-block-paragraph">“Agent use inside most companies right now is shadow IT, with individual developers wiring up their own agents against their own credentials and nobody tracking it. A shared workspace with approval gates and logging gives you one place to see what ran, what it touched, and who authorized it,” said Leone.</p>



<p class="wp-block-paragraph">Those governance capabilities, combined with the ability to run inside customer-controlled environments, according to Chaturvedi, could also help CIOs address security and compliance concerns: “Being open source and self-hostable, a CIO can run it on their own infrastructure and keep code and credentials inside their perimeter rather than sending them to a black-box agent.”</p>



<p class="wp-block-paragraph">That reduction in security concerns, combined with Kiro Crew’s human-approval workflows, could provide enterprises with a lower-risk path to broader agent adoption, Jha said. “Since it embeds consistency and security screening at scale, and because review remains human-approved, it’s a low-risk entry point for demonstrating agentic ROI before extending trust to higher-stakes, unattended workflows.”</p>



<h2 class="wp-block-heading">Not without trade-offs</h2>



<p class="wp-block-paragraph">Despite its benefits, the adoption of Kiro Crew comes with trade-offs, analysts warned.</p>



<p class="wp-block-paragraph">Adopting Kiro Crew may not be a simple plug-and-play operation, said <a href="https://www.linkedin.com/in/slwalter/" target="_blank" rel="noreferrer noopener">Stephanie Walter</a>, practice lead for AI Stack at HyperFRAME Research. Rather, it introduces yet another orchestration layer for enterprises to manage and secure, she said.</p>



<p class="wp-block-paragraph">Enterprises would need to draft up policies covering least-privilege access, human approvals, memory retention, code provenance, and auditability before allowing persistent agents to operate across source code repositories and CI/CD pipelines, Walter said.</p>



<p class="wp-block-paragraph">More so because most enterprises, Walter added, are still not operationally ready to manage swarms of autonomous AI agents: “Many are still struggling to measure the cost and value of individual AI agents. Parallel agents multiply model calls, compute, CI activity, API usage, tool access, and human review, not just token consumption.”</p>



<h2 class="wp-block-heading">Open architecture, but questions remain</h2>



<p class="wp-block-paragraph">Even for organizations that are ready to experiment with autonomous coding agents, integrating Kiro Crew into existing development environments may require additional work.</p>



<p class="wp-block-paragraph">Although AWS built Kiro Crew around open standards such as Agent Client Protocol (ACP) and Model Context Protocol (MCP), the platform runs on the proprietary <a href="https://kiro.dev/cli/" target="_blank" rel="noreferrer noopener">Kiro CLI</a> at launch, according to Mesaros.</p>



<p class="wp-block-paragraph">That means enterprises using other AI coding agents, such as Claude Code, Codex, or Devin, may need to build and validate their own connectors before they can use Kiro Crew as their orchestration layer.</p>



<p class="wp-block-paragraph">“The dependency is real. AWS says Crew runs on the Kiro CLI at launch, and that CLI is proprietary and metered by credits, so it’s the harness actually wired up on day one. Until someone runs a different agent under Crew and shows it working, the open part stops at the orchestration layer,” said Leone.</p>



<p class="wp-block-paragraph">For enterprises and development teams already using Kiro, however, adoption is expected to be more straightforward, as Kiro Crew can reuse existing .kiro configurations, including steering files, skills, and custom agents, without requiring additional setup, according to Mesaros.</p>



<p class="wp-block-paragraph">The new offering, due to its open-source nature, is free as well, Mesaros pointed out, adding that customers need to pay only for the AI coding agents and tools they choose to connect to Crew.</p>



<p class="wp-block-paragraph">AWS said it will govern the project through a publicly listed steering committee operating under an open governance model, with proposals submitted as pull requests and debated openly.</p>



<p class="wp-block-paragraph">Kiro and AWS engineers will initially maintain the project, with trusted community contributors expected to join the maintainer group over time, it added.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Texas halts new data centers as governor calls for audits]]></title>
<description><![CDATA[Texas Governor Greg Abbott has paused new data center development until an audit has been completed.]]></description>
<link>https://tsecurity.de/de/3703718/it-nachrichten/texas-halts-new-data-centers-as-governor-calls-for-audits/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3703718/it-nachrichten/texas-halts-new-data-centers-as-governor-calls-for-audits/</guid>
<pubDate>Tue, 04 Aug 2026 17:48:54 +0200</pubDate>
<content:encoded><![CDATA[Texas Governor Greg Abbott has paused new data center development until an audit has been completed.]]></content:encoded>
</item>
<item>
<title><![CDATA[Texas halts new data centers as governor calls for audits]]></title>
<description><![CDATA[Texas Governor Greg Abbott has paused new data center development until an audit has been completed.]]></description>
<link>https://tsecurity.de/de/3703701/ai-nachrichten/texas-halts-new-data-centers-as-governor-calls-for-audits/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3703701/ai-nachrichten/texas-halts-new-data-centers-as-governor-calls-for-audits/</guid>
<pubDate>Tue, 04 Aug 2026 17:42:58 +0200</pubDate>
<content:encoded><![CDATA[Texas Governor Greg Abbott has paused new data center development until an audit has been completed.]]></content:encoded>
</item>
<item>
<title><![CDATA[Rapid7 Releases Metasploit Framework 6.5 | MCP AI Integration And Malleable C2]]></title>
<description><![CDATA[Rapid7 has officially launched Metasploit Framework 6.5, packing two years of core development, 422 new modules, and major…
The post Rapid7 Releases Metasploit Framework 6.5 | MCP AI Integration And Malleable C2 appeared first on Hackers Online Club.]]></description>
<link>https://tsecurity.de/de/3703634/it-security-nachrichten/rapid7-releases-metasploit-framework-65-mcp-ai-integration-and-malleable-c2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3703634/it-security-nachrichten/rapid7-releases-metasploit-framework-65-mcp-ai-integration-and-malleable-c2/</guid>
<pubDate>Tue, 04 Aug 2026 17:13:40 +0200</pubDate>
<content:encoded><![CDATA[<p>Rapid7 has officially launched Metasploit Framework 6.5, packing two years of core development, 422 new modules, and major…</p>
<p>The post <a href="https://hackersonlineclub.com/metasploit-new-mcp-ai-malleable-c2/">Rapid7 Releases Metasploit Framework 6.5 | MCP AI Integration And Malleable C2</a> appeared first on <a href="https://hackersonlineclub.com/">Hackers Online Club</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Data center energy constraints and moratoriums are mounting. Expect to see stalled AI projects]]></title>
<description><![CDATA[In mid-July, New York became the first state to impose a state-wide moratorium on new data center construction.



“Data center development threatens to hike up utility bills, deplete our natural resources, and create uncertainty for New Yorkers,” wrote Governor Kathy Hochul in her executive orde...]]></description>
<link>https://tsecurity.de/de/3703633/it-security-nachrichten/data-center-energy-constraints-and-moratoriums-are-mounting-expect-to-see-stalled-ai-projects/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3703633/it-security-nachrichten/data-center-energy-constraints-and-moratoriums-are-mounting-expect-to-see-stalled-ai-projects/</guid>
<pubDate>Tue, 04 Aug 2026 17:13:39 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">In mid-July, New York became the first state to impose a <a href="https://www.governor.ny.gov/news/first-statewide-moratorium-new-hyperscale-data-centers-launched-governor-kathy-hochul" target="_blank" rel="noreferrer noopener">state-wide moratorium</a> on new data center construction.</p>



<p class="wp-block-paragraph">“Data center development threatens to hike up utility bills, deplete our natural resources, and create uncertainty for New Yorkers,” wrote Governor Kathy Hochul in her executive order. The moratorium is planned to last for a year, and the state will use the time to research the impact of data centers on energy demand and require data centers to either pay more for their energy or supply their own.</p>



<p class="wp-block-paragraph">And 127 other U.S. jurisdictions have similar moratoriums, according to the <a href="https://www.interconnectedcapital.com/research/data-center-moratoriums" target="_blank" rel="noreferrer noopener">U.S. Data Center Moratorium Tracker</a>.</p>



<p class="wp-block-paragraph">More restrictions are proposed, both at the state and at the federal level. According to <a href="https://www.datacenterwatch.org/q1-2026" target="_blank" rel="noreferrer noopener">Data Center Watch</a>, at least 75 U.S. data center projects, worth about $130 billion, were blocked or delayed in the first quarter of 2026, the largest quarterly number on record—and roughly equal to the total for all of 2025. And <a href="https://heatmap.news/politics/americans-oppose-data-centers-poll" target="_blank" rel="noreferrer noopener">71% of Americans</a> now oppose data center construction in their area, according to a survey by Embold Research, up from just 42% last summer.</p>



<p class="wp-block-paragraph">The main reason? As with the New York state moratorium, energy costs are the top issue.</p>



<p class="wp-block-paragraph">Data centers are projected to increase average electricity costs by 6% to 29% by 2030, according to research from <a href="https://iopscience.iop.org/article/10.1088/1748-9326/ae6c3d" target="_blank" rel="noreferrer noopener">North Carolina State University</a>, Carnegie Mellon University, the University of Pittsburgh, and the University of Toronto. Some states will see increases of as much as 57%, with Virginia and Texas hit the hardest, the group found.</p>



<p class="wp-block-paragraph">There were bans and moratoriums on data centers even before the current AI boom, when data centers required 10 to 25 megawatts of power, says Gartner analyst <a href="https://www.linkedin.com/in/a-stanish/">Autumn Stanish</a>. “Now there’s an expansion of those facilities, reaching 100 megawatts. And some builds are as big as 2 gigawatts of power. There’s one in Louisiana that’s planned to consume 5 gigawatts of power.”</p>



<p class="wp-block-paragraph">Just how much is 5 gigawatts? Enough to power 4 million homes—nearly all the homes in Michigan or more than the total number of households in New York City— according to the <a href="https://powering-intelligence.epri.com/executive-summary.html" target="_blank" rel="noreferrer noopener">Electric Power Research Institute</a>.</p>



<p class="wp-block-paragraph">That’s a big shift, Stanish says. U.S. electricity consumption has been relatively level for the past 30 years, and with the lack of new demand, there’s been less new construction, and the grid has started to age. “And now we’re struggling,” she says. “We need to ramp up capacity, but it’s going to take time to get there.”</p>



<p class="wp-block-paragraph">According to <a href="https://www.datacentermap.com/datacenters/" target="_blank" rel="noreferrer noopener">Data Center Map</a>, there are now over 4,500 data centers in the U.S., which is more than in the next 16 countries combined. And it’s not enough. The overall vacancy rate in North American data centers is now 0.9%, states a <a href="https://www.cbre.com/insights/reports/global-data-center-trends-2026" target="_blank" rel="noreferrer noopener">June CBRE report</a>.</p>



<p class="wp-block-paragraph">“Right now, the data center market is very competitive in terms of trying to grab capacity,” says <a href="https://www.linkedin.com/in/ryan-mallory-3483504/">Ryan Mallory</a>, CEO at Flexential, a colocation provider with 42 data centers in 18 U.S. markets and four more under development. “We’re in the process of acquiring a number of additional properties,” Mallory adds. “You have to be planning for the future.”</p>



<p class="wp-block-paragraph">But the demand for space is even higher than the pace of construction. “Most capacity out to 2027 is completely sold, not just for Flexential, but for any data center out there,” Mallory says.</p>



<p class="wp-block-paragraph">Flexential has an easier time finding locations than other data center companies because its facilities are typically in the 22 to 36 megawatt range, which is a reasonable size to connect to a power company. “Generally, they either have the infrastructure ready to go, or we can work with them to have power available in the near term,” Mallory says. “We’re not coming in asking for 500 megawatts on day one or 1 gigawatt in twelve months.”</p>



<p class="wp-block-paragraph">And if the local utility can’t supply enough power and needs to build more generation or transmission capacity? “We would pay our fair share of whatever that augment would be,” Mallory says. “We would not expect any other use to pay for what we would take.”</p>



<p class="wp-block-paragraph">In addition, Flexential also has 100% generator backup in its data centers in case there’s an issue with the grid. Power concerns are the No. 1 factor when Flexential is deciding where to locate its next data center, Mallory says.</p>



<p class="wp-block-paragraph">This constraint on data centers is affecting AI rollouts. According to <a href="https://www.flexential.com/resources/press-release/flexential-announces-2026-state-ai-infrastructure-report" target="_blank" rel="noreferrer noopener">Flexential’s annual survey of IT decision makers</a> at large organizations, released in May, power is now the main constraint to AI deployment nationwide. When deciding where to put AI workloads, 89% of respondents said that access to reliable grid power was one of the most important factors, and 72% said they had moderate or extreme concern about electricity price volatility. In addition, 82% of organizations said that limited access to high-performance AI compute is a moderate or severe constraint.</p>



<p class="wp-block-paragraph">In the big picture, global electricity demand grew by 3% in 2025—but energy demand from data centers grew by 17%, according to <a href="https://www.iea.org/news/data-centre-electricity-use-surged-in-2025-even-with-tightening-bottlenecks-driving-a-scramble-for-solutions" target="_blank" rel="noreferrer noopener">the International Energy Agency</a>. And demand from AI-focused data centers, in particular, grew by 50%. The largest tech companies spent more than $400 billion on capital expenditures in 2025, and that number is expected to increase by 75% in 2026. And AI factory capacity more than tripled in the last 18 months, according to the agency.</p>



<p class="wp-block-paragraph">Real estate advisory firm Newmark noted that <a href="https://www.nmrk.com/insights/market-report/2026-u-s-data-center-market-outlook">energy constraints and delayed grid connections</a> are holding back new data center projects. It cited permitting delays for new gas plants, congested grid-interconnection queues, and uncertain timelines for next-generation energy solutions among the issues. As a result, data center capacity won’t be able to meet forecasted AI demand, and will limit how fast AI adoption can scale, Newmark predicted.</p>



<h2 class="wp-block-heading">Fastest data center growth on record</h2>



<p class="wp-block-paragraph">There aren’t enough data centers being built—even though the number of data centers being built, despite all the delays, all the opposition, and all the moratoriums, is enormous. According to Newmark, there are now 280 data center projects underway in 32 states, with development at an all-time high. Data centers is the only commercial real estate sector showing accelerating construction growth, the firm reports.</p>



<p class="wp-block-paragraph">Other researchers corroborate this report. According to <a href="https://news.constructconnect.com/july-2026-data-center-report-year-to-date-spending-four-times-the-2025-record" target="_blank" rel="noreferrer noopener">economists at ConstructConnect</a>, $58 billion was spent on data center construction so far this year, more than four times the amount at the same time last year. We’re now seeing an average $10 billion worth of data center starts—meaning that ground is broken and construction has begun—per month. That’s 300% higher than a year ago, the report says. And, prior to 2024, monthly starts were well under $1 billion. The growth curve in the report is exponential.</p>



<p class="wp-block-paragraph">Part of the dollar amount growth is because data centers are becoming much more expensive. Many projects have per-square-foot costs of more than $1,000.</p>



<p class="wp-block-paragraph">ConstructConnect is also tracking nearly 100 data center projects expected to begin construction before the end of the year, totaling more than $101 billion in planned spending—and that’s not including Google’s $100 billion Kestrel data center project.</p>



<p class="wp-block-paragraph">However, power infrastructure project starts rose just 2.7%  during the first five months of 2026 compared to the same period in 2025. That’s expected to grow, though. ConstructConnect expects a 30.8% increase in new power projects for all of 2026 compared to 2025.</p>



<p class="wp-block-paragraph">SemiAnalysis confirms the record-high growth in new data center construction and predicts that total capacity will grow by 21 gigawatts in 2026 to 84 gigawatts in 2030.</p>



<p class="wp-block-paragraph"></p>



<h2 class="wp-block-heading">Facing the power challenge</h2>



<p class="wp-block-paragraph">According to <a href="https://powering-intelligence.epri.com/executive-summary.html" target="_blank" rel="noreferrer noopener">EPRI</a>, 15 to 25% of data center electricity is already being used for AI workloads, and that number is rising rapidly. Data centers already consume between 4% to 5% of US electricity, and that share is expected to grow to 9% to 17% by 2030.</p>



<p class="wp-block-paragraph">In addition to choosing the best possible geographic location for their facilities, data center operators have a couple of other options for dealing with their power constraints. One is to get more efficient. Data center operators are also looking for new ways to cool down the facilities, as well as installing newer, more efficient equipment.</p>



<p class="wp-block-paragraph">“Liquid cooling—immersion and direct-to-chip—that’s going to save you a massive amount of energy,” says Gartner’s Stanish. The other strategy is to make their own power, which is easier for smaller data centers than for the largest ones.</p>



<p class="wp-block-paragraph">“If you have a 5 gigawatt data center, nuclear is the only way to do it,” says Stanish. “But the first one won’t come online until 2035, 2030 at the earliest.”</p>



<p class="wp-block-paragraph">Today, generators powered by natural gas are the most popular option for on-site power, says <a href="https://intelligence.uptimeinstitute.com/author/pjudge">Peter Judge</a>, a senior research analyst at Uptime Intelligence. “But you’re asking the community around you to accept a major source of emissions causing global warming and also local issues like particulates and noise and heat,” he says.</p>



<p class="wp-block-paragraph">Fuel cells are more efficient, he says, and don’t emit particulates, but they’re more expensive and less reliable than generators and have other operational issues.</p>



<p class="wp-block-paragraph">One company that recently decided to go with fuel cells is <a href="https://www.oracle.com/news/announcement/oracle-borderplex-and-bloom-energy-to-power-project-jupiter-with-fuel-cell-technology-2026-04-27/">Or</a><a href="https://www.oracle.com/news/announcement/oracle-borderplex-and-bloom-energy-to-power-project-jupiter-with-fuel-cell-technology-2026-04-27/" target="_blank" rel="noreferrer noopener">a</a><a href="https://www.oracle.com/news/announcement/oracle-borderplex-and-bloom-energy-to-power-project-jupiter-with-fuel-cell-technology-2026-04-27/">cle</a>, which will use 2.45 gigawatts worth of fuel cells to power its Project Jupiter data center in New Mexico, replacing the previous plan to use gas turbines and diesel generators. According to Oracle, the fuel cells will significantly reduce emissions, use only a “negligible” amount of water, and be quieter than turbines and generators. Plus, the on-site power generation will help protect energy rates of area residents.</p>



<p class="wp-block-paragraph">“If you want to build a data center, there’s a better way to build it,” says <a href="https://www.linkedin.com/in/nataliesunderland/">Natalie Sunderland</a>, chief marketing and communications officer at Bloom Energy, which makes the fuel cells that Oracle plans to deploy. And companies aren’t about to scale back on their AI ambitions or reduce their demands for data centers, she says.</p>



<p class="wp-block-paragraph">But when the data center is going to draw more power than the entire local community, the focus is going to shift to on-site power generation, says <a href="https://www.linkedin.com/in/carl-cottuli-5800846/">Carl Cottuli</a>, Bloom’s head of development engineering.</p>



<p class="wp-block-paragraph">According to a <a href="https://www.bloomenergy.com/news/ai-data-center-growth-hinges-on-solving-both-power-constraints-and-community-concerns-bloom-energy-report-finds/" target="_blank" rel="noreferrer noopener">survey of 156 data center decision makers that Bloom</a> released in mid-June, 61% of data center developers plan to deploy on-site power if the local grid can’t meet their needs. “They know they’ve got a constraint, and they have to act on it,” Cottuli says.</p>



<p class="wp-block-paragraph">And the survey numbers might actually be on the low side, says <a href="https://www.linkedin.com/in/mihirn/">Mihir Nandkeolyar</a>, director of business development and technology strategy for global data center solutions at Johnson Controls. Many data center operators planning new facilities haven’t yet approached the local utility companies—and learned that a connection might not be available for five more years, he says. “So, they may shift from the grid power column to the on-site power column,” he says.</p>



<p class="wp-block-paragraph">Another factor that may push data centers towards more on-site power is the lack of transmission capacity. Even if the local power utility can generate the electricity that a data center needs, it doesn’t necessarily mean that the power can get there.</p>



<p class="wp-block-paragraph">A draft <a href="https://www.energy.gov/oe/national-transmission-needs-study" target="_blank" rel="noreferrer noopener">Department of Energy report</a>, released in early July, called transmission limitations a “critical bottleneck” to connecting new power generation facilities to the grid. Much of the existing infrastructure is old and needs to be replaced, even as “the load growth from data centers has become a particular focus in the industry that is driving upward trends in demand.”</p>



<p class="wp-block-paragraph">“The backlog is growing for the right level of transmission infrastructure to keep up with demand for AI workloads in particular,” says <a href="https://www.linkedin.com/in/matt-schnugg-b702a73/">Matt Schnugg</a>, chief product officer for Schneider Electric Digital Grid.</p>



<p class="wp-block-paragraph">Either way, the relationships between the data centers and the surrounding communities will be changing. The New York State moratorium is just the latest example of the new scrutiny data centers will be facing. According to the Bloom survey, 28% of data center developers say community scrutiny has worsened or significantly worsened. Top concerns include electricity price increases, water consumption, and negative impacts on grid reliability.</p>



<p class="wp-block-paragraph">Meanwhile, not all government involvement is there to slow down data center builds. In late June, the <a href="https://www.ferc.gov/news-events/news/ferc-launches-aggressive-targeted-action-speed-large-load-integration" target="_blank" rel="noreferrer noopener">Federal Energy Regulatory Commission</a> moved to speed up electric grid connections for data centers and instructed six regional grid operators to either justify or update their connection rules to make that happen.</p>



<p class="wp-block-paragraph">Data centers are now getting large enough that their presence on the power grid affects other users, says Uptime Institute’s Judge. “So, like it or not, they will be regulated more stringently by grid authorities everywhere.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Silo Cast Responds to Fan Theories in New Apple TV Video]]></title>
<description><![CDATA[Apple TV has released a new video featuring the cast of Silo as they react to fan theories surrounding the show’s expanding mystery and its third season.



Silo stars examine viewers’ biggest theories




https://youtu.be/DxsqywdrezY




The video, titled “The Cast of Silo Responds to Fan Theori...]]></description>
<link>https://tsecurity.de/de/3703420/ios-mac-os/silo-cast-responds-to-fan-theories-in-new-apple-tv-video/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3703420/ios-mac-os/silo-cast-responds-to-fan-theories-in-new-apple-tv-video/</guid>
<pubDate>Tue, 04 Aug 2026 16:09:44 +0200</pubDate>
<content:encoded><![CDATA[Apple TV has released a new video featuring the cast of Silo as they react to fan theories surrounding the show’s expanding mystery and its third season.



Silo stars examine viewers’ biggest theories




https://youtu.be/DxsqywdrezY




The video, titled “The Cast of Silo Responds to Fan Theories,” gives the actors a chance to consider ideas shared by viewers who have closely followed the show’s hidden clues, uncertain histories and powerful systems of control.



Rather than revealing which theories are correct, the cast discusses the possibilities while protecting the major surprises still ahead. Their reactions show how carefully viewers have examined the silos, the outside world and the people responsible for creating the underground society.



The discussion arrives during Silo Season 3, which follows two connected timelines. In the present, Juliette Nichols survives her cleaning and returns to a community recovering from rebellion, but she struggles with memory loss as another threat emerges.



Meanwhile, the Before Times storyline takes viewers centuries into the past. Journalist Helen Drew and Congressman Daniel Keene begin investigating a conspiracy connected to the creation of the silos and the events that destroyed the world above.



Season 3 moves closer to the truth



Fan theories have remained central to Silo because the series reveals its answers slowly. Questions about the Algorithm, the Safeguard system, the number of silos and the original purpose of the project continue to shape the story.



Season 3 also expands the cast, with Rebecca Ferguson returning as Juliette alongside Common, Tim Robbins, Jessica Henwick and Ashley Zukerman. Apple has already renewed Silo for a fourth and final season, allowing the series to complete the story based on Hugh Howey’s novels.



The new fan-theory video is available through Apple TV’s official YouTube channel, while Silo Season 3 continues streaming on Apple TV.]]></content:encoded>
</item>
<item>
<title><![CDATA[Third-Party Vendor Risk When Your Development Team Is Offshore]]></title>
<description><![CDATA[Most vendor risk programs were designed for suppliers who never touch a line of code. The questionnaire that works for a payroll processor or an office cleaning firm falls apart when the vendor in question writes your software. An offshore development partner holds repository access, deployment c...]]></description>
<link>https://tsecurity.de/de/3703412/it-security-nachrichten/third-party-vendor-risk-when-your-development-team-is-offshore/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3703412/it-security-nachrichten/third-party-vendor-risk-when-your-development-team-is-offshore/</guid>
<pubDate>Tue, 04 Aug 2026 15:59:01 +0200</pubDate>
<content:encoded><![CDATA[<div class="hs-featured-image-wrapper"> 
 <a href="https://www.cm-alliance.com/cybersecurity-blog/third-party-vendor-risk-when-your-development-team-is-offshore" title="" class="hs-featured-image-link"> <img src="https://www.cm-alliance.com/hubfs/Vendor_Risk_Management_1100x400.webp" alt="Third-Party Vendor Risk Management " class="hs-featured-image"> </a> 
</div> 
<p><span>Most vendor risk programs were designed for suppliers who never touch a line of code. The questionnaire that works for a payroll processor or an office cleaning firm falls apart when the vendor in question writes your software. An offshore development partner holds repository access, deployment credentials, and often a clear view of your customer data. That combination puts them in a category of their own, and plenty of security teams still assess them with the same template they use for everyone else.</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI monocultures: the code review problem nobody's talking about]]></title>
<description><![CDATA[Why independent AI review and governance are essential for secure, reliable software development.]]></description>
<link>https://tsecurity.de/de/3703403/it-nachrichten/ai-monocultures-the-code-review-problem-nobodys-talking-about/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3703403/it-nachrichten/ai-monocultures-the-code-review-problem-nobodys-talking-about/</guid>
<pubDate>Tue, 04 Aug 2026 15:56:34 +0200</pubDate>
<content:encoded><![CDATA[Why independent AI review and governance are essential for secure, reliable software development.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Confirms iPhone to Windows Clipboard Sync, Likely Coming in iOS 28]]></title>
<description><![CDATA[Apple is working on a new feature that will let users copy and paste content between an iPhone and a Windows PC after Microsoft requested better interoperability under the European Union's Digital Markets Act.



The feature aims to bring a workflow similar to Apple's Universal Clipboard to Windo...]]></description>
<link>https://tsecurity.de/de/3703258/ios-mac-os/apple-confirms-iphone-to-windows-clipboard-sync-likely-coming-in-ios-28/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3703258/ios-mac-os/apple-confirms-iphone-to-windows-clipboard-sync-likely-coming-in-ios-28/</guid>
<pubDate>Tue, 04 Aug 2026 15:03:04 +0200</pubDate>
<content:encoded><![CDATA[Apple is working on a new feature that will let users copy and paste content between an iPhone and a Windows PC after Microsoft requested better interoperability under the European Union's Digital Markets Act.



The feature aims to bring a workflow similar to Apple's Universal Clipboard to Windows users, although Apple says it still requires a significant amount of engineering work before it is ready. Based on Apple's current timeline, the feature is expected to arrive around fall 2027 and will likely remain limited to the European Union.



MacRumors spotted Apple's latest update on its EU interoperability requests page, where the company confirmed that it plans to develop a solution that lets developers create extensions to share and import clipboard content between an iPhone and paired accessories, including Windows PCs. 



Microsoft requested the feature because Windows currently cannot match the seamless copy and paste experience available between Apple devices through Universal Clipboard.



Apple outlines how the feature will work







Apple says the new system will rely on the frameworks it introduced with iOS 26.5 and will require users to approve clipboard sharing for each paired Windows PC through AccessorySetupKit before synchronization begins.




"We will introduce a new solution that will follow similar patterns to the Accessory Notifications and Accessory Live Activities frameworks that were introduced on iOS26.5. It will enable you to create an extension to share and import pasteboard items with paired accessories. The system will notify your extension when items are copied into the clipboard; then your extension can use the Accessory Transport Extension framework to share the contents with your accessory as necessary using available transports."




Microsoft originally argued that cross-device copy and paste has become a basic productivity feature that users expect across their primary devices, especially when they regularly switch between a phone and a computer.




"Cross-device copy and paste is a foundational productivity interaction that users expect to 'just work' across their primary devices."




Apple previously warned that it first needed to determine whether such a feature could protect the integrity of iOS and avoid creating problems for the operating system or its intellectual property. 



After completing that assessment, the company agreed to move forward and described the project as a significant engineering effort that should reach developer beta after development finishes in fall 2027, with a public release expected later. Although Apple has not confirmed the software version, the current timeline points to the feature arriving with iOS 28.]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent]]></title>
<description><![CDATA[Google deleted three AI agent workflows from its Agent Development Kit (ADK) Python repository. Pillar Security showed that a public GitHub issue could manipulate a triage agent into triggering a privileged code-fixing agent.

The researchers said the public agent could be prompt-injected into po...]]></description>
<link>https://tsecurity.de/de/3703238/it-security-nachrichten/google-deletes-3-adk-ai-workflows-after-malicious-github-issue-could-trigger-privileged-agent/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3703238/it-security-nachrichten/google-deletes-3-adk-ai-workflows-after-malicious-github-issue-could-trigger-privileged-agent/</guid>
<pubDate>Tue, 04 Aug 2026 14:47:38 +0200</pubDate>
<content:encoded><![CDATA[Google deleted three AI agent workflows from its Agent Development Kit (ADK) Python repository. Pillar Security showed that a public GitHub issue could manipulate a triage agent into triggering a privileged code-fixing agent.

The researchers said the public agent could be prompt-injected into posting /adk-issue-fix as adk-bot. They identified the bot as a collaborator, so that comment satisfied]]></content:encoded>
</item>
<item>
<title><![CDATA[Why meta agents must become the economic intelligence layer of the agentic enterprise]]></title>
<description><![CDATA[In “Micro and macro agents: The emerging architecture of the agentic enterprise,” I proposed a three-layer architecture for enterprise AI.




Micro agents execute specialized tasks.



Macro agents orchestrate end-to-end business processes.



Meta agents provide governance through monitoring, c...]]></description>
<link>https://tsecurity.de/de/3703201/it-security-nachrichten/why-meta-agents-must-become-the-economic-intelligence-layer-of-the-agentic-enterprise/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3703201/it-security-nachrichten/why-meta-agents-must-become-the-economic-intelligence-layer-of-the-agentic-enterprise/</guid>
<pubDate>Tue, 04 Aug 2026 14:27:12 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">In “<a href="https://www.cio.com/article/4157977/micro-and-macro-agents-the-emerging-architecture-of-the-agentic-enterprise.html?utm=hybrid_search">Micro and macro agents: The emerging architecture of the agentic enterprise</a>,” I proposed a three-layer architecture for enterprise AI.</p>



<ol class="wp-block-list">
<li><strong>Micro agents</strong> execute specialized tasks.</li>



<li><strong>Macro agents</strong> orchestrate end-to-end business processes.</li>



<li><strong>Meta agents</strong> provide governance through monitoring, compliance, security, and human oversight.</li>
</ol>



<p class="wp-block-paragraph">As enterprises begin deploying thousands — and eventually tens of thousands — of autonomous agents, token costs have become a major concern. According to <a href="https://www.gartner.com/en/newsroom/press-releases/2026-06-24-gartner-predicts-ai-coding-costs-will-surpass-average-developer-salary-by-2028-as-token-consumption-surges">Gartner</a>, rising token-driven AI spend is straining budgets and challenging cost justification.</p>



<p class="wp-block-paragraph">To track this economic concern, meta agents should do more than simply being the governance agents.</p>



<p class="wp-block-paragraph">They should become the economic intelligence layer of the enterprise.</p>



<p class="wp-block-paragraph">Their responsibility is not only ensuring AI behaves responsibly.</p>



<p class="wp-block-paragraph">It is ensuring AI creates measurable business value.</p>



<h2 class="wp-block-heading">The missing economic model for AI</h2>



<p class="wp-block-paragraph">Every major technology revolution eventually develops its own economic framework:</p>



<ul class="wp-block-list">
<li>Manufacturing measured productivity.</li>



<li>Cloud computing measured infrastructure utilization.</li>



<li>Digital businesses measured customer acquisition costs and lifetime value.</li>
</ul>



<p class="wp-block-paragraph">The agentic enterprise now requires its own financial discipline. Every AI prompt. Every reasoning cycle. Every interaction between agents. Every autonomous workflow.</p>



<p class="wp-block-paragraph">Tokens have quietly become the <a href="https://www.networkworld.com/article/4153278/tokenomics-why-it-leaders-need-to-pay-attention-to-ai-tokens.html?utm_source=miso&amp;utm_medium=related&amp;utm_campaign=thumbnail_list">operational currency</a> of enterprise AI. <a href="https://www.cio.com/article/4184596/tokenomics-in-enterprise-ai.html?utm=hybrid_search">Tokenomics is now a foundational part of enterprise AI architecture.</a></p>



<p class="wp-block-paragraph">Yet today, most organizations measure only one thing: Cost. How many tokens were consumed? Which models cost the most? What was the monthly inference bill?</p>



<p class="wp-block-paragraph">These are useful operational metrics.</p>



<p class="wp-block-paragraph">They are not strategic business metrics. Boards rarely ask how much electricity a factory consumed. They ask how much value the factory produced.</p>



<p class="wp-block-paragraph">Enterprise AI deserves the same conversation.</p>



<p class="wp-block-paragraph">This is where I was thinking about the laws of physics.  Based on physics laws,  energy cannot be created or destroyed. It is transformed into another form. Electricity becomes light. Chemical energy becomes motion. Solar energy becomes electricity.</p>



<p class="wp-block-paragraph">Enterprise AI offers a similar management lesson.</p>



<h2 class="wp-block-heading">Intelligence must be transformed into value</h2>



<p class="wp-block-paragraph">Tokens are not valuable because they are consumed. They become valuable only when they are transformed into business outcomes. A faster loan application decision. A fraud detection. A better customer experience. Higher software quality. Greater employee productivity. A new business opportunity.</p>



<p class="wp-block-paragraph">This leads to what I call return on tokens (ROT).</p>



<p class="wp-block-paragraph">ROT measures how effectively an organization converts token consumption into measurable business value.</p>



<p class="wp-block-paragraph">Instead of asking, “How many tokens did we consume,” leaders should ask, “How much enterprise value did every million tokens create?”</p>



<p class="wp-block-paragraph">The <a href="https://en.wikipedia.org/wiki/Second_law_of_thermodynamics">Second Law of Thermodynamics</a> tells us something equally important: Every energy transformation introduces inefficiencies. Although total energy is conserved, some inevitably becomes less useful for doing work.</p>



<p class="wp-block-paragraph">Enterprise AI behaves similarly.</p>



<h2 class="wp-block-heading">The second law: Every AI transformation creates friction</h2>



<p class="wp-block-paragraph">Not every token creates value. Some tokens are spent on repeated reasoning. Some generate redundant conversations between agents. Some support oversized context windows. Some produce hallucinations requiring correction. Some route simple tasks to unnecessarily expensive models.</p>



<p class="wp-block-paragraph">The tokens are not lost. But they create very little useful business work.</p>



<p class="wp-block-paragraph">I refer to this as token entropy. Token entropy represents the portion of AI activity that consumes intelligence without producing proportional business outcomes.</p>



<p class="wp-block-paragraph">Every agentic enterprise will experience token entropy. The organizations that win will be the ones that continuously identify and reduce it.</p>



<h2 class="wp-block-heading">Beyond energy: The importance of exergy</h2>



<p class="wp-block-paragraph">Thermodynamics offers another concept that is even more relevant. It is called Exergy.</p>



<p class="wp-block-paragraph">Unlike energy, exergy measures the amount of energy that can actually be converted into useful work. Two systems may contain the same amount of energy while producing dramatically different levels of useful output.</p>



<p class="wp-block-paragraph">The same principle applies to enterprise AI. Two organizations may consume exactly the same number of tokens.</p>



<p class="wp-block-paragraph">One generates meeting summaries.</p>



<p class="wp-block-paragraph">The other transforms loan  processing, accelerates software development, detects fraud, improves customer retention, and creates new revenue streams.</p>



<p class="wp-block-paragraph">Their token consumption is identical. Their business impact is not.</p>



<p class="wp-block-paragraph">Borrowing it as a management analogy, not claiming that AI tokens literally obey the thermodynamic definition of exergy. I think of this as token exergy. It’s not that AI tokens literally obey the thermodynamic definition of exergy. </p>



<p class="wp-block-paragraph">Token exergy measures how much of an organization’s AI intelligence is converted into useful business work. It is not enough to consume tokens efficiently. Organizations must convert those tokens into outcomes that matter.</p>



<h2 class="wp-block-heading">The meta agent evolves</h2>



<p class="wp-block-paragraph">This is where meta agents become transformational.</p>



<p class="wp-block-paragraph">Today we think of them as governance agents. Tomorrow they become economic governors.</p>



<p class="wp-block-paragraph">Meta agents continuously monitor every interaction across the enterprise and answer questions such as:</p>



<ul class="wp-block-list">
<li>Which agents produce the highest ROT?</li>



<li>Where is token entropy increasing?</li>



<li>Which workflows generate the highest token exergy?</li>



<li>Which models deliver the greatest business value per token?</li>



<li>Which agents should use smaller models?</li>



<li>Which prompts should be optimized?</li>



<li>Which workflows require human intervention?</li>



<li>Which autonomous processes should be redesigned?</li>
</ul>



<p class="wp-block-paragraph">Meta agents no longer simply supervise AI. They optimize its economics.</p>



<h2 class="wp-block-heading">The economic intelligence layer</h2>



<p class="wp-block-paragraph">The architecture now becomes complete.</p>



<ul class="wp-block-list">
<li><strong>Micro agents:</strong> Perform work.</li>



<li><strong>Macro agents:</strong> Coordinate work.</li>



<li><strong>Meta agents:</strong> OGovern, observe, optimize, and continuously improve the economics of intelligence.</li>
</ul>



<p class="wp-block-paragraph">Their objective is straightforward:</p>



<ul class="wp-block-list">
<li>Maximize return on tokens.</li>



<li>Minimize token entropy.</li>



<li>Increase token exergy.</li>
</ul>



<p class="wp-block-paragraph">This represents a shift from AI governance to AI economics<strong>.</strong></p>



<h2 class="wp-block-heading">The executive dashboard of tomorrow</h2>



<p class="wp-block-paragraph">The executive dashboard of the future will not focus solely on infrastructure metrics. It will measure intelligence performance.</p>



<p class="wp-block-paragraph">Imagine a boardroom dashboard displaying:</p>



<ul class="wp-block-list">
<li>Return on tokens (ROT)</li>



<li>Token entropy index</li>



<li>Token exergy score</li>



<li>Business value per million tokens</li>



<li>Agent productivity index</li>



<li>Cost per autonomous decision</li>



<li>AI value by business unit</li>



<li>Human escalation rate</li>



<li>Model effectiveness score</li>
</ul>



<p class="wp-block-paragraph">These metrics move AI discussions beyond engineering. They make AI accountable for business outcomes.</p>



<h2 class="wp-block-heading">A new responsibility for CIOs</h2>



<p class="wp-block-paragraph">The next generation of CIOs will not simply deploy AI. They will manage an economy of intelligence.</p>



<p class="wp-block-paragraph">Their role will resemble that of a portfolio manager — allocating AI capacity where it creates the greatest enterprise value, reducing waste, and continuously improving the productivity of every autonomous workflow.</p>



<p class="wp-block-paragraph">That responsibility cannot be fulfilled by dashboards alone. It requires an intelligent layer capable of observing, learning, and optimizing the entire agent ecosystem.</p>



<p class="wp-block-paragraph">That is the emerging role of the meta agent.</p>



<h2 class="wp-block-heading">The next competitive advantage</h2>



<p class="wp-block-paragraph">Every technological revolution rewards organizations that learn to measure what others overlook.</p>



<p class="wp-block-paragraph">Factories measured productivity — not fuel consumption.</p>



<p class="wp-block-paragraph">Digital businesses measured customer engagement — not server utilization.</p>



<p class="wp-block-paragraph">The agentic enterprise will reward organizations that measure intelligence itself.</p>



<p class="wp-block-paragraph">The winners will not be those deploying the largest models. Nor the most agents. Nor consuming the fewest tokens.</p>



<p class="wp-block-paragraph">They will be the organizations that continuously maximize return on tokens, relentlessly reduce token entropy, and increase token exergy.</p>



<p class="wp-block-paragraph">I believe this is the next evolution of the agentic enterprise.</p>



<p class="wp-block-paragraph">Not simply governed intelligence, but economically optimized intelligence.</p>



<p class="wp-block-paragraph"><a href="https://www.cio.com/article/4183263/the-ai-adoption-spree-is-over-time-to-focus-on-value.html?utm=hybrid_search">The AI adoption spending spree is over. Time to focus on value.</a></p>



<p class="wp-block-paragraph">And in that future, meta agents will serve not only as the guardians of AI — but as the stewards of enterprise intelligence economics.</p>



<p class="wp-block-paragraph">Through this framework I strongly believe that executives can easily remember the key measures for economic intelligence. </p>



<ul class="wp-block-list">
<li><strong>ROT (return on tokens):</strong> How much value did AI create?</li>



<li><strong>Token entropy:</strong> Where are we wasting AI intelligence?</li>



<li><strong>Token exergy:</strong> How effectively are we converting AI intelligence into useful business work?</li>
</ul>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why meta agents must become the economic intelligence layer of the agentic enterprise]]></title>
<description><![CDATA[In “Micro and macro agents: The emerging architecture of the agentic enterprise,” I proposed a three-layer architecture for enterprise AI.




Micro agents execute specialized tasks.



Macro agents orchestrate end-to-end business processes.



Meta agents provide governance through monitoring, c...]]></description>
<link>https://tsecurity.de/de/3703196/it-nachrichten/why-meta-agents-must-become-the-economic-intelligence-layer-of-the-agentic-enterprise/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3703196/it-nachrichten/why-meta-agents-must-become-the-economic-intelligence-layer-of-the-agentic-enterprise/</guid>
<pubDate>Tue, 04 Aug 2026 14:25:10 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">In “<a href="https://www.cio.com/article/4157977/micro-and-macro-agents-the-emerging-architecture-of-the-agentic-enterprise.html?utm=hybrid_search">Micro and macro agents: The emerging architecture of the agentic enterprise</a>,” I proposed a three-layer architecture for enterprise AI.</p>



<ol class="wp-block-list">
<li><strong>Micro agents</strong> execute specialized tasks.</li>



<li><strong>Macro agents</strong> orchestrate end-to-end business processes.</li>



<li><strong>Meta agents</strong> provide governance through monitoring, compliance, security, and human oversight.</li>
</ol>



<p class="wp-block-paragraph">As enterprises begin deploying thousands — and eventually tens of thousands — of autonomous agents, token costs have become a major concern. According to <a href="https://www.gartner.com/en/newsroom/press-releases/2026-06-24-gartner-predicts-ai-coding-costs-will-surpass-average-developer-salary-by-2028-as-token-consumption-surges">Gartner</a>, rising token-driven AI spend is straining budgets and challenging cost justification.</p>



<p class="wp-block-paragraph">To track this economic concern, meta agents should do more than simply being the governance agents.</p>



<p class="wp-block-paragraph">They should become the economic intelligence layer of the enterprise.</p>



<p class="wp-block-paragraph">Their responsibility is not only ensuring AI behaves responsibly.</p>



<p class="wp-block-paragraph">It is ensuring AI creates measurable business value.</p>



<h2 class="wp-block-heading">The missing economic model for AI</h2>



<p class="wp-block-paragraph">Every major technology revolution eventually develops its own economic framework:</p>



<ul class="wp-block-list">
<li>Manufacturing measured productivity.</li>



<li>Cloud computing measured infrastructure utilization.</li>



<li>Digital businesses measured customer acquisition costs and lifetime value.</li>
</ul>



<p class="wp-block-paragraph">The agentic enterprise now requires its own financial discipline. Every AI prompt. Every reasoning cycle. Every interaction between agents. Every autonomous workflow.</p>



<p class="wp-block-paragraph">Tokens have quietly become the <a href="https://www.networkworld.com/article/4153278/tokenomics-why-it-leaders-need-to-pay-attention-to-ai-tokens.html?utm_source=miso&amp;utm_medium=related&amp;utm_campaign=thumbnail_list">operational currency</a> of enterprise AI. <a href="https://www.cio.com/article/4184596/tokenomics-in-enterprise-ai.html?utm=hybrid_search">Tokenomics is now a foundational part of enterprise AI architecture.</a></p>



<p class="wp-block-paragraph">Yet today, most organizations measure only one thing: Cost. How many tokens were consumed? Which models cost the most? What was the monthly inference bill?</p>



<p class="wp-block-paragraph">These are useful operational metrics.</p>



<p class="wp-block-paragraph">They are not strategic business metrics. Boards rarely ask how much electricity a factory consumed. They ask how much value the factory produced.</p>



<p class="wp-block-paragraph">Enterprise AI deserves the same conversation.</p>



<p class="wp-block-paragraph">This is where I was thinking about the laws of physics.  Based on physics laws,  energy cannot be created or destroyed. It is transformed into another form. Electricity becomes light. Chemical energy becomes motion. Solar energy becomes electricity.</p>



<p class="wp-block-paragraph">Enterprise AI offers a similar management lesson.</p>



<h2 class="wp-block-heading">Intelligence must be transformed into value</h2>



<p class="wp-block-paragraph">Tokens are not valuable because they are consumed. They become valuable only when they are transformed into business outcomes. A faster loan application decision. A fraud detection. A better customer experience. Higher software quality. Greater employee productivity. A new business opportunity.</p>



<p class="wp-block-paragraph">This leads to what I call return on tokens (ROT).</p>



<p class="wp-block-paragraph">ROT measures how effectively an organization converts token consumption into measurable business value.</p>



<p class="wp-block-paragraph">Instead of asking, “How many tokens did we consume,” leaders should ask, “How much enterprise value did every million tokens create?”</p>



<p class="wp-block-paragraph">The <a href="https://en.wikipedia.org/wiki/Second_law_of_thermodynamics">Second Law of Thermodynamics</a> tells us something equally important: Every energy transformation introduces inefficiencies. Although total energy is conserved, some inevitably becomes less useful for doing work.</p>



<p class="wp-block-paragraph">Enterprise AI behaves similarly.</p>



<h2 class="wp-block-heading">The second law: Every AI transformation creates friction</h2>



<p class="wp-block-paragraph">Not every token creates value. Some tokens are spent on repeated reasoning. Some generate redundant conversations between agents. Some support oversized context windows. Some produce hallucinations requiring correction. Some route simple tasks to unnecessarily expensive models.</p>



<p class="wp-block-paragraph">The tokens are not lost. But they create very little useful business work.</p>



<p class="wp-block-paragraph">I refer to this as token entropy. Token entropy represents the portion of AI activity that consumes intelligence without producing proportional business outcomes.</p>



<p class="wp-block-paragraph">Every agentic enterprise will experience token entropy. The organizations that win will be the ones that continuously identify and reduce it.</p>



<h2 class="wp-block-heading">Beyond energy: The importance of exergy</h2>



<p class="wp-block-paragraph">Thermodynamics offers another concept that is even more relevant. It is called Exergy.</p>



<p class="wp-block-paragraph">Unlike energy, exergy measures the amount of energy that can actually be converted into useful work. Two systems may contain the same amount of energy while producing dramatically different levels of useful output.</p>



<p class="wp-block-paragraph">The same principle applies to enterprise AI. Two organizations may consume exactly the same number of tokens.</p>



<p class="wp-block-paragraph">One generates meeting summaries.</p>



<p class="wp-block-paragraph">The other transforms loan  processing, accelerates software development, detects fraud, improves customer retention, and creates new revenue streams.</p>



<p class="wp-block-paragraph">Their token consumption is identical. Their business impact is not.</p>



<p class="wp-block-paragraph">Borrowing it as a management analogy, not claiming that AI tokens literally obey the thermodynamic definition of exergy. I think of this as token exergy. It’s not that AI tokens literally obey the thermodynamic definition of exergy. </p>



<p class="wp-block-paragraph">Token exergy measures how much of an organization’s AI intelligence is converted into useful business work. It is not enough to consume tokens efficiently. Organizations must convert those tokens into outcomes that matter.</p>



<h2 class="wp-block-heading">The meta agent evolves</h2>



<p class="wp-block-paragraph">This is where meta agents become transformational.</p>



<p class="wp-block-paragraph">Today we think of them as governance agents. Tomorrow they become economic governors.</p>



<p class="wp-block-paragraph">Meta agents continuously monitor every interaction across the enterprise and answer questions such as:</p>



<ul class="wp-block-list">
<li>Which agents produce the highest ROT?</li>



<li>Where is token entropy increasing?</li>



<li>Which workflows generate the highest token exergy?</li>



<li>Which models deliver the greatest business value per token?</li>



<li>Which agents should use smaller models?</li>



<li>Which prompts should be optimized?</li>



<li>Which workflows require human intervention?</li>



<li>Which autonomous processes should be redesigned?</li>
</ul>



<p class="wp-block-paragraph">Meta agents no longer simply supervise AI. They optimize its economics.</p>



<h2 class="wp-block-heading">The economic intelligence layer</h2>



<p class="wp-block-paragraph">The architecture now becomes complete.</p>



<ul class="wp-block-list">
<li><strong>Micro agents:</strong> Perform work.</li>



<li><strong>Macro agents:</strong> Coordinate work.</li>



<li><strong>Meta agents:</strong> OGovern, observe, optimize, and continuously improve the economics of intelligence.</li>
</ul>



<p class="wp-block-paragraph">Their objective is straightforward:</p>



<ul class="wp-block-list">
<li>Maximize return on tokens.</li>



<li>Minimize token entropy.</li>



<li>Increase token exergy.</li>
</ul>



<p class="wp-block-paragraph">This represents a shift from AI governance to AI economics<strong>.</strong></p>



<h2 class="wp-block-heading">The executive dashboard of tomorrow</h2>



<p class="wp-block-paragraph">The executive dashboard of the future will not focus solely on infrastructure metrics. It will measure intelligence performance.</p>



<p class="wp-block-paragraph">Imagine a boardroom dashboard displaying:</p>



<ul class="wp-block-list">
<li>Return on tokens (ROT)</li>



<li>Token entropy index</li>



<li>Token exergy score</li>



<li>Business value per million tokens</li>



<li>Agent productivity index</li>



<li>Cost per autonomous decision</li>



<li>AI value by business unit</li>



<li>Human escalation rate</li>



<li>Model effectiveness score</li>
</ul>



<p class="wp-block-paragraph">These metrics move AI discussions beyond engineering. They make AI accountable for business outcomes.</p>



<h2 class="wp-block-heading">A new responsibility for CIOs</h2>



<p class="wp-block-paragraph">The next generation of CIOs will not simply deploy AI. They will manage an economy of intelligence.</p>



<p class="wp-block-paragraph">Their role will resemble that of a portfolio manager — allocating AI capacity where it creates the greatest enterprise value, reducing waste, and continuously improving the productivity of every autonomous workflow.</p>



<p class="wp-block-paragraph">That responsibility cannot be fulfilled by dashboards alone. It requires an intelligent layer capable of observing, learning, and optimizing the entire agent ecosystem.</p>



<p class="wp-block-paragraph">That is the emerging role of the meta agent.</p>



<h2 class="wp-block-heading">The next competitive advantage</h2>



<p class="wp-block-paragraph">Every technological revolution rewards organizations that learn to measure what others overlook.</p>



<p class="wp-block-paragraph">Factories measured productivity — not fuel consumption.</p>



<p class="wp-block-paragraph">Digital businesses measured customer engagement — not server utilization.</p>



<p class="wp-block-paragraph">The agentic enterprise will reward organizations that measure intelligence itself.</p>



<p class="wp-block-paragraph">The winners will not be those deploying the largest models. Nor the most agents. Nor consuming the fewest tokens.</p>



<p class="wp-block-paragraph">They will be the organizations that continuously maximize return on tokens, relentlessly reduce token entropy, and increase token exergy.</p>



<p class="wp-block-paragraph">I believe this is the next evolution of the agentic enterprise.</p>



<p class="wp-block-paragraph">Not simply governed intelligence, but economically optimized intelligence.</p>



<p class="wp-block-paragraph"><a href="https://www.cio.com/article/4183263/the-ai-adoption-spree-is-over-time-to-focus-on-value.html?utm=hybrid_search">The AI adoption spending spree is over. Time to focus on value.</a></p>



<p class="wp-block-paragraph">And in that future, meta agents will serve not only as the guardians of AI — but as the stewards of enterprise intelligence economics.</p>



<p class="wp-block-paragraph">Through this framework I strongly believe that executives can easily remember the key measures for economic intelligence. </p>



<ul class="wp-block-list">
<li><strong>ROT (return on tokens):</strong> How much value did AI create?</li>



<li><strong>Token entropy:</strong> Where are we wasting AI intelligence?</li>



<li><strong>Token exergy:</strong> How effectively are we converting AI intelligence into useful business work?</li>
</ul>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google ADK flaws reveal what happens when AI agents trust the wrong message]]></title>
<description><![CDATA[Security flaws in automated workflows in the GitHub repository for Google’s Agent Development Kit for Python could allow public-facing AI agents to trigger more privileged automation, opening one path to manipulate pull-request reviews and another to expose credentials, according to a report from...]]></description>
<link>https://tsecurity.de/de/3703097/ai-nachrichten/google-adk-flaws-reveal-what-happens-when-ai-agents-trust-the-wrong-message/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3703097/ai-nachrichten/google-adk-flaws-reveal-what-happens-when-ai-agents-trust-the-wrong-message/</guid>
<pubDate>Tue, 04 Aug 2026 13:57:08 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Security flaws in automated workflows in the GitHub repository for Google’s Agent Development Kit for Python could allow <a href="https://www.csoonline.com/article/4193498/ai-agents-fall-for-indirect-prompt-injection-traps.html" target="_blank">public-facing AI agents</a> to trigger more privileged automation, opening one path to manipulate pull-request reviews and another to expose credentials, according to a <a href="https://www.pillar.security/blog/ill-just-call-you-agent-to-agent-privilege-boundary-failures-in-ci-cd-on-googles-adk-repository">report</a> from Pillar Security.</p>



<p class="wp-block-paragraph">The first attack path involved a triage agent that analyzed pull requests submitted by external contributors. The agent posted its responses through adk-bot, an account with collaborator access to the repository. Pillar found that malicious instructions embedded in a pull request could induce the agent to post an “@gemini-cli” command, triggering a workflow intended for trusted users.</p>



<p class="wp-block-paragraph">That workflow could enable command execution inside its CI runner. Its GitHub token could not push code, but it had write access to issues and pull requests. Pillar said those permissions could be used to alter a maintainer’s comment, submit an approving review as github-actions[bot], and remove a legitimate review request, making a malicious pull request appear ready to merge.</p>



<p class="wp-block-paragraph">Pillar reproduced the first attack chain in its research environment. A maintainer still had to complete the merge, and the report said Google subsequently hardened the repository.</p>



<p class="wp-block-paragraph">The security firm also found a separate attack path in newer workflows built around an Antigravity-based agent. An attacker could place a <a href="https://www.csoonline.com/article/4184455/prompt-injection-breaks-todays-ai-agents-study-warns.html">prompt injection</a> in a public issue and induce an analysis agent to post the command that started a fixing workflow reserved for trusted repository users.</p>



<p class="wp-block-paragraph">The fixing workflow attempted to limit the agent to Git and GitHub commands, but Pillar found that Git could still be used to launch arbitrary code. The researchers demonstrated that the adk-bot personal access token could be extracted from the runner to an attacker-controlled server, while a Google Cloud service account key was also available to the workflow.</p>



<p class="wp-block-paragraph">Pillar said it confirmed on July 2 that the affected workflows had been removed and that Google told the researchers on July 21 that the second issue had been fixed.</p>



<h2 class="wp-block-heading">Agent handoffs expose risk</h2>



<p class="wp-block-paragraph">Pillar described the findings as the “first practical, real-world case of agent-to-agent exploitation” involving a production multi-agent system.</p>



<p class="wp-block-paragraph"><a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research, said the underlying weaknesses were familiar, but their interaction required enterprises to reconsider how authority moves through agentic systems.</p>



<p class="wp-block-paragraph">“Natural language has joined the authorization path,” Gogia said. “That is the change worth reporting, not the ‘first-ever’ framing.”</p>



<p class="wp-block-paragraph">Gogia said an agent’s authority should be measured not only by its assigned tools, but also by the more privileged systems its output can trigger or influence.</p>



<p class="wp-block-paragraph">That broader reach should also shape how CISOs judge the severity of the risk, according to <a href="https://my.idc.com/getdoc.jsp?containerId=PRF005665" target="_blank" rel="noreferrer noopener">Sakshi Grover</a>, senior research manager for IDC Asia Pacific Cybersecurity Services.</p>



<p class="wp-block-paragraph">“For CISOs, materiality should be determined by tracing three things,” said Grover. “First, which agents consume untrusted content such as pull requests, issues, emails, support tickets, or external documents? Second, can the output of those agents directly or indirectly trigger another agent or workflow with higher privileges? Third, what is the maximum effective capability of the identities, credentials, and tools involved?”</p>



<h2 class="wp-block-heading">Mapping transitive authority</h2>



<p class="wp-block-paragraph">Existing security tools may provide only a partial view of how authority moves between agents and workflows.</p>



<p class="wp-block-paragraph">Grover said IAM, PAM, CIEM, and application-security tools can expose individual identities, permissions, and unsafe workflow configurations, but may not recognize that those components form a single event-driven delegation path.</p>



<p class="wp-block-paragraph">“Inventory records what exists, while delegation mapping records what can happen,” Gogia said.</p>



<p class="wp-block-paragraph">Gogia added that security teams should follow external input from the point it reaches an agent through to any downstream system that acts on the result. The review should also account for handoffs embedded in shared workflow state, such as a comment that triggers a command.</p>



<p class="wp-block-paragraph">“The harder question is not whether Agent A can call Agent B but whether Agent A can alter anything Agent B already trusts,” he said.</p>



<p class="wp-block-paragraph">Human approval does not necessarily close that gap. Although the first attack path still required a maintainer to merge the pull request, the manipulated automation could influence the evidence presented to the maintainer.</p>



<p class="wp-block-paragraph">“An attacker needs no merge rights when it can manufacture the evidence that persuades someone else to merge,” Gogia said. He added that approval should bind an independently authenticated reviewer to the exact code or artifact examined. Any material change should invalidate that approval.</p>



<p class="wp-block-paragraph">Grover added that changes to reviews, comments, and approval states should also be treated as security events and exported to an independent logging system that the workflow’s own identity cannot alter.</p>



<p class="wp-block-paragraph"><em>The article originally appeared on <a href="https://www.csoonline.com/article/4204906/google-adk-flaws-reveal-what-happens-when-ai-agents-trust-the-wrong-message.html">CSO</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google ADK flaws reveal what happens when AI agents trust the wrong message]]></title>
<description><![CDATA[Security flaws in automated workflows in the GitHub repository for Google’s Agent Development Kit for Python could allow public-facing AI agents to trigger more privileged automation, opening one path to manipulate pull-request reviews and another to expose credentials, according to a report from...]]></description>
<link>https://tsecurity.de/de/3703074/it-security-nachrichten/google-adk-flaws-reveal-what-happens-when-ai-agents-trust-the-wrong-message/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3703074/it-security-nachrichten/google-adk-flaws-reveal-what-happens-when-ai-agents-trust-the-wrong-message/</guid>
<pubDate>Tue, 04 Aug 2026 13:42:43 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Security flaws in automated workflows in the GitHub repository for Google’s Agent Development Kit for Python could allow <a href="https://www.csoonline.com/article/4193498/ai-agents-fall-for-indirect-prompt-injection-traps.html" target="_blank">public-facing AI agents</a> to trigger more privileged automation, opening one path to manipulate pull-request reviews and another to expose credentials, according to a <a href="https://www.pillar.security/blog/ill-just-call-you-agent-to-agent-privilege-boundary-failures-in-ci-cd-on-googles-adk-repository">report</a> from Pillar Security.</p>



<p class="wp-block-paragraph">The first attack path involved a triage agent that analyzed pull requests submitted by external contributors. The agent posted its responses through adk-bot, an account with collaborator access to the repository. Pillar found that malicious instructions embedded in a pull request could induce the agent to post an “@gemini-cli” command, triggering a workflow intended for trusted users.</p>



<p class="wp-block-paragraph">That workflow could enable command execution inside its CI runner. Its GitHub token could not push code, but it had write access to issues and pull requests. Pillar said those permissions could be used to alter a maintainer’s comment, submit an approving review as github-actions[bot], and remove a legitimate review request, making a malicious pull request appear ready to merge.</p>



<p class="wp-block-paragraph">Pillar reproduced the first attack chain in its research environment. A maintainer still had to complete the merge, and the report said Google subsequently hardened the repository.</p>



<p class="wp-block-paragraph">The security firm also found a separate attack path in newer workflows built around an Antigravity-based agent. An attacker could place a <a href="https://www.csoonline.com/article/4184455/prompt-injection-breaks-todays-ai-agents-study-warns.html">prompt injection</a> in a public issue and induce an analysis agent to post the command that started a fixing workflow reserved for trusted repository users.</p>



<p class="wp-block-paragraph">The fixing workflow attempted to limit the agent to Git and GitHub commands, but Pillar found that Git could still be used to launch arbitrary code. The researchers demonstrated that the adk-bot personal access token could be extracted from the runner to an attacker-controlled server, while a Google Cloud service account key was also available to the workflow.</p>



<p class="wp-block-paragraph">Pillar said it confirmed on July 2 that the affected workflows had been removed and that Google told the researchers on July 21 that the second issue had been fixed.</p>



<h2 class="wp-block-heading">Agent handoffs expose risk</h2>



<p class="wp-block-paragraph">Pillar described the findings as the “first practical, real-world case of agent-to-agent exploitation” involving a production multi-agent system.</p>



<p class="wp-block-paragraph"><a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research, said the underlying weaknesses were familiar, but their interaction required enterprises to reconsider how authority moves through agentic systems.</p>



<p class="wp-block-paragraph">“Natural language has joined the authorization path,” Gogia said. “That is the change worth reporting, not the ‘first-ever’ framing.”</p>



<p class="wp-block-paragraph">Gogia said an agent’s authority should be measured not only by its assigned tools, but also by the more privileged systems its output can trigger or influence.</p>



<p class="wp-block-paragraph">That broader reach should also shape how CISOs judge the severity of the risk, according to <a href="https://my.idc.com/getdoc.jsp?containerId=PRF005665" target="_blank" rel="noreferrer noopener">Sakshi Grover</a>, senior research manager for IDC Asia Pacific Cybersecurity Services.</p>



<p class="wp-block-paragraph">“For CISOs, materiality should be determined by tracing three things,” said Grover. “First, which agents consume untrusted content such as pull requests, issues, emails, support tickets, or external documents? Second, can the output of those agents directly or indirectly trigger another agent or workflow with higher privileges? Third, what is the maximum effective capability of the identities, credentials, and tools involved?”</p>



<h2 class="wp-block-heading">Mapping transitive authority</h2>



<p class="wp-block-paragraph">Existing security tools may provide only a partial view of how authority moves between agents and workflows.</p>



<p class="wp-block-paragraph">Grover said IAM, PAM, CIEM, and application-security tools can expose individual identities, permissions, and unsafe workflow configurations, but may not recognize that those components form a single event-driven delegation path.</p>



<p class="wp-block-paragraph">“Inventory records what exists, while delegation mapping records what can happen,” Gogia said.</p>



<p class="wp-block-paragraph">Gogia added that security teams should follow external input from the point it reaches an agent through to any downstream system that acts on the result. The review should also account for handoffs embedded in shared workflow state, such as a comment that triggers a command.</p>



<p class="wp-block-paragraph">“The harder question is not whether Agent A can call Agent B but whether Agent A can alter anything Agent B already trusts,” he said.</p>



<p class="wp-block-paragraph">Human approval does not necessarily close that gap. Although the first attack path still required a maintainer to merge the pull request, the manipulated automation could influence the evidence presented to the maintainer.</p>



<p class="wp-block-paragraph">“An attacker needs no merge rights when it can manufacture the evidence that persuades someone else to merge,” Gogia said. He added that approval should bind an independently authenticated reviewer to the exact code or artifact examined. Any material change should invalidate that approval.</p>



<p class="wp-block-paragraph">Grover added that changes to reviews, comments, and approval states should also be treated as security events and exported to an independent logging system that the workflow’s own identity cannot alter.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[John Ternus Rehires Former Apple VP Ahead of CEO Takeover]]></title>
<description><![CDATA[John Ternus is preparing to take over as Apple CEO on September 1, and he has started shaping the leadership team that will support him during the transition. His latest move brings former Apple hardware engineering executive Laura Legros back to the company after her retirement in 2022.



Bloom...]]></description>
<link>https://tsecurity.de/de/3703014/ios-mac-os/john-ternus-rehires-former-apple-vp-ahead-of-ceo-takeover/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3703014/ios-mac-os/john-ternus-rehires-former-apple-vp-ahead-of-ceo-takeover/</guid>
<pubDate>Tue, 04 Aug 2026 13:34:28 +0200</pubDate>
<content:encoded><![CDATA[John Ternus is preparing to take over as Apple CEO on September 1, and he has started shaping the leadership team that will support him during the transition. His latest move brings former Apple hardware engineering executive Laura Legros back to the company after her retirement in 2022.



Bloomberg reports that Legros will join Ternus’s management team as a vice president working across several parts of Apple. She will report directly to Ternus once he officially replaces Tim Cook as chief executive.




“Legros helped manage product delivery, development schedules and coordination across engineering teams to ensure they remained aligned,” Bloomberg’s Mark Gurman reported while outlining her previous responsibilities at Apple.




Legros previously served as one of Ternus’s most trusted deputies and played a visible role during major Apple launches. She introduced a redesigned MacBook Air in 2018 and later presented the current iPad Air design in 2020.



Apple prepares for wider leadership changes



Ternus has spent the past several months shadowing Cook, helping lead executive meetings and meeting senior leaders across Apple. He has also taken part in road-map reviews covering several divisions as the company prepares for the next year.



The leadership change will place Ternus in charge during a period when several senior Apple executives are nearing retirement. Gurman reports that the incoming CEO will likely oversee further changes involving long-serving leaders, including App Store chief Phil Schiller and Luca Maestri, who manages Apple’s real estate and information systems.



Bringing Legros back gives Ternus an experienced executive who already understands Apple’s hardware teams, product schedules and internal decision-making process as he prepares to lead the company.]]></content:encoded>
</item>
<item>
<title><![CDATA[The enterprise AI strategy that outlasts any single model]]></title>
<description><![CDATA[In January of this year, few enterprise tech leaders would have bet on Anthropic over OpenAI. Today, Claude reigns supreme (inspiring a notable 180 by Elon Musk), with Gemini threatening to take market share and introduce pricing models that could flip the leaderboard on its head again. That’s ex...]]></description>
<link>https://tsecurity.de/de/3702962/it-security-nachrichten/the-enterprise-ai-strategy-that-outlasts-any-single-model/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3702962/it-security-nachrichten/the-enterprise-ai-strategy-that-outlasts-any-single-model/</guid>
<pubDate>Tue, 04 Aug 2026 13:17:00 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">In January of this year, few enterprise tech leaders would have bet on Anthropic over OpenAI. Today, <a href="https://www.forbes.com/sites/sandycarter/2026/06/05/claude-becomes-the-enterprise-favorite-as-anthropic-passes-openai/">Claude reigns supreme</a> (inspiring a <a href="https://finance.yahoo.com/technology/ai/articles/musk-calls-rival-anthropic-current-185914796.html">notable 180 by Elon Musk</a>), with Gemini threatening to take market share and <a href="https://www.reuters.com/business/google-expected-court-coders-consumers-io-conference-2026-05-19/">introduce pricing models</a> that could flip the leaderboard on its head again. That’s exactly why betting on a single model is a dangerous strategy.</p>



<p class="wp-block-paragraph">The most successful organizations won’t be those trying to guess tomorrow’s top-tier model, nor will they wait passively for future releases. Instead, they will invest in underlying frameworks that continuously improve regardless of which specific AI model drives them.</p>



<h2 class="wp-block-heading">Why betting on one AI model is a losing strategy</h2>



<p class="wp-block-paragraph">Our strategy for AI, through <a href="https://www.economist.com/science-and-technology/2026/06/07/how-artificial-intelligence-got-better-at-building-itself">recursive self-improvement</a> (RSI), is rooted in this core principle. RSI is an approach to AI that compounds its own abilities by improving itself. If done carefully, RSI can function as an overarching layer above <em>any</em> model. Crucially, given RSI’s inherently compounding trajectory, it represents the most likely contender to be the approach that reaches superintelligence, no matter which model is used underneath.</p>



<p class="wp-block-paragraph">Though recently achieving the status of a <a href="https://techcrunch.com/2026/05/28/rsi-is-the-new-agi-and-its-just-as-hard-to-pin-down/">Silicon Valley buzzword</a>, applying something like RSI to unlock superintelligence has been the Holy Grail of AI research for decades. It’s what researchers like us have recognized since the 1960s as a critical step along the path towards what we call artificial superintelligence (ASI) today.</p>



<h2 class="wp-block-heading">Recursive self-improvement compounds value beyond the model</h2>



<p class="wp-block-paragraph">The fundamental premise of RSI is that the next phase transition in AI won’t come from a system that has been taught to improve by any of the traditional methods of the past few years. Relying purely on data, compute and human intuition to generate exponentially improving capabilities is a path with hard physical and practical limits. Instead, the leap will come from a system that invents its own improvements and feeds them back into itself.</p>



<p class="wp-block-paragraph">RSI has already delivered what business leaders would recognize as a virtuous cycle. Each improvement increases the system’s capacity to generate the next improvement. Competitive advantage compounds because the system benefits from both its own recursive progress and every improvement in the underlying models.</p>



<p class="wp-block-paragraph">As Anthropic puts it, AI that can improve itself would be a “major development in the history of technology.”</p>



<p class="wp-block-paragraph">Indeed, we believe it’s the single most important frontier of AI research. Anthropic’s model-specific approach to RSI is already paying off for them: a recent <a href="https://www.anthropic.com/institute/recursive-self-improvement">Anthropic Institute report</a> captures the pace of change with real world impact, “Claude-written code was somewhat worse than human-written code at Anthropic in late 2025, is roughly at parity today, and we expect it to be strictly better within the year.”</p>



<p class="wp-block-paragraph">That’s worth applauding.</p>



<p class="wp-block-paragraph">But what about the companies not currently building an in-house model? For them, looking at improvements that only take place inside the model someone else develops is unnecessarily limiting. It makes more sense to embrace a model-agnostic approach to RSI that improves whenever any new model is released.</p>



<p class="wp-block-paragraph">Approaching the model as one component of a system without relying on any individual provider or tool makes it possible to achieve recursive improvement at the system level. By using an RSI approach that works outside the model and can swap models instantaneously, companies can immediately benefit from the compounding effects of self-improving AI.</p>



<h2 class="wp-block-heading">Build a model-agnostic AI strategy that benefits from every breakthrough</h2>



<p class="wp-block-paragraph">This holistic approach to RSI fits the market today. The AI landscape is becoming more dynamic by the month. Frontier models leapfrog one another, open-weight models improve at remarkable speed, pricing strategies change and entirely new capabilities emerge in rapid succession. For enterprise leaders, the lesson isn’t to predict the next winner. It’s to build systems that improve regardless of which model comes out ahead.</p>



<p class="wp-block-paragraph">In fact, organizations that tie their future to a single model provider risk getting left behind altogether if a different model’s next iteration leapfrogs the one they’ve signed a long-term contract to use.</p>



<p class="wp-block-paragraph">Every enterprise tech leader already understands the power of virtuous cycles. Amazon didn’t build an enduring competitive advantage by betting on a single product. Every improvement to its logistics network attracted more sellers, which increased selection and order volume, which justified further investment in logistics. Visa became more valuable as more merchants accepted its cards, attracting more cardholders, which, in turn, encouraged even more merchants to join.</p>



<p class="wp-block-paragraph"><a></a>Organizations that anchor their AI strategy to a single model provider will spend the next decade reacting every time the frontier shifts. On the other hand, organizations that build model-agnostic systems will benefit from every shift. Every improvement from Anthropic, OpenAI, Google, Meta or the next breakthrough model becomes another source of competitive advantage.</p>



<p class="wp-block-paragraph"><a></a>The world’s most durable companies don’t simply accumulate assets – they build systems where every improvement makes the next improvement easier; creating long-term advantage.</p>



<p class="wp-block-paragraph"><a></a>Enterprise AI should be approached the same way.</p>



<p class="wp-block-paragraph"><a></a>For enterprise tech leaders, that’s the strategic shift that matters. Stop asking which model deserves your long-term bet and instead, start asking whether your AI strategy creates its own virtuous cycle.<a></a><a></a><a></a></p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The enterprise AI strategy that outlasts any single model]]></title>
<description><![CDATA[In January of this year, few enterprise tech leaders would have bet on Anthropic over OpenAI. Today, Claude reigns supreme (inspiring a notable 180 by Elon Musk), with Gemini threatening to take market share and introduce pricing models that could flip the leaderboard on its head again. That’s ex...]]></description>
<link>https://tsecurity.de/de/3702949/it-nachrichten/the-enterprise-ai-strategy-that-outlasts-any-single-model/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3702949/it-nachrichten/the-enterprise-ai-strategy-that-outlasts-any-single-model/</guid>
<pubDate>Tue, 04 Aug 2026 13:15:58 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">In January of this year, few enterprise tech leaders would have bet on Anthropic over OpenAI. Today, <a href="https://www.forbes.com/sites/sandycarter/2026/06/05/claude-becomes-the-enterprise-favorite-as-anthropic-passes-openai/">Claude reigns supreme</a> (inspiring a <a href="https://finance.yahoo.com/technology/ai/articles/musk-calls-rival-anthropic-current-185914796.html">notable 180 by Elon Musk</a>), with Gemini threatening to take market share and <a href="https://www.reuters.com/business/google-expected-court-coders-consumers-io-conference-2026-05-19/">introduce pricing models</a> that could flip the leaderboard on its head again. That’s exactly why betting on a single model is a dangerous strategy.</p>



<p class="wp-block-paragraph">The most successful organizations won’t be those trying to guess tomorrow’s top-tier model, nor will they wait passively for future releases. Instead, they will invest in underlying frameworks that continuously improve regardless of which specific AI model drives them.</p>



<h2 class="wp-block-heading">Why betting on one AI model is a losing strategy</h2>



<p class="wp-block-paragraph">Our strategy for AI, through <a href="https://www.economist.com/science-and-technology/2026/06/07/how-artificial-intelligence-got-better-at-building-itself">recursive self-improvement</a> (RSI), is rooted in this core principle. RSI is an approach to AI that compounds its own abilities by improving itself. If done carefully, RSI can function as an overarching layer above <em>any</em> model. Crucially, given RSI’s inherently compounding trajectory, it represents the most likely contender to be the approach that reaches superintelligence, no matter which model is used underneath.</p>



<p class="wp-block-paragraph">Though recently achieving the status of a <a href="https://techcrunch.com/2026/05/28/rsi-is-the-new-agi-and-its-just-as-hard-to-pin-down/">Silicon Valley buzzword</a>, applying something like RSI to unlock superintelligence has been the Holy Grail of AI research for decades. It’s what researchers like us have recognized since the 1960s as a critical step along the path towards what we call artificial superintelligence (ASI) today.</p>



<h2 class="wp-block-heading">Recursive self-improvement compounds value beyond the model</h2>



<p class="wp-block-paragraph">The fundamental premise of RSI is that the next phase transition in AI won’t come from a system that has been taught to improve by any of the traditional methods of the past few years. Relying purely on data, compute and human intuition to generate exponentially improving capabilities is a path with hard physical and practical limits. Instead, the leap will come from a system that invents its own improvements and feeds them back into itself.</p>



<p class="wp-block-paragraph">RSI has already delivered what business leaders would recognize as a virtuous cycle. Each improvement increases the system’s capacity to generate the next improvement. Competitive advantage compounds because the system benefits from both its own recursive progress and every improvement in the underlying models.</p>



<p class="wp-block-paragraph">As Anthropic puts it, AI that can improve itself would be a “major development in the history of technology.”</p>



<p class="wp-block-paragraph">Indeed, we believe it’s the single most important frontier of AI research. Anthropic’s model-specific approach to RSI is already paying off for them: a recent <a href="https://www.anthropic.com/institute/recursive-self-improvement">Anthropic Institute report</a> captures the pace of change with real world impact, “Claude-written code was somewhat worse than human-written code at Anthropic in late 2025, is roughly at parity today, and we expect it to be strictly better within the year.”</p>



<p class="wp-block-paragraph">That’s worth applauding.</p>



<p class="wp-block-paragraph">But what about the companies not currently building an in-house model? For them, looking at improvements that only take place inside the model someone else develops is unnecessarily limiting. It makes more sense to embrace a model-agnostic approach to RSI that improves whenever any new model is released.</p>



<p class="wp-block-paragraph">Approaching the model as one component of a system without relying on any individual provider or tool makes it possible to achieve recursive improvement at the system level. By using an RSI approach that works outside the model and can swap models instantaneously, companies can immediately benefit from the compounding effects of self-improving AI.</p>



<h2 class="wp-block-heading">Build a model-agnostic AI strategy that benefits from every breakthrough</h2>



<p class="wp-block-paragraph">This holistic approach to RSI fits the market today. The AI landscape is becoming more dynamic by the month. Frontier models leapfrog one another, open-weight models improve at remarkable speed, pricing strategies change and entirely new capabilities emerge in rapid succession. For enterprise leaders, the lesson isn’t to predict the next winner. It’s to build systems that improve regardless of which model comes out ahead.</p>



<p class="wp-block-paragraph">In fact, organizations that tie their future to a single model provider risk getting left behind altogether if a different model’s next iteration leapfrogs the one they’ve signed a long-term contract to use.</p>



<p class="wp-block-paragraph">Every enterprise tech leader already understands the power of virtuous cycles. Amazon didn’t build an enduring competitive advantage by betting on a single product. Every improvement to its logistics network attracted more sellers, which increased selection and order volume, which justified further investment in logistics. Visa became more valuable as more merchants accepted its cards, attracting more cardholders, which, in turn, encouraged even more merchants to join.</p>



<p class="wp-block-paragraph"><a></a>Organizations that anchor their AI strategy to a single model provider will spend the next decade reacting every time the frontier shifts. On the other hand, organizations that build model-agnostic systems will benefit from every shift. Every improvement from Anthropic, OpenAI, Google, Meta or the next breakthrough model becomes another source of competitive advantage.</p>



<p class="wp-block-paragraph"><a></a>The world’s most durable companies don’t simply accumulate assets – they build systems where every improvement makes the next improvement easier; creating long-term advantage.</p>



<p class="wp-block-paragraph"><a></a>Enterprise AI should be approached the same way.</p>



<p class="wp-block-paragraph"><a></a>For enterprise tech leaders, that’s the strategic shift that matters. Stop asking which model deserves your long-term bet and instead, start asking whether your AI strategy creates its own virtuous cycle.<a></a><a></a><a></a></p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[20 traits of innovative and invaluable project managers]]></title>
<description><![CDATA[Projects are becoming more complex, with higher stakes and faster delivery times.



At the same time automation and AI are changing how projects are designed, managed, and delivered. Indeed, some pieces of project management are now routinely handled by machines.



Some may think that AI and au...]]></description>
<link>https://tsecurity.de/de/3702873/it-nachrichten/20-traits-of-innovative-and-invaluable-project-managers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3702873/it-nachrichten/20-traits-of-innovative-and-invaluable-project-managers/</guid>
<pubDate>Tue, 04 Aug 2026 12:16:11 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Projects are becoming more complex, with higher stakes and faster delivery times.</p>



<p class="wp-block-paragraph">At the same time automation and AI are changing how projects are designed, managed, and delivered. Indeed, some pieces of project management are now routinely handled by machines.</p>



<p class="wp-block-paragraph">Some may think that AI and automation will make project managers obsolete, or at least less critical to project success. Executives say that’s not the case. Project managers are as important now as they ever were to project success.</p>



<p class="wp-block-paragraph">“As we move forward, the role of project manager is actually becoming increasingly important for finding the right things to invest in, defining scope, and staying focused on value,” says <a href="https://www.linkedin.com/in/noah-fletcher-9012ba4/">Noah Fletcher</a>, a partner in the operations excellence practice at consultancy West Monroe. “As we continue to accelerate, their value is really about quality — quality of what you’re trying to accomplish.”</p>



<p class="wp-block-paragraph">That doesn’t mean that the role of project manager is static. Rather, the role is evolving, with what it takes to be successful is changing to meet the needs of the moment.</p>



<p class="wp-block-paragraph">To thrive, project managers need to hone a complex combination of technical, business, and interpersonal skills. The Project Management Institute attempts to decode what it takes to be a successful project manager with its <a href="https://www.pmi.org/learning/training-development/talent-triangle">PMI Talent Triangle</a>, comprising Ways of Working, Power Skills, and Business Acumen.</p>



<p class="wp-block-paragraph">Not surprisingly, there’s a lot packed into those three areas. Effective project managers must know how to define <a href="https://www.cio.com/article/193441/what-is-project-scope-defining-and-outlining-project-success.html">the scope of a project</a>, identify necessary resources, and schedule those resources — all part of the technical aspect of the job. They must also <a href="https://www.cio.com/article/196244/stakeholder-management-your-plan-for-influencing-project-outcomes.html">manage stakeholders</a> and ensure projects align with business goals — skills that fall under the other two talent buckets.</p>



<p class="wp-block-paragraph">As lengthy as the PMI’s list of required skills is, experienced project leaders say that’s not enough to rise to the top of the profession; highly effective project managers today bring even more to their jobs.</p>



<p class="wp-block-paragraph">They’re curious, flexible, and adaptive — and they learn from and know how to right their mistakes. They’re empathetic, persuasive, and visionary. They know how to play to their own and others’ strengths.</p>



<p class="wp-block-paragraph">Leading project professionals say the most successful PMs are those who know the academic parts of the job — that is, the elements that are taught — but they also bring finesse to the work.</p>



<p class="wp-block-paragraph">So, what characteristics distinguish the most effective project managers? Longtime project leaders list the following key traits and skills as vital to succeeding at a high level.</p>



<h2 class="wp-block-heading">1. They serve as a strategic business partner</h2>



<p class="wp-block-paragraph">Top-level project managers are more than good managers. They have high-level strategic leadership skills and know how their projects fit within overall strategic goals, making them well equipped to make the right decisions for the project and the organization as a whole.</p>



<p class="wp-block-paragraph">“A project exists because it responds to a need of the business. That might be due to trends impacting the business or a challenge in running the business, but without understanding that, it will be hard for the project manager to deliver a successful project,” says <a href="https://www.pmi.org/about/leadership-governance/karla-eidem">Karla Eidem</a>, a Project Management Professional (PMP) and PMI’s global head of transformation and project delivery.</p>



<h2 class="wp-block-heading">2. They know the business</h2>



<p class="wp-block-paragraph">The most effective project managers aren’t just great leaders; they’re also business-savvy.</p>



<p class="wp-block-paragraph">“They understand strategy and business context,” Fletcher says. As they deal with shifting resources and changing market dynamics that happen during many projects, they focus on what work will bring business value — not merely what will tick off items on a task list. “That ability to work on the right thing is one of the most important things that a project manager can have,” Fletcher adds.</p>



<h2 class="wp-block-heading">3. They’re strong technologists</h2>



<p class="wp-block-paragraph">Projects today nearly always involve technology, making it essential to have technology skills. But standout project managers are true technologists, too.</p>



<p class="wp-block-paragraph">“Increasingly IT is touching so many different area, and we’re seeing systems and architecture getting more connected, so understanding how business and operations fit together is critical,” Fletcher says.</p>



<h2 class="wp-block-heading">4. They’re financially astute</h2>



<p class="wp-block-paragraph">Project management always involved budget management, but the task today requires more than balancing the books. It also involves understanding how projects and the core components of any given initiative bring value to the business. That takes financial acumen and the ability to make smart decisions during project execution to ensure the business sees returns on its investment.</p>



<p class="wp-block-paragraph">“The best project managers know the business drivers and can get depth on how the project impacts the business financially,” Fletcher says. “They have a good value management framework, that end-to-end process that can take the business case all the way through.”</p>



<h2 class="wp-block-heading">5. They possess extraordinary organizational skills</h2>



<p class="wp-block-paragraph">Top-notch project managers are highly organized individuals. But it’s not just about making a list and sticking with it. They understand how project plans and resources are intertwined with other goings-on within the organization. That organizational capacity enables them to adjust their plans and resources when needed.</p>



<p class="wp-block-paragraph"><a href="https://www.pmi.org/about/leadership-governance/lenka-pincot">Lenka Pincot</a>, chief of staff to the CEO at PMI, says today’s top-notch project managers are “orchestrators” who can pull together the complex components of modern projects and get them to work in harmony.</p>



<p class="wp-block-paragraph">“Organizations need orchestrators who can synchronize all the changes happening so the results all make sense,” she says. She notes that orchestration takes systems thinking as well as the ability to identify and plan for unintended consequences.</p>



<h2 class="wp-block-heading">6. They’re problem-solvers</h2>



<p class="wp-block-paragraph">The best project managers are good at delving into and solving for the “why” behind projects.</p>



<p class="wp-block-paragraph">“They enjoy problem-solving,” Pincot says. “[As project managers], we’re not handed projects; we are handed problems to solve. So we need to get to the bottom of what’s not working. We need to ask questions and really listen for what someone’s true interests are.”</p>



<h2 class="wp-block-heading">7. They thrive in fast-paced environments</h2>



<p class="wp-block-paragraph">Executives constantly talk about the speed of change today. Teams must work fast to keep up with shifting technology and business contexts, and project managers must be able to facilitate that, Fletcher says.</p>



<p class="wp-block-paragraph">“The ability to quickly identify the right tools, assign the right resources, accelerate testing, and to move things forward fast without compromising quality is a huge thing today,” he adds.</p>



<h2 class="wp-block-heading">8. They are flexible</h2>



<p class="wp-block-paragraph">Similarly, highly effective project managers are flexible, so they themselves aren’t flummoxed when project plans need adjustments — something that happens increasingly more often in the modern digital world.</p>



<p class="wp-block-paragraph">“Adaptability is huge,” says <a href="https://www.linkedin.com/in/krista-phillips-pmp-858aab98/">Krista Phillips</a>, a PMP holder and project management consultant. “Things are always going to change, priorities adjust, resources adjust, timelines change. Project managers must be able to successfully manage all that.”</p>



<h2 class="wp-block-heading">9. They are persuasive</h2>



<p class="wp-block-paragraph">Project managers typically manage teams but aren’t the boss of any of them, meaning they must be capable of leading and workers without having to lean on any official authority, explains <a href="https://www.linkedin.com/in/juliefbutcher/">Julie Butcher</a>, a fractional CIO work and transformation principal consultant with Butte Information Group. The best project managers are masters of this skill.</p>



<h2 class="wp-block-heading">10. They have ‘extreme awareness’</h2>



<p class="wp-block-paragraph"><a href="https://www.infotech.com/profiles/barry-cousins">Barry Cousins</a>, a distinguished analyst and research fellow specializing in project portfolio management, project management, and organizational change management at Info-Tech Research Group, says top project managers possess what he calls “extreme awareness of resource capacity and utilization.”</p>



<p class="wp-block-paragraph">“Savvy project managers in the modern era have immediate implicit awareness of the capacity around them, so then they’re going to know right off the bat when their projects are going to fall short,” Cousin adds. Furthermore, they’re more comfortable alerting business leaders to that situation because they’re able to quantify the shortfall.</p>



<p class="wp-block-paragraph">Others agree, saying this all speaks to the need for project managers to have strong emotional intelligence.</p>



<h2 class="wp-block-heading">11. They have highly tuned stakeholder management skills</h2>



<p class="wp-block-paragraph">Project managers work with numerous stakeholders from various departments within and outside their organizations, and those who manage those relationships best understand each stakeholder’s perspectives, say <a href="https://www.linkedin.com/in/te-wu/">Te Wu</a>, CEO and chief project officer at PMO Advisory.</p>



<p class="wp-block-paragraph">Wu adds that stakeholders can now also include AI agents.</p>



<p class="wp-block-paragraph">For example, some stakeholders may be more risk adverse than others, or more resistant to change, or more prone to panic when problems arise.</p>



<p class="wp-block-paragraph">Veteran project leaders say managers who can identify and empathize with those perspectives can tailor their communications, plans, and training to address each stakeholder’s unique points of view.</p>



<h2 class="wp-block-heading">12. They understand who has authority</h2>



<p class="wp-block-paragraph">Organizations today have distributed authority, so project managers must know who has say over what pieces — whether they’re dealing with 10 IT architects who each control a piece of the IT environment or 10 executives who have responsibilities for separate areas of the enterprise impacted by a project.</p>



<p class="wp-block-paragraph">“The savvy project manager knows to give them all room to succeed,” Cousins explains. That means staying on top of what each person’s realm of authority needs for the project to succeed, identifying who has ownership for what pieces, and knowing which person has true authority and can get others to line up behind him or her.</p>



<p class="wp-block-paragraph">“It often requires getting to know people who are at a layer of the company that you don’t play in,” Cousins says.</p>



<h2 class="wp-block-heading">13. They can navigate office politics</h2>



<p class="wp-block-paragraph">In addition to being good at stakeholder management, elite project managers also know how to navigate office politics. That means navigating not only individual stakeholder’s needs and expectations but also understanding how those stakeholders interact with each other, who has influence over the others, and who has power to override the authority of others.</p>



<p class="wp-block-paragraph">“They know when to apply what type of pressure to get something accomplished,” Wu adds.</p>



<h2 class="wp-block-heading">14. They’re decisive</h2>



<p class="wp-block-paragraph">Given the speed, complexity and fluidity of project work today, project managers must be critical thinkers and decisive decision-makers. Otherwise, they risk falling into analysis-paralysis and bringing work to a halt.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/varunbijlani/">Varun Bijlani</a>, global managing partner for solutions and delivery at IBM Consulting, says the best project managers can confidently and consistently make good calls even in the face of ambiguity.</p>



<p class="wp-block-paragraph">“IT projects are rife with it, even though everyone walks in expecting full clarity and specificity: requirements shift, priorities compete, expectations are unclear, unplanned technical issues arise,” he says. “AI can surface options and synthesize information fast, but it can’t apply the contextual judgment, reasoning, and organizational awareness needed to weigh trade-offs and commit to a direction when the path isn’t clear. That’s still a human call.”</p>



<h2 class="wp-block-heading">15. They communicate effectively</h2>



<p class="wp-block-paragraph">Considering communication plays a significant role in <a href="https://www.cio.com/article/196244/stakeholder-management-your-plan-for-influencing-project-outcomes.html">managing projects, teams, and other stakeholders</a>, it is one of the essential skills for effective project managers, according to longtime project managers.</p>



<p class="wp-block-paragraph">Communication doesn’t just mean being a stellar facilitator, speaker, or writer; it requires good listening skills, too. As such, top managers actively listen to what’s said — and not said — and can take context into account.</p>



<p class="wp-block-paragraph">These skills enable project managers to synthesize information and then clearly and concisely sharing that information back with all those involved, Pincot explains.</p>



<p class="wp-block-paragraph">“They have to be able to translate business needs to technology teams and explain how technology creates value for the business so that everyone can understand and trust that information,” she adds.</p>



<h2 class="wp-block-heading">16. They build community</h2>



<p class="wp-block-paragraph">“I believe the ‘P’ in PM is for the people: You can’t do a project without a team. And the team might not report to the project manager, so you have to have collaborative leadership, problem-solving, and communication skills to activate your team. Without that you can’t really move the needle,” Eidem says. “But in a project, you’re working with people who might have different priorities and different understanding of the goals of the project, so it’s the project manager’s responsibility to make sure everyone is aligned and knows where they’re going.”</p>



<p class="wp-block-paragraph">Butcher agrees, saying that the best project managers know how to build a sense of community among the teams as well as with the workers on the periphery of projects so that everyone is willing to work toward a shared objective.</p>



<h2 class="wp-block-heading">17. They build rapport</h2>



<p class="wp-block-paragraph">Top project managers are also skilled at developing strong rapport with those around them — even for short-lived projects — knowing that good connections and solid relationships lead to success.</p>



<p class="wp-block-paragraph">“When you build rapport, there’s a shared understanding,” Phillips says. That shared understanding pays dividends. Project managers who take time to build up relationships are more likely to have others share information that could impact their projects, and they’re more likely to get help from others if they make difficult requests — such as staying late or coming in on a weekend to catch up.</p>



<h2 class="wp-block-heading">18. They’re confident leaders</h2>



<p class="wp-block-paragraph">According to Wu, effective project managers must possess confidence.</p>



<p class="wp-block-paragraph">“They have a can-do attitude, and that attitude needs to be a bit infectious,” he says. “They don’t have the be cheerleaders, but they do have to have a mindset that sees what’s possible and not just the issues and what’s at risk.”</p>



<p class="wp-block-paragraph">That allows them to present an optimistic attitude that can propel teams forward even during difficult stretches, Butcher adds. Project managers who possess such confidence are those with a track record of success and are competent in foundational project management skills such as planning and team-building, she says.</p>



<h2 class="wp-block-heading">19. They serve as change agents</h2>



<p class="wp-block-paragraph">Change is inevitable and can be highly disruptive to all areas of business and personal life; project management is no exception. Highly effective project managers understand this, embrace it, and build elements of uncertainty into their project plans. They also recognize the need to work closely with change management experts to help stakeholders adapt to change and better prepare for the future state of things.</p>



<h2 class="wp-block-heading">20. They possess an even-keeled demeanor</h2>



<p class="wp-block-paragraph">Even well-planned projects run into problems, and even highly skilled project managers can hit significant setbacks. But the best project managers don’t display panic, anger, or despair even under pressure; they keep their cool.</p>



<p class="wp-block-paragraph">“Projects can create a lot of pressure, and there can be seemingly conflicting priorities, so staying calm is an essential trait for project managers,” Pincot says.</p>



<p class="wp-block-paragraph"><strong>More on project management:</strong></p>



<ul class="wp-block-list">
<li><a href="https://www.cio.com/article/244577/top-project-management-methodologies.html">Top 20 project management methodologies</a></li>



<li><a href="https://www.cio.com/article/228109/project-management-tips-strategies-best-practices.html">Project management guide: Tips, strategies, best practices</a></li>



<li><a href="https://www.cio.com/article/230682/what-is-a-project-manager-the-lead-role-for-project-success.html">What is a project manager? The lead role for project success</a></li>



<li><a href="https://www.cio.com/article/230398/top-project-management-certifications.html">Top 15 project management certifications</a></li>



<li><a href="https://www.cio.com/article/286354/project-management-7-must-have-project-management-skills-for-it-pros.html">7 must-have project management skills</a></li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[20 traits of innovative and invaluable project managers]]></title>
<description><![CDATA[Projects are becoming more complex, with higher stakes and faster delivery times.



At the same time automation and AI are changing how projects are designed, managed, and delivered. Indeed, some pieces of project management are now routinely handled by machines.



Some may think that AI and au...]]></description>
<link>https://tsecurity.de/de/3702815/it-security-nachrichten/20-traits-of-innovative-and-invaluable-project-managers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3702815/it-security-nachrichten/20-traits-of-innovative-and-invaluable-project-managers/</guid>
<pubDate>Tue, 04 Aug 2026 12:05:56 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Projects are becoming more complex, with higher stakes and faster delivery times.</p>



<p class="wp-block-paragraph">At the same time automation and AI are changing how projects are designed, managed, and delivered. Indeed, some pieces of project management are now routinely handled by machines.</p>



<p class="wp-block-paragraph">Some may think that AI and automation will make project managers obsolete, or at least less critical to project success. Executives say that’s not the case. Project managers are as important now as they ever were to project success.</p>



<p class="wp-block-paragraph">“As we move forward, the role of project manager is actually becoming increasingly important for finding the right things to invest in, defining scope, and staying focused on value,” says <a href="https://www.linkedin.com/in/noah-fletcher-9012ba4/">Noah Fletcher</a>, a partner in the operations excellence practice at consultancy West Monroe. “As we continue to accelerate, their value is really about quality — quality of what you’re trying to accomplish.”</p>



<p class="wp-block-paragraph">That doesn’t mean that the role of project manager is static. Rather, the role is evolving, with what it takes to be successful is changing to meet the needs of the moment.</p>



<p class="wp-block-paragraph">To thrive, project managers need to hone a complex combination of technical, business, and interpersonal skills. The Project Management Institute attempts to decode what it takes to be a successful project manager with its <a href="https://www.pmi.org/learning/training-development/talent-triangle">PMI Talent Triangle</a>, comprising Ways of Working, Power Skills, and Business Acumen.</p>



<p class="wp-block-paragraph">Not surprisingly, there’s a lot packed into those three areas. Effective project managers must know how to define <a href="https://www.cio.com/article/193441/what-is-project-scope-defining-and-outlining-project-success.html">the scope of a project</a>, identify necessary resources, and schedule those resources — all part of the technical aspect of the job. They must also <a href="https://www.cio.com/article/196244/stakeholder-management-your-plan-for-influencing-project-outcomes.html">manage stakeholders</a> and ensure projects align with business goals — skills that fall under the other two talent buckets.</p>



<p class="wp-block-paragraph">As lengthy as the PMI’s list of required skills is, experienced project leaders say that’s not enough to rise to the top of the profession; highly effective project managers today bring even more to their jobs.</p>



<p class="wp-block-paragraph">They’re curious, flexible, and adaptive — and they learn from and know how to right their mistakes. They’re empathetic, persuasive, and visionary. They know how to play to their own and others’ strengths.</p>



<p class="wp-block-paragraph">Leading project professionals say the most successful PMs are those who know the academic parts of the job — that is, the elements that are taught — but they also bring finesse to the work.</p>



<p class="wp-block-paragraph">So, what characteristics distinguish the most effective project managers? Longtime project leaders list the following key traits and skills as vital to succeeding at a high level.</p>



<h2 class="wp-block-heading">1. They serve as a strategic business partner</h2>



<p class="wp-block-paragraph">Top-level project managers are more than good managers. They have high-level strategic leadership skills and know how their projects fit within overall strategic goals, making them well equipped to make the right decisions for the project and the organization as a whole.</p>



<p class="wp-block-paragraph">“A project exists because it responds to a need of the business. That might be due to trends impacting the business or a challenge in running the business, but without understanding that, it will be hard for the project manager to deliver a successful project,” says <a href="https://www.pmi.org/about/leadership-governance/karla-eidem">Karla Eidem</a>, a Project Management Professional (PMP) and PMI’s global head of transformation and project delivery.</p>



<h2 class="wp-block-heading">2. They know the business</h2>



<p class="wp-block-paragraph">The most effective project managers aren’t just great leaders; they’re also business-savvy.</p>



<p class="wp-block-paragraph">“They understand strategy and business context,” Fletcher says. As they deal with shifting resources and changing market dynamics that happen during many projects, they focus on what work will bring business value — not merely what will tick off items on a task list. “That ability to work on the right thing is one of the most important things that a project manager can have,” Fletcher adds.</p>



<h2 class="wp-block-heading">3. They’re strong technologists</h2>



<p class="wp-block-paragraph">Projects today nearly always involve technology, making it essential to have technology skills. But standout project managers are true technologists, too.</p>



<p class="wp-block-paragraph">“Increasingly IT is touching so many different area, and we’re seeing systems and architecture getting more connected, so understanding how business and operations fit together is critical,” Fletcher says.</p>



<h2 class="wp-block-heading">4. They’re financially astute</h2>



<p class="wp-block-paragraph">Project management always involved budget management, but the task today requires more than balancing the books. It also involves understanding how projects and the core components of any given initiative bring value to the business. That takes financial acumen and the ability to make smart decisions during project execution to ensure the business sees returns on its investment.</p>



<p class="wp-block-paragraph">“The best project managers know the business drivers and can get depth on how the project impacts the business financially,” Fletcher says. “They have a good value management framework, that end-to-end process that can take the business case all the way through.”</p>



<h2 class="wp-block-heading">5. They possess extraordinary organizational skills</h2>



<p class="wp-block-paragraph">Top-notch project managers are highly organized individuals. But it’s not just about making a list and sticking with it. They understand how project plans and resources are intertwined with other goings-on within the organization. That organizational capacity enables them to adjust their plans and resources when needed.</p>



<p class="wp-block-paragraph"><a href="https://www.pmi.org/about/leadership-governance/lenka-pincot">Lenka Pincot</a>, chief of staff to the CEO at PMI, says today’s top-notch project managers are “orchestrators” who can pull together the complex components of modern projects and get them to work in harmony.</p>



<p class="wp-block-paragraph">“Organizations need orchestrators who can synchronize all the changes happening so the results all make sense,” she says. She notes that orchestration takes systems thinking as well as the ability to identify and plan for unintended consequences.</p>



<h2 class="wp-block-heading">6. They’re problem-solvers</h2>



<p class="wp-block-paragraph">The best project managers are good at delving into and solving for the “why” behind projects.</p>



<p class="wp-block-paragraph">“They enjoy problem-solving,” Pincot says. “[As project managers], we’re not handed projects; we are handed problems to solve. So we need to get to the bottom of what’s not working. We need to ask questions and really listen for what someone’s true interests are.”</p>



<h2 class="wp-block-heading">7. They thrive in fast-paced environments</h2>



<p class="wp-block-paragraph">Executives constantly talk about the speed of change today. Teams must work fast to keep up with shifting technology and business contexts, and project managers must be able to facilitate that, Fletcher says.</p>



<p class="wp-block-paragraph">“The ability to quickly identify the right tools, assign the right resources, accelerate testing, and to move things forward fast without compromising quality is a huge thing today,” he adds.</p>



<h2 class="wp-block-heading">8. They are flexible</h2>



<p class="wp-block-paragraph">Similarly, highly effective project managers are flexible, so they themselves aren’t flummoxed when project plans need adjustments — something that happens increasingly more often in the modern digital world.</p>



<p class="wp-block-paragraph">“Adaptability is huge,” says <a href="https://www.linkedin.com/in/krista-phillips-pmp-858aab98/">Krista Phillips</a>, a PMP holder and project management consultant. “Things are always going to change, priorities adjust, resources adjust, timelines change. Project managers must be able to successfully manage all that.”</p>



<h2 class="wp-block-heading">9. They are persuasive</h2>



<p class="wp-block-paragraph">Project managers typically manage teams but aren’t the boss of any of them, meaning they must be capable of leading and workers without having to lean on any official authority, explains <a href="https://www.linkedin.com/in/juliefbutcher/">Julie Butcher</a>, a fractional CIO work and transformation principal consultant with Butte Information Group. The best project managers are masters of this skill.</p>



<h2 class="wp-block-heading">10. They have ‘extreme awareness’</h2>



<p class="wp-block-paragraph"><a href="https://www.infotech.com/profiles/barry-cousins">Barry Cousins</a>, a distinguished analyst and research fellow specializing in project portfolio management, project management, and organizational change management at Info-Tech Research Group, says top project managers possess what he calls “extreme awareness of resource capacity and utilization.”</p>



<p class="wp-block-paragraph">“Savvy project managers in the modern era have immediate implicit awareness of the capacity around them, so then they’re going to know right off the bat when their projects are going to fall short,” Cousin adds. Furthermore, they’re more comfortable alerting business leaders to that situation because they’re able to quantify the shortfall.</p>



<p class="wp-block-paragraph">Others agree, saying this all speaks to the need for project managers to have strong emotional intelligence.</p>



<h2 class="wp-block-heading">11. They have highly tuned stakeholder management skills</h2>



<p class="wp-block-paragraph">Project managers work with numerous stakeholders from various departments within and outside their organizations, and those who manage those relationships best understand each stakeholder’s perspectives, say <a href="https://www.linkedin.com/in/te-wu/">Te Wu</a>, CEO and chief project officer at PMO Advisory.</p>



<p class="wp-block-paragraph">Wu adds that stakeholders can now also include AI agents.</p>



<p class="wp-block-paragraph">For example, some stakeholders may be more risk adverse than others, or more resistant to change, or more prone to panic when problems arise.</p>



<p class="wp-block-paragraph">Veteran project leaders say managers who can identify and empathize with those perspectives can tailor their communications, plans, and training to address each stakeholder’s unique points of view.</p>



<h2 class="wp-block-heading">12. They understand who has authority</h2>



<p class="wp-block-paragraph">Organizations today have distributed authority, so project managers must know who has say over what pieces — whether they’re dealing with 10 IT architects who each control a piece of the IT environment or 10 executives who have responsibilities for separate areas of the enterprise impacted by a project.</p>



<p class="wp-block-paragraph">“The savvy project manager knows to give them all room to succeed,” Cousins explains. That means staying on top of what each person’s realm of authority needs for the project to succeed, identifying who has ownership for what pieces, and knowing which person has true authority and can get others to line up behind him or her.</p>



<p class="wp-block-paragraph">“It often requires getting to know people who are at a layer of the company that you don’t play in,” Cousins says.</p>



<h2 class="wp-block-heading">13. They can navigate office politics</h2>



<p class="wp-block-paragraph">In addition to being good at stakeholder management, elite project managers also know how to navigate office politics. That means navigating not only individual stakeholder’s needs and expectations but also understanding how those stakeholders interact with each other, who has influence over the others, and who has power to override the authority of others.</p>



<p class="wp-block-paragraph">“They know when to apply what type of pressure to get something accomplished,” Wu adds.</p>



<h2 class="wp-block-heading">14. They’re decisive</h2>



<p class="wp-block-paragraph">Given the speed, complexity and fluidity of project work today, project managers must be critical thinkers and decisive decision-makers. Otherwise, they risk falling into analysis-paralysis and bringing work to a halt.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/varunbijlani/">Varun Bijlani</a>, global managing partner for solutions and delivery at IBM Consulting, says the best project managers can confidently and consistently make good calls even in the face of ambiguity.</p>



<p class="wp-block-paragraph">“IT projects are rife with it, even though everyone walks in expecting full clarity and specificity: requirements shift, priorities compete, expectations are unclear, unplanned technical issues arise,” he says. “AI can surface options and synthesize information fast, but it can’t apply the contextual judgment, reasoning, and organizational awareness needed to weigh trade-offs and commit to a direction when the path isn’t clear. That’s still a human call.”</p>



<h2 class="wp-block-heading">15. They communicate effectively</h2>



<p class="wp-block-paragraph">Considering communication plays a significant role in <a href="https://www.cio.com/article/196244/stakeholder-management-your-plan-for-influencing-project-outcomes.html">managing projects, teams, and other stakeholders</a>, it is one of the essential skills for effective project managers, according to longtime project managers.</p>



<p class="wp-block-paragraph">Communication doesn’t just mean being a stellar facilitator, speaker, or writer; it requires good listening skills, too. As such, top managers actively listen to what’s said — and not said — and can take context into account.</p>



<p class="wp-block-paragraph">These skills enable project managers to synthesize information and then clearly and concisely sharing that information back with all those involved, Pincot explains.</p>



<p class="wp-block-paragraph">“They have to be able to translate business needs to technology teams and explain how technology creates value for the business so that everyone can understand and trust that information,” she adds.</p>



<h2 class="wp-block-heading">16. They build community</h2>



<p class="wp-block-paragraph">“I believe the ‘P’ in PM is for the people: You can’t do a project without a team. And the team might not report to the project manager, so you have to have collaborative leadership, problem-solving, and communication skills to activate your team. Without that you can’t really move the needle,” Eidem says. “But in a project, you’re working with people who might have different priorities and different understanding of the goals of the project, so it’s the project manager’s responsibility to make sure everyone is aligned and knows where they’re going.”</p>



<p class="wp-block-paragraph">Butcher agrees, saying that the best project managers know how to build a sense of community among the teams as well as with the workers on the periphery of projects so that everyone is willing to work toward a shared objective.</p>



<h2 class="wp-block-heading">17. They build rapport</h2>



<p class="wp-block-paragraph">Top project managers are also skilled at developing strong rapport with those around them — even for short-lived projects — knowing that good connections and solid relationships lead to success.</p>



<p class="wp-block-paragraph">“When you build rapport, there’s a shared understanding,” Phillips says. That shared understanding pays dividends. Project managers who take time to build up relationships are more likely to have others share information that could impact their projects, and they’re more likely to get help from others if they make difficult requests — such as staying late or coming in on a weekend to catch up.</p>



<h2 class="wp-block-heading">18. They’re confident leaders</h2>



<p class="wp-block-paragraph">According to Wu, effective project managers must possess confidence.</p>



<p class="wp-block-paragraph">“They have a can-do attitude, and that attitude needs to be a bit infectious,” he says. “They don’t have the be cheerleaders, but they do have to have a mindset that sees what’s possible and not just the issues and what’s at risk.”</p>



<p class="wp-block-paragraph">That allows them to present an optimistic attitude that can propel teams forward even during difficult stretches, Butcher adds. Project managers who possess such confidence are those with a track record of success and are competent in foundational project management skills such as planning and team-building, she says.</p>



<h2 class="wp-block-heading">19. They serve as change agents</h2>



<p class="wp-block-paragraph">Change is inevitable and can be highly disruptive to all areas of business and personal life; project management is no exception. Highly effective project managers understand this, embrace it, and build elements of uncertainty into their project plans. They also recognize the need to work closely with change management experts to help stakeholders adapt to change and better prepare for the future state of things.</p>



<h2 class="wp-block-heading">20. They possess an even-keeled demeanor</h2>



<p class="wp-block-paragraph">Even well-planned projects run into problems, and even highly skilled project managers can hit significant setbacks. But the best project managers don’t display panic, anger, or despair even under pressure; they keep their cool.</p>



<p class="wp-block-paragraph">“Projects can create a lot of pressure, and there can be seemingly conflicting priorities, so staying calm is an essential trait for project managers,” Pincot says.</p>



<p class="wp-block-paragraph"><strong>More on project management:</strong></p>



<ul class="wp-block-list">
<li><a href="https://www.cio.com/article/244577/top-project-management-methodologies.html">Top 20 project management methodologies</a></li>



<li><a href="https://www.cio.com/article/228109/project-management-tips-strategies-best-practices.html">Project management guide: Tips, strategies, best practices</a></li>



<li><a href="https://www.cio.com/article/230682/what-is-a-project-manager-the-lead-role-for-project-success.html">What is a project manager? The lead role for project success</a></li>



<li><a href="https://www.cio.com/article/230398/top-project-management-certifications.html">Top 15 project management certifications</a></li>



<li><a href="https://www.cio.com/article/286354/project-management-7-must-have-project-management-skills-for-it-pros.html">7 must-have project management skills</a></li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Testing Update] 2026-08-04 - Kernels, Mesa, Nvidia, COSMIC, Deepin, Firefox, QEmu, Vulkan]]></title>
<description><![CDATA[Hello Manjaro user community, here we have another set of package updates. We are continuing our development of the upcoming release of ‘Bian-May’ which can be expected Mid or End of August. Development speed may be a little slower the upcoming weeks. However, still let us know any issues you may...]]></description>
<link>https://tsecurity.de/de/3702781/unix-server/testing-update-2026-08-04-kernels-mesa-nvidia-cosmic-deepin-firefox-qemu-vulkan/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3702781/unix-server/testing-update-2026-08-04-kernels-mesa-nvidia-cosmic-deepin-firefox-qemu-vulkan/</guid>
<pubDate>Tue, 04 Aug 2026 11:55:37 +0200</pubDate>
<content:encoded><![CDATA[<div data-theme-toc="true"> </div>
<p>Hello Manjaro user community, here we have another set of package updates. We are continuing our development of the upcoming release of ‘Bian-May’ which can be expected Mid or End of August. Development speed may be a little slower the upcoming weeks. However, still let us know any issues you may found thus far.</p>
<h3><a name="p-869091-current-promotions-1" class="anchor" href="https://forum.manjaro.org/#p-869091-current-promotions-1" aria-label="Heading link"></a>Current Promotions</h3>
<ul>
<li>Get the latest Gaming Laptop by Slimbook powered by Manjaro: <a href="https://slimbook.com/manjaro">Slimbook Manjaro III</a></li>
<li>Protect your personal data, keep yourself safe with Surfshark VPN: <a href="https://get.surfshark.net/aff_c?offer_id=6&amp;aff_id=14558-">See current promotion</a></li>
</ul>
<h2><a name="p-869091-recent-news-2" class="anchor" href="https://forum.manjaro.org/#p-869091-recent-news-2" aria-label="Heading link"></a>Recent News</h2>

New in Manjaro GNOME!
Or, if you prefer the command line: <a href="https://forum.manjaro.org/t/testing-update-2026-08-04-kernels-mesa-nvidia-cosmic-deepin-firefox-qemu-vulkan/189353/1">(click for more details)</a>

KDE Plasma users with SDDM can now migrate to Plasma Login Manager <a href="https://forum.manjaro.org/t/testing-update-2026-08-04-kernels-mesa-nvidia-cosmic-deepin-firefox-qemu-vulkan/189353/1">(click for more details)</a>

NVIDIA 590 driver drops Pascal support <a href="https://forum.manjaro.org/t/testing-update-2026-08-04-kernels-mesa-nvidia-cosmic-deepin-firefox-qemu-vulkan/189353/1">(click for more details)</a>
<ul>
<li><a href="https://forum.manjaro.org/t/manjaro-26-1-bian-may-preview-released/187389" class="inline-onebox">Manjaro 26.1 Bian-May - Preview released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-26-0-anh-linh-released/184526" class="inline-onebox">Manjaro 26.0 Anh-Linh released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-summit-public-alpha-now-available/176995" class="inline-onebox">Manjaro Summit public Alpha now available</a></li>
<li>As of Linux 6.16.12, the 6.16 series is now EOL (End Of Life). Please install 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 6.17.13, the 6.17 series is now EOL (End Of Life). Please install 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 6.19.14, the 6.19 series is now EOL (End Of Life). Please install 7.0, and/or 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 7.0.14, the 7.0 series is now EOL (End Of Life). Please install 7.1, and/or 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
</ul>

Previous News <a href="https://forum.manjaro.org/t/testing-update-2026-08-04-kernels-mesa-nvidia-cosmic-deepin-firefox-qemu-vulkan/189353/1">(click for more details)</a>
<h2><a name="p-869091-notable-package-updates-3" class="anchor" href="https://forum.manjaro.org/#p-869091-notable-package-updates-3" aria-label="Heading link"></a>Notable Package Updates</h2>
<ul>
<li><strong>Kernels</strong>
<ul>
<li>updates to toolchain</li>
</ul>
</li>
<li><strong>dracut</strong> <a href="https://github.com/dracut-ng/dracut/releases/tag/112">112</a></li>
<li><strong>QEmu</strong> <a href="https://wiki.qemu.org/ChangeLog/11.0">11.0.3</a></li>
<li><strong>Vulkan SDK</strong> <a href="https://vulkan.lunarg.com/doc/view/latest/windows/release_notes.html">1.4.357.0</a></li>
<li><strong>Nvidia</strong> <a href="https://www.nvidia.com/en-us/drivers/details/274517/">580.178.04</a>, <a href="https://www.nvidia.com/en-us/drivers/details/274513/">610.57.04</a></li>
<li><strong>Firefox</strong> <a href="https://www.firefox.com/firefox/153.0.1/releasenotes/">153.0.1</a></li>
<li><strong>COSMIC</strong> Epoch <a href="https://github.com/pop-os/cosmic-epoch/releases/tag/epoch-1.5.0">1.5.0</a></li>
<li>Updates to <strong>Deepin</strong> and <strong>Python</strong></li>
</ul>
<h2><a name="p-869091-additional-info-4" class="anchor" href="https://forum.manjaro.org/#p-869091-additional-info-4" aria-label="Heading link"></a>Additional Info</h2>

Python 3.14 info <a href="https://forum.manjaro.org/t/testing-update-2026-08-04-kernels-mesa-nvidia-cosmic-deepin-firefox-qemu-vulkan/189353/1">(click for more details)</a>

Info about AUR packages <a href="https://forum.manjaro.org/t/testing-update-2026-08-04-kernels-mesa-nvidia-cosmic-deepin-firefox-qemu-vulkan/189353/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr>
<p><strong>Our current supported kernels</strong></p>
<ul>
<li>linux61 6.1.180</li>
<li>linux66 6.6.148</li>
<li>linux612 6.12.101</li>
<li>linux618 6.18.42</li>
<li>linux71 7.1.6</li>
<li>linux72 7.2.0-rc6</li>
<li>linux61-rt 6.1.167_rt62</li>
<li>linux66-rt 6.6.135_rt74</li>
<li>linux612-rt 6.12.89_rt18</li>
</ul>
<p><strong>Package Changes</strong> (8/3/26 15:37 CEST)</p>
<ul>
<li>testing core x86_64:  71 new and 71 removed package(s)</li>
<li>testing extra x86_64:  1250 new and 1248 removed package(s)</li>
<li>testing multilib x86_64:  40 new and 40 removed package(s)</li>
</ul>
<p>A list of all package changes can be found <a href="https://gist.github.com/hphilm/a5f1f07ad47d31dc29dcd7fec38a21bd/raw">here</a>.</p>

<ul>
<li>No issue, everything went smoothly</li>
<li>Yes there was an issue. I was able to resolve it myself.(Please post your solution)</li>
<li>Yes I am currently experiencing an issue due to the update. (Please post about it)</li>
</ul>
<p><a href="https://forum.manjaro.org/t/testing-update-2026-08-04-kernels-mesa-nvidia-cosmic-deepin-firefox-qemu-vulkan/189353/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
<hr>
            <p><small>3 posts - 2 participants</small></p>
            <p><a href="https://forum.manjaro.org/t/testing-update-2026-08-04-kernels-mesa-nvidia-cosmic-deepin-firefox-qemu-vulkan/189353">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[A Malicious GitHub Issue Could Turn Google’s AI Agent Against Its Own CI/CD Pipeline]]></title>
<description><![CDATA[A first practical, real-world case of agent-to-agent exploitation inside a production multi-agent system, a novel attack class that turns one AI agent against another to compromise a software supply chain. The flaw was found in google/adk-python, the repository behind Google’s Agent Development K...]]></description>
<link>https://tsecurity.de/de/3702776/it-security-nachrichten/a-malicious-github-issue-could-turn-googles-ai-agent-against-its-own-cicd-pipeline/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3702776/it-security-nachrichten/a-malicious-github-issue-could-turn-googles-ai-agent-against-its-own-cicd-pipeline/</guid>
<pubDate>Tue, 04 Aug 2026 11:50:54 +0200</pubDate>
<content:encoded><![CDATA[<p>A first practical, real-world case of agent-to-agent exploitation inside a production multi-agent system, a novel attack class that turns one AI agent against another to compromise a software supply chain. The flaw was found in google/adk-python, the repository behind Google’s Agent Development Kit for Python, an SDK widely used by developers to build their own […]</p>
<p>The post <a href="https://cybersecuritynews.com/ai-agent-against-its-own-ci-cd-pipeline/">A Malicious GitHub Issue Could Turn Google’s AI Agent Against Its Own CI/CD Pipeline</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chinese Military Researchers Use AI Distillation to Train Drone and Battlefield Systems]]></title>
<description><![CDATA[Chinese military-linked researchers are studying ways to turn the outputs of advanced Western AI systems into smaller, cheaper models for drones, battlefield tools, cyber work, and public-security platforms. The concern is not a single malicious program, but a technique that could speed developme...]]></description>
<link>https://tsecurity.de/de/3702720/it-security-nachrichten/chinese-military-researchers-use-ai-distillation-to-train-drone-and-battlefield-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3702720/it-security-nachrichten/chinese-military-researchers-use-ai-distillation-to-train-drone-and-battlefield-systems/</guid>
<pubDate>Tue, 04 Aug 2026 11:28:48 +0200</pubDate>
<content:encoded><![CDATA[<p>Chinese military-linked researchers are studying ways to turn the outputs of advanced Western AI systems into smaller, cheaper models for drones, battlefield tools, cyber work, and public-security platforms. The concern is not a single malicious program, but a technique that could speed development of dual-use systems while weakening safeguards built into the original models. Known […]</p>
<p>The post <a href="https://cybersecuritynews.com/chinese-military-researchers-use-ai-distillation/">Chinese Military Researchers Use AI Distillation to Train Drone and Battlefield Systems</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Enabling the next generation of AI data centers]]></title>
<description><![CDATA[Exploring how power, cooling and grid constraints are reshaping AI data center development.]]></description>
<link>https://tsecurity.de/de/3702705/it-nachrichten/enabling-the-next-generation-of-ai-data-centers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3702705/it-nachrichten/enabling-the-next-generation-of-ai-data-centers/</guid>
<pubDate>Tue, 04 Aug 2026 11:23:00 +0200</pubDate>
<content:encoded><![CDATA[Exploring how power, cooling and grid constraints are reshaping AI data center development.]]></content:encoded>
</item>
<item>
<title><![CDATA[Attackers are crafting malicious AI instruction files to turn your agentic workflows into quiet criminal helpers]]></title>
<description><![CDATA[AI agents are increasingly being deployed across the enterprise, a rapid adoption that has significantly broadened the organization’s attack surface, turning sharable AI agent resources and configuration files into backdoors, security experts warn.



AI-assisted software developers have been inc...]]></description>
<link>https://tsecurity.de/de/3702597/it-security-nachrichten/attackers-are-crafting-malicious-ai-instruction-files-to-turn-your-agentic-workflows-into-quiet-criminal-helpers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3702597/it-security-nachrichten/attackers-are-crafting-malicious-ai-instruction-files-to-turn-your-agentic-workflows-into-quiet-criminal-helpers/</guid>
<pubDate>Tue, 04 Aug 2026 10:49:51 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">AI agents are increasingly being deployed across the enterprise, a rapid adoption that has significantly broadened the organization’s attack surface, turning sharable AI agent resources and configuration files into backdoors, security experts warn.</p>



<p class="wp-block-paragraph">AI-assisted software developers have been increasingly targeted through malicious IDE extensions, rogue MCP servers, and poisoned AI skills, all of which provide attackers inroads into organizations’ development pipelines and beyond. But these AI helper resources are not the only types of instruction files that developers and users share with one another when making use of AI coding assistants and command-line interface (CLI) agents.</p>



<p class="wp-block-paragraph">For example, Anthropic’s Claude Code CLI agent loads system prompts from a file called <code>CLAUDE.md</code>. This file contains instructions that are sent to the LLM along with every user prompt to avoid having to repeat rules, user preferences, and persona definitions for the model.</p>



<p class="wp-block-paragraph"><code>CLAUDE.md</code> can be used globally for all projects or be used on a per-project basis to include instructions about how the LLM should operate within that project. It’s not unusual for <code>CLAUDE.md</code> files to be included in a shared repository to ensure project-relevant consistency in the conventions developers use when working with Claude Code.</p>



<p class="wp-block-paragraph">Other coding agents have similar files, such as OpenAI Codex’s <code>AGENTS.md</code> or Google Gemini’s <code>GEMINI.md</code>. AI-assisted IDEs such as Cursor or Cline have <code>.cursorrules</code> and <code>.clinerules</code>. GitHub Copilot has <code>.github/copilot-instructions.md</code>. Then there are JSON configuration files that could also contain executable code, such as <code>mcp.json</code>, <code>hooks.json</code>, or <code>settings.json</code>. Hooks are a popular way to deliver scripts and commands based on triggers during an agentic loop.</p>



<p class="wp-block-paragraph">All these files could hide malicious code or instructions and should be regularly checked and validated, especially if imported from the internet along with a repository.</p>



<p class="wp-block-paragraph">Researchers from security firm Mitiga recently shed light on this threat, releasing a report on code repositories they found in the wild with malicious instructions injected in such files. The files instructed the target agent to exfiltrate all prompts typed by the user, including all sensitive information they might contain, as well as environment variables and other credentials used by the agent. The researchers dubbed this backdoor attack technique “PromptLogger,” and it is one enterprise security teams and developers are likely to see more of in the future.</p>



<p class="wp-block-paragraph">“Traditional keyloggers capture keystrokes and send them to an attacker,” Mitiga’s researchers write in <a href="https://www.mitiga.io/resources/promptlogger-ai-instruction-file-exfiltration-report">their report on the attack vector</a>. “PromptLogger-style behavior captures something richer: the prompts and sometimes responses exchanged with an attacker. That matters because prompts increasingly contain source code, architectural plans, credentials pasted for troubleshooting, internal documentation, debugging output, customer samples, business logic, and operator intent.”</p>



<p class="wp-block-paragraph">Enterprises have been apprehensive about <a href="https://www.csoonline.com/article/3964282/cisos-no-closer-to-containing-shadow-ais-skyrocketing-data-risks.html">corporate data leakage via shadow AI use</a> for good reason. This type of attack enables surveillance of corporate even on vetted and sanctioned AI tools.</p>



<p class="wp-block-paragraph">Moreover, this attack leaves no malicious binary on disk, does not inject code into other processes, and has no classic persistence mechanisms. As a result, it won’t be detected by EDRs or from a workstation monitoring perspective, because it looks like normal tool usage given that the agent itself is performing the exfiltration.</p>



<h2 class="wp-block-heading">Exfiltration to external cloud-hosted databases</h2>



<p class="wp-block-paragraph">Mitiga’s researchers found and reported multiple examples of agent instruction file poisoning on GitHub repositories. None were popular repositories accessed by a large number of developers, but they don’t need to be. Links to these repositories could be sent to victims in targeted attacks, as has been seen in <a href="https://www.csoonline.com/article/3518577/fake-recruitment-campaign-targets-developers-using-trojanized-python-packages.html">fake recruitment attacks</a> where developers are asked during the interview process to clone GitHub projects containing malicious code.</p>



<p class="wp-block-paragraph">One example was a DevOps repository containing poisoned <code>.cursorrules</code> and <code>.github/copilot-instructions.md</code>. The repository contained a full-stack application built with React + Vite frontend, along with Express API, PostgreSQL, nginx configuration, Docker containers, GitLab CI jobs, and AWS infrastructure setup files for Terraform and Terragrrunt. In other words, everything needed to deploy that application.</p>



<p class="wp-block-paragraph">Despite the <code>README.md</code> file being benign, the agent instruction files distributed in the repo contained instructions for the AI agent loading them to execute a <code>curl</code> command silently without mentioning it to the user before responding to their prompt. That command copied the user’s prompt to a database hosted on the Supabase service using a hardcoded access token.</p>



<p class="wp-block-paragraph">In another case the researchers found an MLOps repository with an end-to-end machine learning pipeline for training, evaluating, and deploying computer vision models. The repository had a <code>.clinerules</code> file that instructed the agent to verify its environment by collecting several environment variables and command outputs and send them to a site hosted on the Webhook.site service. The collected <code>env</code> variables included Weights &amp; Biases (WANDB) API key, AWS access key, GitHub access token, and MLFlow tracking URL.</p>



<p class="wp-block-paragraph">“This is direct credential collection,” the researchers’ report notes. “Webhook.site gives the operator an easy request sink that can be created anonymously and monitored in real time.”</p>



<p class="wp-block-paragraph">A similar environment secrets collection attack was detected in another repository that claimed to be a starter kit for FastAPI, a framework for API development. The <code>.cursorrules</code> and <code>CLAUDE.md</code> files in the repository instructed the agent to send the contents of the local <code>.env</code> file to a Webhook.site endpoint supposedly for synchronization across the team. However, it also contained instructions to suppress the command output and hide this action from the user.</p>



<p class="wp-block-paragraph">Finally, a <code>GEMINI.md</code> file hosted inside a repository masqueraded as an environment validation step required to pass “Zero Trust” compliance checks. As part of this check, the agent was told to inject an initialization block into every generated or modified Python file, which would then scan the OS environment for any values with <code>key</code>, <code>secret</code>, <code>token</code>, or <code>pass</code> in their names and exfiltrate them to a Pipedream endpoint.</p>



<p class="wp-block-paragraph">This technique exceeds just poisoning the agent and using it for exfiltration. Instead, it uses the agent to inject backdoor code into other Python files that might be copied to other systems, including continuous integration (CI) jobs, containers, and production workloads.</p>



<p class="wp-block-paragraph">Some intentional behavior that involves agent instruction files could create risk without the developers realizing it. For example, the researchers found a repository where the <code>CLAUDE.md</code> contained instructions to use the Snipara MCP during commits to store documentation, dependencies, environment variables, and implementation context.</p>



<p class="wp-block-paragraph">Snipara is a remote cross-project memory layer for AI agents so this use case seems legitimate and intentional. However, if not approved by the security team, it creates a second system that can hold credentials and sensitive data outside the visibility of monitoring systems.<br><br>AI agent workflows under attack</p>



<p class="wp-block-paragraph">What the PromptLogger technique highlights is that attackers are not only breaking down agentic workflows to find new enterprise weak points but transforming those workflows into tools for performing criminal work on their behalf, undetected and unmonitored.</p>



<p class="wp-block-paragraph">“AI instruction files were designed to make coding assistants more useful,” Mitiga’s researchers emphasize. “They define project conventions, preferred commands, memory behavior, hooks and tools usage. In practice, they also create a security-relevant layer that many teams still treat as documentation.”</p>



<p class="wp-block-paragraph">This is just one example of a trend that find AI agents fast becoming an unmonitored blind spot that attackers are proving quick to exploit for initial access.</p>



<p class="wp-block-paragraph">Last month, researchers from security firm AIR <a href="https://www.csoonline.com/article/4188840/how-a-malicious-ai-agent-skill-passed-security-checks-and-reached-26000-users.html">built a proof-of-concept malicious skill file</a>, published it to a popular marketplace and promoted it on Instagram. The skill — a file containing task-specific instructions for AI agents — was eventually installed by more than 26,000 designers and marketers, many working for companies.</p>



<p class="wp-block-paragraph">AI agent skill files are no different in principle from <code>CLAUDE.md</code> or <code>.cursorrules</code>. They contain instructions that AI agents execute at various stages of operation. As such, inspecting such files when they are created or modified is imperative.</p>



<p class="wp-block-paragraph">Mitiga researchers propose several static scan patterns that could reveal risky commands in such files, but they also advise security teams to monitor developer workstations for traffic to services such as Webhook.site, Pipedream, Supabase, or Telegram Bot API.</p>



<p class="wp-block-paragraph">Unexpected outbound HTTP requests before or after assistant responses; repeated POST requests containing environment variables, project paths, or prompt text; and the addition of new MCP servers, URL overrides, or tool endpoints to agent configurations should be investigated.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Spain Offers $1.14 Billion To Get Thirty Meter Telescope Moved To Canary Islands]]></title>
<description><![CDATA[Longtime Slashdot reader schwit1 shares a report from Behind the Black: In a new bid to get the Thirty Meter Telescope (TMT) to move from Hawaii, which has blocked its construction for more than a decade, the Spanish government has put together a $1.14 billion package that would not only pay for ...]]></description>
<link>https://tsecurity.de/de/3702456/it-security-nachrichten/spain-offers-114-billion-to-get-thirty-meter-telescope-moved-to-canary-islands/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3702456/it-security-nachrichten/spain-offers-114-billion-to-get-thirty-meter-telescope-moved-to-canary-islands/</guid>
<pubDate>Tue, 04 Aug 2026 09:12:45 +0200</pubDate>
<content:encoded><![CDATA[Longtime Slashdot reader schwit1 shares a report from Behind the Black: In a new bid to get the Thirty Meter Telescope (TMT) to move from Hawaii, which has blocked its construction for more than a decade, the Spanish government has put together a $1.14 billion package that would not only pay for construction on the Canary Islands, but would finance an additional half century of operations. Tech Times provides some additional details: The package is conditional on the TMT International Observatory formally choosing La Palma as its construction site. The financing architecture has three pillars and two additional contingent instruments. The first pillar is 400 million euros (approximately $456 million USD) from Spain's Ministry of Science, Innovation and Universities, routed through the Centre for Technological Development and Innovation (CDTI). This figure was first pledged a year ago in July 2025 as Spain's initial bid.
 
The second pillar is a 300 million-euro (approximately $342 million USD) loan from the EIB [European Investment Bank] itself -- subject to satisfactory completion of the bank's technical, financial, and legal due diligence and approval by its governing bodies.
 
The third is a potential 300 million-euro (approximately $342 million USD) participation from the Instituto de Credito Oficial (ICO), Spain's state development finance institution, evaluated under equivalent conditions to the EIB loan but subject to its own separate analysis. Spain's export credit agency, Cesce, may also provide coverage instruments, and the EIB has left open the possibility of expanding its support through intermediated financing mechanisms or guarantees.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Spain+Offers+%241.14+Billion+To+Get+Thirty+Meter+Telescope+Moved+To+Canary+Islands%3A+https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F08%2F04%2F0040200%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F08%2F04%2F0040200%2Fspain-offers-114-billion-to-get-thirty-meter-telescope-moved-to-canary-islands%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://science.slashdot.org/story/26/08/04/0040200/spain-offers-114-billion-to-get-thirty-meter-telescope-moved-to-canary-islands?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-13584 | Mitsubishi Electric MELSEC MX Controller message integrity (EUVD-2026-51024)]]></title>
<description><![CDATA[A vulnerability was found in Mitsubishi Electric MELSEC MX Controller, Master, local module, CC-Link IE TSN interface board, Motion module, Motion Control Board, Block-type remote module, Analog-Digital converter module, Digital-Analog converter module, CC-Link IE TSN compatible coupler, FPGA mod...]]></description>
<link>https://tsecurity.de/de/3702389/sicherheitsluecken/cve-2026-13584-mitsubishi-electric-melsec-mx-controller-message-integrity-euvd-2026-51024/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3702389/sicherheitsluecken/cve-2026-13584-mitsubishi-electric-melsec-mx-controller-message-integrity-euvd-2026-51024/</guid>
<pubDate>Tue, 04 Aug 2026 08:39:36 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/mitsubishi_electric:melsec_mx_controller">Mitsubishi Electric MELSEC MX Controller, Master, local module, CC-Link IE TSN interface board, Motion module, Motion Control Board, Block-type remote module, Analog-Digital converter module, Digital-Analog converter module, CC-Link IE TSN compatible coupler, FPGA module, Tension meter, AC Servo MELSERVO-J5, AC Servo MELSERVO-JET, Liner Track System MTR-S series, Inverter FR-A800, F800, E800 Series, Industrial Robot CR800-D series controller Network Base Card, CC-Link IE TSN expansion unit, CC-Link IE TSN-CC-Link IE Field Network bridge module, CC-Link IE TSN-AnyWireASLINK bridge module, Energy Measuring Unit CC-Link IE TSN Communication Unit, Industrial Computer MELIPC series, GOT3000 Series, CC-Link IE TSN Communication Unit, Motion Control Software, CC-Link IE TSN Communication Software for Windows, Analysis Support Software MELSOFT VIMA, Designated communication LSI DeviceKit, Designated communication LSI, Remote Station Communication LSI with GbE-PHY, CC-Link IE TSN Master, local module Designated communication LSI SDK and Remote station software development kit</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. The affected element is an unknown function. The manipulation results in improper enforcement of message integrity.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2026-13584">CVE-2026-13584</a>. The attack may be launched remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Cybersecurity jobs available right now: August 4, 2026]]></title>
<description><![CDATA[Application Security Engineer Arcadia | USA | Remote – View job details As an Application Security Engineer, you will lead the application vulnerability management process by prioritizing and driving remediation of security findings. You will integrate and automate security tools within CI/CD pip...]]></description>
<link>https://tsecurity.de/de/3702162/it-security-nachrichten/cybersecurity-jobs-available-right-now-august-4-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3702162/it-security-nachrichten/cybersecurity-jobs-available-right-now-august-4-2026/</guid>
<pubDate>Tue, 04 Aug 2026 06:20:11 +0200</pubDate>
<content:encoded><![CDATA[<p>Application Security Engineer Arcadia | USA | Remote – View job details As an Application Security Engineer, you will lead the application vulnerability management process by prioritizing and driving remediation of security findings. You will integrate and automate security tools within CI/CD pipelines, establish a Security Champions program to promote secure development practices, support application security during incident response, and work with product and engineering teams to embed security into the software development lifecycle through … <a href="https://www.helpnetsecurity.com/2026/08/04/cybersecurity-jobs-available-right-now-august-4-2026/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/08/04/cybersecurity-jobs-available-right-now-august-4-2026/">Cybersecurity jobs available right now: August 4, 2026</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GitHub pushes stacked pull requests into public preview]]></title>
<description><![CDATA[Advancing on software development, GitHub has announced the public preview of stacked pull requests. 



The public preview was announced July 30. 



Stacked pull requests break large changes into a chain of smaller, dependent pull requests. A stacked pull request is an ordered series of pull re...]]></description>
<link>https://tsecurity.de/de/3702092/ai-nachrichten/github-pushes-stacked-pull-requests-into-public-preview/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3702092/ai-nachrichten/github-pushes-stacked-pull-requests-into-public-preview/</guid>
<pubDate>Tue, 04 Aug 2026 04:13:14 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Advancing on software development, GitHub has announced the public preview of <a href="https://docs.github.com/en/pull-requests/how-tos/stacked-pull-requests" data-type="link" data-id="https://docs.github.com/en/pull-requests/how-tos/stacked-pull-requests">stacked pull requests</a>. </p>



<p class="wp-block-paragraph">The public preview was announced <a href="https://github.blog/changelog/2026-07-30-stacked-pull-requests-are-now-in-public-preview/#get-started-with-the-cli-extension">July 30</a>. </p>



<p class="wp-block-paragraph">Stacked pull requests break large changes into a chain of smaller, dependent pull requests. A stacked pull request is an ordered series of pull requests that each represent focused layers of a change,” GitHub said in the announcement. The goal is to make pull requests easier to review, and to avoid splitting work across multiple branches that must be continually rebased.</p>



<p class="wp-block-paragraph">According to GitHub, teams can: </p>



<ul class="wp-block-list">
<li>Keep large changes moving by reviewing short, narrowly scoped pull requests in parallel.</li>



<li>Maintain quality across every layer by using focused pull request reviews alongside each branch protections to protect main.</li>



<li>Merge some, one, or all by landing an entire stack altogether or individual layers one at a time.</li>
</ul>



<p class="wp-block-paragraph">Using stacked pull requests requires the gh stack extension fo the GitHub CLI. Developers can install the extension with the following command:</p>



<pre class="wp-block-code"><code>gh extension install github/gh-stack</code></pre>



<p class="wp-block-paragraph">In what may have been a response to the rising tide of AI-generated code, GitHub <a href="https://www.infoworld.com/article/4158575/github-adds-stacked-prs-to-speed-complex-code-reviews.html">announced stacked pull requests in April</a>. </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Three AI security mistakes that will haunt enterprises]]></title>
<description><![CDATA[There is a lot of talk about the coming enterprise AI reality, in which AI finally arrives in production systems. You might not know it, but this reality—or nightmare, depending on how you handle it—is already happening.



It all starts with a “pilot,” a “prototype,” or a “side project.” Maybe s...]]></description>
<link>https://tsecurity.de/de/3702093/ai-nachrichten/three-ai-security-mistakes-that-will-haunt-enterprises/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3702093/ai-nachrichten/three-ai-security-mistakes-that-will-haunt-enterprises/</guid>
<pubDate>Tue, 04 Aug 2026 04:13:14 +0200</pubDate>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">There is a lot of talk about the coming enterprise AI reality, in which AI finally arrives in production systems. You might not know it, but this reality—or nightmare, depending on how you handle it—is already happening.</p>



<p class="wp-block-paragraph">It all starts with a “pilot,” a “prototype,” or a “side project.” Maybe someone builds an internal dashboard with an agent. The dashboard quickly becomes indispensable, and all of a sudden the experiment becomes production. Along the way, no one thought to ask the boring, inconvenient questions: What exactly was pulled from npm, PyPI, or Docker Hub? How is (or was) authentication configured? Is anyone watching for supply chain attacks against the tools and libraries the agents chose?</p>



<p class="wp-block-paragraph">And it’s not just a one-off project here or a couple of applications there. AI is enabling organizations to generate more code and ship more products and projects, more quickly, than ever before. By the time security teams get a look, the business is hooked and there’s no turning back. An actual nightmare has begun.</p>



<p class="wp-block-paragraph">There are three major problems that make the nightmare real. </p>



<h2 class="wp-block-heading">Components you never explicitly chose</h2>



<p class="wp-block-paragraph">When you ask an AI agent to build an app, it doesn’t just spit out a single script. It quietly assembles an entire ecosystem around whatever problem you’ve described to it. It pulls in a web framework, grabs a bunch of libraries, stands up databases, and then it potentially builds everything on dependencies in container images.</p>



<p class="wp-block-paragraph">From a productivity perspective, this is awesome. However, from a security standpoint, it’s worrisome, to say the least. When I’ve built apps like this myself, I couldn’t begin to tell you all of the components that were being used unless I went back and asked the agent to explain itself.</p>



<p class="wp-block-paragraph">We live in a world where anyone can publish to npm or PyPI, and we’ve seen attackers slip malicious packages into those ecosystems or compromise ones that are widely used. Some of the recent incidents have involved security and devops tools themselves pulling a compromised dependency, running it as part of CI/CD with elevated privileges, and quietly exfiltrating secrets or tampering with builds. I personally experienced this type of compromise a couple of months ago, and had to update all of my credentials in GitHub.</p>



<p class="wp-block-paragraph">Pulling unvetted code is bad; now layer AI agents on top of that. They default to whatever is easiest to discover and integrate. If a package solves a problem in front of the agent, the agent will add it. This is the old “download a random library from the Internet” problem, but now it’s on autopilot, at scale, and moving at a pace we’ve never seen before.</p>



<p class="wp-block-paragraph">To solve this problem, we must provide the agents with an innate sense of our risk tolerance, an approved components list, our desires around logging, etc. We can do this with spec files and what the industry calls constitutions. Collectively, this is called harness engineering, which we will talk more about later.</p>



<h2 class="wp-block-heading">Skills shifting from code to architecture</h2>



<p class="wp-block-paragraph">There has been a lot of hand-wringing about <a href="https://www.infoworld.com/article/4065771/why-we-need-junior-developers.html" data-type="link" data-id="https://www.infoworld.com/article/4065771/why-we-need-junior-developers.html">whether junior developers</a> will ever <a href="https://www.infoworld.com/article/4152683/what-next-for-junior-developers.html" data-type="link" data-id="https://www.infoworld.com/article/4152683/what-next-for-junior-developers.html">really learn to code</a> if AI is doing all of their coding for them.</p>



<p class="wp-block-paragraph">That’s not what worries me.</p>



<p class="wp-block-paragraph">I think it’s fine to let an agent spit out code. It’s a job they are really good at. What they are not really good at is identifying and avoiding problems in code.</p>



<p class="wp-block-paragraph">I haven’t written code in quite some time. I can, but it doesn’t make sense for me to do so. What is worth my while is noticing when an agent suggests something dumb or even dangerous (or both).</p>



<p class="wp-block-paragraph">For example, while working on a recent personal project, an agent proposed exposing a memory server on the public Internet with no authentication. The agent wired things up so smoothly that, at first glance, everything looked fine and just worked. But then I paused and asked, “Wait, how is this actually authenticating? Where’s the password, secret token, or OAuth in this flow?” Turns out it wasn’t authenticating and there was no password. If I hadn’t taken that beat—and then argued with the agent for a while—the app would have gone live with no protection.</p>



<p class="wp-block-paragraph">So, the skills issue isn’t about whether we will lose the ability to code but rather whether we have the ability to ask questions and be discerning, and whether we have the understanding to know when something doesn’t look or even feel right. Do organizations have people who know what a dangerous software pattern looks like when the agent suggests it? You need people who can recognize when an authentication flow is too permissive, when a data store should never be exposed beyond a certain boundary, and when an architecture has become such a steaming pile of technical debt that the right answer is to throw away a whole layer and rebuild it.</p>



<p class="wp-block-paragraph">You need people who know that “what works” isn’t the same as “what’s safe” or “what’s right” and who can argue back with the agent when the former doesn’t line up with the latter.</p>



<p class="wp-block-paragraph">It’s not about syntax. It’s about architecture, supply chain awareness, and the willingness to say, “We’re tearing this down and doing it right,” even when the prototype looks good on the surface. Teach your AI-assisted coders basic security principles, basic architectural patterns. The AI will teach them the more advanced stuff, as long as they keep asking questions.</p>



<h2 class="wp-block-heading">Agents with no harness</h2>



<p class="wp-block-paragraph">The third problem is that we’ve unleashed some very capable agents into our development workflows without treating them like first-class actors that need governance.</p>



<p class="wp-block-paragraph">Many organizations are wiring AI assistants into a repo or IDE and letting them scaffold projects and pipelines. Maybe they bolt on a security scanner and declare “AI enablement.” That’s not a governance model, that’s optimism (and not even cautious optimism).</p>



<p class="wp-block-paragraph">Indeed, a code-generating agent with broad access to your repos, your CI/CD pipeline, and your artifact registries is effectively a hyper-productive and not-very-well-trained junior developer with access to the Internet and no ingrained sense of organizational policies. It can introduce new tools, new dependencies, and new patterns faster than your review processes can handle.</p>



<p class="wp-block-paragraph">In my personal projects, I’ve started to think of this as what AI coders call a harness-engineering problem. For every agent that’s responsible for building or wiring code, I try to put other agents in the loop that are responsible for tearing it down, at least conceptually. For example, one agent focuses on security and looks for obvious vulnerabilities and bad practices. Another looks at architecture and points out when the app design is veering into unmaintainable territory. A third looks at performance and reliability issues, which are themselves a kind of security concern when you think about things like denial of service and resource exhaustion. Pair this with constitutions that give the agents first principles on architecture, security, and design, and this is no longer vibe coding, it’s harness engineering at scale for all of your projects.</p>



<p class="wp-block-paragraph">What I am doing isn’t perfect; there is no perfect in this space, because these are non-deterministic, statistical tools. But, many organizations aren’t even doing this. In effect, their agents are freelancing. They’re vibe coding. They’re not constrained to trusted registries or hardened base images. They’re not required to log their decisions in a way that security can audit. No one owns the harness, and that means a lot of implementation decisions have fully shifted from humans to systems that no one is really watching.</p>



<h2 class="wp-block-heading">New problems require new thinking</h2>



<p class="wp-block-paragraph">The enterprise AI nightmare is not a killer robot; it’s the erosion of our ability to see and control what’s running in our own environments at the exact moment our velocity is exploding. The danger is in ceding your agency. It’s in shipping applications that internal and external customers love—and don’t want to give up—but inherently aren’t safe. Right now, someone in your organization is using AI to build a capable app, pulling in who knows what from who knows where and adding it to your infrastructure.</p>



<p class="wp-block-paragraph">The good news is that these problems are identifiable. They are also solvable, although it will take a new form of thinking than what solved problems in the past. You must think statistically, and declare constitutions with first principles. You can standardize trusted stacks and registries. You can retrain people around architectural security rather than just “secure coding.” You can start treating agent harnesses as systems that deserve design reviews and edits.</p>



<p class="wp-block-paragraph">But, none of that can happen until the enterprise is willing to admit that the nightmare is already here.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[House of the Dragon Season 3 Episode 7 Recap: Alicent Turns Against Aemond]]></title>
<description><![CDATA[House of the Dragon Season 3, Episode 7 brings several troubled Targaryens back together while revealing that one of the Greens’ most powerful dragons remains alive. The penultimate episode follows Rhaenyra’s search for Daemon and Rhaena, Alicent’s dangerous mission at Harrenhal, and Aegon’s unex...]]></description>
<link>https://tsecurity.de/de/3702076/ios-mac-os/house-of-the-dragon-season-3-episode-7-recap-alicent-turns-against-aemond/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3702076/ios-mac-os/house-of-the-dragon-season-3-episode-7-recap-alicent-turns-against-aemond/</guid>
<pubDate>Tue, 04 Aug 2026 04:06:33 +0200</pubDate>
<content:encoded><![CDATA[House of the Dragon Season 3, Episode 7 brings several troubled Targaryens back together while revealing that one of the Greens’ most powerful dragons remains alive. The penultimate episode follows Rhaenyra’s search for Daemon and Rhaena, Alicent’s dangerous mission at Harrenhal, and Aegon’s unexpected reunion with Sunfyre.




Release date: August 2, 2026



Streaming service: HBO Max



US broadcast: HBO



Genre: Fantasy drama



Season: 3



Episode: 7 of 8



Director: Nina Lopez-Corrado



Season finale date: August 9, 2026




The episode continues the conflict created by Rhaena’s decision to claim Sheepstealer and disappear with Daemon. Rhaenyra leaves King’s Landing on Syrax after learning more about Daemon’s absence, leading to a tense confrontation involving Syrax, Sheepstealer, Caraxes, and Seasmoke.



Major spoilers ahead



Rhaenyra finds Daemon and Rhaena, but the meeting quickly turns dangerous as the dragons react to one another. Rhaena remains deeply affected by Jacaerys’ death and believes her choices helped cause the tragedy. Rhaenyra eventually saves her and takes her back to King’s Landing, where Baela forgives her sister.



Daemon’s actions create another serious problem for Rhaenyra. She already doubts his loyalty, and his secret involvement with Rhaena and Sheepstealer gives her another reason to question whether he still supports her rule. Although they avoid a final break, their relationship remains unstable heading into the finale.



Rhaenyra later turns to Mysaria for comfort. Their growing closeness gives Rhaenyra a private escape from the political pressure surrounding her, but her grief and mistrust continue to influence her decisions.



Alicent makes her move against Aemond



At Harrenhal, Aemond becomes increasingly violent and unpredictable. After killing Ser Adrian, he falls deeper under Alys Rivers’ influence and experiences a disturbing vision involving Alicent.



The real Alicent arrives with orders that could remove Aemond from the war. She poisons him with nightshade, although the episode leaves his immediate fate uncertain. Her decision shows that she now sees her son as a threat to any remaining hope of controlling the conflict.



Meanwhile, Helaena’s visions become clearer. She sees herself riding Dreamfyre and burning an army, while other images point towards personal loss, unrest in King’s Landing, and a much colder danger waiting in the distant future. Dreamfyre’s appearance also gives viewers their first substantial look at Helaena’s bond with her dragon.



Sunfyre returns to save Aegon



The episode’s biggest surprise comes when Aegon faces enemy soldiers in the forest. Just as he appears trapped, Sunfyre emerges and burns the attackers.



Sunfyre survived the Battle at Rook’s Rest despite suffering terrible injuries alongside Aegon. Both rider and dragon now carry severe scars, making their reunion one of the episode’s strongest moments. Aegon finally regains some confidence after spending much of the season injured, isolated, and dependent on others.



At Tumbleton, Ormund Hightower also tries to convince Ulf the White to abandon Rhaenyra by offering him titles and status. Ulf has not completed his betrayal yet, but his interest in the offer creates another major risk for Team Black before the final battle.



House of the Dragon Season 3, Episode 7 places Sunfyre back on the board, leaves Aemond poisoned, and pushes Rhaenyra closer to a direct conflict with Daemon. With only one episode remaining, the season finale now has several betrayals, dragon battles, and family confrontations to resolve.



What do you think Sunfyre’s return means for Aegon, and will Ulf betray Rhaenyra in the finale? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Is Dead City Season 3 Turning Negan Into a Villain Again?]]></title>
<description><![CDATA[The Walking Dead: Dead City Season 3 has quickly raised questions about Negan’s future, especially after he killed the Dama despite Maggie choosing to keep her alive. The decision looks like a return to his old habits, but his reasons suggest a more complicated change.




Premiere date: July 26,...]]></description>
<link>https://tsecurity.de/de/3702077/ios-mac-os/is-dead-city-season-3-turning-negan-into-a-villain-again/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3702077/ios-mac-os/is-dead-city-season-3-turning-negan-into-a-villain-again/</guid>
<pubDate>Tue, 04 Aug 2026 04:06:33 +0200</pubDate>
<content:encoded><![CDATA[The Walking Dead: Dead City Season 3 has quickly raised questions about Negan’s future, especially after he killed the Dama despite Maggie choosing to keep her alive. The decision looks like a return to his old habits, but his reasons suggest a more complicated change.




Premiere date: July 26, 2026



New episodes: Sundays on AMC and AMC+



Season length: Eight episodes



Finale date: September 13, 2026



Genre: Post-apocalyptic horror drama



Main cast: Lauren Cohan as Maggie and Jeffrey Dean Morgan as Negan




Season 3 follows Maggie and Negan as they attempt to build a stable community in Manhattan, even as new conflicts threaten their uneasy partnership. The season also introduces new regular cast members, including Jimmi Simpson, Aimee Garcia, and Raúl Castillo.



Spoilers for Dead City Season 3, Episode 2



Episode 2, titled “Haven,” places Negan at the centre of another brutal death. Maggie captures the Dama and decides to imprison her, showing that she wants their new settlement to follow rules rather than personal revenge.



Negan ignores that decision and kills the Dama himself.



His actions immediately create tension because Maggie had already made her position clear. Negan does not simply kill an active attacker during a fight. He executes a prisoner after the immediate threat has passed, which closely resembles the controlling and violent leader viewers met during the original series.



However, the Dama had tortured Hershel and removed one of his toes. Negan also distrusts Renata’s leadership and believes Maggie should take control of Manhattan. His decision appears to come from revenge, concern for Maggie’s family, and his belief that dangerous enemies cannot be allowed to survive.



Is Negan returning to his old ways?



Negan has spent years trying to prove that he understands the damage he caused. During the final seasons of The Walking Dead, he protected Judith, helped defeat the Whisperers, apologised to Maggie, and accepted that she might never forgive him for killing Glenn.



Dead City continued that growth by showing his guilt over Ginny’s father and his willingness to protect people without demanding loyalty in return. He remained violent, but the series usually presented that violence as a last resort.



Killing the Dama changes that pattern. Negan enjoys taking control of the situation and refuses to respect Maggie’s judgment. That behaviour reflects the former Savior leader who believed only he could decide who deserved punishment.



Still, the episode does not completely erase his development. The old Negan killed people to create fear and maintain authority. Season 3 Negan kills the Dama because he believes she will remain a threat and because of what she did to Hershel.



The distinction matters, although it does not excuse his actions.



Negan’s growth could face its biggest test



Season 3 appears ready to examine whether Negan can remain a better man when violence once again gives him influence. His decision may also force Maggie to consider whether she can build a community alongside someone who repeatedly places his own judgment above everyone else’s.



Negan’s character growth has never followed a straight path, and “Haven” shows that his darker instincts remain close to the surface. The real answer will depend on whether he accepts responsibility for killing the Dama or begins using protection as an excuse to regain control.



Do you think Dead City Season 3 is undoing Negan’s redemption, or does killing the Dama fit the person he has become? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Qwen3.8-Max arrives with a bold claim: it outperforms GPT-5.6 Sol Max and Fable 5 on agentic computer use]]></title>
<description><![CDATA[Chinese e-commerce and cloud giant Alibaba's famed Qwen team of AI researchers last night unveiled Qwen3.8-Max, a new flagship 2.4-trillion-parameter mixture-of-experts (MoE) multimodal large language model (LLM) that targets one of the most competitive corners of the frontier AI market: autonomo...]]></description>
<link>https://tsecurity.de/de/3702026/it-nachrichten/qwen38-max-arrives-with-a-bold-claim-it-outperforms-gpt-56-sol-max-and-fable-5-on-agentic-computer-use/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3702026/it-nachrichten/qwen38-max-arrives-with-a-bold-claim-it-outperforms-gpt-56-sol-max-and-fable-5-on-agentic-computer-use/</guid>
<pubDate>Tue, 04 Aug 2026 02:29:58 +0200</pubDate>
<content:encoded><![CDATA[<p>Chinese e-commerce and cloud giant Alibaba's famed Qwen team of AI researchers last night <a href="https://x.com/Alibaba_Qwen/status/2084100707423289643">unveiled Qwen3.8-Max</a>, a new flagship 2.4-trillion-parameter mixture-of-experts (MoE) multimodal large language model (LLM) that targets one of the most competitive corners of the frontier AI market: autonomous software engineering and long-horizon enterprise work. </p><p>If the company's published benchmarks hold up under broader independent testing, Qwen3.8-Max doesn't merely compete with today's leading proprietary models — it surpasses several of them on some key benchmarks in agentic computing.</p><p>Most notably, Qwen reports that Qwen3.8-Max scores 86.1 on the <a href="https://llm-stats.com/benchmarks/osworld-verified">OSWorld-Verified</a> benchmark measuring how well  ahead of GPT-5.6 Sol Max (83.2) and Fable 5 (85.0), while also posting the highest reported score on PaperBench and leading or remaining highly competitive across software engineering, research reproduction, multimodal reasoning, and visual web development benchmarks.</p><p>The release also signals a potentially significant strategic shift for Alibaba: the company says open weights for Qwen3.8-Max will be released next week, alongside Qwen3.8-27B. </p><p>If that happens under a permissive license, it would represent the first time a Max-class Qwen model becomes available for self-hosted deployment—a move that could substantially reshape enterprise adoption. </p><p>One important caveat remains, however: Alibaba has not yet disclosed the licensing terms, leaving open the possibility that the release could use a more restrictive custom license, as we saw recently with <a href="https://venturebeat.com/technology/kimi-k3s-full-weights-are-here-but-theyre-open-with-a-caveat-what-enterprises-should-know">Chinese rival Moonshot's open Kimi K3 frontier model</a>, rather than a broadly permissive one such as Apache 2.0.</p><h2><b>A different definition of 'frontier'</b></h2><p>Over the past year, the competitive landscape for foundation models has become increasingly specialized.</p><p>OpenAI has largely focused its GPT series on general reasoning, multimodal interaction and enterprise productivity.</p><p>Anthropic's Claude series has emphasized coding and dependable long-context reasoning. Google continues to push Gemini toward multimodal productivity and web-native workflows. </p><p>Moonshot AI's Kimi K3 recently entered the conversation by pairing frontier-class performance with an open-weight release.</p><p>Qwen3.8-Max attempts to combine many of these strengths into a single model aimed squarely at enterprise automation.</p><p>Rather than emphasizing conversational intelligence, Alibaba is positioning the model as an autonomous coworker capable of executing projects that span days rather than minutes. </p><p>According to the company, Qwen3.8-Max can autonomously complete software projects lasting more than 10 days, reproduce research papers involving thousands of lines of code, perform iterative chip-design optimization, and continuously revise plans using multimodal feedback loops.</p><p>Those demonstrations remain company-produced and have not yet been broadly replicated by independent evaluators. Nevertheless, they illustrate a growing industry trend: frontier models are increasingly competing on their ability to finish entire workflows rather than answer individual prompts.</p><h2><b>Benchmarks increasingly reward autonomous execution</b></h2><p>The benchmark suite released alongside Qwen3.8-Max reflects this shift.</p><p>Instead of focusing solely on traditional reasoning exams or coding puzzles, many of the highlighted evaluations measure long-horizon execution.</p><p>On OSWorld-Verified, which evaluates computer-use agents interacting with desktop environments, Qwen3.8-Max posts 86.1, ahead of GPT-5.6 Sol Max's 83.2, Fable 5's 85.0, and Gemini 3.1 Pro's 76.2.</p><p>The model also leads:</p><ul><li><p>PaperBench: 93.0</p></li><li><p>TerminalBench 2.1: 86.6</p></li><li><p>Vision2Web: 69.0</p></li><li><p>LVBench: 81.8</p></li><li><p>ERQA: 77.8</p></li></ul><p>Elsewhere, it remains competitive with proprietary leaders while trailing in several categories. </p><p>On the professional software engineering benchmark SWE-Pro, for example, OpenAI's model posts the highest reported score, while Opus 4.8 continues to lead on certain software engineering evaluations and Agents' Last Exam. </p><p>Rather than dominating every benchmark, Qwen appears to offer one of the broadest balanced performance profiles currently available.</p><p>That balance may ultimately matter more for enterprise buyers than isolated benchmark wins.</p><p>Many organizations increasingly evaluate models based on how reliably they complete heterogeneous workflows—writing code, reading documents, navigating interfaces, generating reports, inspecting images and coordinating multiple subtasks—rather than optimizing for one narrow capability.</p><h2><b>Where Qwen3.8-Max appears strongest</b></h2><p>Assuming Alibaba's published results translate into production deployments, several enterprise workloads stand out as particularly well suited for Qwen3.8-Max.</p><p><b>1. Long-running software engineering</b></p><p>Alibaba's primary demonstration involves autonomous software development extending beyond ten days.</p><p>While enterprises should treat these demonstrations as vendor claims until independently reproduced, they align with a growing interest in persistent coding agents that operate continuously rather than interactively.</p><p>Organizations experimenting with autonomous engineering teams, CI/CD automation, repository maintenance, regression testing or feature implementation may find Qwen particularly attractive if its agentic performance proves consistent outside laboratory settings.</p><p><b>2. Computer-use agents</b></p><p>The strongest differentiator may be computer use.</p><p>OSWorld has rapidly become one of the industry's most closely watched benchmarks because it measures a model's ability to interact with operating systems instead of simply generating text.</p><p>Models capable of reliably navigating desktop software can automate countless repetitive business processes, including document processing, enterprise software integration, internal operations and legacy workflows where APIs may not exist.</p><p>Leading OSWorld could therefore translate into real operational advantages if benchmark performance generalizes to production environments.</p><p><b>3. Research automation</b></p><p>Qwen's PaperBench leadership suggests strong potential for organizations performing scientific computing, literature review, experiment reproduction and technical analysis.</p><p>Research institutions, pharmaceutical companies and industrial R&amp;D teams increasingly use LLMs not only for summarization but also for executing reproducible computational workflows. Models capable of maintaining context across extended sessions become increasingly valuable in these environments.</p><p><b>4. Multimodal industrial workflows</b></p><p>Unlike earlier multimodal systems that primarily analyze uploaded images, Qwen describes vision as an ongoing feedback mechanism integrated into planning and execution.</p><p>That architecture could prove particularly useful in manufacturing, logistics, engineering inspection and design review, where visual inputs continuously inform operational decisions rather than serving as isolated prompts.</p><h2><b>The economics may prove just as important</b></h2><p>Perhaps the biggest competitive pressure comes not from benchmark scores but from pricing through Qwen's application programming interface (API) on <a href="https://www.qwencloud.com/models/qwen3.8-max">QwenCloud</a> (based in China):</p><p>Qwen3.8-Max launches at $2/$6 per million input/output tokens, a mid-priced model but undercutting the top U.S. proprietary offerings to which it is benchmarked against by meaningful percentages, less than 1/3 the combined in/out price of Claude Opus 5 and less than 1/4 the price of GPT-5.6 Sol Max. </p><table><tbody><tr><td><p><b>Model</b></p></td><td><p><b>Input ($/1M)</b></p></td><td><p><b>Output ($/1M)</b></p></td><td><p><b>Total ($/1M)</b></p></td><td><p><b>Source</b></p></td></tr><tr><td><p>MiMo-V2.5 Flash</p></td><td><p>$0.10</p></td><td><p>$0.30</p></td><td><p>$0.40</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p>deepseek-v4-flash</p></td><td><p>$0.14</p></td><td><p>$0.28</p></td><td><p>$0.42</p></td><td><p><a href="https://api-docs.deepseek.com/quick_start/pricing">DeepSeek</a></p></td></tr><tr><td><p>deepseek-v4-pro</p></td><td><p>$0.435</p></td><td><p>$0.87</p></td><td><p>$1.305</p></td><td><p><a href="https://api-docs.deepseek.com/quick_start/pricing">DeepSeek</a></p></td></tr><tr><td><p>GPT-5.6 Luna</p></td><td><p>$0.20</p></td><td><p>$1.20</p></td><td><p>$1.40</p></td><td><p><a href="https://openai.com/index/advancing-the-price-performance-frontier-with-gpt-5-6/">OpenAI</a></p></td></tr><tr><td><p>MiniMax-M3</p></td><td><p>$0.30</p></td><td><p>$1.20</p></td><td><p>$1.50</p></td><td><p><a href="https://platform.minimax.io/subscribe/token-plan?tab=api-enterprise">MiniMax</a></p></td></tr><tr><td><p>LongCat-2.0 — limited-time promo</p></td><td><p>$0.30</p></td><td><p>$1.20</p></td><td><p>$1.50</p></td><td><p><a href="https://longcat.chat/platform/docs/APIPayAsYouGo.html">LongCat</a></p></td></tr><tr><td><p>Gemini 3.1 Flash-Lite</p></td><td><p>$0.25</p></td><td><p>$1.50</p></td><td><p>$1.75</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Qwen3.7-Plus</p></td><td><p>$0.40</p></td><td><p>$1.60</p></td><td><p>$2.00</p></td><td><p><a href="https://modelstudio.console.alibabacloud.com/ap-southeast-1?tab=doc#/doc/?type=model&amp;url=2840914_2&amp;modelId=qwen3.7-plus&amp;serviceSite=international">Alibaba Cloud</a></p></td></tr><tr><td><p>MiMo-V2.5</p></td><td><p>$0.40</p></td><td><p>$2.00</p></td><td><p>$2.40</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p>Gemini 3.5 Flash-Lite</p></td><td><p>$0.30</p></td><td><p>$2.50</p></td><td><p>$2.80</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>LongCat-2.0 — standard</p></td><td><p>$0.75</p></td><td><p>$2.95</p></td><td><p>$3.70</p></td><td><p><a href="https://longcat.chat/platform/docs/APIPayAsYouGo.html">LongCat</a></p></td></tr><tr><td><p>MiMo-V2.5 Pro (≤256K)</p></td><td><p>$1.00</p></td><td><p>$3.00</p></td><td><p>$4.00</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p>GLM-5.2</p></td><td><p>$1.40</p></td><td><p>$4.40</p></td><td><p>$5.80</p></td><td><p><a href="https://docs.z.ai/guides/overview/pricing">Z.ai</a></p></td></tr><tr><td><p>Grok 4.5</p></td><td><p>$2.00</p></td><td><p>$6.00</p></td><td><p>$8.00</p></td><td><p><a href="https://docs.x.ai/developers/models">xAI</a></p></td></tr><tr><td><p>MiMo-V2.5 Pro (&gt;256K)</p></td><td><p>$2.00</p></td><td><p>$6.00</p></td><td><p>$8.00</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p><b>Qwen3.8-Max</b></p></td><td><p><b>$2.00</b></p></td><td><p><b>$6.00</b></p></td><td><p><b>$8.00</b></p></td><td><p><b></b><a href="https://www.qwencloud.com/models/qwen3.8-max"><b>QwenCloud</b></a></p></td></tr><tr><td><p>Gemini 3.6 Flash</p></td><td><p>$1.50</p></td><td><p>$7.50</p></td><td><p>$9.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Qwen3.7-Max</p></td><td><p>$2.50</p></td><td><p>$7.50</p></td><td><p>$10.00</p></td><td><p><a href="https://modelstudio.console.alibabacloud.com/ap-southeast-1?tab=doc#/doc/?type=model&amp;url=2840914_2&amp;modelId=qwen3.7-max&amp;serviceSite=international">Alibaba Cloud</a></p></td></tr><tr><td><p>Gemini 3.5 Flash</p></td><td><p>$1.50</p></td><td><p>$9.00</p></td><td><p>$10.50</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (≤200K)</p></td><td><p>$2.00</p></td><td><p>$12.00</p></td><td><p>$14.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>GPT-5.6 Terra</p></td><td><p>$2.00</p></td><td><p>$12.00</p></td><td><p>$14.00</p></td><td><p><a href="https://openai.com/index/advancing-the-price-performance-frontier-with-gpt-5-6/">OpenAI</a></p></td></tr><tr><td><p>GPT-5.4</p></td><td><p>$2.50</p></td><td><p>$15.00</p></td><td><p>$17.50</p></td><td><p><a href="https://openai.com/api/pricing/">OpenAI</a></p></td></tr><tr><td><p>Kimi K3</p></td><td><p>$3.00</p></td><td><p>$15.00</p></td><td><p>$18.00</p></td><td><p><a href="https://platform.kimi.ai/docs/pricing/chat-k3">Moonshot AI</a></p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (&gt;200K)</p></td><td><p>$4.00</p></td><td><p>$18.00</p></td><td><p>$22.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Claude Opus 5</p></td><td><p>$5.00</p></td><td><p>$25.00</p></td><td><p>$30.00</p></td><td><p><a href="https://platform.claude.com/docs/en/about-claude/pricing">Anthropic</a></p></td></tr><tr><td><p>GPT-5.5</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://openai.com/api/pricing/">OpenAI</a></p></td></tr><tr><td><p>GPT-5.5 Instant (chat-latest)</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://developers.openai.com/api/docs/models/chat-latest">OpenAI</a></p></td></tr><tr><td><p>Sakana Fugu Ultra (≤272K)</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://console.sakana.ai/pricing#subscription-plan">Sakana AI</a></p></td></tr><tr><td><p>GPT-5.6 Sol — Standard mode</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://openai.com/index/advancing-the-price-performance-frontier-with-gpt-5-6/">OpenAI</a></p></td></tr><tr><td><p>Claude Fable 5 / Claude Mythos 5</p></td><td><p>$10.00</p></td><td><p>$50.00</p></td><td><p>$60.00</p></td><td><p><a href="https://platform.claude.com/docs/en/about-claude/models/overview">Anthropic</a></p></td></tr><tr><td><p>GPT-5.6 Sol — Fast mode</p></td><td><p>$10.00</p></td><td><p>$60.00</p></td><td><p>$70.00</p></td><td><p><a href="https://openai.com/index/advancing-the-price-performance-frontier-with-gpt-5-6/">OpenAI</a></p></td></tr></tbody></table><p>Lower inference costs increasingly matter because agentic systems consume dramatically more tokens than conventional chatbots — a reality that likely factored into OpenAI's decision late last week to <a href="https://venturebeat.com/article-pv/ai-price-wars-openai-cuts-gpt-5-6-luna-prices-by-80-as-model-competition-shifts-toward-cost">cut the API prices of its mid- and lower-end GPT-5.6 lineup of models</a> (Terra and Luna) by 20% and 80%, respectively. </p><p>Indeed, as those running these systems can attest, multi-hour autonomous workflows, iterative planning and continuous self-correction can generate millions of tokens during a single task.</p><p>For enterprises deploying hundreds or thousands of agents simultaneously, inference costs often become one of the largest operational expenses. Small reductions in per-token pricing therefore compound rapidly.</p><h2><b>How it compares with American frontier models</b></h2><p>Despite headline benchmark comparisons, Qwen3.8-Max should not necessarily be viewed as a wholesale replacement for leading American models.</p><p>Instead, its strengths suggest different deployment strategies.</p><p>OpenAI's GPT family continues to excel as a broadly capable enterprise reasoning platform with mature tooling, ecosystem integration and extensive commercial deployment. Organizations already invested in Microsoft ecosystems or OpenAI's enterprise offerings may continue to value those operational advantages even if Qwen leads on selected agent benchmarks.</p><p>Anthropic's Claude Opus remains widely regarded as one of the strongest coding assistants, particularly for careful software engineering and long-context reasoning. Some enterprises may still prefer Claude for human-in-the-loop development where reliability and predictable behavior outweigh raw autonomy.</p><p>Google Gemini continues to differentiate itself through deep Workspace integration, multimodal capabilities and Google Cloud services, making it attractive for organizations already standardized on Google's enterprise stack.</p><p>Where Qwen appears most compelling is for enterprises prioritizing autonomous execution, extended planning horizons and favorable inference economics without sacrificing frontier-level performance.</p><h2><b>The open-weight question remains unanswered</b></h2><p>The largest unknown surrounding Qwen3.8-Max has little to do with benchmarks.</p><p>Alibaba says open weights are coming next week. However, neither the announcement nor the provided documentation specifies the license that will govern those weights.</p><p>That distinction could prove critical.</p><p>A permissive license such as Apache 2.0 would significantly broaden enterprise adoption by allowing organizations to self-host, fine-tune and integrate the model into proprietary products with relatively few restrictions.</p><p>A custom license—similar to approaches used by several recent frontier releases—could impose limitations on commercial deployment, redistribution, field of use or model modification. Such restrictions would narrow the appeal for enterprises seeking long-term infrastructure investments, regardless of the model's technical performance.</p><p>Moonshot AI's recent Kimi K3 release illustrates why this distinction matters. While Kimi K3 made its weights openly available to all, its<a href="https://venturebeat.com/technology/kimi-k3s-full-weights-are-here-but-theyre-open-with-a-caveat-what-enterprises-should-know"> licensing terms included specific terms</a> including a disclosure and a commercial license requirement for those offering it as a "Model as a Service." </p><p>Until Alibaba publishes Qwen3.8-Max's license, organizations considering self-hosting should treat the open-weight announcement as promising but incomplete.</p><h2><b>An increasingly crowded frontier</b></h2><p>Qwen3.8-Max arrives during one of the fastest-moving periods in the history of foundation models.</p><p>Within weeks, developers have seen major releases from Moonshot AI, OpenAI, Anthropic and others, each emphasizing different strengths: reasoning, coding, multimodality, autonomous agents or economics.</p><p>Alibaba's contribution is notable because it combines competitive benchmark performance, aggressive pricing, a million-token context window and a stated commitment to releasing weights for its flagship model.</p><p>Whether it becomes the preferred platform for enterprise autonomous agents will ultimately depend less on leaderboard positions than on broader independent validation, production reliability and the licensing terms accompanying the forthcoming weight release. </p><p>Those factors—not benchmark charts alone—will determine whether Qwen3.8-Max becomes a genuine alternative to the leading American proprietary models or simply another impressive entrant in an increasingly crowded frontier AI race.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cisco exec testifies at US Senate panel on AI’s network impact]]></title>
<description><![CDATA[AI is profoundly changing enterprise and service provider networks, and operators must evolve to support AI workloads, according to a Cisco executive who testified last week at a US Senate subcommitee meeting.



Bob Everson, chief architect of provider mobility with Cisco, spoke before the Subco...]]></description>
<link>https://tsecurity.de/de/3701786/it-security-nachrichten/cisco-exec-testifies-at-us-senate-panel-on-ais-network-impact/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3701786/it-security-nachrichten/cisco-exec-testifies-at-us-senate-panel-on-ais-network-impact/</guid>
<pubDate>Tue, 04 Aug 2026 01:17:07 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">AI is profoundly changing enterprise and service provider networks, and operators must evolve to support AI workloads, according to a Cisco executive who <a href="https://www.commerce.senate.gov/wp-content/uploads/meetings/379d9950-dc84-b1bf-2c6a-ee1ebb42fbe2/Everson_Testimony-7.30.26-Final_d1fc268a-ed9e-42a7-abbe-d52a960f49e1.pdf">testified last week</a> at a US Senate subcommitee meeting.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/bobeverson/">Bob Everson</a>, chief architect of provider mobility with Cisco, spoke before the Subcommittee on Telecommunications and Media, which falls under the U.S. Senate Committee on Commerce, Science, and Transportation. Everson shared Cisco’s perspective on the status of AI and focused on two core questions: How is AI reshaping our networks, and how can networks leverage the power of AI?</p>



<p class="wp-block-paragraph">The July 30 hearing, titled “Intelligent Networks: Powering Artificial Intelligence and Transforming Communications,” was planned to explore how the rapid adoption of AI has impacted network infrastructure.</p>



<p class="wp-block-paragraph">“We will explore how widespread AI use has forced networks to evolve, requiring more capacity and more complex designs so that AI can run efficiently on those networks,” said <a href="https://www.fischer.senate.gov/public/">U.S. Senator Deb Fischer</a> (R-Neb), Chairman of the Senate Commerce Subcommittee on Telecommunications and Media, in her <a href="https://www.commerce.senate.gov/press/rep/release/fischer-leads-hearing-on-ai-in-communications-networks/?utm_source=chatgpt.com">opening statement</a>. “We will consider how government, providers, and other industries are responding to that demand. Private companies have invested hundreds of billions of dollars in network deployment in recent years. Various federal broadband programs have also provided billions to support targeted network deployment and maintenance throughout the country.”</p>



<p class="wp-block-paragraph">Others who testified came from organizations including U.S. Telecom, Vanderbilt University, and Nebraska Public Service Commission.</p>



<p class="wp-block-paragraph">“AI is changing not only the volume of network traffic, but the behavior. Cisco measured a fourfold increase in AI inference traffic over eight months. Networks have traditionally been optimized for content flowing downstream. AI is far more two-way and uplink-intensive: prompts, context, sensor data, and agent activity all travel back toward AI models, and the resulting connections are active longer than conventional web transactions,” said Everson. “AI agents amplify these effects by operating at software speed. In our testing, an agent generated 450 percent more traffic than a person performing the same task, and roughly 70 percent of that additional traffic was inference.”</p>



<p class="wp-block-paragraph">“In campus and branch networks—like the one that powers the Senate office building we are sitting in today—we have already seen customers report a 34% increase in traffic tied to AI workloads over the last 12 months, and they expect to see a 96% increase this coming year,” Everson said. </p>



<p class="wp-block-paragraph">“Half of enterprise customers report that AI demand is concentrated on their Wi-Fi networks, and 73% of organizations already face or expect to face campus and branch capacity limitations within the next 24 months. This is largely because large majorities of organizations report increases in east-west traffic, latency-sensitive traffic, and continuous, automated AI traffic.  While the large majority of AI to date has come from foundation models running on central infrastructure, we are seeing enterprises deploy more small language models, open-source models, and specialized models—such as vision and voice models—which can be distributed throughout the network. Each of these characteristics underscores the value of the FCC’s forward-thinking decision in 2020 to authorize the full 6 GHz band for unlicensed Wi-Fi use,” Everson said.</p>



<p class="wp-block-paragraph">In his prepared remarks, Everson cited a number of areas that are impacted by AI, including:</p>



<ul class="wp-block-list">
<li><strong>Infrastructure</strong>: AI is driving the shift toward edge computing. Service providers must also consider “AI-native” traffic profiles for several reasons, including technical considerations, cost, and data sovereignty and security issues.</li>



<li><strong>Technical</strong>: Physical AI use cases such as robotics, autonomous vehicles, and industrial automation could require sub-millisecond decision-making. If an autonomous robot sends data to a central cloud and has to wait for a response, the round-trip latency could be too high for safe, real-time operation.</li>



<li><strong>Cost</strong>: AI operations generate massive amounts of data. For example, high-definition video analytics for public safety can generate terabytes of data daily. Backhauling that data to a central cloud is prohibitively expensive and creates massive network congestion.</li>



<li><strong>Data sovereignty and security</strong>: Enterprises and governments are increasingly concerned about data sovereignty and security. Many customers have security or regulatory concerns about moving sensitive information across the public internet to a third-party cloud provider.</li>
</ul>



<h2 class="wp-block-heading">Potential benefits of AI-driven networks</h2>



<p class="wp-block-paragraph">Networks will leverage AI for increased performance and resiliency, Everson stated.</p>



<p class="wp-block-paragraph">“While AI workloads present several challenges for network operators seeking to ensure seamless performance, reliability, and security, there is a tremendous opportunity to leverage AI to deliver new applications and better performance, infuse security into the fabric of the network, and manage the increased complexity,” Everson said. “Agentic AI will change the nature of traffic on the network, but it will also provide network operators new tools to operate at machine speed and deliver greater performance, efficiency, and security.”</p>



<p class="wp-block-paragraph">AgenticOps also lets the network act as a self-healing system, Everson said. “Cisco’s AI-native tools enable the network to reroute traffic, adjust capacity, or reconfigure network nodes when the system detects performance degradation or an impending hardware failure. This dramatically increases uptime and reliability for mission-critical services,” Everson said.</p>



<p class="wp-block-paragraph">One of the most significant challenges for network operators is the talent gap in managing increasingly complex, software-defined networks, Everson said.</p>



<p class="wp-block-paragraph">“AgenticOps allows operators to automate repetitive, low-value tasks—such as ticket resolution, configuration updates, and routine maintenance. These tools also help close the workforce talent gap by lowering the barrier. to entry and allowing more junior analysts to ramp up quickly,” Everson said. “By automating these tasks, Cisco’s AI-enabled platforms can free network engineers to focus on higher-level architectural strategy and innovation, and free cybersecurity analysts to dedicate more time to strategic threat hunting and detection engineering.”</p>



<p class="wp-block-paragraph">In addition to changes in traffic patterns, networks are moving toward AI-native platforms that will become the fabric of intelligent connectivity rather than a simple pipe. As network operators move compute toward the network edge—such as at a cell site where a tower sits—they will be able to run applications directly from the network, Everson said. </p>



<p class="wp-block-paragraph">“One promising application is Integrated Sensing and Communication (ISAC), which combines wireless communications and radio-frequency sensing to “see” objects’ position and path using radio waves that reflect off them. Unlike optical sensors, it can detect intrusion even in low-light conditions, through smoke, or around obstructions where traditional video analytics might fail,” Everson said. “This technology has been prototyped and demonstrated already, and it holds great promise for autonomous systems and robotics, AI-driven smart facilities, and public safety.”</p>



<p class="wp-block-paragraph">In closing, Everson offered three suggestions for the committee to act on in the future:</p>



<ul class="wp-block-list">
<li><strong>Accelerate the U.S. AI-native stack.</strong> Cisco is investing across multiple dimensions of AI native networking, bringing new capabilities to 5G-Advanced today while building the foundation for 6G. One example of this commitment is AI-WIN—a collaboration among Cisco, NVIDIA, MITRE, Orion Development Company, Booz Allen, and T-Mobile—which brings AI, compute, and wireless together to create a secure, American-led path from 5G-Advanced to AI native 6G. “I encourage Congress to lean in on areas where the United States has a strategic leadership role, such as compute, core networking, and applications,” Everson stated.</li>



<li><strong>Modernize permitting and infrastructure.</strong> As computing becomes more distributed, permitting must enable rapid and responsible deployment. As this Committee considers the future of the Universal Service Fund, it should account for the evolving costs of AI-ready networks so rural and urban communities can share in the benefits, he stated.</li>



<li><strong>Maintain a balanced spectrum policy.</strong> The 800 megahertz of licensed spectrum recently made available by Congress is essential to high-capacity, high-uplink connectivity. The FCC’s authorization of the 6 gigahertz band for unlicensed use is equally important to meeting enterprise demand. “A dependable pipeline of both is foundational to American leadership, and I thank you for your efforts to rebuild it.”</li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft CEO Touts His Own DIY AI Project To Wall Street and His 20 Million Followers]]></title>
<description><![CDATA[theodp writes: During Microsoft's 2026Q4 earnings call, CEO Microsoft Satya Nadella took time to tout a dashboard he personally created using AI from a Morgan Stanley analyst's PDF research report, which suggested a rosy payback for the so-called MAG7's ('Magnificent 7' companies) massive capital...]]></description>
<link>https://tsecurity.de/de/3701774/it-security-nachrichten/microsoft-ceo-touts-his-own-diy-ai-project-to-wall-street-and-his-20-million-followers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3701774/it-security-nachrichten/microsoft-ceo-touts-his-own-diy-ai-project-to-wall-street-and-his-20-million-followers/</guid>
<pubDate>Tue, 04 Aug 2026 01:16:48 +0200</pubDate>
<content:encoded><![CDATA[theodp writes: During Microsoft's 2026Q4 earnings call, CEO Microsoft Satya Nadella took time to tout a dashboard he personally created using AI from a Morgan Stanley analyst's PDF research report, which suggested a rosy payback for the so-called MAG7's ('Magnificent 7' companies) massive capital expenditures on AI (to which Nadella later added a "not financial advice" disclaimer). "It would be fun for you, Adam. I think one of your colleagues put out an ROIC [Return on Invested Capital] document. I took that document to Copilot, which is a PDF, and I said, 'Build me a new Power BI dashboard, essentially.' But here is the thing. It built a rich semantic model that went into my Fabric with OneLake that brought all the data in from the external sources. In fact, it was current with all the SEC filings of all the MAG7. And then on top of that, the repo itself is in GitHub, but the artifact is sitting in my Copilot as a site. That, to me, is a classic example of an enterprise-wide workflow. I, as a knowledge worker, could go create a dashboard. The data engineer can go to Fabric and find the artifact. The professional developer can go to the repo and find it in GitHub. And by the way, it's all registered with Agent 365. That's a little bit of what Amy is describing as the coming together of a new way to work, even while at the same time, bringing IT, security and manageability of it."
 
After Nadella's show-and-tell drew an underwhelming response during the call ("That's very helpful. Thank you." said the Morgan Stanley analyst whose team's work Nadella scraped with AI), Nadella turned to social media with posts on LinkedIn (12M followers) and Twitter/X (8M followers) to make the case for why his DIY project was such a brilliant demonstration of how AI enables governance, controls, security, development, testing, deployment, maintenance, data analysis/modeling, visualization, usability, and value. "Some more detail on the ROIC Intelligence App I built yesterday and mentioned on today's earnings call," Nadella wrote on LinkedIn. "I took the PDF that Brian Nowak at Morgan Stanley put together for Hyperscale ROIC this week and used Copilot code (coming in our new superapp) with a single prompt + skill (/drill-me) to create the plan, then used autopilot in auto to create the full app (with history, lookups, scenarios, what-ifs, etc). And /rubber-duck to test. And the best part is that all the artifacts are in my enterprise environment. My app is in Copilot, my code is in GitHub Enterprise; all my data pipelines/lake/semantic models are in Fabric. And everything is under Agent 365 IT/Sec/FinOps control! So this is not about Tokenmaxxing or vibe coding. Every step of the way the rails are engineered to create value, making everything a long-term reusable asset, with governance/security, and cost controls. This is the full system to drive business value. Disclosures: This is all pulled from public sources, and for illustrative purposes only...not financial advice! :) Here is the app and architecture..."
 
Not unexpectedly, the accompanying screenshot of a splash page for the BI app and a buzzword-laden complicated architecture diagram drew universal praise from LinkedIn fans, but also a few barbs from less-than-impressed commenters on Nadella's Twitter/X post, some of whom suggested Nadella's project might even represent a jump-the-shark moment for AI mania. "That he doesn't see whats wrong with saying 'My app is in Copilot, my code is in GitHub Enterprise; all my data pipelines/lake/semantic models are in Fabric' is exactly why MS is failing at AI,'" replied @PassingPixels on X/Twitter. "Dude is having to run 5 different systems to emulate babies first vibe code." @zigmund_ignatov added, "Why do we call glorified slide show an app?" @Mathupiriyan quipped, "Looks like Copilot just turned a PDF into a profit crystal ball." Unimpressed, @Markusndnb remarked, "So you created a web page using tons of proprietary MS tools." And @FishyAccounting called on Nadella to show-his-work, saying "Post the prompt or it didn't happen." (btw, Microsoft President Brad Smith similarly declined to provide the prompt for his own self-described amazing AI DIY reporting project that he touted at Microsoft's Shareholder Meeting last December).
 
So, does Nadella's self-promoted AI reworking of someone else's PDF research report strike you as an amazing example of everything that's good about AI, or does it conjure up memories of The Emperor's New Clothes?<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Microsoft+CEO+Touts+His+Own+DIY+AI+Project+To+Wall+Street+and+His+20+Million+Followers%3A+https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F08%2F03%2F1934211%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F08%2F03%2F1934211%2Fmicrosoft-ceo-touts-his-own-diy-ai-project-to-wall-street-and-his-20-million-followers%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://slashdot.org/story/26/08/03/1934211/microsoft-ceo-touts-his-own-diy-ai-project-to-wall-street-and-his-20-million-followers?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA['Generative AI is already changing what malicious software packages look like and how threat actors are beginning to probe AI-based code systems': Amazon flags North Korean hacker group as being behind the surge in open source supply chain attacks]]></title>
<description><![CDATA[Amazon linked a North Korean hacking group to software supply chain attacks while warning generative AI is changing malware development techniques.]]></description>
<link>https://tsecurity.de/de/3701735/it-nachrichten/generative-ai-is-already-changing-what-malicious-software-packages-look-like-and-how-threat-actors-are-beginning-to-probe-ai-based-code-systems-amazon-flags-north-korean-hacker-group-as-being-behind-the-surge-in-open-source-supply-chain-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3701735/it-nachrichten/generative-ai-is-already-changing-what-malicious-software-packages-look-like-and-how-threat-actors-are-beginning-to-probe-ai-based-code-systems-amazon-flags-north-korean-hacker-group-as-being-behind-the-surge-in-open-source-supply-chain-attacks/</guid>
<pubDate>Tue, 04 Aug 2026 01:16:32 +0200</pubDate>
<content:encoded><![CDATA[Amazon linked a North Korean hacking group to software supply chain attacks while warning generative AI is changing malware development techniques.]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Teams Always Need to Modernize. AI Is Changing the Game.]]></title>
<description><![CDATA[From helping in-source software development to streamlining resident-facing systems, AI is a new partner to governments overhauling legacy systems. Here's how IT organizations are using it today.]]></description>
<link>https://tsecurity.de/de/3701651/ai-nachrichten/it-teams-always-need-to-modernize-ai-is-changing-the-game/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3701651/ai-nachrichten/it-teams-always-need-to-modernize-ai-is-changing-the-game/</guid>
<pubDate>Mon, 03 Aug 2026 20:24:28 +0200</pubDate>
<content:encoded><![CDATA[From helping in-source software development to streamlining resident-facing systems, AI is a new partner to governments overhauling legacy systems. Here's how IT organizations are using it today.]]></content:encoded>
</item>
<item>
<title><![CDATA[Hashimoto’s Superlogical bets that agentic software development needs more than a better terminal]]></title>
<description><![CDATA[The rise of AI coding agents is beginning to expose a longstanding weakness in software development: work remains fragmented across developer terminals, CI pipelines, remote servers, and production systems.



Superlogical, a startup founded by HashiCorp co-founder Mitchell Hashimoto, aims to sol...]]></description>
<link>https://tsecurity.de/de/3701642/ai-nachrichten/hashimotos-superlogical-bets-that-agentic-software-development-needs-more-than-a-better-terminal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3701642/ai-nachrichten/hashimotos-superlogical-bets-that-agentic-software-development-needs-more-than-a-better-terminal/</guid>
<pubDate>Mon, 03 Aug 2026 20:24:27 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The rise of AI coding agents is beginning to expose a longstanding weakness in software development: work remains fragmented across developer terminals, CI pipelines, remote servers, and production systems.</p>



<p class="wp-block-paragraph">Superlogical, a startup founded by HashiCorp co-founder <a href="https://mitchellh.com/" target="_blank" rel="noreferrer noopener">Mitchell Hashimoto</a>, aims to solve that by turning the terminal into a persistent execution layer that both developers and AI agents can share.</p>



<p class="wp-block-paragraph">It is proposing to do so with the help of a server-side multiplexer that keeps software sessions “alive” across devices and environments, allowing humans and AI agents to resume, share, and manage long-running coding sessions without losing context.</p>



<p class="wp-block-paragraph">In contrast, traditional multiplexers, such as <a href="https://github.com/tmux/tmux" target="_blank" rel="noreferrer noopener">tmux</a>, were designed to preserve terminal sessions for individual users, allowing developers to detach and reconnect to terminal sessions after network interruptions.</p>



<p class="wp-block-paragraph">That limitation, according to analysts, is becoming a real pain point for developers and enterprises adopting long-running AI coding agents.</p>



<p class="wp-block-paragraph">“Tools like tmux were built for a human watching one terminal, but agents now run for hours in the background, and existing tools have zero awareness of whether an agent is waiting for your approval or still thinking,” said <a href="https://www.linkedin.com/in/manoj-chandra-jha-b5ab0a13/" target="_blank" rel="noreferrer noopener">Manoj Chandra Jha</a>, principal analyst at Nord-IQ Research.</p>



<p class="wp-block-paragraph">This means that developers might often have to manually reconnect to sessions simply to determine whether work is progressing, blocked, or ready for review, which becomes increasingly cumbersome as enterprise teams begin running multiple autonomous coding agents simultaneously, Jha added.</p>



<p class="wp-block-paragraph">To address that challenge, Superlogical moves the session, not just the terminal connection.</p>



<p class="wp-block-paragraph">Instead of having both the server and client repeatedly parse and render terminal output, the new multiplexer stores the authoritative session state on the server and streams raw terminal data to clients, which independently reconstruct the same session using Hashimoto’s <a href="https://mitchellh.com/writing/libghostty-is-coming" target="_blank" rel="noreferrer noopener">libghostty rendering engine</a>.</p>



<p class="wp-block-paragraph">This approach, Jha said, will allow developers and AI agents to reconnect to, share, and resume long-running sessions from desktop, mobile, or web clients while preserving the same execution context.</p>



<p class="wp-block-paragraph">That means reduced interruptions, simplified remote development, and improved productivity for cloud-native and AI-assisted software engineering, echoed <a href="https://pareekh.com/about/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, principal analyst at Pareekh Consulting. </p>



<p class="wp-block-paragraph">For CIOs, however, the appeal isn’t the speed of development but more control.</p>



<p class="wp-block-paragraph">“Right now, AI agents run in the background with basically no audit trail. A standardized session that tracks exactly what happened, who did what, and hands off cleanly between human and AI could make it much easier to monitor and secure all this new agent activity,” Jain said.</p>



<p class="wp-block-paragraph">The approach could also help enterprises gain a single control layer for tracking, auditing, and managing autonomous software work instead of relying on multiple monitoring, observability, and workflow tools, Jha added.</p>



<p class="wp-block-paragraph">Jha cautioned that enterprises should view Superlogical as an early-stage technology rather than a mature infrastructure platform: “The product remains in beta and has yet to be independently benchmarked or proven at enterprise scale.”</p>



<p class="wp-block-paragraph">Whether Superlogical ultimately becomes that persistent execution layer or remains a more capable alternative to tmux will depend on whether it can prove those benefits at enterprise scale, the analyst added.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Alibaba takes aim at OpenAI and Anthropic with Qwen3.8-Max launch]]></title>
<description><![CDATA[Alibaba on Monday introduced Qwen3.8-Max, its largest artificial intelligence model to date, expanding its enterprise AI portfolio with an open-weight model designed for software engineering, multimodal reasoning, and other knowledge-intensive business workloads.



In a blog post announcing the ...]]></description>
<link>https://tsecurity.de/de/3701643/ai-nachrichten/alibaba-takes-aim-at-openai-and-anthropic-with-qwen38-max-launch/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3701643/ai-nachrichten/alibaba-takes-aim-at-openai-and-anthropic-with-qwen38-max-launch/</guid>
<pubDate>Mon, 03 Aug 2026 20:24:27 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Alibaba on Monday introduced Qwen3.8-Max, its largest artificial intelligence model to date, expanding its enterprise AI portfolio with an open-weight model designed for software engineering, multimodal reasoning, and other knowledge-intensive business workloads.</p>



<p class="wp-block-paragraph">In a <a href="https://qwen.ai/blog?id=qwen3.8" target="_blank" rel="noreferrer noopener">blog post</a> announcing the launch, Alibaba described Qwen3.8-Max as a 2.4-trillion-parameter mixture-of-experts (MoE) model that activates only about 95 billion parameters during inference.</p>



<p class="wp-block-paragraph">The company said the architecture is intended to improve inference efficiency while supporting coding, reasoning and multimodal tasks, with open-weight versions scheduled for release next week through Alibaba Cloud’s Model Studio.</p>



<p class="wp-block-paragraph">“We believe it’s one of the most powerful model available today, compatible to leading frontier AI models, second only to Fable 5,” Alibaba said in an X <a href="https://x.com/Alibaba_Qwen/status/2078759124914098291" target="_blank" rel="noreferrer noopener">post</a>.</p>



<h2 class="wp-block-heading">Benchmarks target Anthropic and OpenAI’s coding models</h2>



<p class="wp-block-paragraph">Alibaba published internal test results comparing Qwen3.8-Max against Claude Opus 4.8, Claude Fable 5, and OpenAI’s GPT-5.6 Sol on coding benchmarks, including SWE-bench Pro and a proprietary evaluation the company calls NL2Repo-Bench.</p>



<p class="wp-block-paragraph">The company said it evaluated competing models using each vendor’s own coding harness, Claude Code for Anthropic’s models and Codex for GPT-5.6 Sol, and reported the highest published score across available configurations for each rival.</p>



<p class="wp-block-paragraph">Charlie Dai, vice president and principal analyst at Forrester, said the launch signals Alibaba is closing ground on proprietary leaders, though that isn’t the full picture.</p>



<p class="wp-block-paragraph">“Alibaba is narrowing the gap, but the larger story is the rapid maturation of open-weight models,” Dai said. “Enterprises increasingly have credible alternatives to proprietary frontier models, particularly for software engineering, domain customization, sovereignty, and cost-sensitive deployments, where openness often matters as much as absolute model performance.”</p>



<h2 class="wp-block-heading">Company touts a 16-day autonomous coding run</h2>



<p class="wp-block-paragraph">Alibaba said it tested the model on three unsupervised, multi-day coding projects requiring it to take a task from an empty project folder to completion without human assistance, including one project the company said took 16 days to complete on its own.</p>



<p class="wp-block-paragraph">Alibaba also highlighted enterprise applications across legal compliance, financial analysis, engineering design, quantitative research and multimodal content creation, saying the model is intended to complete entire business workflows rather than individual AI-assisted tasks.</p>



<p class="wp-block-paragraph">Amit Jena, development manager for AI at Kanerika, said that the claim deserves more scrutiny than it has received.</p>



<p class="wp-block-paragraph">“The claim worth examining is not the parameter count. Alibaba says the model completed a software engineering project in 16 days. That sentence has been reprinted everywhere and interrogated nowhere,” Jena said. “Sixteen days of what? How many times did a human step in? Did the output survive code review?”</p>



<p class="wp-block-paragraph">Jena said the open-weight commitment itself should also be read carefully. “Publishing weights is a separate act from opening an API endpoint,” he said. “Until there is a repository, a licence and a model card, open-weight describes an intention.”</p>



<h2 class="wp-block-heading">Analysts say inference efficiency isn’t the real constraint</h2>



<p class="wp-block-paragraph">Alibaba’s mixture-of-experts architecture activates roughly 95 billion of the model’s 2.4 trillion parameters per request, a design the company says lowers inference costs.</p>



<p class="wp-block-paragraph">Dai said that tradeoff now matters more to enterprise buyers than raw model size. “Inference efficiency now matters more than raw model size for most enterprises,” he said. “Activating only a fraction of total parameters can significantly reduce serving costs and infrastructure requirements, making frontier-class performance more accessible for production deployments where scalability, latency, and economics are often bigger concerns than benchmark leadership.”</p>



<p class="wp-block-paragraph">Jena said efficiency gains matter less than an organization’s ability to actually test the model. “Efficiency stopped being the interesting question. The constraint that actually binds is evaluation throughput,” he said.</p>



<p class="wp-block-paragraph">Nitish Tyagi, senior principal analyst at Gartner, said the significance of the release lies less in the parameter count than in what it signals about competitive pressure on AI deployment costs.</p>



<p class="wp-block-paragraph">“Gartner has previously predicted that, without stronger cost controls, AI coding expenses could exceed the average developer’s salary,” Tyagi said. “The combination of open weights, a mixture-of-experts architecture, and a one-million-token context window represents a meaningful step toward making AI-augmented software development more economically viable.”</p>



<p class="wp-block-paragraph">Tyagi cautioned that enterprises need to look beyond inference costs when weighing the model for production use.</p>



<p class="wp-block-paragraph">“Many organizations outside China may be hesitant to rely on models hosted within China, leading them to deploy through hyperscalers or on-premises infrastructure, both of which introduce additional costs,” he said.</p>



<p class="wp-block-paragraph">Open-weight models also typically lack the indemnification protections that come with commercial AI vendors, he said, meaning enterprises need their own security, governance, and code-scanning controls to catch copyright and intellectual property risks before production deployment.</p>



<h2 class="wp-block-heading">What CIOs should look out for</h2>



<p class="wp-block-paragraph">Jena said the flagship model announced Monday may not be the one enterprises end up running.</p>



<p class="wp-block-paragraph">“Qwen3.8-27B, announced alongside the flagship and almost entirely ignored in coverage,” is the more deployable option for most organizations, he said, since it can run on infrastructure they own and fine-tune on their own data.</p>



<p class="wp-block-paragraph">Dai said enterprise leaders evaluating the release should prioritize transparency and total cost of ownership over headline figures. “The key question is whether Qwen3.8 delivers measurable business outcomes, enterprise-grade reliability, lower total cost of ownership, and options for digital sovereignty compared with competing models,” he said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sequoia’s Shaun Maguire leads $1B round for nuclear startup Valar Atomics]]></title>
<description><![CDATA[Valar Atomics raised $1 billion at a $6 billion valuation after signing a development deal with Nvidia in June.]]></description>
<link>https://tsecurity.de/de/3701632/ai-nachrichten/sequoias-shaun-maguire-leads-1b-round-for-nuclear-startup-valar-atomics/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3701632/ai-nachrichten/sequoias-shaun-maguire-leads-1b-round-for-nuclear-startup-valar-atomics/</guid>
<pubDate>Mon, 03 Aug 2026 20:24:24 +0200</pubDate>
<content:encoded><![CDATA[Valar Atomics raised $1 billion at a $6 billion valuation after signing a development deal with Nvidia in June.]]></content:encoded>
</item>
<item>
<title><![CDATA[The Assets You Don’t Know You Own: Attack Surface Sprawl Is a Discovery Problem, Not a Tooling Problem]]></title>
<description><![CDATA[Modern organizations no longer operate within a fixed network perimeter. Cloud services, remote work, third-party integrations, and rapid digital expansion have made the boundary between "inside" and "outside" for the enterprise increasingly difficult to define. 


Attackers exploit this ambiguit...]]></description>
<link>https://tsecurity.de/de/3701325/it-security-nachrichten/the-assets-you-dont-know-you-own-attack-surface-sprawl-is-a-discovery-problem-not-a-tooling-problem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3701325/it-security-nachrichten/the-assets-you-dont-know-you-own-attack-surface-sprawl-is-a-discovery-problem-not-a-tooling-problem/</guid>
<pubDate>Mon, 03 Aug 2026 20:19:02 +0200</pubDate>
<content:encoded><![CDATA[<p><img width="1200" height="600" src="https://cyble.com/wp-content/uploads/2026/08/Attack-Surface.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Attack Surface" decoding="async" srcset="https://cyble.com/wp-content/uploads/2026/08/Attack-Surface.webp 1200w, https://cyble.com/wp-content/uploads/2026/08/Attack-Surface-300x150.webp 300w, https://cyble.com/wp-content/uploads/2026/08/Attack-Surface-1024x512.webp 1024w, https://cyble.com/wp-content/uploads/2026/08/Attack-Surface-768x384.webp 768w" sizes="(max-width: 1200px) 100vw, 1200px" title="The Assets You Don't Know You Own: Attack Surface Sprawl Is a Discovery Problem, Not a Tooling Problem 1"></p>
<p><!-- wp:paragraph --></p>
<p>Modern organizations no longer operate within a fixed network perimeter. Cloud services, remote work, third-party integrations, and rapid digital expansion have made the boundary between "inside" and "outside" for the enterprise increasingly difficult to define. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Attackers exploit this ambiguity by scanning continuously for weaknesses across an organization's hardware, software, cloud, and internet-facing assets. The uncomfortable truth security leaders must confront is simple: an organization cannot secure what it does not know it has. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Attack surface expansion is frequently framed as a tooling gap, but the evidence points elsewhere — toward a persistent, structural failure in attack surface discovery, asset discovery, and visibility. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Why Attack Surface Sprawl Happens</strong> </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>Attack surfaces expand for several identifiable and recurring reasons. Cloud adoption introduces new workloads, storage resources, and services that may be provisioned outside formal IT review processes, creating visibility gaps.  </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Effective cloud asset discovery has become important as organizations struggle to maintain awareness of resources created across distributed cloud environments. Shadow IT further increases complexity when business units deploy applications, platforms, or services without security teams being aware of their existence, creating additional shadow IT risk. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Multi-cloud environments can fragment visibility across different providers, each with varying configuration standards and security controls. During mergers and acquisitions, organizations often inherit unknown infrastructure and assets from newly integrated entities, making it difficult to establish complete visibility. Forgotten infrastructure, including systems that were intended to be decommissioned but remain accessible online, can continue to create exposure risks. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Third-party services also expand the attack surface by introducing dependencies on vendors, suppliers, and partners whose security weaknesses may impact the organization. In addition, temporary development environments are frequently left active, misconfigured, or unmonitored after their original purpose has ended. As organizations continue adding internet-facing assets at a rapid pace, traditional manual inventory processes struggle to maintain an accurate and complete view of the modern attack surface. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Discovery Is the Real Challenge</strong> </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>Security tools, firewalls, endpoint detection, vulnerability scanners, and vulnerability management tools can only act on assets that are already registered in an inventory. They cannot protect what has never been identified. This is why NIST's Cybersecurity Framework places asset understanding at the very foundation of its Identify function: organizations must understand their data, hardware, software, systems, facilities, services, people, and supplier relationships before they can prioritize risk. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Traditional asset inventories, built on periodic audits and manual record-keeping, cannot keep pace with environments that change hourly. CISA's own directive on federal network visibility frames this directly, stating that its core focus areas, asset discovery and vulnerability enumeration, are essential building blocks of operational visibility that many organizations still lack. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The visibility gap is not a failure of detection technology; it is a failure to first establish a complete, current record of what exists. Strong IT asset inventory security practices require organizations to continuously identify, classify, and monitor assets across their environments. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong> Why Organizations Lose Sight of Their Digital Assets</strong> </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>Government agencies and independent research organizations consistently point to the same conclusion: unknown and unmanaged assets represent a significant source of organizational risk. Without a complete understanding of what exists across an environment, security teams cannot accurately assess exposure, prioritize vulnerabilities, or reduce potential attack paths. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>This challenge is reflected in CISA’s approach to asset visibility. CISA’s Binding Operational Directive 23-01 requires federal civilian agencies to maintain continuously updated asset inventories and identify vulnerabilities across discovered systems, emphasizing that comprehensive asset visibility is a necessary foundation for effective vulnerability management.  </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Similarly, CISA’s Cyber Asset Attack Surface Management (CAASM) resources highlight the importance of understanding and reducing exposure across software, hardware, and network environments, reinforcing the idea that organizations must first identify their assets before they can effectively protect them. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The UK’s National Cyber Security Centre (NCSC) has also emphasized the importance of visibility into modern attack surfaces. NCSC notes that threat actors continuously scan organizations’ hardware, software, services, and cloud assets to identify weaknesses. External attack surface management (EASM) approaches are designed to help defenders achieve comparable visibility into their exposed digital footprint.  </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>NCSC’s Active Cyber Defence trials further demonstrated that organizations gained security benefits from EASM capabilities beyond vulnerability identification alone, largely because these tools improved awareness of externally exposed assets. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Cyble Research and Intelligence Labs (CRIL) has similarly documented how misconfigured and outdated internet-facing assets continue to expand opportunities for threat actors. Cyble’s research highlights sustained targeting of public-facing infrastructure, including exploitation patterns associated with campaigns such as the MOVEit-linked Clop ransomware attacks, demonstrating how exposed systems can become entry points for large-scale compromises. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The scale of exposed infrastructure further illustrates the challenge organizations face in maintaining visibility. Cyble’s ODIN platform identified more than 660,000 exposed cloud storage buckets and over 91 million exposed hosts, with more than 200 billion files accessible due to cloud misconfigurations. These findings demonstrate the extent to which digital assets can exist outside formal security oversight and create unknown exposure risks. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Cyble’s analysis of the attack surface management landscape also highlights that the discipline emerged in response to the growing need for organizations to discover unknown technology assets. The approach has evolved into complementary areas, including External Attack Surface Management (EASM), which focuses on internet-facing assets, and Cyber Asset Attack Surface Management (CAASM), which provides broader visibility into internal environments.  </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Together, these capabilities address the central challenge facing modern security teams: gaining an accurate understanding of the assets they need to protect. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Best Practices</strong> </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>Guidance from these sources converges on a consistent set of practices: </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Continuous asset discovery</strong> rather than periodic, point-in-time audits. </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>External attack surface management</strong> to maintain an attacker's-eye view of internet-facing infrastructure. </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Asset inventory validation</strong> against NIST's Identify function categories, including supplier and third-party systems. </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Continuous monitoring</strong> for newly exposed services, certificate issues, and configuration drift. </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Risk prioritization</strong> is based on exploitability and business impact once assets are known. </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Third-party exposure management</strong>, since vendor and supplier assets extend the organizational attack surface. </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Conclusion</strong> </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>The recurring theme across CISA, NIST, NCSC, and Cyble research is not a shortage of security tools; it is a shortage of visibility. Vulnerability scanners, firewalls, and detection platforms are only as effective as the asset inventory feeding them.  </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Organizations that treat discovery as a one-time or occasional exercise will continue to carry unknown, unmanaged, and forgotten assets into every future incident. Reducing organizational risk begins with a foundational discipline: knowing, continuously and comprehensively, what exists. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Know what's exposed before an attacker finds it first. <a href="https://cyble.com/external-threat-profile-report/" target="_blank" rel="noreferrer noopener"><strong>Get a Free External Threat Profile →</strong></a></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>References</strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:list {"ordered":true,"start":1} --></p>
<ol start="1" class="wp-block-list"><!-- wp:list-item -->
<li><a href="https://www.cisa.gov/news-events/directives/bod-23-01-improving-asset-visibility-and-vulnerability-detection-federal-networks" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/directives/bod-23-01-improving-asset-visibility-and-vulnerability-detection-federal-networks</a> </li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><a href="https://www.cisa.gov/resources-tools/services/cyber-asset-attack-surface-management-caasm" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/resources-tools/services/cyber-asset-attack-surface-management-caasm</a> </li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><a href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf" target="_blank" rel="noreferrer noopener">https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf</a> </li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><a href="https://www.ncsc.gov.uk/guidance/external-attack-surface-management-buyers-guide" target="_blank" rel="noreferrer noopener">https://www.ncsc.gov.uk/guidance/external-attack-surface-management-buyers-guide</a> </li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><a href="https://www.ncsc.gov.uk/blog-post/active-cyber-defence-2-insights-easm-trials" target="_blank" rel="noreferrer noopener">https://www.ncsc.gov.uk/blog-post/active-cyber-defence-2-insights-easm-trials</a> </li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><a href="https://cyble.com/knowledge-hub/what-is-external-attack-surface-management/" target="_blank" rel="noreferrer noopener">https://cyble.com/knowledge-hub/what-is-external-attack-surface-management/</a></li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><a href="https://cyble.com/knowledge-hub/third-party-risk-management-attack-surface/" target="_blank" rel="noreferrer noopener">https://cyble.com/knowledge-hub/third-party-risk-management-attack-surface/</a> </li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><a href="https://cyble.com/blog/unmasking-the-critical-risk-of-internet-exposed-assets-to-public-and-private-organizations/" target="_blank" rel="noreferrer noopener">https://cyble.com/blog/unmasking-the-critical-risk-of-internet-exposed-assets-to-public-and-private-organizations/</a> </li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><a href="https://cyble.com/blog/detects-200-billion-files-exposed-in-cloud-buckets/" target="_blank" rel="noreferrer noopener">https://cyble.com/blog/detects-200-billion-files-exposed-in-cloud-buckets/</a> </li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><a href="https://cyble.com/blog/cyble-recognized-in-forresters-attack-surface-management-solutions-landscape-q2-2024-report/" target="_blank" rel="noreferrer noopener">https://cyble.com/blog/cyble-recognized-in-forresters-attack-surface-management-solutions-landscape-q2-2024-report/</a> </li>
<p><!-- /wp:list-item --></p></ol>
<p><!-- /wp:list --></p>
<p><!-- wp:list {"ordered":true,"start":3} --></p>
<ol start="3" class="wp-block-list"></ol>
<p><!-- /wp:list --></p>
<p><!-- wp:list {"ordered":true,"start":4} --></p>
<ol start="4" class="wp-block-list"></ol>
<p><!-- /wp:list --></p>
<p><!-- wp:list {"ordered":true,"start":5} --></p>
<ol start="5" class="wp-block-list"></ol>
<p><!-- /wp:list --></p>
<p><!-- wp:list {"ordered":true,"start":6} --></p>
<ol start="6" class="wp-block-list"></ol>
<p><!-- /wp:list --></p>
<p><!-- wp:list {"ordered":true,"start":7} --></p>
<ol start="7" class="wp-block-list"></ol>
<p><!-- /wp:list --></p>
<p><!-- wp:list {"ordered":true,"start":8} --></p>
<ol start="8" class="wp-block-list"></ol>
<p><!-- /wp:list --></p>
<p><!-- wp:list {"ordered":true,"start":9} --></p>
<ol start="9" class="wp-block-list"></ol>
<p><!-- /wp:list --></p>
<p><!-- wp:list {"ordered":true,"start":10} --></p>
<ol start="10" class="wp-block-list"></ol>
<p><!-- /wp:list --></p>
<p><!-- wp:list {"ordered":true,"start":11} --></p>
<ol start="11" class="wp-block-list"></ol>
<p><!-- /wp:list --></p>
<p>The post <a rel="nofollow" href="https://cyble.com/blog/attack-surface-discovery-asset-visibility/">The Assets You Don’t Know You Own: Attack Surface Sprawl Is a Discovery Problem, Not a Tooling Problem</a> appeared first on <a rel="nofollow" href="https://cyble.com/">Cyble</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Pro 5.1 Released]]></title>
<description><![CDATA[Today marks the release of Metasploit Pro 5.1 - building upon the foundation laid in 5.0, adding new evasion primitives for HTTP Meterpreter payloads, support for tracking service hierarchies, a deeper and more interactive Network Topology view, and continuing our commitment to a modern, consiste...]]></description>
<link>https://tsecurity.de/de/3701274/it-security-nachrichten/metasploit-pro-51-released/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3701274/it-security-nachrichten/metasploit-pro-51-released/</guid>
<pubDate>Mon, 03 Aug 2026 20:18:47 +0200</pubDate>
<content:encoded><![CDATA[<p><span>Today marks the release of Metasploit Pro 5.1 - building upon the foundation laid in 5.0, adding new evasion primitives for HTTP Meterpreter payloads, support for tracking service hierarchies, a deeper and more interactive Network Topology view, and continuing our commitment to a modern, consistent UI. This release is powered by </span><a href="https://www.rapid7.com/blog/post/pt-metasploit-framework-6-5-released/" target="_blank" title="Metasploit Framework 6.5 Released"><span>Metasploit Framework 6.5</span></a><span>.</span></p><h2><span>Malleable C2 Profiles</span></h2><p></p><p><span>One of the most requested capabilities in modern red-team engagements is the ability to blend Meterpreter's network traffic into legitimate-looking patterns. Metasploit Pro 5.1 brings full Malleable C2 profile support, powered by Metasploit Framework 6.5, directly into the Pro UI — no command-line knowledge required.</span></p><p><span>Malleable C2 profiles let you load a standard profile and reshape Meterpreter's HTTP(S) traffic to emulate legitimate services, browser sessions, or any other traffic pattern you need. All Meterpreter flavours — Windows, Linux, Java, Python, and PHP — are supported, including stageless and staged payloads (e.g. </span><span><span data-type="inlineCode">meterpreter/reverse_https</span></span><span> and </span><span><span data-type="inlineCode">meterpreter_reverse_https</span></span><span>). This functionality is compatible with </span><a href="https://github.com/BC-SECURITY/Malleable-C2-Profiles" target="_blank" title="Malleable C2 profiles"><span>publicly available profile libraries</span></a><span>.</span></p><h2><span>Profile support across the Pro UI</span></h2><p></p><p><span>Malleable C2 profiles are now available in every part of the workflow where a payload is configured:</span></p><ul><li><span><strong>Single Module Run:</strong></span><span> The module options page now includes a Malleable C2 section.</span></li><li><span><strong>Listeners (New &amp; Edit):</strong></span><span> You can now choose from profiles already uploaded to the server or upload a new </span><span><span data-type="inlineCode">.profile</span></span><span> file directly from your browser.</span></li><li><span><strong>Payload Generator:</strong></span><span> The standalone payload generator also exposes the profile picker, so standalone payloads can carry the same C2 profile as the rest of your operation.</span><br></li></ul><p><span></span><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt00c8f7cfba369f9b/6a6b58a317e9ee7712e39f56/mal-1.png" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="mal-1.png" asset-alt="mal-1.png" inline="true" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt00c8f7cfba369f9b/6a6b58a317e9ee7712e39f56/mal-1.png" data-sys-asset-uid="blt00c8f7cfba369f9b" data-sys-asset-filename="mal-1.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="mal-1.png" sys-style-type="display"></p><p><span><em>Figure 1 Malleable Profiles</em></span></p><h2><span>Improved Payload Section</span></h2><p><br><span>Alongside the Malleable C2 integration, the payload selector has been overhauled across the Listener, Module Run, and Payload Generator pages. You can now filter payloads by platform and stage, making it much faster to find the right payload in large lists.</span></p><p><span><em></em></span></p><p><span><em></em></span><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt5b8c9d84c56f4976/6a6b5ee417e9ee9f1ce39f77/mal-2.png" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="mal-2.png" asset-alt="mal-2.png" inline="true" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt5b8c9d84c56f4976/6a6b5ee417e9ee9f1ce39f77/mal-2.png" data-sys-asset-uid="blt5b8c9d84c56f4976" data-sys-asset-filename="mal-2.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="mal-2.png" sys-style-type="display"></p><p><span><em>Figure 2: Advanced Payload Options</em></span></p><p><span><em></em></span></p><p><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt5386f342760bb33c/6a6b6204a20f98921fdec716/select-1.png" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="select-1.png" asset-alt="select-1.png" inline="true" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt5386f342760bb33c/6a6b6204a20f98921fdec716/select-1.png" data-sys-asset-uid="blt5386f342760bb33c" data-sys-asset-filename="select-1.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="select-1.png" sys-style-type="display"></p><p><span><em>Figure 3: Additional Payload Options</em></span></p><h2><span>Service Hierarchy Tracking Support</span></h2><p></p><p><span>The Discovered Services table has been overhauled with a cleaner, more capable interface consistent with the rest of Pro 5.1.</span></p><ul><li><span><strong>Service hierarchy visibility:</strong></span><span> The most significant new capability. Services can have parent-child relationships - for example, an HTTP service running over TCP, or a tunnelled protocol layered over another. The new table exposes this hierarchy directly with dedicated columns showing each service's parent and child services, so you can immediately understand how discovered services relate to one another without drilling into individual records.</span></li><li><span><strong>Search and sort across all columns:</strong></span><span> You can now search across host name, host address, service name, protocol, port, and info in a single query. All major columns are sortable, including parent services.</span></li><li><span><strong>Inline editing:</strong></span><span> Service fields (name, port, protocol, state, resource) can be edited directly from the table without navigating away.</span></li></ul><p><span></span></p><p><span></span><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blte99ed4bec8ace3d0/6a6b649cbe6e8040b26c6b9b/service-1.png" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="service-1.png" asset-alt="service-1.png" inline="true" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blte99ed4bec8ace3d0/6a6b649cbe6e8040b26c6b9b/service-1.png" data-sys-asset-uid="blte99ed4bec8ace3d0" data-sys-asset-filename="service-1.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="service-1.png" sys-style-type="display"></p><p><span><em>Figure 4: Service Options</em></span></p><p><span><em></em></span></p><p><span><em></em></span><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blte899cf4f4f3abbe0/6a6b65164e3795c06488dd53/service-2.png" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="service-2.png" asset-alt="service-2.png" inline="true" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blte899cf4f4f3abbe0/6a6b65164e3795c06488dd53/service-2.png" data-sys-asset-uid="blte899cf4f4f3abbe0" data-sys-asset-filename="service-2.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="service-2.png" sys-style-type="display"></p><p><span><em>Figure 5: Service </em></span><em>Hierarchy</em><span><em> Display</em></span></p><h2><span>Network Topology Enhancements</span><br></h2><p><span>Building on Metasploit Pro 5.0's improvements to the Network Topology, we've added additional support and functionality for exploring your internal infrastructure. Previously, each node in the graph provided a high level summary of the host details when hovering over the node. This has now been moved into a dedicated side panel that surfaces everything you know about a host without leaving the topology view.</span></p><h2><span>Rich host information panels</span></h2><p></p><p><span>Click any node in the topology graph and the side panel now shows a consolidated summary of everything Metasploit knows about that host:</span></p><ul><li><span><strong>Sessions:</strong></span><span> all sessions (open and closed) opened against the host, including session type, exploit used, payload, and timestamps.</span></li><li><span><strong>Loot: </strong></span><span>captured loot items associated with the host, including type, name, and content type.</span></li><li><span><strong>Credentials:</strong></span><span> cracked and captured credentials organised by service, de-duplicated and sorted with successful logins first.</span></li><li><span><strong>Modules run:</strong></span><span> a list of every module that has been executed against the host.</span></li><li><span><strong>Tags:</strong></span><span> any tags applied to the host or its sessions.</span></li></ul><p><span></span><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt099cc5a0c6188dc7/6a6b6634724d9602dd02acb2/info-1.png" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="info-1.png" asset-alt="info-1.png" inline="true" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt099cc5a0c6188dc7/6a6b6634724d9602dd02acb2/info-1.png" data-sys-asset-uid="blt099cc5a0c6188dc7" data-sys-asset-filename="info-1.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="info-1.png" sys-style-type="display"></p><p><span><em>Figure 6: Network Topology Display</em></span></p><h2><span>New filter options</span></h2><p></p><p><span>The topology graph toolbar has three new filters to help focus on the hosts that matter:</span></p><ul><li><span><strong>Filter by bruteforce</strong></span><span> - highlight services that can be bruteforced remotely on a host.</span></li><li><span><strong>Filter by tag</strong></span><span> - narrow the graph to hosts carrying a specific session or host tag.</span></li><li><span><strong>Filter by username</strong></span><span> - show only hosts where a particular user account has been compromised.</span></li><li><span><strong>Filter by module</strong></span><span> - surface hosts that have had a specific module run against them.</span></li></ul><p><span><em></em></span></p><p><span><em></em></span><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltea875f08e2fd2aa2/6a6c7e89b966e121b163cdbc/info-2.png" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="info-2.png" asset-alt="info-2.png" inline="true" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltea875f08e2fd2aa2/6a6c7e89b966e121b163cdbc/info-2.png" data-sys-asset-uid="bltea875f08e2fd2aa2" data-sys-asset-filename="info-2.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="info-2.png" sys-style-type="display"></p><p><span><em>Figure 7: Network Topology Graph Filter Options</em></span></p><p><span><em></em></span></p><h2><span>Discovered Vulnerabilities - Modern UI</span></h2><p></p><p><span>The Discovered Vulnerabilities table has been fully rewritten, bringing it in line with the UI overhaul introduced across the rest of Pro in 5.0.</span></p><p><span>Key improvements:</span></p><ul><li><span><strong>High level view and granular views</strong></span><span> - Each registered vulnerability provides a high view such as references and affected services, as well as a more granular expandable breakdown view.</span></li><li><span><strong>Inline editing</strong></span><span> - vulnerability details can be edited directly from the table without navigating to a separate page.</span></li><li><span><strong>Nexpose integration preserved</strong></span><span> - all existing InsightVM/Nexpose push and pull workflows are retained in the new implementation.</span></li></ul><p><span><em></em></span><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blta640a6584832d135/6a6c803423f3b863303c3b20/disc-1.png" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="disc-1.png" asset-alt="disc-1.png" inline="true" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blta640a6584832d135/6a6c803423f3b863303c3b20/disc-1.png" data-sys-asset-uid="blta640a6584832d135" data-sys-asset-filename="disc-1.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="disc-1.png" sys-style-type="display"></p><p><span><em>Figure 8: Discovered Vulnerabilities Modern UI</em></span></p><h2><span>Attack technique filtering support</span></h2><p></p><p><span>MITRE ATT&amp;CK® is a globally-accessible knowledge base of adversary tactics and techniques based on real-world observations. The ATT&amp;CK knowledge base is used as a foundation for the development of specific threat models and methodologies in the private sector, in government, and in the cybersecurity product and service community. Metasploit Pro now supports searching for modules by these techniques:</span></p><p><span></span></p><p><span></span><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt660c6c699331ea15/6a6c848878b5fed09f8f066d/mod-1.png" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="mod-1.png" asset-alt="mod-1.png" inline="true" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt660c6c699331ea15/6a6c848878b5fed09f8f066d/mod-1.png" data-sys-asset-uid="blt660c6c699331ea15" data-sys-asset-filename="mod-1.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="mod-1.png" sys-style-type="display"></p><p><span><em>Figure 9: Attack Technique Filtering Search</em></span></p><h2><span>Upgrading</span></h2><p></p><p><span>Existing Pro installations can be upgraded through the standard update mechanism. Full upgrade instructions are available in the </span><a href="https://help.metasploit.com/Content/managing-updating-metasploit/updating-metasploit.html" target="_blank" title="Metasploit Updates"><span>Metasploit Pro documentation</span></a><span>.</span></p><p><span>These features are available in Metasploit Pro 5.1.0 onwards. We're proud to collaborate with our customers, who are often the source of inspiration for product evolution. Ideas for improvements or enhancements can be shared with our Support team to help refine and submit them to the Product team on your behalf.</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The SOC’s AI maturity model]]></title>
<description><![CDATA[The path to next-generation AI Security Operations Centers (SOCs), where AI works hand-in-hand with human analysts, is paved with ambitious goals. This ideal SOC incorporates AI across every task to stop fast-moving threats. But a fully AI-powered SOC isn’t a single deployment or a switch you jus...]]></description>
<link>https://tsecurity.de/de/3701253/it-security-nachrichten/the-socs-ai-maturity-model/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3701253/it-security-nachrichten/the-socs-ai-maturity-model/</guid>
<pubDate>Mon, 03 Aug 2026 20:16:54 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The path to next-generation AI Security Operations Centers (SOCs), where AI works hand-in-hand with human analysts, is paved with ambitious goals. This ideal SOC incorporates AI across every task to stop fast-moving threats. But a fully AI-powered SOC isn’t a single deployment or a switch you just flip on. It is a staged rollout that’s built over time. There are levels of dependence on AI, starting with basic assistance, moving through automation, and ultimately reaching autonomous response. Each stage in the progression increases the model’s scope and narrows analyst involvement.</p>



<p class="wp-block-paragraph">This means that organizations embracing automation at any level must put their trust in the model. However, achieving trust depends on <a href="https://corelight.com/cp/provably-better-data?utm_source=cio-online&amp;utm_medium=brandpost-article&amp;utm_campaign=awareness-wave-2">data</a>. The data must be valid (and verifiable) so AI can propose logical conclusions, recommend appropriate actions for the organization’s needs and risk tolerances, and (at the autonomous stage) act on an analyst’s behalf without raising the risk of compromise and/or incorrect behavior.</p>



<p class="wp-block-paragraph">This article focuses on what enables movement between stages and how teams can build expertise alongside capabilities.</p>



<p class="wp-block-paragraph"><strong>Stage 1: Assistance</strong></p>



<p class="wp-block-paragraph">In its simplest SOC use case, AI helps analysts interpret data faster and more accurately, analyzing data, explaining alerts, summarizing logs, and translating detection logic. Many mature SOCs already operate here. AI sits close to analysts but doesn’t directly make decisions; it improves comprehension and can influence outcomes.</p>



<p class="wp-block-paragraph"><strong>Stage 2: Automation</strong></p>



<p class="wp-block-paragraph">This is where agentic AI enters the SOC. AI runs investigations, applies context, and proposes actions or interpretations while analysts retain oversight for accuracy and decision-making. AI starts shaping the investigative path rather than just explaining it, introducing efficiencies alongside uncertainty about when to trust (versus validating recommendations).</p>



<p class="wp-block-paragraph"><strong>Stage 3: Autonomy</strong></p>



<p class="wp-block-paragraph">At level three, AI operates with near independence; analysts oversee strategy but aren’t involved in individual tasks. The key shift from stage 2 is the removal of case-by-case approval for routine decisions. Instead, agents run on continuous policy constraints, feedback loops, and auditability structures.</p>



<p class="wp-block-paragraph">Security teams are accustomed to validating evidence before acting, but autonomous systems invert that relationship, forcing teams to trust evidence they may only review after an action executes. Many operators will be wary, even as they recognize the efficiencies AI offers when deployed correctly.</p>



<h4 class="wp-block-heading"><strong>How SOCs are starting to trust AI</strong></h4>



<p class="wp-block-paragraph">Moving from assistance to automation is largely a data problem. Moving from automation to autonomy is about trusting the model and the decisions it produces.</p>



<p class="wp-block-paragraph">What’s necessary to progress is structural confidence in how outputs are produced, validated, and traced, rooted in reliable network data that turns doubt into decisions. If data is incomplete or overly interpreted, the model preserves and amplifies those issues.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph">“If your data itself has bias,” says Vijit Nair, SVP of Product at <a href="https://corelight.com/?utm_source=cio-online&amp;utm_medium=brandpost-article&amp;utm_campaign=awareness-wave-2">Corelight</a>, “the tools skew towards that judgment. AI does not fix poor inputs. It scales them.”</p>
</blockquote>



<p class="wp-block-paragraph">Stan Kiefer, Senior Manager for Data Science at Corelight, adds that, “AI alone is not trustworthy at this point, and without data to reference back, it may never be.”</p>



<p class="wp-block-paragraph">Analysts should be able to inspect the evidence behind a model’s conclusion, which requires data and algorithms to be open to human inspection.</p>



<h4 class="wp-block-heading"><strong>Network security and AI</strong></h4>



<p class="wp-block-paragraph">To make that trust practical, teams need an evidence layer that is comprehensive, difficult to fake, and easy to audit. For many SOCs, that evidence layer is network data.</p>



<p class="wp-block-paragraph">Network data tells the most complete story of an environment, but it’s voluminous and easy to misinterpret without context. AI removes this complexity, letting analysts query network data without mastering every analysis technique, making it a knowledge multiplier rather than just a force multiplier. The difference: A knowledge multiplier helps humans operate above their current expertise; a tier-one analyst can ask a complex question and get an evidence-based answer, gradually building skills to operate at a higher level with more confidence.</p>



<p class="wp-block-paragraph">This has real implications for analyst development and team stability. Analysts can experience greater accomplishment, driving productivity and performance and reducing the chance of burnout.</p>



<h4 class="wp-block-heading"><strong>Analyst development and AI</strong></h4>



<p class="wp-block-paragraph">The SOC has long relied on repetitive work, especially for tier-one analysts. Their work is necessary but often neither instructive nor interesting, and it contributes to burnout and turnover. AI, especially agentic AI, can help mitigate that.</p>



<p class="wp-block-paragraph">AI doesn’t eliminate judgment; it removes friction and tedium. As Nair puts it, this is the difference between “craft” (manually working through data) and “art” (deciding what matters and what to do next).</p>



<p class="wp-block-paragraph">“AI ‘eats the craft’ so people can focus on the art,” he says. “It’s to have them spend less time on repetitive work and more on work that requires knowledge and judgment.”</p>



<p class="wp-block-paragraph">Kiefer estimates AI could cut time to competency by half or more. By replicating an analyst’s workflow, surfacing recurring steps, and explaining complex detections in plain language, AI accelerates the learning curve.</p>



<h4 class="wp-block-heading"><strong>The bottom line</strong></h4>



<p class="wp-block-paragraph">The real constraint on SOC AI maturity is trust, and trust depends on reliable data that makes outputs traceable and evidence inspectable. Moving through each stage reduces repetitive correlation work and shifts analyst effort toward the interpretation and validation that require human judgment.</p>



<p class="wp-block-paragraph">Key points for your team’s AI journey:</p>



<ul class="wp-block-list">
<li>Maturity is a staged process: assistance, automation, and autonomy reflect increasing delegation and trust requirements</li>



<li>Trust is evidence-based: analysts need traceable outputs, not opaque recommendations</li>



<li>Data quality is paramount: incomplete or low-context telemetry inhibits AI effectiveness</li>



<li>Verification enables progression: auditability determines how far AI can safely move into decision-making</li>
</ul>



<h4 class="wp-block-heading"><a></a><strong>Corelight: Provably better data</strong></h4>



<p class="wp-block-paragraph">AI is only as effective as the data behind it. Corelight network detection and response (NDR) delivers data that’s open, transparent, and explainable — in turn helping detect evasive threats, reduce triage time, and enable agentic AI throughout the SOC. Corelight’s structured network evidence preserves protocol-level context to produce a more complete dataset for investigation and AI. When analysts and AI can reason from evidence instead of isolated alerts or metadata, they can validate findings, reconstruct activity, and reach more reliable conclusions. <a href="https://corelight.com/cp/elitedefense?utm_source=cio-online&amp;utm_medium=brandpost-article&amp;utm_campaign=awareness-wave-2">Learn more about Corelight</a>.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Companies winning with AI operate differently. Here’s how.]]></title>
<description><![CDATA[The first phase of the AI race was largely about access. Companies rushed to adopt tools, launch pilots, and demonstrate that they were moving quickly enough to keep pace with the market. In many organizations, simply showing momentum became the strategy.



Leadership teams wanted to signal inno...]]></description>
<link>https://tsecurity.de/de/3701256/it-security-nachrichten/companies-winning-with-ai-operate-differently-heres-how/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3701256/it-security-nachrichten/companies-winning-with-ai-operate-differently-heres-how/</guid>
<pubDate>Mon, 03 Aug 2026 20:16:54 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The first phase of the AI race was largely about access. Companies rushed to adopt tools, launch pilots, and demonstrate that they were moving quickly enough to keep pace with the market. In many organizations, simply showing momentum became the strategy.</p>



<p class="wp-block-paragraph">Leadership teams wanted to signal innovation, employees were encouraged to experiment, and new technologies were layered into existing workflows with the assumption that adoption itself would create advantage over time.</p>



<p class="wp-block-paragraph">It has become clear: access was never going to be the differentiator for very long. The next phase of this shift will favor companies that are able to operate differently because of AI, not simply companies that use AI more often. </p>



<p class="wp-block-paragraph">That distinction matters because it moves the conversation away from tools and toward operating models, leadership discipline, decision-making structures, and organizational adaptability, which is where the real competitive separation is beginning to happen.</p>



<h3 class="wp-block-heading"><strong>Speed becomes structural</strong></h3>



<p class="wp-block-paragraph">One of the most significant changes AI creates within organizations is the compression of time across nearly every part of the business. It is easy to frame this conversation around productivity gains alone, but the more meaningful shift is happening around how quickly organizations are expected to respond, execute, prioritize, and make decisions while customers, competitors, and markets all begin moving faster simultaneously. What once felt like manageable friction inside a company can quickly become a competitive liability when the surrounding market is operating at a different speed.</p>



<p class="wp-block-paragraph">That reality is creating pressure on operating structures that were originally designed for a slower business environment. Approval chains, heavily layered decision-making models, fragmented ownership structures, and manual dependencies become harder to sustain when speed itself starts shaping competitiveness.</p>



<p class="wp-block-paragraph">AI is reducing the cost of execution at the same time that it is increasing the competitive cost of operating slowly, and many organizations are still underestimating how meaningful that shift will become over the next several years.</p>



<p class="wp-block-paragraph">What makes this different from prior technology shifts is that speed is starting to become structural. Organizations that can absorb information, make decisions, and execute quickly without creating internal chaos are going to operate very differently from companies still built around slower, heavily layered processes.</p>



<h3 class="wp-block-heading"><strong>AI exposes operational inefficiency</strong></h3>



<p class="wp-block-paragraph">What complicates this further is that AI often exposes operational weaknesses faster than it resolves them. There is still a tendency to think about AI primarily as a technology deployment exercise when, in practice, many companies discover that it quickly becomes a broader execution and organizational discipline challenge instead. As <a href="https://reputation.com/resources/articles/single-platform-reputation-management-how-consolidation-delivers-maximum-value" target="_blank" rel="noreferrer noopener">companies attempt to accelerate, disconnected systems</a>, inconsistent data, siloed teams, and outdated processes become more visible because they begin interfering directly with execution speed, customer responsiveness, and organizational adaptability. In many ways, AI amplifies the operational maturity a company already has.</p>



<p class="wp-block-paragraph">Organizations with strong systems, disciplined information management, clear accountability structures, and healthy decision-making processes can often accelerate effectively because the underlying foundation already supports speed and adaptability. Organizations operating with fragmented workflows and unclear ownership structures tend to experience the opposite effect, where acceleration exposes friction that previously existed quietly in the background but becomes much harder to ignore once the pace of the business changes.</p>



<p class="wp-block-paragraph">Many leadership teams still assume AI will compensate for inefficiency when, in reality, it often exposes those weaknesses faster. AI does not eliminate friction inside the business – it exposes where that friction already exists.</p>



<h3 class="wp-block-heading"><strong>Judgment becomes more valuable</strong></h3>



<p class="wp-block-paragraph">The conversation around talent is evolving in a similar way, and many organizations are still framing this transition too narrowly. Much of the public discussion continues to focus on workforce reduction, but the more important shift is actually about how organizations direct human attention, judgment, and expertise toward the areas where those capabilities create the most value. As routine work becomes easier to automate, qualities like judgment, adaptability, prioritization, and the ability to operate effectively in ambiguity become increasingly important rather than less.</p>



<p class="wp-block-paragraph">The organizations gaining the greatest advantage in this environment are not simply becoming faster or more efficient. They are becoming better at creating leverage from the expertise they already have by reducing the amount of time capable people spend navigating processes, chasing information, or managing friction that no longer needs to exist. That changes the role of leadership as well. Managers become increasingly important not as controllers of process, but as providers of context, prioritization, direction, and decision clarity in environments where speed and ambiguity increasingly coexist.</p>



<p class="wp-block-paragraph">The companies winning in this next phase of the market will not necessarily have fewer people. They will deploy talent differently, make decisions faster, and create organizations where capable teams are able to focus more energy on solving meaningful problems instead of managing complexity.</p>



<h3 class="wp-block-heading"><strong>Customer expectations are changing faster than companies are</strong></h3>



<p class="wp-block-paragraph">At the same time, customer expectations are evolving faster than many organizations are adapting internally. AI is reshaping how customers think about responsiveness, personalization, consistency, and speed, and experiences that once felt differentiated are quickly becoming baseline expectations. That creates a growing tension for companies still operating through slower internal systems while customers continue recalibrating what “good” looks like in real time based on the experiences they are having elsewhere.</p>



<p class="wp-block-paragraph">This shift also has important implications for trust and visibility. As <a href="https://reputation.com/resources/reports-guides/ai-is-rewriting-the-rules-of-reputation" target="_blank" rel="noreferrer noopener">AI increasingly influences how companies are discovered, compared, evaluated, and discussed</a>, reputation becomes much more deeply connected to how organizations are surfaced and interpreted at scale. In an AI-driven environment, reputation is no longer simply a brand asset that exists adjacent to the business. It increasingly becomes part of the infrastructure through which trust is established in the first place, particularly as AI increasingly shapes how customers discover and evaluate companies.</p>



<p class="wp-block-paragraph">Companies that continue operating through slower internal systems will increasingly struggle to meet the expectations AI is teaching customers to have.</p>



<h3 class="wp-block-heading"><strong>Leadership teams must redesign before they feel ready</strong></h3>



<p class="wp-block-paragraph">One of the biggest leadership challenges in this environment is that many executive teams are still waiting for a level of certainty that no longer really exists. Most organizations naturally want stable playbooks, lower-risk transitions, and more complete information before making significant structural changes, but markets moving at this pace rarely provide that level of clarity in advance.</p>



<p class="wp-block-paragraph">The companies moving first are not waiting for perfect certainty before redesigning how they operate. They understand that adaptability itself is becoming a competitive advantage. That does not mean acting recklessly or abandoning discipline; it means recognizing that operating models originally designed for stability and predictability can struggle in environments defined by acceleration, constant iteration, and rapidly changing customer expectations.</p>



<p class="wp-block-paragraph">The leadership challenge is no longer simply deciding whether AI matters. The more difficult question is how quickly organizations are willing and able to evolve around what AI makes possible.</p>



<h3 class="wp-block-heading"><strong>Most companies are measuring the wrong signals</strong></h3>



<p class="wp-block-paragraph">Many companies are still measuring the wrong signals when evaluating whether their AI strategy is working. Leadership teams focus on adoption metrics such as the number of tools deployed, pilot programs launched, employee usage statistics, or isolated productivity gains. But those measurements often signal experimentation rather than transformation.</p>



<p class="wp-block-paragraph">The more meaningful indicators are behavioral and organizational.</p>



<ul class="wp-block-list">
<li>Is the organization making decisions faster without creating confusion?</li>



<li>Has unnecessary complexity been removed from critical workflows?</li>



<li>Are customers experiencing less friction and greater responsiveness?</li>



<li>Is information moving more effectively across the business?</li>



<li>Are capable employees spending more time solving meaningful problems instead of managing process and coordination overhead?</li>



<li>Can the organization adapt quickly when conditions change without becoming unstable internally?</li>
</ul>



<p class="wp-block-paragraph">Over time, the separation between companies experimenting with AI and companies truly built to operate in an AI-first environment will become difficult to ignore. The organizations leading in the next phase of the market will not simply adopt new technologies faster. They will build companies designed to adapt, decide, and operate differently because of them, while competitors still operating through legacy structures will struggle to keep pace.</p>



<h3 class="wp-block-heading"><strong>About the author</strong></h3>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="946" height="1024" sizes="auto, (max-width: 946px) 100vw, 946px"&gt;</figure><p class="imageCredit">Reputation</p></div>



<p class="wp-block-paragraph">Joe Burton is an accomplished executive who has led public and private billion-dollar organizations in driving new product portfolios, go-to-market strategies, and innovative business models. Having spent the earlier parts of his career in information technology, Joe is passionate about fostering more transparency and trust in the digital world, while championing high performing cultures aligned to mission, vision and social responsibility.</p>



<p class="wp-block-paragraph">A recognized global transformational change executive, Joe has held the CEO role at Telesign and Poly, as well as serving as the Chief Technology Officer of Unified Communications at Cisco. Having started his career as an engineer, Joe brings both product and development expertise as well as a wealth of knowledge on big data, analytics, machine learning, SaaS, networking, unified communications, consumer electronics, and IoT.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The SOC’s AI maturity model]]></title>
<description><![CDATA[The path to next-generation AI Security Operations Centers (SOCs), where AI works hand-in-hand with human analysts, is paved with ambitious goals. This ideal SOC incorporates AI across every task to stop fast-moving threats. But a fully AI-powered SOC isn’t a single deployment or a switch you jus...]]></description>
<link>https://tsecurity.de/de/3701142/it-nachrichten/the-socs-ai-maturity-model/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3701142/it-nachrichten/the-socs-ai-maturity-model/</guid>
<pubDate>Mon, 03 Aug 2026 20:15:54 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The path to next-generation AI Security Operations Centers (SOCs), where AI works hand-in-hand with human analysts, is paved with ambitious goals. This ideal SOC incorporates AI across every task to stop fast-moving threats. But a fully AI-powered SOC isn’t a single deployment or a switch you just flip on. It is a staged rollout that’s built over time. There are levels of dependence on AI, starting with basic assistance, moving through automation, and ultimately reaching autonomous response. Each stage in the progression increases the model’s scope and narrows analyst involvement.</p>



<p class="wp-block-paragraph">This means that organizations embracing automation at any level must put their trust in the model. However, achieving trust depends on <a href="https://corelight.com/cp/provably-better-data?utm_source=cio-online&amp;utm_medium=brandpost-article&amp;utm_campaign=awareness-wave-2">data</a>. The data must be valid (and verifiable) so AI can propose logical conclusions, recommend appropriate actions for the organization’s needs and risk tolerances, and (at the autonomous stage) act on an analyst’s behalf without raising the risk of compromise and/or incorrect behavior.</p>



<p class="wp-block-paragraph">This article focuses on what enables movement between stages and how teams can build expertise alongside capabilities.</p>



<p class="wp-block-paragraph"><strong>Stage 1: Assistance</strong></p>



<p class="wp-block-paragraph">In its simplest SOC use case, AI helps analysts interpret data faster and more accurately, analyzing data, explaining alerts, summarizing logs, and translating detection logic. Many mature SOCs already operate here. AI sits close to analysts but doesn’t directly make decisions; it improves comprehension and can influence outcomes.</p>



<p class="wp-block-paragraph"><strong>Stage 2: Automation</strong></p>



<p class="wp-block-paragraph">This is where agentic AI enters the SOC. AI runs investigations, applies context, and proposes actions or interpretations while analysts retain oversight for accuracy and decision-making. AI starts shaping the investigative path rather than just explaining it, introducing efficiencies alongside uncertainty about when to trust (versus validating recommendations).</p>



<p class="wp-block-paragraph"><strong>Stage 3: Autonomy</strong></p>



<p class="wp-block-paragraph">At level three, AI operates with near independence; analysts oversee strategy but aren’t involved in individual tasks. The key shift from stage 2 is the removal of case-by-case approval for routine decisions. Instead, agents run on continuous policy constraints, feedback loops, and auditability structures.</p>



<p class="wp-block-paragraph">Security teams are accustomed to validating evidence before acting, but autonomous systems invert that relationship, forcing teams to trust evidence they may only review after an action executes. Many operators will be wary, even as they recognize the efficiencies AI offers when deployed correctly.</p>



<h4 class="wp-block-heading"><strong>How SOCs are starting to trust AI</strong></h4>



<p class="wp-block-paragraph">Moving from assistance to automation is largely a data problem. Moving from automation to autonomy is about trusting the model and the decisions it produces.</p>



<p class="wp-block-paragraph">What’s necessary to progress is structural confidence in how outputs are produced, validated, and traced, rooted in reliable network data that turns doubt into decisions. If data is incomplete or overly interpreted, the model preserves and amplifies those issues.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph">“If your data itself has bias,” says Vijit Nair, SVP of Product at <a href="https://corelight.com/?utm_source=cio-online&amp;utm_medium=brandpost-article&amp;utm_campaign=awareness-wave-2">Corelight</a>, “the tools skew towards that judgment. AI does not fix poor inputs. It scales them.”</p>
</blockquote>



<p class="wp-block-paragraph">Stan Kiefer, Senior Manager for Data Science at Corelight, adds that, “AI alone is not trustworthy at this point, and without data to reference back, it may never be.”</p>



<p class="wp-block-paragraph">Analysts should be able to inspect the evidence behind a model’s conclusion, which requires data and algorithms to be open to human inspection.</p>



<h4 class="wp-block-heading"><strong>Network security and AI</strong></h4>



<p class="wp-block-paragraph">To make that trust practical, teams need an evidence layer that is comprehensive, difficult to fake, and easy to audit. For many SOCs, that evidence layer is network data.</p>



<p class="wp-block-paragraph">Network data tells the most complete story of an environment, but it’s voluminous and easy to misinterpret without context. AI removes this complexity, letting analysts query network data without mastering every analysis technique, making it a knowledge multiplier rather than just a force multiplier. The difference: A knowledge multiplier helps humans operate above their current expertise; a tier-one analyst can ask a complex question and get an evidence-based answer, gradually building skills to operate at a higher level with more confidence.</p>



<p class="wp-block-paragraph">This has real implications for analyst development and team stability. Analysts can experience greater accomplishment, driving productivity and performance and reducing the chance of burnout.</p>



<h4 class="wp-block-heading"><strong>Analyst development and AI</strong></h4>



<p class="wp-block-paragraph">The SOC has long relied on repetitive work, especially for tier-one analysts. Their work is necessary but often neither instructive nor interesting, and it contributes to burnout and turnover. AI, especially agentic AI, can help mitigate that.</p>



<p class="wp-block-paragraph">AI doesn’t eliminate judgment; it removes friction and tedium. As Nair puts it, this is the difference between “craft” (manually working through data) and “art” (deciding what matters and what to do next).</p>



<p class="wp-block-paragraph">“AI ‘eats the craft’ so people can focus on the art,” he says. “It’s to have them spend less time on repetitive work and more on work that requires knowledge and judgment.”</p>



<p class="wp-block-paragraph">Kiefer estimates AI could cut time to competency by half or more. By replicating an analyst’s workflow, surfacing recurring steps, and explaining complex detections in plain language, AI accelerates the learning curve.</p>



<h4 class="wp-block-heading"><strong>The bottom line</strong></h4>



<p class="wp-block-paragraph">The real constraint on SOC AI maturity is trust, and trust depends on reliable data that makes outputs traceable and evidence inspectable. Moving through each stage reduces repetitive correlation work and shifts analyst effort toward the interpretation and validation that require human judgment.</p>



<p class="wp-block-paragraph">Key points for your team’s AI journey:</p>



<ul class="wp-block-list">
<li>Maturity is a staged process: assistance, automation, and autonomy reflect increasing delegation and trust requirements</li>



<li>Trust is evidence-based: analysts need traceable outputs, not opaque recommendations</li>



<li>Data quality is paramount: incomplete or low-context telemetry inhibits AI effectiveness</li>



<li>Verification enables progression: auditability determines how far AI can safely move into decision-making</li>
</ul>



<h4 class="wp-block-heading"><a></a><strong>Corelight: Provably better data</strong></h4>



<p class="wp-block-paragraph">AI is only as effective as the data behind it. Corelight network detection and response (NDR) delivers data that’s open, transparent, and explainable — in turn helping detect evasive threats, reduce triage time, and enable agentic AI throughout the SOC. Corelight’s structured network evidence preserves protocol-level context to produce a more complete dataset for investigation and AI. When analysts and AI can reason from evidence instead of isolated alerts or metadata, they can validate findings, reconstruct activity, and reach more reliable conclusions. <a href="https://corelight.com/cp/elitedefense?utm_source=cio-online&amp;utm_medium=brandpost-article&amp;utm_campaign=awareness-wave-2">Learn more about Corelight</a>.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Companies winning with AI operate differently. Here’s how.]]></title>
<description><![CDATA[The first phase of the AI race was largely about access. Companies rushed to adopt tools, launch pilots, and demonstrate that they were moving quickly enough to keep pace with the market. In many organizations, simply showing momentum became the strategy.



Leadership teams wanted to signal inno...]]></description>
<link>https://tsecurity.de/de/3701145/it-nachrichten/companies-winning-with-ai-operate-differently-heres-how/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3701145/it-nachrichten/companies-winning-with-ai-operate-differently-heres-how/</guid>
<pubDate>Mon, 03 Aug 2026 20:15:54 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The first phase of the AI race was largely about access. Companies rushed to adopt tools, launch pilots, and demonstrate that they were moving quickly enough to keep pace with the market. In many organizations, simply showing momentum became the strategy.</p>



<p class="wp-block-paragraph">Leadership teams wanted to signal innovation, employees were encouraged to experiment, and new technologies were layered into existing workflows with the assumption that adoption itself would create advantage over time.</p>



<p class="wp-block-paragraph">It has become clear: access was never going to be the differentiator for very long. The next phase of this shift will favor companies that are able to operate differently because of AI, not simply companies that use AI more often. </p>



<p class="wp-block-paragraph">That distinction matters because it moves the conversation away from tools and toward operating models, leadership discipline, decision-making structures, and organizational adaptability, which is where the real competitive separation is beginning to happen.</p>



<h3 class="wp-block-heading"><strong>Speed becomes structural</strong></h3>



<p class="wp-block-paragraph">One of the most significant changes AI creates within organizations is the compression of time across nearly every part of the business. It is easy to frame this conversation around productivity gains alone, but the more meaningful shift is happening around how quickly organizations are expected to respond, execute, prioritize, and make decisions while customers, competitors, and markets all begin moving faster simultaneously. What once felt like manageable friction inside a company can quickly become a competitive liability when the surrounding market is operating at a different speed.</p>



<p class="wp-block-paragraph">That reality is creating pressure on operating structures that were originally designed for a slower business environment. Approval chains, heavily layered decision-making models, fragmented ownership structures, and manual dependencies become harder to sustain when speed itself starts shaping competitiveness.</p>



<p class="wp-block-paragraph">AI is reducing the cost of execution at the same time that it is increasing the competitive cost of operating slowly, and many organizations are still underestimating how meaningful that shift will become over the next several years.</p>



<p class="wp-block-paragraph">What makes this different from prior technology shifts is that speed is starting to become structural. Organizations that can absorb information, make decisions, and execute quickly without creating internal chaos are going to operate very differently from companies still built around slower, heavily layered processes.</p>



<h3 class="wp-block-heading"><strong>AI exposes operational inefficiency</strong></h3>



<p class="wp-block-paragraph">What complicates this further is that AI often exposes operational weaknesses faster than it resolves them. There is still a tendency to think about AI primarily as a technology deployment exercise when, in practice, many companies discover that it quickly becomes a broader execution and organizational discipline challenge instead. As <a href="https://reputation.com/resources/articles/single-platform-reputation-management-how-consolidation-delivers-maximum-value" target="_blank" rel="noreferrer noopener">companies attempt to accelerate, disconnected systems</a>, inconsistent data, siloed teams, and outdated processes become more visible because they begin interfering directly with execution speed, customer responsiveness, and organizational adaptability. In many ways, AI amplifies the operational maturity a company already has.</p>



<p class="wp-block-paragraph">Organizations with strong systems, disciplined information management, clear accountability structures, and healthy decision-making processes can often accelerate effectively because the underlying foundation already supports speed and adaptability. Organizations operating with fragmented workflows and unclear ownership structures tend to experience the opposite effect, where acceleration exposes friction that previously existed quietly in the background but becomes much harder to ignore once the pace of the business changes.</p>



<p class="wp-block-paragraph">Many leadership teams still assume AI will compensate for inefficiency when, in reality, it often exposes those weaknesses faster. AI does not eliminate friction inside the business – it exposes where that friction already exists.</p>



<h3 class="wp-block-heading"><strong>Judgment becomes more valuable</strong></h3>



<p class="wp-block-paragraph">The conversation around talent is evolving in a similar way, and many organizations are still framing this transition too narrowly. Much of the public discussion continues to focus on workforce reduction, but the more important shift is actually about how organizations direct human attention, judgment, and expertise toward the areas where those capabilities create the most value. As routine work becomes easier to automate, qualities like judgment, adaptability, prioritization, and the ability to operate effectively in ambiguity become increasingly important rather than less.</p>



<p class="wp-block-paragraph">The organizations gaining the greatest advantage in this environment are not simply becoming faster or more efficient. They are becoming better at creating leverage from the expertise they already have by reducing the amount of time capable people spend navigating processes, chasing information, or managing friction that no longer needs to exist. That changes the role of leadership as well. Managers become increasingly important not as controllers of process, but as providers of context, prioritization, direction, and decision clarity in environments where speed and ambiguity increasingly coexist.</p>



<p class="wp-block-paragraph">The companies winning in this next phase of the market will not necessarily have fewer people. They will deploy talent differently, make decisions faster, and create organizations where capable teams are able to focus more energy on solving meaningful problems instead of managing complexity.</p>



<h3 class="wp-block-heading"><strong>Customer expectations are changing faster than companies are</strong></h3>



<p class="wp-block-paragraph">At the same time, customer expectations are evolving faster than many organizations are adapting internally. AI is reshaping how customers think about responsiveness, personalization, consistency, and speed, and experiences that once felt differentiated are quickly becoming baseline expectations. That creates a growing tension for companies still operating through slower internal systems while customers continue recalibrating what “good” looks like in real time based on the experiences they are having elsewhere.</p>



<p class="wp-block-paragraph">This shift also has important implications for trust and visibility. As <a href="https://reputation.com/resources/reports-guides/ai-is-rewriting-the-rules-of-reputation" target="_blank" rel="noreferrer noopener">AI increasingly influences how companies are discovered, compared, evaluated, and discussed</a>, reputation becomes much more deeply connected to how organizations are surfaced and interpreted at scale. In an AI-driven environment, reputation is no longer simply a brand asset that exists adjacent to the business. It increasingly becomes part of the infrastructure through which trust is established in the first place, particularly as AI increasingly shapes how customers discover and evaluate companies.</p>



<p class="wp-block-paragraph">Companies that continue operating through slower internal systems will increasingly struggle to meet the expectations AI is teaching customers to have.</p>



<h3 class="wp-block-heading"><strong>Leadership teams must redesign before they feel ready</strong></h3>



<p class="wp-block-paragraph">One of the biggest leadership challenges in this environment is that many executive teams are still waiting for a level of certainty that no longer really exists. Most organizations naturally want stable playbooks, lower-risk transitions, and more complete information before making significant structural changes, but markets moving at this pace rarely provide that level of clarity in advance.</p>



<p class="wp-block-paragraph">The companies moving first are not waiting for perfect certainty before redesigning how they operate. They understand that adaptability itself is becoming a competitive advantage. That does not mean acting recklessly or abandoning discipline; it means recognizing that operating models originally designed for stability and predictability can struggle in environments defined by acceleration, constant iteration, and rapidly changing customer expectations.</p>



<p class="wp-block-paragraph">The leadership challenge is no longer simply deciding whether AI matters. The more difficult question is how quickly organizations are willing and able to evolve around what AI makes possible.</p>



<h3 class="wp-block-heading"><strong>Most companies are measuring the wrong signals</strong></h3>



<p class="wp-block-paragraph">Many companies are still measuring the wrong signals when evaluating whether their AI strategy is working. Leadership teams focus on adoption metrics such as the number of tools deployed, pilot programs launched, employee usage statistics, or isolated productivity gains. But those measurements often signal experimentation rather than transformation.</p>



<p class="wp-block-paragraph">The more meaningful indicators are behavioral and organizational.</p>



<ul class="wp-block-list">
<li>Is the organization making decisions faster without creating confusion?</li>



<li>Has unnecessary complexity been removed from critical workflows?</li>



<li>Are customers experiencing less friction and greater responsiveness?</li>



<li>Is information moving more effectively across the business?</li>



<li>Are capable employees spending more time solving meaningful problems instead of managing process and coordination overhead?</li>



<li>Can the organization adapt quickly when conditions change without becoming unstable internally?</li>
</ul>



<p class="wp-block-paragraph">Over time, the separation between companies experimenting with AI and companies truly built to operate in an AI-first environment will become difficult to ignore. The organizations leading in the next phase of the market will not simply adopt new technologies faster. They will build companies designed to adapt, decide, and operate differently because of them, while competitors still operating through legacy structures will struggle to keep pace.</p>



<h3 class="wp-block-heading"><strong>About the author</strong></h3>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="946" height="1024" sizes="auto, (max-width: 946px) 100vw, 946px"&gt;</figure><p class="imageCredit">Reputation</p></div>



<p class="wp-block-paragraph">Joe Burton is an accomplished executive who has led public and private billion-dollar organizations in driving new product portfolios, go-to-market strategies, and innovative business models. Having spent the earlier parts of his career in information technology, Joe is passionate about fostering more transparency and trust in the digital world, while championing high performing cultures aligned to mission, vision and social responsibility.</p>



<p class="wp-block-paragraph">A recognized global transformational change executive, Joe has held the CEO role at Telesign and Poly, as well as serving as the Chief Technology Officer of Unified Communications at Cisco. Having started his career as an engineer, Joe brings both product and development expertise as well as a wealth of knowledge on big data, analytics, machine learning, SaaS, networking, unified communications, consumer electronics, and IoT.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Alibaba takes aim at OpenAI and Anthropic with Qwen3.8-Max launch]]></title>
<description><![CDATA[Alibaba on Monday introduced Qwen3.8-Max, its largest artificial intelligence model to date, expanding its enterprise AI portfolio with an open-weight model designed for software engineering, multimodal reasoning, and other knowledge-intensive business workloads.



In a blog post announcing the ...]]></description>
<link>https://tsecurity.de/de/3701149/it-nachrichten/alibaba-takes-aim-at-openai-and-anthropic-with-qwen38-max-launch/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3701149/it-nachrichten/alibaba-takes-aim-at-openai-and-anthropic-with-qwen38-max-launch/</guid>
<pubDate>Mon, 03 Aug 2026 20:15:54 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Alibaba on Monday introduced Qwen3.8-Max, its largest artificial intelligence model to date, expanding its enterprise AI portfolio with an open-weight model designed for software engineering, multimodal reasoning, and other knowledge-intensive business workloads.</p>



<p class="wp-block-paragraph">In a <a href="https://qwen.ai/blog?id=qwen3.8" target="_blank" rel="noreferrer noopener">blog post</a> announcing the launch, Alibaba described Qwen3.8-Max as a 2.4-trillion-parameter mixture-of-experts (MoE) model that activates only about 95 billion parameters during inference.</p>



<p class="wp-block-paragraph">The company said the architecture is intended to improve inference efficiency while supporting coding, reasoning and multimodal tasks, with open-weight versions scheduled for release next week through Alibaba Cloud’s Model Studio.</p>



<p class="wp-block-paragraph">“We believe it’s one of the most powerful model available today, compatible to leading frontier AI models, second only to Fable 5,” Alibaba said in an X <a href="https://x.com/Alibaba_Qwen/status/2078759124914098291" target="_blank" rel="noreferrer noopener">post</a>.</p>



<h2 class="wp-block-heading">Benchmarks target Anthropic and OpenAI’s coding models</h2>



<p class="wp-block-paragraph">Alibaba published internal test results comparing Qwen3.8-Max against Claude Opus 4.8, Claude Fable 5, and OpenAI’s GPT-5.6 Sol on coding benchmarks, including SWE-bench Pro and a proprietary evaluation the company calls NL2Repo-Bench.</p>



<p class="wp-block-paragraph">The company said it evaluated competing models using each vendor’s own coding harness, Claude Code for Anthropic’s models and Codex for GPT-5.6 Sol, and reported the highest published score across available configurations for each rival.</p>



<p class="wp-block-paragraph">Charlie Dai, vice president and principal analyst at Forrester, said the launch signals Alibaba is closing ground on proprietary leaders, though that isn’t the full picture.</p>



<p class="wp-block-paragraph">“Alibaba is narrowing the gap, but the larger story is the rapid maturation of open-weight models,” Dai said. “Enterprises increasingly have credible alternatives to proprietary frontier models, particularly for software engineering, domain customization, sovereignty, and cost-sensitive deployments, where openness often matters as much as absolute model performance.”</p>



<h2 class="wp-block-heading">Company touts a 16-day autonomous coding run</h2>



<p class="wp-block-paragraph">Alibaba said it tested the model on three unsupervised, multi-day coding projects requiring it to take a task from an empty project folder to completion without human assistance, including one project the company said took 16 days to complete on its own.</p>



<p class="wp-block-paragraph">Alibaba also highlighted enterprise applications across legal compliance, financial analysis, engineering design, quantitative research and multimodal content creation, saying the model is intended to complete entire business workflows rather than individual AI-assisted tasks.</p>



<p class="wp-block-paragraph">Amit Jena, development manager for AI at Kanerika, said that the claim deserves more scrutiny than it has received.</p>



<p class="wp-block-paragraph">“The claim worth examining is not the parameter count. Alibaba says the model completed a software engineering project in 16 days. That sentence has been reprinted everywhere and interrogated nowhere,” Jena said. “Sixteen days of what? How many times did a human step in? Did the output survive code review?”</p>



<p class="wp-block-paragraph">Jena said the open-weight commitment itself should also be read carefully. “Publishing weights is a separate act from opening an API endpoint,” he said. “Until there is a repository, a licence and a model card, open-weight describes an intention.”</p>



<h2 class="wp-block-heading">Analysts say inference efficiency isn’t the real constraint</h2>



<p class="wp-block-paragraph">Alibaba’s mixture-of-experts architecture activates roughly 95 billion of the model’s 2.4 trillion parameters per request, a design the company says lowers inference costs.</p>



<p class="wp-block-paragraph">Dai said that tradeoff now matters more to enterprise buyers than raw model size. “Inference efficiency now matters more than raw model size for most enterprises,” he said. “Activating only a fraction of total parameters can significantly reduce serving costs and infrastructure requirements, making frontier-class performance more accessible for production deployments where scalability, latency, and economics are often bigger concerns than benchmark leadership.”</p>



<p class="wp-block-paragraph">Jena said efficiency gains matter less than an organization’s ability to actually test the model. “Efficiency stopped being the interesting question. The constraint that actually binds is evaluation throughput,” he said.</p>



<p class="wp-block-paragraph">Nitish Tyagi, senior principal analyst at Gartner, said the significance of the release lies less in the parameter count than in what it signals about competitive pressure on AI deployment costs.</p>



<p class="wp-block-paragraph">“Gartner has previously predicted that, without stronger cost controls, AI coding expenses could exceed the average developer’s salary,” Tyagi said. “The combination of open weights, a mixture-of-experts architecture, and a one-million-token context window represents a meaningful step toward making AI-augmented software development more economically viable.”</p>



<p class="wp-block-paragraph">Tyagi cautioned that enterprises need to look beyond inference costs when weighing the model for production use.</p>



<p class="wp-block-paragraph">“Many organizations outside China may be hesitant to rely on models hosted within China, leading them to deploy through hyperscalers or on-premises infrastructure, both of which introduce additional costs,” he said.</p>



<p class="wp-block-paragraph">Open-weight models also typically lack the indemnification protections that come with commercial AI vendors, he said, meaning enterprises need their own security, governance, and code-scanning controls to catch copyright and intellectual property risks before production deployment.</p>



<h2 class="wp-block-heading">What CIOs should look out for</h2>



<p class="wp-block-paragraph">Jena said the flagship model announced Monday may not be the one enterprises end up running.</p>



<p class="wp-block-paragraph">“Qwen3.8-27B, announced alongside the flagship and almost entirely ignored in coverage,” is the more deployable option for most organizations, he said, since it can run on infrastructure they own and fine-tune on their own data.</p>



<p class="wp-block-paragraph">Dai said enterprise leaders evaluating the release should prioritize transparency and total cost of ownership over headline figures. “The key question is whether Qwen3.8 delivers measurable business outcomes, enterprise-grade reliability, lower total cost of ownership, and options for digital sovereignty compared with competing models,” he said.</p>



<p class="wp-block-paragraph"><em>The article originally appeared on <a href="https://www.infoworld.com/article/4204415/alibaba-takes-aim-at-openai-and-anthropic-with-qwen3-8-max-launch.html">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sequoia’s Shaun Maguire leads $1B round for nuclear startup Valar Atomics]]></title>
<description><![CDATA[Valar Atomics raised $1 billion at a $6 billion valuation after signing a development deal with Nvidia in June.]]></description>
<link>https://tsecurity.de/de/3701048/it-nachrichten/sequoias-shaun-maguire-leads-1b-round-for-nuclear-startup-valar-atomics/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3701048/it-nachrichten/sequoias-shaun-maguire-leads-1b-round-for-nuclear-startup-valar-atomics/</guid>
<pubDate>Mon, 03 Aug 2026 20:15:44 +0200</pubDate>
<content:encoded><![CDATA[Valar Atomics raised $1 billion at a $6 billion valuation after signing a development deal with Nvidia in June.]]></content:encoded>
</item>
<item>
<title><![CDATA[PlasmaSolve bought by Apple to help make thin & durable device enclosures]]></title>
<description><![CDATA[Czech company PlasmaSolve has been acquired by Apple, likely for its software that helps optimize manufacturing of scratch-resistant metallic coatings.PlasmaSolve's main product was a plasma technology simulator called MatSight, which has been removed from sale since Apple acquired the company - ...]]></description>
<link>https://tsecurity.de/de/3700804/ios-mac-os/plasmasolve-bought-by-apple-to-help-make-thin-durable-device-enclosures/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3700804/ios-mac-os/plasmasolve-bought-by-apple-to-help-make-thin-durable-device-enclosures/</guid>
<pubDate>Mon, 03 Aug 2026 15:43:29 +0200</pubDate>
<content:encoded><![CDATA[Czech company PlasmaSolve has been acquired by Apple, likely for its software that helps optimize manufacturing of scratch-resistant metallic coatings.<br><br><div><img src="https://media.appleinsider.com/gallery/68436-144213-000-lead-MatSight-xl.jpg" alt="Logo with the word matsight in lowercase purple letters overlapping a rounded, slanted purple capsule shape, with small text reading by PlasmaSolve in the lower right corner"><br><span>PlasmaSolve's main product was a plasma technology simulator called MatSight, which has been removed from sale since Apple acquired the company - image credit: PlasmaSolve</span></div><br>Apple already uses PVD (physical vapor deposition) in its existing <a href="https://appleinsider.com/articles/24/06/26/inside-apple-hardware-prototype-and-development-stages">coating processes</a> for devices, but it is aiming to refine and develop this through acquiring PlasmaSolve. PlasmaSolve was founded in 2016 by Adam Obrusnik, and  makes a simulation software package called MatSight.<br><br>MatSight models PVD and PECVD (plasma-enhanced chemical vapor deposition) to improve process designs.<br><br><br> <a href="https://appleinsider.com/articles/26/08/03/plasmasolve-bought-by-apple-to-help-make-thin-durable-device-enclosures?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/245138?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kuna: Decompiler Development in the Age of Coding Agents]]></title>
<description><![CDATA[submitted by    /u/mttd   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3700688/reverse-engineering/kuna-decompiler-development-in-the-age-of-coding-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3700688/reverse-engineering/kuna-decompiler-development-in-the-age-of-coding-agents/</guid>
<pubDate>Mon, 03 Aug 2026 12:47:40 +0200</pubDate>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/mttd"> /u/mttd </a> <br> <span><a href="https://noelo.org/blog/kuna-release/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ReverseEngineering/comments/1vak710/kuna_decompiler_development_in_the_age_of_coding/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Exploiting the order of operations (Pwnable)]]></title>
<description><![CDATA[Have you ever wondering if the order of operations when voilated can lead to a vulnerability? Maybe the thought never crossed your mind? Either way this week we exploit a binary that did not account for the order of operations - more specifically the "mistake" pwnable binary exploitation challeng...]]></description>
<link>https://tsecurity.de/de/3700665/malware-trojaner-viren/exploiting-the-order-of-operations-pwnable/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3700665/malware-trojaner-viren/exploiting-the-order-of-operations-pwnable/</guid>
<pubDate>Mon, 03 Aug 2026 12:47:06 +0200</pubDate>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Have you ever wondering if the order of operations when voilated can lead to a vulnerability? Maybe the thought never crossed your mind? Either way this week we exploit a binary that did not account for the order of operations - more specifically the "mistake" pwnable binary exploitation challenge! </p> <p>This is a great tutorial for beginners and even advanced developers who may not have encountered a bug like this. Either way don't be intimidated just because this is an exploit development tutorial. </p> <p>Check out the latest tutorial using the link below:</p> <p><a href="https://youtu.be/9n1vCuqAk-k?si=IvzW95y4XxnivOxm">https://youtu.be/9n1vCuqAk-k?si=IvzW95y4XxnivOxm</a> </p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/AdvisorPowerful9769"> /u/AdvisorPowerful9769 </a> <br> <span><a href="https://www.reddit.com/r/ExploitDev/comments/1va0j54/exploiting_the_order_of_operations_pwnable/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1va0j54/exploiting_the_order_of_operations_pwnable/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[I am beginner and i have interest in exploit development path :)]]></title>
<description><![CDATA[I am total confused to where to start learning the exploit development stuff, because i have read the "Hacking : The art of exploitation" but it seems old and i want to learn stuff that really modern not old stuff, but i know it is essential to learn basic first, but i don't want to learn it from...]]></description>
<link>https://tsecurity.de/de/3700664/malware-trojaner-viren/i-am-beginner-and-i-have-interest-in-exploit-development-path/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3700664/malware-trojaner-viren/i-am-beginner-and-i-have-interest-in-exploit-development-path/</guid>
<pubDate>Mon, 03 Aug 2026 12:47:02 +0200</pubDate>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I am total confused to where to start learning the exploit development stuff, because i have read the "Hacking : The art of exploitation" but it seems old and i want to learn stuff that really modern not old stuff, but i know it is essential to learn basic first, but i don't want to learn it from book it is nightmare and such a long way.</p> <p>Anyone please share resource that is actually focus on real world learning way, and total real world stuff, and please make share in structured way it is possible ::</p> <p>I appreciate if you help me, in advance, thank you :)</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Sad-Shopping-2661"> /u/Sad-Shopping-2661 </a> <br> <span><a href="https://www.reddit.com/r/ExploitDev/comments/1vbhtrz/i_am_beginner_and_i_have_interest_in_exploit/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1vbhtrz/i_am_beginner_and_i_have_interest_in_exploit/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Three scary AI security mistakes haunting enterprises]]></title>
<description><![CDATA[There is a lot of talk about the coming enterprise AI reality, in which AI finally arrives in production systems. You might not know it, but this reality—or nightmare, depending on how you handle it—is already happening.



It all starts with a “pilot,” a “prototype,” or a “side project.” Maybe s...]]></description>
<link>https://tsecurity.de/de/3700609/ai-nachrichten/three-scary-ai-security-mistakes-haunting-enterprises/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3700609/ai-nachrichten/three-scary-ai-security-mistakes-haunting-enterprises/</guid>
<pubDate>Mon, 03 Aug 2026 12:13:04 +0200</pubDate>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">There is a lot of talk about the coming enterprise AI reality, in which AI finally arrives in production systems. You might not know it, but this reality—or nightmare, depending on how you handle it—is already happening.</p>



<p class="wp-block-paragraph">It all starts with a “pilot,” a “prototype,” or a “side project.” Maybe someone builds an internal dashboard with an agent. The dashboard quickly becomes indispensable, and all of a sudden the experiment becomes production. Along the way, no one thought to ask the boring, inconvenient questions: What exactly was pulled from npm, PyPI, or Docker Hub? How is (or was) authentication configured? Is anyone watching for supply chain attacks against the tools and libraries the agents chose?</p>



<p class="wp-block-paragraph">And it’s not just a one-off project here or a couple of applications there. AI is enabling organizations to generate more code and ship more products and projects, more quickly, than ever before. By the time security teams get a look, the business is hooked and there’s no turning back. An actual nightmare has begun.</p>



<p class="wp-block-paragraph">There are three major problems that make the nightmare real. </p>



<h2 class="wp-block-heading">Components you never explicitly chose</h2>



<p class="wp-block-paragraph">When you ask an AI agent to build an app, it doesn’t just spit out a single script. It quietly assembles an entire ecosystem around whatever problem you’ve described to it. It pulls in a web framework, grabs a bunch of libraries, stands up databases, and then it potentially builds everything on dependencies in container images.</p>



<p class="wp-block-paragraph">From a productivity perspective, this is awesome. However, from a security standpoint, it’s worrisome, to say the least. When I’ve built apps like this myself, I couldn’t begin to tell you all of the components that were being used unless I went back and asked the agent to explain itself.</p>



<p class="wp-block-paragraph">We live in a world where anyone can publish to npm or PyPI, and we’ve seen attackers slip malicious packages into those ecosystems or compromise ones that are widely used. Some of the recent incidents have involved security and devops tools themselves pulling a compromised dependency, running it as part of CI/CD with elevated privileges, and quietly exfiltrating secrets or tampering with builds. I personally experienced this type of compromise a couple of months ago, and had to update all of my credentials in GitHub.</p>



<p class="wp-block-paragraph">Pulling unvetted code is bad; now layer AI agents on top of that. They default to whatever is easiest to discover and integrate. If a package solves a problem in front of the agent, the agent will add it. This is the old “download a random library from the Internet” problem, but now it’s on autopilot, at scale, and moving at a pace we’ve never seen before.</p>



<p class="wp-block-paragraph">To solve this problem, we must provide the agents with an innate sense of our risk tolerance, an approved components list, our desires around logging, etc. We can do this with spec files and what the industry calls constitutions. Collectively, this is called harness engineering, which we will talk more about later.</p>



<h2 class="wp-block-heading">Skills shifting from code to architecture</h2>



<p class="wp-block-paragraph">There has been a lot of hand-wringing about <a href="https://www.infoworld.com/article/4065771/why-we-need-junior-developers.html" data-type="link" data-id="https://www.infoworld.com/article/4065771/why-we-need-junior-developers.html">whether junior developers</a> will ever <a href="https://www.infoworld.com/article/4152683/what-next-for-junior-developers.html" data-type="link" data-id="https://www.infoworld.com/article/4152683/what-next-for-junior-developers.html">really learn to code</a> if AI is doing all of their coding for them.</p>



<p class="wp-block-paragraph">That’s not what worries me.</p>



<p class="wp-block-paragraph">I think it’s fine to let an agent spit out code. It’s a job they are really good at. What they are not really good at is identifying and avoiding problems in code.</p>



<p class="wp-block-paragraph">I haven’t written code in quite some time. I can, but it doesn’t make sense for me to do so. What is worth my while is noticing when an agent suggests something dumb or even dangerous (or both).</p>



<p class="wp-block-paragraph">For example, while working on a recent personal project, an agent proposed exposing a memory server on the public Internet with no authentication. The agent wired things up so smoothly that, at first glance, everything looked fine and just worked. But then I paused and asked, “Wait, how is this actually authenticating? Where’s the password, secret token, or OAuth in this flow?” Turns out it wasn’t authenticating and there was no password. If I hadn’t taken that beat—and then argued with the agent for a while—the app would have gone live with no protection.</p>



<p class="wp-block-paragraph">So, the skills issue isn’t about whether we will lose the ability to code but rather whether we have the ability to ask questions and be discerning, and whether we have the understanding to know when something doesn’t look or even feel right. Do organizations have people who know what a dangerous software pattern looks like when the agent suggests it? You need people who can recognize when an authentication flow is too permissive, when a data store should never be exposed beyond a certain boundary, and when an architecture has become such a steaming pile of technical debt that the right answer is to throw away a whole layer and rebuild it.</p>



<p class="wp-block-paragraph">You need people who know that “what works” isn’t the same as “what’s safe” or “what’s right” and who can argue back with the agent when the former doesn’t line up with the latter.</p>



<p class="wp-block-paragraph">It’s not about syntax. It’s about architecture, supply chain awareness, and the willingness to say, “We’re tearing this down and doing it right,” even when the prototype looks good on the surface. Teach your AI-assisted coders basic security principles, basic architectural patterns. The AI will teach them the more advanced stuff, as long as they keep asking questions.</p>



<h2 class="wp-block-heading">Agents with no harness</h2>



<p class="wp-block-paragraph">The third problem is that we’ve unleashed some very capable agents into our development workflows without treating them like first-class actors that need governance.</p>



<p class="wp-block-paragraph">Many organizations are wiring AI assistants into a repo or IDE and letting them scaffold projects and pipelines. Maybe they bolt on a security scanner and declare “AI enablement.” That’s not a governance model, that’s optimism (and not even cautious optimism).</p>



<p class="wp-block-paragraph">Indeed, a code-generating agent with broad access to your repos, your CI/CD pipeline, and your artifact registries is effectively a hyper-productive and not-very-well-trained junior developer with access to the Internet and no ingrained sense of organizational policies. It can introduce new tools, new dependencies, and new patterns faster than your review processes can handle.</p>



<p class="wp-block-paragraph">In my personal projects, I’ve started to think of this as what AI coders call a harness-engineering problem. For every agent that’s responsible for building or wiring code, I try to put other agents in the loop that are responsible for tearing it down, at least conceptually. For example, one agent focuses on security and looks for obvious vulnerabilities and bad practices. Another looks at architecture and points out when the app design is veering into unmaintainable territory. A third looks at performance and reliability issues, which are themselves a kind of security concern when you think about things like denial of service and resource exhaustion. Pair this with constitutions that give the agents first principles on architecture, security, and design, and this is no longer vibe coding, it’s harness engineering at scale for all of your projects.</p>



<p class="wp-block-paragraph">What I am doing isn’t perfect; there is no perfect in this space, because these are non-deterministic, statistical tools. But, many organizations aren’t even doing this. In effect, their agents are freelancing. They’re vibe coding. They’re not constrained to trusted registries or hardened base images. They’re not required to log their decisions in a way that security can audit. No one owns the harness, and that means a lot of implementation decisions have fully shifted from humans to systems that no one is really watching.</p>



<h2 class="wp-block-heading">New problems require new thinking</h2>



<p class="wp-block-paragraph">The enterprise AI nightmare is not a killer robot; it’s the erosion of our ability to see and control what’s running in our own environments at the exact moment our velocity is exploding. The danger is in ceding your agency. It’s in shipping applications that internal and external customers love—and don’t want to give up—but inherently aren’t safe. Right now, someone in your organization is using AI to build a capable app, pulling in who knows what from who knows where and adding it to your infrastructure.</p>



<p class="wp-block-paragraph">The good news is that these problems are identifiable. They are also solvable, although it will take a new form of thinking than what solved problems in the past. You must think statistically, and declare constitutions with first principles. You can standardize trusted stacks and registries. You can retrain people around architectural security rather than just “secure coding.” You can start treating agent harnesses as systems that deserve design reviews and edits.</p>



<p class="wp-block-paragraph">But, none of that can happen until the enterprise is willing to admit that the nightmare is already here.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Get started with the Typst programming language for documents]]></title>
<description><![CDATA[When we think of documents, or documentation, they tend to fall into two circles. First are business documents, typically composed with an office application like Microsoft Word or Google Docs. Second is project documentation, often created semi-automatically from a project using an app like Sphi...]]></description>
<link>https://tsecurity.de/de/3700611/ai-nachrichten/get-started-with-the-typst-programming-language-for-documents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3700611/ai-nachrichten/get-started-with-the-typst-programming-language-for-documents/</guid>
<pubDate>Mon, 03 Aug 2026 12:13:04 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">When we think of documents, or documentation, they tend to fall into two circles. First are business documents, typically composed with an office application like Microsoft Word or Google Docs. Second is project documentation, often created semi-automatically from a project using an app like Sphinx or Pandoc.</p>



<p class="wp-block-paragraph">But there’s a third circle, one that can overlap the other two. These are documents produced by a typesetting language—a combination of markup and programming language used to produce books, textbooks, academic journals, scientific papers, technical manuals, and other documents where the formatting and layout is crucial.</p>



<p class="wp-block-paragraph">A typesetting language allows you to create a handy, human-readable document that serves both as a single source of truth and as a foundation for outputting to print, web, e-book, and other formats. Over the last few years, an open-source project has shaped up to be a powerful choice for meeting all of those needs: <a href="https://typst.app/">Typst</a> (pronounced “typist”).</p>



<h2 class="wp-block-heading">TeX, LaTex, and now Typst</h2>



<p class="wp-block-paragraph">For decades, the preeminent typesetting language was <a href="https://en.wikipedia.org/wiki/TeX">TeX</a>, better known in its more recent incarnation <a href="https://en.wikipedia.org/wiki/LaTeX">LaTeX</a>. TeX was originally created by <a href="https://en.wikipedia.org/wiki/Donald_Knuth" data-type="link" data-id="https://en.wikipedia.org/wiki/Donald_Knuth">Donald Knuth</a> in 1978, and LaTex followed in 1984.</p>



<p class="wp-block-paragraph">TeX and LaTeX have broad adoption and they’re almost universally supported and understood. But they have two big, long-standing problems. The first is they’re old. They were created for an entirely different world of computing, and their age shows in cumbersome syntax and management. The second is the general complexity of using their language. In fact, LaTex was originally created as a way to make using TeX less complicated, but the underlying complexity of TeX was impossible to hide. </p>



<p class="wp-block-paragraph">Typst was created as a clean-slate solution to the problems and limitations of TeX and LaTeX. It shares many of the same ideas. For instance, Typst lets you typeset mathematical formulas using a syntax similar to the syntax used to express mathematical formulas in a programming language. But it does not try to be compatible with TeX syntax (although you can use third-party tools to convert TeX formulas to Typst.)</p>



<h2 class="wp-block-heading">Typst CLI, web app, and VS Code extension</h2>



<p class="wp-block-paragraph">Typst is available as a standalone command-line program (the open-source <a href="https://typst.app/open-source/" data-type="link" data-id="https://typst.app/open-source/">Typst compiler</a>), as a hosted web playground (the <a href="https://typst.app/" data-type="link" data-id="https://typst.app/">Typst app</a>, shown below), or as an add-on for Visual Studio Code (<a href="https://marketplace.visualstudio.com/items?itemName=myriad-dreamin.tinymist" data-type="link" data-id="https://marketplace.visualstudio.com/items?itemName=myriad-dreamin.tinymist">Tinymist Typst</a> being the most popular). The web playground gives you the fastest possible hands-on experience: all you need to do is start typing, and you’ll see a live preview. (The Tinymist add-on for VS Code also displays previews.)</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/image_808.png?w=1024" alt="Typst web playground." class="wp-image-4200172" width="1024" height="638" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>The web playground for Typst. All content is previewed live as you type. The current export mode, PDF, preserves positioning and formatting exactly.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p class="wp-block-paragraph">For most basic documents, Typst doesn’t require much extra syntax. You can just type Markdown-flavored text, and have that formatted as you’d expect. Underscores and asterisks can be used for emphasis or bold; section heads can be set with equals signs at the start of a line; and so on.</p>



<p class="wp-block-paragraph">Typst’s programming capabilities come into the picture when you want to start modifying the document’s presentation beyond its defaults. For instance, if you wanted to set the page size, margins, fonts, and paragraph formatting, you’d use declarations like these:</p>



<pre class="wp-block-code"><code><span class="hljs-selector-id">#set</span> <span class="hljs-selector-tag">page</span>(<span class="hljs-attribute">width</span>:<span class="hljs-number">5.25in</span>, <span class="hljs-attribute">height</span>:<span class="hljs-number">8in</span>, <span class="hljs-attribute">margin</span>: .<span class="hljs-number">5in</span>)
<span class="hljs-selector-id">#set</span> <span class="hljs-selector-tag">text</span>(<span class="hljs-attribute">size</span>: <span class="hljs-number">11pt</span>, <span class="hljs-attribute">font</span>: <span class="hljs-string">"Libre Baskerville"</span>)
<span class="hljs-selector-id">#set</span> <span class="hljs-selector-tag">par</span>(<span class="hljs-attribute">first-line-indent</span>: <span class="hljs-number">1.75em</span>,<span class="hljs-attribute">justify</span>: true)
</code></pre>



<p class="wp-block-paragraph"><code>#set</code> commands make changes from that point forward in the document. If you place these at the top of your document, they affect everything below it. But you could use other <code>#set</code> commands later to override those changes — for instance, if you switch from one text column to two.</p>



<h2 class="wp-block-heading">Typst code mode</h2>



<p class="wp-block-paragraph">The hash (<code>#</code>) in Typst (except when escaped with a slash) is used to signal a switch from regular text (markup mode) to Typst commands (code mode). Those commands can span multiple lines, until the Typst code block or expression is concluded:</p>



<pre class="wp-block-code"><code>This is regular text.

<span class="hljs-selector-id">#let</span> inline_image(img) = {
  box(<span class="hljs-attribute">height</span>: <span class="hljs-number">8em</span>, place(top+left, dx: <span class="hljs-number">5pt</span>, square(
      image(<span class="hljs-selector-tag">img</span>, <span class="hljs-attribute">height</span>:<span class="hljs-number">100%</span>, fit:<span class="hljs-string">"cover"</span>)
  )))
}

This is regular text again.</code></pre>



<p class="wp-block-paragraph">Here, we’ve used <code>#let</code> to define a function that takes one argument (the name of an image), and inserted it into an inline box. The curly braces indicate the body of the function, but individual lines end in a line break as in Python, not in a semicolon as in JavaScript.</p>



<p class="wp-block-paragraph">Typst exports to various formats — PDF, images, and HTML — although it’s optimized for the static layouts of PDF and images. Some kinds of formatting don’t render by default in HTML mode, if only because Typst can’t make reliable guarantees about how to do that (e.g., page headers and footers, which don’t really exist in HTML). What you <em>can</em> do is determine what the current export target is, via the <code>target()</code> function, and take action based on that:</p>



<pre class="wp-block-code"><code>#let sectionbreak(txt) = {
  context(
    <span class="hljs-keyword">if</span> target()==<span class="hljs-string">"html"</span> {
      html.elem(<span class="hljs-string">"div"</span>, attrs:(<span class="hljs-class"><span class="hljs-keyword">class</span>:<span class="hljs-type">"section-break"))[]</span></span>
      <span class="hljs-keyword">return</span>
    }
    <span class="hljs-keyword">else</span> {
    divider()
  })
}
</code></pre>



<p class="wp-block-paragraph">In this example, we’re creating a <code>sectionbreak()</code> function that has two behaviors. For HTML targets, it inserts an empty <code>div</code> tag with a CSS class that we could style with a style sheet. For all other targets, it defaults to the built-in <code>divider()</code> function.</p>



<p class="wp-block-paragraph">All of the document’s attributes are available in Typst code. The <a href="https://typst.app/docs/reference/introspection/query/"><code>query</code></a> function uses a syntax similar to JavaScript’s element querying system:</p>



<pre class="wp-block-code"><code>query(
    <span class="hljs-name">heading</span>.where(
      <span class="hljs-name">level</span>: <span class="hljs-number">1</span>,
    )
)
</code></pre>



<p class="wp-block-paragraph">This would return all document headings at level 1, then let you iterate over them, manipulate their contents, perform other introspection, and so on.</p>



<p class="wp-block-paragraph">Typst also has its own package manager and <a href="https://typst.app/universe/">package directory</a>. Packages do not need to be formally installed from the directory; you can simply reference them in your Typst program with an <code>import</code> statement, and they’ll be included.</p>



<h2 class="wp-block-heading">Typst math mode</h2>



<p class="wp-block-paragraph">Typst’s math blocks are patterned after TeX, but aren’t a drop-in replacement for TeX. That said, anyone with a little programming experience should be able to pick up how Typst’s math mode works.</p>



<p class="wp-block-paragraph">Math formulas are set aside from text by dollar signs:</p>



<pre class="wp-block-code"><code>$ sum_(k=<span class="hljs-number">1</span>)^<span class="hljs-built_in">n</span> k = (<span class="hljs-built_in">n</span>(<span class="hljs-comment">n+1</span>)) / <span class="hljs-number">2</span> $
</code></pre>



<p class="wp-block-paragraph">This block renders to the equation shown in the above screenshot. As with the hash, the dollar sign can be escaped with a slash if you need it in text. </p>



<p class="wp-block-paragraph">If you have a great deal of existing material composed in TeX, you can use a third-party tool to translate that TeX to Typst. The <a href="https://typst.app/universe/package/mitex/">MiTex</a> package can perform this inline for individual formulas or entire TeX documents.</p>



<h2 class="wp-block-heading">Automating Typst</h2>



<p class="wp-block-paragraph">The Typst language and ecosystem are still relatively new, and the language has limitations. Some are just a matter of features needing further development. Others, like the strict limitations on paths for imports or reading data, are by design.</p>



<p class="wp-block-paragraph">One way to get around limitations in Typst is to wrap it in another programming language. Python is an easy choice, and the <a href="https://pypi.org/project/typst/"><code>typst</code></a> Python library provides a high-level way to drive the Typst compiler. This lets you orchestrate complex workflows with multiple files, read data outside of the project root, or perform Typst queries to read document data.</p>



<p class="wp-block-paragraph">In time, some of what you might need to shim up this way may become native features. The community around Typst is already quite active (over a thousand packages are available for it), and new releases come regularly.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Russian Hackers Exploit Hotel Wi-Fi in New CaptiveCrunch Espionage Campaign]]></title>
<description><![CDATA[Microsoft Threat Intelligence has uncovered CaptiveCrunch, a cyber espionage campaign linked to Storm-2945, a subgroup of Midnight Blizzard, the Russian state-linked threat actor associated with Russia's Foreign Intelligence Service (SVR).  

Active since early May 2026, the operation targets b...]]></description>
<link>https://tsecurity.de/de/3700544/it-security-nachrichten/russian-hackers-exploit-hotel-wi-fi-in-new-captivecrunch-espionage-campaign/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3700544/it-security-nachrichten/russian-hackers-exploit-hotel-wi-fi-in-new-captivecrunch-espionage-campaign/</guid>
<pubDate>Mon, 03 Aug 2026 12:06:40 +0200</pubDate>
<content:encoded><![CDATA[<p><img width="824" height="498" src="https://thecyberexpress.com/wp-content/uploads/CaptiveCrunch.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="CaptiveCrunch" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/CaptiveCrunch.webp 824w, https://thecyberexpress.com/wp-content/uploads/CaptiveCrunch-300x181.webp 300w, https://thecyberexpress.com/wp-content/uploads/CaptiveCrunch-768x464.webp 768w, https://thecyberexpress.com/wp-content/uploads/CaptiveCrunch-600x363.webp 600w, https://thecyberexpress.com/wp-content/uploads/CaptiveCrunch-150x91.webp 150w, https://thecyberexpress.com/wp-content/uploads/CaptiveCrunch-750x453.webp 750w, https://thecyberexpress.com/wp-content/uploads/CaptiveCrunch.webp 824w, https://thecyberexpress.com/wp-content/uploads/CaptiveCrunch-300x181.webp 300w, https://thecyberexpress.com/wp-content/uploads/CaptiveCrunch-768x464.webp 768w, https://thecyberexpress.com/wp-content/uploads/CaptiveCrunch-600x363.webp 600w, https://thecyberexpress.com/wp-content/uploads/CaptiveCrunch-150x91.webp 150w, https://thecyberexpress.com/wp-content/uploads/CaptiveCrunch-750x453.webp 750w" sizes="(max-width: 824px) 100vw, 824px" title="Russian Hackers Exploit Hotel Wi-Fi in New CaptiveCrunch Espionage Campaign 1"></p><span data-contrast="auto">Microsoft Threat Intelligence has uncovered CaptiveCrunch, a cyber espionage campaign linked to Storm-2945, a subgroup of Midnight Blizzard, the Russian state-linked threat actor associated with Russia's Foreign Intelligence Service (SVR). </span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Active since early May 2026, the operation targets business travelers by exploiting hospitality Wi-Fi networks and captive portals in hotels, conference centers, and similar venues. The campaign combines adversary-in-the-middle attacks, phishing, <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-malware/" title="malware" data-wpil-keyword-link="linked" data-wpil-monitor-id="29232">malware</a> deployment, and AI-assisted development to steal credentials and infiltrate enterprise environments.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Storm-2945 Uses Hospitality Networks to Target Travelers</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">According to Microsoft, Storm-2945 manipulates DNS and HTTP traffic on public <a href="https://thecyberexpress.com/vulnerabilities-in-philips-smart-lighting/" target="_blank" rel="noopener">Wi-Fi networks</a> using captive portals. By intercepting users before they reach legitimate websites, attackers redirect victims to malicious infrastructure that hosts fake Microsoft sign-in pages or <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-malware/" target="_blank" rel="noopener" title="malware" data-wpil-keyword-link="linked" data-wpil-monitor-id="29236">malware</a> downloads.</span>

<span data-contrast="auto">This approach allows the Midnight Blizzard campaign to compromise users without requiring them to intentionally visit suspicious websites. Microsoft believes the attackers may have gained access to shared captive portal infrastructure used across multiple hospitality providers, expanding the scale of the CaptiveCrunch operation beyond isolated venues.</span>
<h3 aria-level="2"><b><span data-contrast="none">Credential Theft and Malware Deployment</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">A key objective of CaptiveCrunch is stealing Microsoft Entra ID credentials. Researchers observed Storm-2945 using counterfeit Microsoft login pages and device code <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-phishing/" target="_blank" rel="noopener" title="phishing" data-wpil-keyword-link="linked" data-wpil-monitor-id="29237">phishing</a> to gain unauthorized access to Microsoft 365 accounts. Once authentication succeeds, the attackers register compromised devices and collect <a href="https://thecyberexpress.com/salesforce-sfmc-ampscript-vulnerability/" target="_blank" rel="noopener">cloud data</a>, making corporate travelers especially attractive targets.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">The campaign also distributes malware disguised as browser or operating system updates through convincing "ClickFix" prompts that encourage users to run scripts or install software. Similar tactics have targeted Android users by prompting them to download malicious APK files.</span>

<span data-contrast="auto">The primary payload is CornFlake, a Windows <a href="https://thecyberexpress.com/valleyrat-variant-links-to-chinese-hackers/" target="_blank" rel="noopener">remote access trojan</a> written in Go that installs itself as a persistent "Cloud Sync Service." It maintains persistence through Windows services, registry keys, and scheduled tasks while enabling attackers to log keystrokes, capture screenshots, monitor clipboard activity, record webcam and microphone data, steal browser credentials, exfiltrate files, monitor USB devices, and execute remote commands through PowerShell or Windows Command Prompt. Communications with command-and-control servers are encrypted to evade analysis.</span>
<h3 aria-level="2"><b><span data-contrast="none">AI-Assisted Malware and Centralized Control</span></b></h3>
<span data-contrast="auto">Supporting CornFlake is ChocoShell, a PowerShell-based <a class="wpil_keyword_link" href="https://cyble.com/malware/infostealer/" target="_blank" rel="noopener" title="infostealer" data-wpil-keyword-link="linked" data-wpil-monitor-id="29234">infostealer</a> that operates entirely in memory to avoid detection. It extracts browser passwords, Microsoft 365 Single Sign-On tokens, Azure Active Directory authentication tokens, Wi-Fi credentials, and session cookies while bypassing AMSI, User Account Control, and virtual analysis environments. Microsoft researchers noted that ChocoShell's source code contains detailed developer comments, suggesting significant AI-assisted development.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">The attackers manage infected systems through FruitStone, a web-based command-and-control platform that allows operators to deploy malware, execute remote commands, collect stolen credentials, review screenshots and keystrokes, configure campaigns, and organize compromised devices by geography and operational status.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Microsoft's Defensive Guidance</span></b></h3>
<span data-contrast="auto"><a href="https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/" target="_blank" rel="nofollow noopener">Microsoft assesses</a> with high confidence that Storm-2945 operates as part of Midnight Blizzard because of overlaps in tooling, phishing techniques, victim selection, and cloud exploitation methods. The Russian state-linked <a class="wpil_keyword_link" href="https://cyble.com/threat-actor/" target="_blank" rel="noopener" title="threat actor" data-wpil-keyword-link="linked" data-wpil-monitor-id="29235">threat actor</a> has previously targeted governments, diplomatic organizations, NGOs, IT providers, and other strategic sectors.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">To reduce exposure to CaptiveCrunch, Microsoft recommends treating public Wi-Fi as untrusted, enforcing phishing-resistant <a href="https://thecyberexpress.com/miami-county-approves-2024-grant/" target="_blank" rel="noopener">multi-factor authentication</a> or passkeys, restricting OAuth permissions, monitoring device registrations, and applying Conditional Access policies. </span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Organizations should also educate employees about ClickFix-style <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-social-engineering/" target="_blank" rel="noopener" title="social engineering" data-wpil-keyword-link="linked" data-wpil-monitor-id="29233">social engineering</a> and avoid installing software, certificates, or updates delivered through</span><span data-contrast="auto"> captive portals. Business travelers are encouraged to use trusted VPNs, mobile hotspots, or enterprise-managed travel routers whenever possible.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":240,"335559739":240}'> </span>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI is making cybersecurity fundamentals more important than ever]]></title>
<description><![CDATA[When OpenAI disclosed that one of its models escaped a test environment and broke into Hugging Face’s systems on its own, headlines cast the incident as the start of a new era of AI-driven attacks. But the underlying cause of the incident was a familiar one: a misconfigured sandbox — the same kin...]]></description>
<link>https://tsecurity.de/de/3700543/it-security-nachrichten/ai-is-making-cybersecurity-fundamentals-more-important-than-ever/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3700543/it-security-nachrichten/ai-is-making-cybersecurity-fundamentals-more-important-than-ever/</guid>
<pubDate>Mon, 03 Aug 2026 12:06:35 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">When OpenAI disclosed that one of its models <a href="https://www.csoonline.com/article/4200043/openai-model-escape-puts-enterprise-ai-defenses-on-notice.html">escaped a test environment</a> and broke into Hugging Face’s systems on its own, headlines cast the incident as the start of a new era of AI-driven attacks. But the underlying cause of the incident was a familiar one: <a href="https://cloudsecurityalliance.org/artifacts/hugging-face-ciso-post-mortem">a misconfigured sandbox</a> — the same kind of fundamental security failure that has enabled breaches for decades, with or without AI.</p>



<p class="wp-block-paragraph">AI systems are indeed <a href="https://www.csoonline.com/article/4196409/ai-powered-breaches-provide-wake-up-call-for-incident-response.html">already finding software vulnerabilities</a>, tailoring social-engineering attacks, analyzing enormous volumes of security data, and beginning to act autonomously across interconnected systems. But the more immediate lesson, experts say, may be less glamorous: The fundamental cybersecurity practices that organizations have struggled to perform for decades are becoming more important, not less.</p>



<p class="wp-block-paragraph">“The cybersecurity fundamentals are as important as ever, probably more so,” <a href="https://www.linkedin.com/in/ericbrandwine/">Eric Brandwine</a>, VP and distinguished engineer at Amazon Web Services, tells CSO. “It’s the exact same story that it’s always been — all of the cybersecurity fundamentals — but you’ve got to be more agile, you’ve got to be more responsive.”</p>



<h2 class="wp-block-heading">AI puts security debt front and center</h2>



<p class="wp-block-paragraph">Cybersecurity programs have always operated under pressure to accept unresolved vulnerabilities, incomplete inventories, aging infrastructure, and poorly controlled access, because fixing them is expensive or operationally disruptive. AI changes the consequences: Weaknesses that once took a skilled human considerable time to discover can now be found through automated, repeated examination of applications, infrastructure, and exposed systems.</p>



<p class="wp-block-paragraph">“Our legacy security debt is now front and center,” <a href="https://www.linkedin.com/in/dianakelleysecuritycurve/">Diana Kelley</a>, CISO at Noma Security, tells CSO. “Even simple mistakes that maybe a human wasn’t going to exploit previously, or it was sort of too hard for them to find, we’ve got AI looking again and again, going at machine speed, at agentic scale, looking for all of these exposures and exploiting them potentially.”</p>



<p class="wp-block-paragraph">Kelley points to Noma Security research into an indirect prompt-injection vulnerability called <a href="https://noma.security/blog/forcedleak-agent-risks-exposed-in-salesforce-agentforce/">ForcedLeak</a>. A malicious instruction submitted through a web form <a href="https://www.csoonline.com/article/4063044/vulnerability-in-salesforce-ai-could-be-tricked-into-leaking-crm-data.html">could cause a Salesforce AI agent to exfiltrate sensitive information</a> through an image request. Yet the attack relied on a decidedly conventional oversight: A content security policy still trusted a domain the organization no longer controlled. Researchers registered the abandoned domain for $5. Had it been removed from the content security policy, the exfiltration path would have been blocked.</p>



<p class="wp-block-paragraph">“This was an advanced agentic attack that used indirect prompt injection, but something as simple as DNS hygiene would have prevented it,” Kelley says.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/spafford/">Gene Spafford,</a> distinguished professor of computer science at Purdue University, sees the vulnerabilities AI is uncovering not merely as technical debt but frequently as the product of conscious business decisions. Organizations and vendors have repeatedly prioritized speed, features, and market share over careful engineering, testing, and risk management.</p>



<p class="wp-block-paragraph">“This kind of thing can often be described as a technical debt, but it’s a willful debt,” Spafford tells CSO. “It’s a misplaced sense of prioritization of where investment and spending have gone over many years.”</p>



<p class="wp-block-paragraph">AI systems trained on vast collections of software and security information are particularly effective at recognizing repeated patterns of bad coding, weak configurations, and familiar errors — revealing less about the novelty of the technology than about how much avoidable weakness the industry has allowed to persist.</p>



<p class="wp-block-paragraph">“AI is simply catching up with [decades of inadequate software engineering] for the lack of appropriate due care over the last few decades in development,” Spafford says.</p>



<h2 class="wp-block-heading">Attackers are moving faster, not necessarily differently</h2>



<p class="wp-block-paragraph">Generative and agentic AI may <a href="https://www.csoonline.com/article/4110008/top-cyber-threats-to-your-ai-systems-and-infrastructure.html">introduce distinct risks</a>, including prompt injection, <a href="https://www.csoonline.com/article/4166171/poisoned-truth-the-quiet-security-threat-inside-enterprise-ai.html">data poisoning</a>, and the manipulation of autonomous agents. But much of AI’s near-term impact comes from making familiar attack techniques faster, cheaper, or more precisely targeted.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/chris-betz-903b739b/">Chris Betz</a>, CISO at Google Cloud, describes the defining characteristics of AI-enabled activity as speed, scale, and customization. Traditional automation made it possible to perform the same action repeatedly; AI allows attackers and defenders to perform highly individualized actions repeatedly.</p>



<p class="wp-block-paragraph">“Where automation used to mean doing the same thing at scale, AI allows us to do very specific things at scale,” Betz tells CSO. “While we have to change the way we think, in a lot of ways it means that we have to do more of what we’ve done in the past, and we have to do it at a massive scale.”</p>



<p class="wp-block-paragraph">Familiar controls such as <a href="https://www.csoonline.com/article/570795/how-to-hack-2fa.html">multifactor authentication</a>, <a href="https://www.csoonline.com/article/564201/what-is-zero-trust-a-model-for-more-effective-security.html">zero-trust architectures</a>, <a href="https://www.csoonline.com/article/3520881/patch-management-a-dull-it-pain-that-wont-go-away.html">system patching</a>, and <a href="https://www.csoonline.com/article/3476179/how-your-xdr-is-evaded.html">effective detection and response</a> remain critical. But defenders must apply them consistently enough to withstand attackers who can probe environments continuously and adapt to each target.</p>



<p class="wp-block-paragraph">“You can’t bring just that foundation to an AI fight,” Betz says. “But you need that foundation. That foundation is what gives the defenders their distinct advantage.”</p>



<p class="wp-block-paragraph">The evidence from incident response continues to point toward familiar weaknesses. <a href="https://www.linkedin.com/in/jshier/">John Shier</a>, field CISO at Sophos, says the two leading root causes appearing year after year in the company’s incident investigations are <a href="https://www.csoonline.com/article/1308864/hackers-using-stolen-credentials-to-launch-attacks-as-info-stealing-peaks.html">compromised credentials</a> and <a href="https://www.csoonline.com/article/4176086/vulnerabilities-have-become-cyber-attackers-no-1-door-to-the-enterprise.html">exploited vulnerabilities</a>. In many of those incidents, multifactor authentication was absent from at least some exposed services, and attackers exploited vulnerabilities for which patches had been available for months.</p>



<p class="wp-block-paragraph">“There are no new vulnerability classes, and there are no new attack types. AI hasn’t changed that yet,” Shier tells CSO. “The things that we know how to mitigate and how to deal with are still the ones that the attackers are exploiting writ large.”</p>



<p class="wp-block-paragraph">Shier compares an organization relying on sophisticated detection without basic prevention to a modern vehicle equipped with driver-assistance sensors and airbags — but no brakes. Detection and response was a necessary correction to the notion that every intrusion could be prevented, but it becomes dangerous when organizations treat prevention as outdated or assume AI will contain every malicious action after it begins.</p>



<p class="wp-block-paragraph">That’s the trap Shier sees organizations falling into — treating AI as a reason to worry less about prevention. “It can solve some problems,” he says, “but it can’t solve all of the problems that are addressed by preventive technologies or by reducing or eliminating risks altogether.”</p>



<h2 class="wp-block-heading">Identity, cloud, and SaaS remain pressure points</h2>



<p class="wp-block-paragraph">AI-enabled attackers do not need to “hack in” when they can obtain credentials, session tokens, or authenticated access, and the expansion of cloud services, remote work, and SaaS has given adversaries more identities, permissions, and connections to target.</p>



<p class="wp-block-paragraph"><a href="https://www.crowdstrike.com/en-us/about-us/executive-team/adam-meyers/">Adam Meyers</a>, SVP of counter adversary operations at CrowdStrike, says organizations must first learn to “do cybersecurity well” before expecting advanced technologies to compensate for foundational weaknesses.</p>



<p class="wp-block-paragraph">“Organizations have quickly moved into remote work, and they’ve moved toward cloud systems,” Meyers tells CSO. “In a lot of cases, unfortunately, they haven’t kept pace cybersecurity-wise and haven’t done some of the basics correctly with identity in particular, but also cloud.”</p>



<p class="wp-block-paragraph">Meyers points to identity threat detection and response as an increasingly important baseline capability, because criminal actors are seeking passwords, authentication tokens, and ways to bypass multifactor authentication. Asked whether AI could perform the fundamentals for organizations, he was skeptical of treating the technology as a substitute for implementation and accountability.</p>



<p class="wp-block-paragraph">“The fundamentals are the fundamentals,” he says. “I don’t know if you need AI to do the fundamentals. I think you need to pull up your pants and do the fundamentals.”</p>



<h2 class="wp-block-heading">Good practices block entire classes of attacks</h2>



<p class="wp-block-paragraph">The number of vulnerabilities discovered through AI-assisted research is likely to grow. <a href="https://www.linkedin.com/in/tonysagercyber/">Tony Sager</a>, SVP and chief evangelist at the Center for Internet Security, argues that organizations should not interpret that growth as requiring a unique defense for every newly identified flaw, given that vulnerabilities fall into recurring classes that well-chosen security practices can block or constrain at once.</p>



<p class="wp-block-paragraph">“You can’t think of it as, ‘I have to find and fix every one of them,’ because they’re not all unique. They fall in classes,” Sager tells CSO. “Those good practices — the basics of identity management, configurations, and all those kinds of things — block lots of those different classes of attacks.”</p>



<p class="wp-block-paragraph">Frameworks and prioritized security controls translate complex knowledge about attacks, software flaws, and adversary behavior into a set of repeatable organizational practices. Their recommendations may sound elementary, but the simplicity of the behavior does not mean the analysis behind it is simplistic.</p>



<p class="wp-block-paragraph">“You don’t need to read threat reports,” Sager says. “You just need to engage in the practices that are found in things like the NIST framework and the CIS Critical Security Controls. You get a lot of value out of that, and you should do that because that’s the foundation of good defense.”</p>



<p class="wp-block-paragraph">As AI produces more examples of familiar flaws and gives adversaries the ability to search for them more rapidly, organizations with weak foundational controls will be exposed to more attempts against a larger number of weaknesses.</p>



<p class="wp-block-paragraph">“If you haven’t done these basic things, you’re weaker than ever,” Sager says. “The importance of those fundamental things has only gone up.”</p>



<h2 class="wp-block-heading">Humans must know when the AI is wrong</h2>



<p class="wp-block-paragraph">Cybersecurity fundamentals are not confined to technical controls. Security practitioners must also understand core cybersecurity principles well enough to evaluate AI-generated recommendations and recognize when a model has produced a plausible but incorrect answer.</p>



<p class="wp-block-paragraph">“If you as a human being don’t understand the basics of cybersecurity and you’re relying entirely on whatever AI you’re interacting with to tell you, then if the AI goes off — whether it drifts, gets misaligned, or there’s been poisoning via prompt injection — you have no ability as the person reading this output to figure out if that’s right or not,” Noma Security’s Kelley says.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/scottbeale/">Scott Beale</a>, CEO of ISC2, similarly warns that AI’s ability to increase capacity <a href="https://www.csoonline.com/article/4198016/socs-face-a-human-challenge-as-ai-speeds-alerts-and-threats.html">does not eliminate the need for human judgment</a>. An erroneous recommendation about a coffee shop is inconsequential; one affecting an organization’s systems, data, or response to an attack is not.</p>



<p class="wp-block-paragraph">“You need to be able to differentiate what is accurate and what’s not,” Beale tells CSO. “They also know that when errors are made, it is a human who’s going to be held accountable for whether the right decisions were made.”</p>



<p class="wp-block-paragraph">That accountability, Beale says, is exactly why AI can’t be allowed to lower the floor on human judgment: “Human judgment and human oversight are absolutely critical, even if you’re partnering with these AI tools.”</p>



<h2 class="wp-block-heading">New AI-specific attacks do not replace traditional threats</h2>



<p class="wp-block-paragraph">Organizations must also distinguish between attacks conducted with AI and attacks directed against the AI systems they use.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/rogeragrimes/">Roger Grimes</a>, a longtime security researcher and CISO adviser, says AI-enhanced attackers continue to rely heavily on the two dominant initial-access techniques of the broader internet era: social engineering and exploitation of unpatched vulnerabilities. AI can create more convincing phishing campaigns, deepfakes, and customized lures, while also helping identify known and previously undiscovered software flaws.</p>



<p class="wp-block-paragraph">“When AI threats come, as they already are, they’re going to use and abuse those same traditional, classical ways that hackers have always broken in,” Grimes tells CSO.</p>



<p class="wp-block-paragraph">At the same time, organizations are deploying systems vulnerable to prompt injection, model manipulation, data leakage, and other attacks aimed directly at AI. Grimes compares prompt injection to SQL injection: a form of attack made possible by a particular underlying technology. The difference is that AI will be embedded across desktops, devices, and interconnected services, and an attack against one model may reach an organization through an AI supply chain security teams have not fully mapped.</p>



<p class="wp-block-paragraph">“There are attacks from AI against you, whether or not you’re using AI,” Grimes says. “And then there are attacks to the AI that you use, because we’re all using AI in some way, and that’s only going to grow over time.”</p>



<p class="wp-block-paragraph">Traditional security fundamentals will mitigate many of the pathways attackers use to reach AI systems, but organizations will also need new controls for models, agents, prompts, and AI data flows. This, Grimes says, is an expansion of the security program, not an excuse to abandon what came before.</p>



<h2 class="wp-block-heading">AI can help do the hard, tedious work</h2>



<p class="wp-block-paragraph">None of the experts argues that CISOs should turn away from AI. Used carefully, it can help security teams analyze telemetry, investigate alerts, discover assets, examine code, and identify vulnerabilities — scaling work organizations have historically performed poorly because it is tedious and labor-intensive.</p>



<p class="wp-block-paragraph">AWS’s Brandwine says security organizations need ways to experiment with AI without subjecting every idea to a lengthy production review. A new AI-powered detection, for example, can run in parallel with an established system so defenders can compare results without immediately depending on it. That agility becomes essential as developers produce software faster and employees adopt new models and agents, requiring security teams to keep pace without turning governance into an obstacle employees evade.</p>



<p class="wp-block-paragraph">AI may finally make some aspects of security hygiene easier to sustain — assisting with asset classification, correlating disconnected inventories, prioritizing remediation work, and reducing the manual burden of reviewing logs. But its results will be only as dependable as the systems, data, and human decisions surrounding it.</p>



<p class="wp-block-paragraph">The winning formula is therefore neither “forget AI and return to the basics” nor “let AI solve cybersecurity.” It is to use AI to increase the speed and scale at which organizations perform the fundamentals while preserving the human knowledge, governance, and accountability necessary to determine whether the technology is getting the work right.</p>



<p class="wp-block-paragraph">As Google Cloud’s Betz puts it, the journey is “a firm foundation and a move-faster piece with AI on top.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI can do your tasks. That doesn’t mean it will do your job]]></title>
<description><![CDATA[Much of the conversation around AI and work has centered on a single question: Will AI take my job?



It’s an understandable concern. Every week AI becomes increasingly more capable. We see AI summarizing meetings, generating content, analyzing data, writing software and automating workflows tha...]]></description>
<link>https://tsecurity.de/de/3700521/it-security-nachrichten/ai-can-do-your-tasks-that-doesnt-mean-it-will-do-your-job/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3700521/it-security-nachrichten/ai-can-do-your-tasks-that-doesnt-mean-it-will-do-your-job/</guid>
<pubDate>Mon, 03 Aug 2026 12:03:12 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">Much of the conversation around AI and work has centered on a single question: Will AI take my job?</p>



<p class="wp-block-paragraph">It’s an understandable concern. Every week AI becomes increasingly more capable. We see AI summarizing meetings, generating content, analyzing data, writing software and automating workflows that once required significant human effort. Agentic AI is also becoming more established in the workplace, with virtual agents that can reason, plan and act across workflows. As those capabilities continue to improve, many employees are looking at the tasks they perform every day and wondering how much longer they will belong to them.</p>



<p class="wp-block-paragraph">I believe that question reveals a bigger issue that has little to do with the technology itself.</p>



<p class="wp-block-paragraph">Too many people have become defined by the tasks they perform rather than the value they create. Over time, the administrative work surrounding a role can overshadow the purpose behind it. According to Asana’s <a href="https://asana.com/resources/why-work-about-work-is-bad?utm_source=chatgpt.com">Anatomy of Work Index</a>, knowledge workers spend 60% of their time on “work about work” — coordinating, tracking and managing tasks rather than driving meaningful outcomes. As AI automates more of this work, it can feel less like a productivity breakthrough and more like a threat because many employees equate their value with the activities that consume most of their day.</p>



<p class="wp-block-paragraph">But most people were not hired to perform a task. They were hired to fulfill a purpose.</p>



<h2 class="wp-block-heading">Tasks are not the job</h2>



<p class="wp-block-paragraph">A customer service representative isn’t successful because they spend their day summarizing conversations, looking up account information or navigating multiple systems to find answers. Those activities may have become part of the job, but they aren’t the reason the role exists. Great service professionals build trust, solve problems and create moments that strengthen customer relationships. AI can, and should, take on this administrative work, but the human value has never been in completing those tasks. It has always been in helping customers through moments that matter.</p>



<p class="wp-block-paragraph">The industry increasingly recognizes this distinction. In fact, 91% of CX leaders believe human agents will remain a critical part of delivering customer experience, according to my company’s <a href="https://www.genesys.com/resources/state-of-cx">State of Customer Experience</a> 2026 report. As AI takes on more routine work, the role of the employee doesn’t disappear. It becomes even more focused on the judgment, empathy and relationship-building that customers value most.</p>



<p class="wp-block-paragraph">The same principle applies across every profession. A marketer isn’t measured by the number of presentations they build or approvals they coordinate; they’re hired to shape customer perception and drive growth; an HR professional isn’t successful because they schedule interviews or process paperwork; they’re there to identify, develop and retain talent. The examples go on, but the principle remains the same: Organizations create roles because outcomes need to be achieved, not because tasks need to be completed.<strong></strong></p>



<p class="wp-block-paragraph">I’ve helped lead four major AI transformations, spanning everything from machine learning and big data to conversational AI, generative AI and now agentic AI. While the technology has evolved dramatically, one pattern has remained remarkably consistent.</p>



<p class="wp-block-paragraph">The employees who embrace AI tend to focus on outcomes, while those who fear it often focus on tasks. The more someone defines their contribution through a list of activities, the easier it becomes to imagine AI replacing them. The more someone understands the purpose they serve, the easier it becomes to see AI as a tool that helps them deliver greater value.</p>



<p class="wp-block-paragraph">As part of AI transformations, CIO organizations are often responsible for mapping jobs and core workflows. Inevitably, employees think we’re mapping their jobs to figure out what AI can replace. But once we start identifying repetitive work they’d gladly hand off, perspectives change. Someone says, “If AI handled that, I’d finally have time to work directly with customers.” Another realizes they could spend more time creating. People start thinking less about what AI might replace and more about what they’d finally have time to do. They’re reconnecting with the reason they wanted the role in the first place.</p>



<p class="wp-block-paragraph">I’ve seen this play out as AI adoption expands. Our team responsible for responding to customer RFPs began using AI to analyze requirements, surface relevant information and accelerate response development. Their purpose is to help the organization communicate our value to customers and win new business. By reducing the time spent on low-value activities, AI created more capacity for strategic thinking, collaboration and customer-focused work, which directly influences the revenue and growth of our company.</p>



<p class="wp-block-paragraph">I’ve even had to confront this myself. I used to spend hours coaching leaders before operational reviews: reviewing KPIs, challenging assumptions and helping them prepare for difficult questions. I used to think this was part of what made me valuable as a CIO, but I realized that I didn’t need to spend my time repeating the same coaching session. That’s why I built a virtual coach that helps my team prepare for operational reviews using many of the frameworks and lessons I’ve accumulated throughout my career. Now I have more time to spend strategizing on how to lead through the breakneck speed of AI evolution and helping the business think differently.</p>



<h2 class="wp-block-heading">Rediscovering purpose</h2>



<p class="wp-block-paragraph">What employees are really confronting is a different question: What was my purpose in being hired in the first place?</p>



<p class="wp-block-paragraph">As organizations move from AI experimentation to AI-first operating models, this question becomes harder to avoid. The tension is already visible across the workforce. A recent <a href="https://www.ey.com/en_us/newsroom/2025/10/new-ey-survey-reveals-majority-of-workers-are-enthusiastic-about-agentic-ai-but-leadership-gaps-in-communication-and-lack-of-training-threaten-impact">EY survey</a> found that 84% of employees are eager to embrace agentic AI because they expect it to improve productivity, efficiency and the overall work experience. Yet 56% also worry about their job security working alongside AI systems. Employees aren’t rejecting AI; they’re trying to understand which parts of their contributions remain uniquely theirs as technology takes on more of the tasks they perform today.</p>



<p class="wp-block-paragraph">Success will depend greatly on helping employees reconnect with the value they were hired to create. For leaders looking for practical guidance on how organizations are actually approaching AI-first transformation, the World Economic Forum’s <a href="https://www.weforum.org/publications/the-ai-first-operating-system-a-blueprint-for-operating-and-business-model-innovation/">AI-First Operating System</a> offers a useful framework. Rather than treating AI as another technological tool, this approach encourages organizations to redesign work around value creation. As AI increasingly takes on routine tasks, employees must become clearer about where human judgment, creativity and relationships can create the greatest impact. You cannot redesign work around value if people no longer understand the purpose behind the work that they do.</p>



<p class="wp-block-paragraph">In my experience, the organizations seeing the strongest results are helping employees reconnect with the outcomes they were hired to create. The conversation shifts from “What tasks can AI do?” to “What is the purpose of this role?” Once people answer that question, it becomes much easier to decide what should remain human, what can be delegated to AI and where the combination creates the most value.</p>



<p class="wp-block-paragraph">None of this means change won’t happen. Some responsibilities will disappear. Some jobs will evolve significantly. New roles will emerge that we cannot fully predict today. Every major technology shift creates that kind of change.</p>



<p class="wp-block-paragraph">But I believe many people are looking at this transformation through the wrong lens.</p>



<p class="wp-block-paragraph">The question is not whether AI can do your tasks. The question is whether you understand the purpose behind them. Because while AI may increasingly perform the work, humans will continue to provide the judgment, creativity, accountability and value that give that work meaning.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[12 business analyst certifications to level up your career]]></title>
<description><![CDATA[Business analysts help organizations make the most of the data they collect by finding trends, patterns, and errors that might otherwise go unnoticed. Successful business analysts have the skills to work with data, the acumen to understand the business side of the organization, and the ability to...]]></description>
<link>https://tsecurity.de/de/3700503/it-nachrichten/12-business-analyst-certifications-to-level-up-your-career/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3700503/it-nachrichten/12-business-analyst-certifications-to-level-up-your-career/</guid>
<pubDate>Mon, 03 Aug 2026 12:02:07 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph"><a href="https://www.cio.com/article/276798/what-is-a-business-analyst-a-key-role-for-business-it-efficiencywhat-is-a-business-analyst-a-key-role-for-business-it-efficiency.html">Business analysts</a> help organizations make the most of the data they collect by finding trends, patterns, and errors that might otherwise go unnoticed. <a href="https://www.cio.com/article/189108/essential-traits-of-elite-business-analysts.html">Successful business analysts</a> have the skills to work with data, the acumen to understand the business side of the organization, and the ability to communicate that information to people outside of IT. Certifications provide a great way to prove your business analyst bona fides or get started in the field.</p>



<p class="wp-block-paragraph">Business analytics is a lucrative role in IT, with an average entry-level salary of $80,692 per year. Throughout their careers, <a href="https://www.cio.com/article/276798/project-management-what-do-business-analysts-actually-do-for-software-implementation-projects.html">business analysts</a> report average salaries ranging from $58,000 to $114,000 per year, <a href="https://www.payscale.com/research/US/Job=Business_Analyst%2C_IT/Salary">according to PayScale</a>. If you want to advance your business analyst career, or change career paths, here are 12 certifications that will help prove your mettle. Not finding what you’re looking for? Check out our list of <a href="https://www.cio.com/article/230388/big-data-certifications-that-will-pay-off.html">big data and data analytics certifications</a>.</p>



<h2 class="wp-block-heading">Top 12 business analyst certifications</h2>



<ul class="wp-block-list">
<li>Certified Analytics Professional (CAP)</li>



<li>IIBA Entry Certificate in Business Analysis (ECBA)</li>



<li>IIBA Certification of Competency in Business Analysis (CCBA)</li>



<li>IIBA Certified Business Analysis Professional (CBAP)</li>



<li>IIBA Agile Analysis Certification (AAC)</li>



<li>IIBA Certification in Business Data Analytics (CBDA)</li>



<li>IQBBA Certified Foundation Level Business Analyst (CFLBA)</li>



<li>IQBBA Certified Advanced Level Business Analyst (CALBA)</li>



<li>IQBBA Certified Agile Business Analyst (CABA)</li>



<li>IREB Certified Professional for Requirements Engineering (CPRE)</li>



<li>PMI Professional in Business Analysis (PBA)</li>



<li>Salesforce Certified Business Analyst</li>
</ul>



<h3 class="wp-block-heading">Certified Analytics Professional (CAP)</h3>



<p class="wp-block-paragraph">The <a href="https://www.certifiedanalytics.org/">Certified Analytics Professional (CAP)</a> is a vendor-neutral certification that certifies your skills and ability to draw valuable insights from complex data sets to help guide strategic businesses decisions. There are three levels of the exam — the essentials, pro, and expert certifications. Essentials is for entry-level analytics professionals, Pro is for mid-career analytics practitioners, and Expert is aimed at senior analytics leaders and directors. Depending on the level of certification, each has different requirements ranging from no-prerequisites at the Essentials level to advanced degrees to qualify for the Expert certification.</p>



<ul class="wp-block-list">
<li><em>Essentials exam fee:</em> $195 for INFORMS members, $275 for non-members</li>



<li><em>Professional exam fee:</em> $325 for INFORMS members, $460 for non-members</li>



<li><em>Expert exam fee:</em> $440 for INFORMS members, $640 for non-members</li>
</ul>



<h3 class="wp-block-heading">IIBA Entry Certificate in Business Analysis (ECBA)</h3>



<p class="wp-block-paragraph">The <a href="https://www.cio.com/article/189169/ecba-certification-an-entry-level-credential-for-business-analysts.html">Entry Certificate in Business Analysis (ECBA)</a> is the first level of certification with the International Institute of Business Analysis (IIBA), it’s designed for less experienced and entry-level business analysts. You will need to complete at least 21 hours of professional training credits, within the past four years, before you will be eligible for the exam. You don’t have to renew your ECBA certification, but it’s assumed you’ll move on to the second or third levels of certification.</p>



<ul class="wp-block-list">
<li><em>Exam fee: </em>$395</li>
</ul>



<p class="wp-block-paragraph">For more, <a href="https://www.cio.com/article/189169/ecba-certification-an-entry-level-credential-for-business-analysts.html">see our guide on the ECBA</a>.</p>



<h3 class="wp-block-heading">IIBA Certification of Competency in Business Analysis (CCBA)</h3>



<p class="wp-block-paragraph">Level 2 of the IIBA certification, the <a href="https://www.iiba.org/business-analysis-certifications/ccba/">Certification of Competency in Business Analysis (CCBA)</a> requires a minimum 3,750 hours of business analytics work aligned with the IIBA’s BABOK guide in the past 7 years, 900 hours in two of six BABOK knowledge areas, or 500 hours in four of six BABOK knowledge areas. The certification also requires a minimum of 21 hours of professional development training in the past four years and two professional references. The CCBA exam consists of 130 multiple-choice questions that are scenario-based and require some analysis. It covers fundamentals, underlying competencies, key concepts, techniques, and all six knowledge areas covered in the BABOK.</p>



<ul class="wp-block-list">
<li><em>Application fee:</em> $145</li>



<li><em>Exam fee:</em> $240 for members, $405 for non-members</li>
</ul>



<h3 class="wp-block-heading">IIBA Certified Business Analysis Professional (CBAP)</h3>



<p class="wp-block-paragraph">The <a href="https://www.cio.com/article/189143/cbap-certification-a-high-profile-credential-for-business-analysts.html">Certified Business Analysis Professional (CBAP) certification</a> is the third level of certification with IIBA and is designed for “individuals with extensive business analysis experience.” To qualify for this certification, you’ll need a minimum of 7,500 hours of business analyst work experience in the past 10 years, 900 hours of work experience hours within four of the six BABOK knowledge areas, at least 35 hours of professional development in the past four years and professional references. The exam is 3.5 hours long and includes 120 multiple-choice questions based on case studies. After you pass, you’ll need to report at least 60 hours of continuing development units every three years.</p>



<ul class="wp-block-list">
<li><em>Application fee:</em> $145</li>



<li><em>Exam fee:</em> $350 for members, $505 for non-members</li>
</ul>



<p class="wp-block-paragraph">For more, <a href="https://www.cio.com/article/189143/cbap-certification-a-high-profile-credential-for-business-analysts.html">see our guide on the CBAP</a>.</p>



<h3 class="wp-block-heading">IIBA Agile Analysis Certification (AAC)</h3>



<p class="wp-block-paragraph">The agile methodology has been rising in importance for business analysts over the past several years, according to the IIBA. The association’s competency-based <a href="https://www.iiba.org/business-analysis-certifications/agile-analysis/">Agile Analysis Certification (AAC)</a> exam was designed to address this skillset and to certify business analyst professionals working in agile environments, which require fast adaption and rapid change. The exam was developed using the Agile Extension to the Business Analysis Book of Knowledge (BABOK) guide and released in May 2018 as a standalone certification and is separate from the other IIBA business analyst certifications, which stack on top of one another. The exam’s four main topics include agile mindset (30%), strategy horizon (10%), initiative horizon (25%) and delivery horizon (35%). There aren’t any eligibility requirements to take the exam, but the IIBA recommends at least two to five years of agile-related experience.</p>



<ul class="wp-block-list">
<li><em>Exam fee:</em> $250 for members, $405 for non-members</li>
</ul>



<h3 class="wp-block-heading">IIBA Certification in Business Data Analytics (CBDA)</h3>



<p class="wp-block-paragraph">The <a href="https://www.iiba.org/certification/iiba-certifications/specialized-business-analysis-certifications/business-data-analytics-certification/">Certification Business Data Analytics (IIBA-CBDA)</a> from the IIBA is a certification that “recognizes your ability to effectively execute analysis-related work in support of business analytics initiatives.” To pass the exam, you will need to examine a real-world business problem, identify the data sources and how to obtain data, analyze the data, interpret and report results from the data. You’ll then need demonstrate how those results can influence business decision-making and guide company-level strategies for business analytics.</p>



<ul class="wp-block-list">
<li><em>Exam fee:</em> $250 for members, $405 for non-members</li>
</ul>



<h3 class="wp-block-heading">IQBBA Certified Foundation Level Business Analyst (CFLBA)</h3>



<p class="wp-block-paragraph">The International Qualifications Board for Business Analysts (IQBBA) offers the <a href="https://www.iqbba.org/en/scheme/foundation-level.html">Certified Foundation Level Business Analysis (CFLBA)</a> as an entry-level certification, which will qualify you to earn higher levels of certification. It’s a globally recognized certification with accredited exam and training centers across the world. It’s designed for “people involved in analyzing business processes within an organization, modeling businesses and process improvement.” The foundation level covers enterprise analysis, business analysis process planning, requirements elicitation, requirements analysis, solution validation, tools and techniques, innovation, and design.</p>



<ul class="wp-block-list">
<li><em>Exam fee:</em> $215</li>
</ul>



<h3 class="wp-block-heading">IQBBA Certified Advanced Level Business Analyst (CALBA)</h3>



<p class="wp-block-paragraph">The <a href="https://iqbba.org/iqbba/certifications/calba-certified-advanced-level-business-analysis-course/">IQBBA Certified Advanced Level Business Analysis</a> certification offers an advanced-level qualification for those who have passed the entry-level CFLBA exam. At this level, you’ll gain skills in business analysis process management, strategic analysis and optimization, and requirements management. Learning modules focus on enhancing the skills gained at the foundational level, deepening your knowledge of more advanced skills that will be necessary in your career.</p>



<ul class="wp-block-list">
<li><em>Exam fee: $215</em></li>
</ul>



<h3 class="wp-block-heading">IQBBA Certified Agile Business Analysis (CABA)</h3>



<p class="wp-block-paragraph">The <a href="https://iqbba.org/iqbba/certifications/caba-certified-agile-business-analysis/">IQBBA Certified Agile Business Analyst </a>certification is another foundational-level qualification designed for anyone who wants to strengthen their business analysis skills with a focus on the Agile framework. The course covers how to recognize the role of a BA in agile software development projects, contribute to agile software teams, understand the principles of agile business analysis, and employ BA techniques in an enterprise setting. In addition to BA principles, the course and certification cover agile skills as well, including the 12 principles of the Agile Manifesto and how they intertwine with BA methods.</p>



<ul class="wp-block-list">
<li><em>Exam fee: $215</em></li>
</ul>



<h3 class="wp-block-heading">IREB Certified Professional for Requirements Engineering (CPRE)</h3>



<p class="wp-block-paragraph">The International Requirements Engineering Board (IREB) offers the <a href="https://cpre.ireb.org/en">Certified Professional for Requirements Engineering (CPRE)</a> certification is designed for those working in requirements engineering (RE), and it’s offered at three levels. The Foundation Level is first, where you’ll be certified in the basics of RE. The Practitioner Level is next, where you can choose between four paths, including management, modeling, elicitation, and RE@Agile followed by Specialist level in the same four pathways. Finally, the Expert Level certifies you at the “highest level of expert knowledge,” which includes both your hands-on experience as well as your knowledge and skills gained through previous certifications.</p>



<p class="wp-block-paragraph">Your certification will not expire, and you will not need to renew it. The IREB states that the CPRE is “based on the fundamental methods and approaches of Requirements Engineering, and these alter only slowly,” so at this time, they don’t see a need for renewal.</p>



<ul class="wp-block-list">
<li><em>Exam fee:</em> Varies by testing center</li>
</ul>



<h3 class="wp-block-heading">PMI Professional in Business Analysis (PBA) Certification</h3>



<p class="wp-block-paragraph">The <a href="https://www.pmi.org/certifications/business-analysis-pba">PMI Professional in Business Analysis (PBA)</a> certification is designed for business analysts who work with projects or programs, or project and program managers who work with analytics. It’s offered through the Project Management Institute, which specializes in widely recognized project management certifications, such as the PMP. The certification focuses on business analysis training through hands-on projects and testing on business analysis principles, tools and fundamentals.</p>



<p class="wp-block-paragraph">If you’ve already earned a bachelor’s degree, you’ll need at least three years’ experience, or 4,500 hours, in business analysis consecutively within the past eight years to earn this certification. Without a bachelor’s degree, you’ll need five years or 7,500 hours experience.</p>



<p class="wp-block-paragraph">You’ll be required to earn 60 professional development units within three years after completing the certification to maintain your renewal status. If you let your renewal lapse, your credentials will be suspended for one year until you fulfill the requirements — after that, it will be terminated and you’ll need to reapply.</p>



<ul class="wp-block-list">
<li><em>Exam fee:</em> $405 for PMI members, $555 for non-members</li>
</ul>



<h3 class="wp-block-heading">Salesforce Certified Business Analyst</h3>



<p class="wp-block-paragraph">The Salesforce Certified Business Analyst certification is a vendor-specific certification for business analysts — or similar roles — who work directly with Salesforce technology. The exam covers customer discovery, collaboration with stakeholders, business process mapping, requirements, user stories, and development support and user acceptance. You will need to pass a 60-question multiple choice question test and up to five additional unscored questions. While it’s not required, candidates should have around 2 years of business analyst experience and Salesforce Platform experience.</p>



<ul class="wp-block-list">
<li><em>Exam fee:</em> $200</li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI can do your tasks. That doesn’t mean it will do your job]]></title>
<description><![CDATA[Much of the conversation around AI and work has centered on a single question: Will AI take my job?



It’s an understandable concern. Every week AI becomes increasingly more capable. We see AI summarizing meetings, generating content, analyzing data, writing software and automating workflows tha...]]></description>
<link>https://tsecurity.de/de/3700504/it-nachrichten/ai-can-do-your-tasks-that-doesnt-mean-it-will-do-your-job/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3700504/it-nachrichten/ai-can-do-your-tasks-that-doesnt-mean-it-will-do-your-job/</guid>
<pubDate>Mon, 03 Aug 2026 12:02:07 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">Much of the conversation around AI and work has centered on a single question: Will AI take my job?</p>



<p class="wp-block-paragraph">It’s an understandable concern. Every week AI becomes increasingly more capable. We see AI summarizing meetings, generating content, analyzing data, writing software and automating workflows that once required significant human effort. Agentic AI is also becoming more established in the workplace, with virtual agents that can reason, plan and act across workflows. As those capabilities continue to improve, many employees are looking at the tasks they perform every day and wondering how much longer they will belong to them.</p>



<p class="wp-block-paragraph">I believe that question reveals a bigger issue that has little to do with the technology itself.</p>



<p class="wp-block-paragraph">Too many people have become defined by the tasks they perform rather than the value they create. Over time, the administrative work surrounding a role can overshadow the purpose behind it. According to Asana’s <a href="https://asana.com/resources/why-work-about-work-is-bad?utm_source=chatgpt.com">Anatomy of Work Index</a>, knowledge workers spend 60% of their time on “work about work” — coordinating, tracking and managing tasks rather than driving meaningful outcomes. As AI automates more of this work, it can feel less like a productivity breakthrough and more like a threat because many employees equate their value with the activities that consume most of their day.</p>



<p class="wp-block-paragraph">But most people were not hired to perform a task. They were hired to fulfill a purpose.</p>



<h2 class="wp-block-heading">Tasks are not the job</h2>



<p class="wp-block-paragraph">A customer service representative isn’t successful because they spend their day summarizing conversations, looking up account information or navigating multiple systems to find answers. Those activities may have become part of the job, but they aren’t the reason the role exists. Great service professionals build trust, solve problems and create moments that strengthen customer relationships. AI can, and should, take on this administrative work, but the human value has never been in completing those tasks. It has always been in helping customers through moments that matter.</p>



<p class="wp-block-paragraph">The industry increasingly recognizes this distinction. In fact, 91% of CX leaders believe human agents will remain a critical part of delivering customer experience, according to my company’s <a href="https://www.genesys.com/resources/state-of-cx">State of Customer Experience</a> 2026 report. As AI takes on more routine work, the role of the employee doesn’t disappear. It becomes even more focused on the judgment, empathy and relationship-building that customers value most.</p>



<p class="wp-block-paragraph">The same principle applies across every profession. A marketer isn’t measured by the number of presentations they build or approvals they coordinate; they’re hired to shape customer perception and drive growth; an HR professional isn’t successful because they schedule interviews or process paperwork; they’re there to identify, develop and retain talent. The examples go on, but the principle remains the same: Organizations create roles because outcomes need to be achieved, not because tasks need to be completed.<strong></strong></p>



<p class="wp-block-paragraph">I’ve helped lead four major AI transformations, spanning everything from machine learning and big data to conversational AI, generative AI and now agentic AI. While the technology has evolved dramatically, one pattern has remained remarkably consistent.</p>



<p class="wp-block-paragraph">The employees who embrace AI tend to focus on outcomes, while those who fear it often focus on tasks. The more someone defines their contribution through a list of activities, the easier it becomes to imagine AI replacing them. The more someone understands the purpose they serve, the easier it becomes to see AI as a tool that helps them deliver greater value.</p>



<p class="wp-block-paragraph">As part of AI transformations, CIO organizations are often responsible for mapping jobs and core workflows. Inevitably, employees think we’re mapping their jobs to figure out what AI can replace. But once we start identifying repetitive work they’d gladly hand off, perspectives change. Someone says, “If AI handled that, I’d finally have time to work directly with customers.” Another realizes they could spend more time creating. People start thinking less about what AI might replace and more about what they’d finally have time to do. They’re reconnecting with the reason they wanted the role in the first place.</p>



<p class="wp-block-paragraph">I’ve seen this play out as AI adoption expands. Our team responsible for responding to customer RFPs began using AI to analyze requirements, surface relevant information and accelerate response development. Their purpose is to help the organization communicate our value to customers and win new business. By reducing the time spent on low-value activities, AI created more capacity for strategic thinking, collaboration and customer-focused work, which directly influences the revenue and growth of our company.</p>



<p class="wp-block-paragraph">I’ve even had to confront this myself. I used to spend hours coaching leaders before operational reviews: reviewing KPIs, challenging assumptions and helping them prepare for difficult questions. I used to think this was part of what made me valuable as a CIO, but I realized that I didn’t need to spend my time repeating the same coaching session. That’s why I built a virtual coach that helps my team prepare for operational reviews using many of the frameworks and lessons I’ve accumulated throughout my career. Now I have more time to spend strategizing on how to lead through the breakneck speed of AI evolution and helping the business think differently.</p>



<h2 class="wp-block-heading">Rediscovering purpose</h2>



<p class="wp-block-paragraph">What employees are really confronting is a different question: What was my purpose in being hired in the first place?</p>



<p class="wp-block-paragraph">As organizations move from AI experimentation to AI-first operating models, this question becomes harder to avoid. The tension is already visible across the workforce. A recent <a href="https://www.ey.com/en_us/newsroom/2025/10/new-ey-survey-reveals-majority-of-workers-are-enthusiastic-about-agentic-ai-but-leadership-gaps-in-communication-and-lack-of-training-threaten-impact">EY survey</a> found that 84% of employees are eager to embrace agentic AI because they expect it to improve productivity, efficiency and the overall work experience. Yet 56% also worry about their job security working alongside AI systems. Employees aren’t rejecting AI; they’re trying to understand which parts of their contributions remain uniquely theirs as technology takes on more of the tasks they perform today.</p>



<p class="wp-block-paragraph">Success will depend greatly on helping employees reconnect with the value they were hired to create. For leaders looking for practical guidance on how organizations are actually approaching AI-first transformation, the World Economic Forum’s <a href="https://www.weforum.org/publications/the-ai-first-operating-system-a-blueprint-for-operating-and-business-model-innovation/">AI-First Operating System</a> offers a useful framework. Rather than treating AI as another technological tool, this approach encourages organizations to redesign work around value creation. As AI increasingly takes on routine tasks, employees must become clearer about where human judgment, creativity and relationships can create the greatest impact. You cannot redesign work around value if people no longer understand the purpose behind the work that they do.</p>



<p class="wp-block-paragraph">In my experience, the organizations seeing the strongest results are helping employees reconnect with the outcomes they were hired to create. The conversation shifts from “What tasks can AI do?” to “What is the purpose of this role?” Once people answer that question, it becomes much easier to decide what should remain human, what can be delegated to AI and where the combination creates the most value.</p>



<p class="wp-block-paragraph">None of this means change won’t happen. Some responsibilities will disappear. Some jobs will evolve significantly. New roles will emerge that we cannot fully predict today. Every major technology shift creates that kind of change.</p>



<p class="wp-block-paragraph">But I believe many people are looking at this transformation through the wrong lens.</p>



<p class="wp-block-paragraph">The question is not whether AI can do your tasks. The question is whether you understand the purpose behind them. Because while AI may increasingly perform the work, humans will continue to provide the judgment, creativity, accountability and value that give that work meaning.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The infrastructure debt AI creates isn't in the code. It's in the operations]]></title>
<description><![CDATA[As AI speeds development, organizations must rethink how they govern and manage infrastructure.]]></description>
<link>https://tsecurity.de/de/3700496/it-nachrichten/the-infrastructure-debt-ai-creates-isnt-in-the-code-its-in-the-operations/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3700496/it-nachrichten/the-infrastructure-debt-ai-creates-isnt-in-the-code-its-in-the-operations/</guid>
<pubDate>Mon, 03 Aug 2026 12:02:01 +0200</pubDate>
<content:encoded><![CDATA[As AI speeds development, organizations must rethink how they govern and manage infrastructure.]]></content:encoded>
</item>
<item>
<title><![CDATA[Disruption review – anti-AI thriller boasts knockout cast but tech commentary needs an update]]></title>
<description><![CDATA[Pershing Square Signature Center, New YorkJohn David Washington leads an exceptionally talented cast in a sleek off-Broadway thriller that feels a little datedMaking its US debut three years after its London premiere, Andrew Stein’s Disruption faces the typical battle of the topical play: even wi...]]></description>
<link>https://tsecurity.de/de/3700424/ai-nachrichten/disruption-review-anti-ai-thriller-boasts-knockout-cast-but-tech-commentary-needs-an-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3700424/ai-nachrichten/disruption-review-anti-ai-thriller-boasts-knockout-cast-but-tech-commentary-needs-an-update/</guid>
<pubDate>Mon, 03 Aug 2026 10:28:08 +0200</pubDate>
<content:encoded><![CDATA[<p><strong>Pershing Square Signature Center, New York</strong></p><p>John David Washington leads an exceptionally talented cast in a sleek off-Broadway thriller that feels a little dated</p><p>Making its US debut three years after its London premiere, Andrew Stein’s Disruption faces the typical battle of the topical play: even with the most expedient fast-track to production, works tackling current events are in danger of obsolescence upon arrival, often left at the mercy of the latest update, for better or worse. As far as plays dealing with AI go, New York got Ayad Akhtar’s <a href="https://www.theguardian.com/stage/2024/oct/01/mcneal-robert-downey-jr-play-review">McNeal</a> in 2024, which condescended while saying next to nothing about ChatGPT plagiarism, and was marred, <a href="https://www.theatrely.com/post/mcneal-fights-ai-audience-loses-review">for me</a>, by news of star Robert Downey Jr’s $100m Avengers payday. And earlier this year, the tech-industry moral quandary of Matthew Libby’s Data received bone-chilling boosts from <a href="https://www.theguardian.com/us-news/ng-interactive/2025/sep/22/ice-palantir-data">unfolding reports of Palantir’s work with ICE</a>.</p><p>Stein’s play has to do with the vast amounts of personal information we freely hand over to our tech overlords, and how it could be leveraged against us. It is well-constructed, briskly directed by Hersh Ellis, and with handsome scenic and costume designs by Zoë Hurwitz – both of whom also worked on its 2023 iteration. But aside from a late development that echoes last week’s jump-scare that an OpenAI tool <a href="https://www.theguardian.com/technology/2026/jul/22/openai-says-its-models-went-rogue-and-hacked-startup-in-unprecedented-incident">went rogue</a>, any insights it offers about our present moment are either naively outdated or mired in its overcomplicated web of characters. Charitably, one could chalk this up to the three years lapsed since its premiere; 30 lifetimes in cyberland. But lines like “Data’s the next frontier,” or “Technology has made us so connected to everything except ourselves,” would not have stood a chance in 2010.</p> <a href="https://www.theguardian.com/stage/2026/aug/02/disruption-play-review">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[GOG Officially Expands Linux Support With Native Galaxy Client In Development]]></title>
<description><![CDATA[Long-time Slashdot reader pyroclast shared this report from Linux Journal:

After years of requests from the Linux gaming community, GOG has officially confirmed that it is developing native Linux support for the GOG Galaxy launcher. The announcement marks one of the biggest shifts in the company...]]></description>
<link>https://tsecurity.de/de/3700388/linux-tipps/gog-officially-expands-linux-support-with-native-galaxy-client-in-development/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3700388/linux-tipps/gog-officially-expands-linux-support-with-native-galaxy-client-in-development/</guid>
<pubDate>Mon, 03 Aug 2026 10:26:06 +0200</pubDate>
<content:encoded><![CDATA[Long-time Slashdot reader pyroclast shared this report from Linux Journal:

After years of requests from the Linux gaming community, GOG has officially confirmed that it is developing native Linux support for the GOG Galaxy launcher. The announcement marks one of the biggest shifts in the company's history and signals a stronger commitment to Linux as a first-class gaming platform. While GOG has offered DRM-free Linux game downloads since 2014, its Galaxy launcher has remained exclusive to Windows and macOS — until now. Although the company has not announced a release date, GOG says Linux has become a major area of investment, with development already underway... 

Unlike the web-based game downloads that Linux users already have access to, GOG Galaxy serves as a full-featured game management application. The launcher currently offers features including: 
 — Automatic game installation and updates
 — Cloud save synchronization
 — Achievement tracking
 — Playtime statistics
 — Game library organization
 — Integrated storefront browsing
 — Friends lists and social features
 — Cross-platform launcher integration 
Today, Linux users typically access these capabilities through community projects such as Heroic Games Launcher, Lutris, or Bottles. A native Galaxy client would provide an officially supported alternative with direct integration into GOG's ecosystem... 

For GOG, supporting Linux more fully aligns with its philosophy of giving users greater control over their purchased games.

 

The article argues this news shows Linux growing in importance for game publishers. After the rapid adoption of Valve's Steam Deck, there's also been continuous improvements to Proton and Vulkan, increasing hardware compatibility, and native Linux game development efforts. 

"As more companies recognize the platform's growth, Linux users can expect broader support from game publishers and software developers alike."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=GOG+Officially+Expands+Linux+Support+With+Native+Galaxy+Client+In+Development%3A+https%3A%2F%2Flinux.slashdot.org%2Fstory%2F26%2F08%2F02%2F2019202%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Flinux.slashdot.org%2Fstory%2F26%2F08%2F02%2F2019202%2Fgog-officially-expands-linux-support-with-native-galaxy-client-in-development%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://linux.slashdot.org/story/26/08/02/2019202/gog-officially-expands-linux-support-with-native-galaxy-client-in-development?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Unpopular opinion maybe, but I don't want many people switching to linux]]></title>
<description><![CDATA[I love linux, but I wouldn't want many people switching to it because of enshittification process. Windows was great because most people couldn't afford computers, and those who did made a real effort to understand how it worked. Same with Apple products. I believe it's because people want status...]]></description>
<link>https://tsecurity.de/de/3700361/linux-tipps/unpopular-opinion-maybe-but-i-dont-want-many-people-switching-to-linux/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3700361/linux-tipps/unpopular-opinion-maybe-but-i-dont-want-many-people-switching-to-linux/</guid>
<pubDate>Mon, 03 Aug 2026 10:26:04 +0200</pubDate>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I love linux, but I wouldn't want many people switching to it because of enshittification process. Windows was great because most people couldn't afford computers, and those who did made a real effort to understand how it worked. Same with Apple products. I believe it's because people want status of knowledge and they could achieve that easily if there's not much competition.</p> <p>When Windows and Apple were in early phases (pre 2005 era), it was awesome. People loved windows 95, 98, XP, MS Office, paint etc. Then IT boom arrived, and Windows unofficially became a compulsion. Suddenly people started rejecting new versions of Windows. XP was better than, 7 was better than 8, 8.1 was better than 8, Windows 10 had bloatware, 11 was too heavy and had extra hardware requirements. Basically just downfall of Windows.</p> <p>This is roughly the same story for Orkut <em>(maybe I'm exaggerating for Orkut)</em>, Facebook, Instagram, companies (Both IT and non-IT), even cities too. Just compare a big city with a small town.</p> <p>Linux is awesome and I can't see the same fate of Linux. I think it's awesome that many people can't use it. That maintains a higher standard of the Linux communities. IMO, enshittification by over-adoption is unpreventable and it sucks.</p> <p>What do you think?</p> <p>Edit 1: No, I don't want to gatekeep open source at all. I just want that people who really want to be a part of linux should do so but maintain a standard for that. Look at Reddit, you make a mistake and your post is removed. Standards are maintained and Reddit becomes awesome. Then look at Facebook. No/low standards of content quality to attract masses and look at how people react to "I got this info from Facebook"</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/cnv2"> /u/cnv2 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1ve5k8k/unpopular_opinion_maybe_but_i_dont_want_many/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1ve5k8k/unpopular_opinion_maybe_but_i_dont_want_many/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Distribution Release: AerynOS 2026.08]]></title>
<description><![CDATA[The DistroWatch news feed is brought to you by TUXEDO COMPUTERS.  The AerynOS team have published an update to the experimental distribution. Snapshot 2026.08 includes improved filesystem support, including providing OpenZFS for data pools: "From a development story arc perspective, AerynOS has b...]]></description>
<link>https://tsecurity.de/de/3700349/unix-server/distribution-release-aerynos-202608/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3700349/unix-server/distribution-release-aerynos-202608/</guid>
<pubDate>Mon, 03 Aug 2026 10:25:19 +0200</pubDate>
<content:encoded><![CDATA[The DistroWatch news feed is brought to you by <a href="https://www.tuxedocomputers.com/">TUXEDO COMPUTERS</a>.  The AerynOS team have published an update to the experimental distribution. Snapshot 2026.08 includes improved filesystem support, including providing OpenZFS for data pools: "From a development story arc perspective, AerynOS has been deliberately kept under a very tight leash over the last year, as we have focused on....]]></content:encoded>
</item>
<item>
<title><![CDATA[Need Help with Courses & Certs]]></title>
<description><![CDATA[I just started learning malware analysis for career development. The first issue I ran into is that, while there aren’t many resources on the topic, there are still enough to make choosing between them a bit overwhelming - which is a problem I tend to have whenever I self-study something new. Aft...]]></description>
<link>https://tsecurity.de/de/3700241/malware-trojaner-viren/need-help-with-courses-certs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3700241/malware-trojaner-viren/need-help-with-courses-certs/</guid>
<pubDate>Mon, 03 Aug 2026 10:23:24 +0200</pubDate>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I just started learning malware analysis for career development.</p> <p>The first issue I ran into is that, while there aren’t many resources on the topic, there are still enough to make choosing between them a bit overwhelming - which is a problem I tend to have whenever I self-study something new.</p> <p>After doing some research, these are the courses I have so far, ordered by what I think is the right progression (although I’m not entirely sure, which is why I’m here):<br> 1. Mandiant FLARE Malware Analysis Crash Course (my starting point - I’m currently on page 60, but honestly, it’s been pretty boring so far).<br> 2. Malware Analysis for Hedgehogs bundle.<br> 3. 0ffset.net Zero2Automated Advanced course.<br> I also have a few books that I can use as references whenever I need to dive deeper into a topic:<br> • Windows Internals Part 1 &amp; 2<br> • Windows Kernel Programming by Pavel Yosifovich</p> <p>What do you think about this roadmap? I’m fine with the prices unless there are better alternatives that genuinely offer stronger content rather than just being cheaper.</p> <p>As for certifications, I have no idea what’s worth pursuing. The only ones I’ve come across are GREM from SANS and PMAT from TCM.</p> <p>I’m mainly asking whether there are better options for both courses and certifications. I’d especially prefer something with plenty of hands-on labs and practical work. I tend to struggle with self-paced learning, and I get bored pretty quickly with courses that don’t involve much interaction, even when I’m genuinely interested in the subject.</p> <p>Thanks in advance - I really appreciate any advice.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/everythingisinlimbo"> /u/everythingisinlimbo </a> <br> <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1v7ed2b/need_help_with_courses_certs/">[link]</a></span>   <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1v7ed2b/need_help_with_courses_certs/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[GOG Officially Expands Linux Support With Native Galaxy Client In Development]]></title>
<description><![CDATA[Long-time Slashdot reader pyroclast shared this report from Linux Journal:

After years of requests from the Linux gaming community, GOG has officially confirmed that it is developing native Linux support for the GOG Galaxy launcher. The announcement marks one of the biggest shifts in the company...]]></description>
<link>https://tsecurity.de/de/3700099/it-security-nachrichten/gog-officially-expands-linux-support-with-native-galaxy-client-in-development/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3700099/it-security-nachrichten/gog-officially-expands-linux-support-with-native-galaxy-client-in-development/</guid>
<pubDate>Mon, 03 Aug 2026 10:17:50 +0200</pubDate>
<content:encoded><![CDATA[Long-time Slashdot reader pyroclast shared this report from Linux Journal:

After years of requests from the Linux gaming community, GOG has officially confirmed that it is developing native Linux support for the GOG Galaxy launcher. The announcement marks one of the biggest shifts in the company's history and signals a stronger commitment to Linux as a first-class gaming platform. While GOG has offered DRM-free Linux game downloads since 2014, its Galaxy launcher has remained exclusive to Windows and macOS — until now. Although the company has not announced a release date, GOG says Linux has become a major area of investment, with development already underway... 

Unlike the web-based game downloads that Linux users already have access to, GOG Galaxy serves as a full-featured game management application. The launcher currently offers features including: 
 — Automatic game installation and updates
 — Cloud save synchronization
 — Achievement tracking
 — Playtime statistics
 — Game library organization
 — Integrated storefront browsing
 — Friends lists and social features
 — Cross-platform launcher integration 
Today, Linux users typically access these capabilities through community projects such as Heroic Games Launcher, Lutris, or Bottles. A native Galaxy client would provide an officially supported alternative with direct integration into GOG's ecosystem... 

For GOG, supporting Linux more fully aligns with its philosophy of giving users greater control over their purchased games.

 

The article argues this news shows Linux growing in importance for game publishers. After the rapid adoption of Valve's Steam Deck, there's also been continuous improvements to Proton and Vulkan, increasing hardware compatibility, and native Linux game development efforts. 

"As more companies recognize the platform's growth, Linux users can expect broader support from game publishers and software developers alike."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=GOG+Officially+Expands+Linux+Support+With+Native+Galaxy+Client+In+Development%3A+https%3A%2F%2Flinux.slashdot.org%2Fstory%2F26%2F08%2F02%2F2019202%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Flinux.slashdot.org%2Fstory%2F26%2F08%2F02%2F2019202%2Fgog-officially-expands-linux-support-with-native-galaxy-client-in-development%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://linux.slashdot.org/story/26/08/02/2019202/gog-officially-expands-linux-support-with-native-galaxy-client-in-development?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[JetBrains open sources KotlinLLM runtime code generator]]></title>
<description><![CDATA[KotlinLLM, a research prototype for delegating runtime logic to a large language model (LLM) from Kotlin code, is now going open source and public, JetBrains announced.



Revealed July 28, KotlinLLM is an IntelliJ IDEA plugin prototype for experimenting with LLM-driven “Smart macros” in Kotlin, ...]]></description>
<link>https://tsecurity.de/de/3699901/ai-nachrichten/jetbrains-open-sources-kotlinllm-runtime-code-generator/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699901/ai-nachrichten/jetbrains-open-sources-kotlinllm-runtime-code-generator/</guid>
<pubDate>Mon, 03 Aug 2026 00:16:50 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">KotlinLLM, a research prototype for delegating runtime logic to a <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html" data-type="link" data-id="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html">large language model</a> (LLM) from <a href="https://www.infoworld.com/article/2256390/what-is-kotlin-the-java-alternative-explained.html" data-type="link" data-id="https://www.infoworld.com/article/2256390/what-is-kotlin-the-java-alternative-explained.html">Kotlin</a> code, is now going open source and public, JetBrains announced.</p>



<p class="wp-block-paragraph">Revealed <a href="https://blog.jetbrains.com/research/2026/07/kotlinllm-open-source/">July 28</a>, <a href="https://github.com/JetBrains-Research/kotlinllm-plugin">KotlinLLM</a> is an IntelliJ IDEA plugin prototype for experimenting with LLM-driven “Smart macros” in Kotlin, enabling code generation, runtime updates, and hot-reloading. In software engineering, LLMs are commonly used during development for code completion, code generation, and program comprehension, JetBrains noted, but using an LLM at run time of a compiled application is much less common. The existing options for doing this have the following trade-offs, according to JetBrains:</p>



<ul class="wp-block-list">
<li>Direct runtime delegation is slow, non-deterministic, and costly, and makes the application depend on an LLM service at run time.</li>



<li>External agent workflows<strong> </strong>keep the generated logic outside the codebase, where it is harder to review, test, and ship.</li>



<li>Most prior work (<a href="https://arxiv.org/abs/2405.08965" target="_blank" rel="noreferrer noopener">byLLM</a>, <a href="https://openreview.net/forum?id=E7ZZRnBQU7" target="_blank" rel="noreferrer noopener">nightjar</a>, <a href="https://arxiv.org/abs/2408.01055" target="_blank" rel="noreferrer noopener">Healer</a>) targets interpreted languages like Python, not a compiled, statically typed language like Kotlin.</li>
</ul>



<p class="wp-block-paragraph">KotlinLLM addresses these limitations in three ways, JetBrains said: </p>



<ul class="wp-block-list">
<li>The call site shows that a feature is LLM-backed, so it is visible in code review.</li>



<li>Generated behavior is saved as an ordinary Kotlin source, not kept only in the runtime session. It can be committed, reviewed, tested, and distributed like any other code.</li>



<li>Once generated, the code runs as plain Kotlin without the plugin. For scenarios that are already covered, there is no further LLM call, so no added latency or cost, and the result is reproducible.</li>
</ul>



<p class="wp-block-paragraph">KotlinLLM is open source under Apache License 2.0. The repository contains the KotlinLLM IntelliJ IDEA plugin, the Smart macro API, and example projects. </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical Ruflo flaw lets attackers hijack AI agents through exposed MCP bridge]]></title>
<description><![CDATA[A critical vulnerability in the open-source AI agent platform Ruflo could allow unauthenticated attackers to take control of enterprise AI environments by exploiting an exposed Model Context Protocol (MCP) bridge, according to research published by Noma Security.



The flaw, tracked as CVE-2026-...]]></description>
<link>https://tsecurity.de/de/3699902/ai-nachrichten/critical-ruflo-flaw-lets-attackers-hijack-ai-agents-through-exposed-mcp-bridge/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699902/ai-nachrichten/critical-ruflo-flaw-lets-attackers-hijack-ai-agents-through-exposed-mcp-bridge/</guid>
<pubDate>Mon, 03 Aug 2026 00:16:50 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">A critical vulnerability in the open-source AI agent platform Ruflo could allow unauthenticated attackers to take control of enterprise AI environments by exploiting an exposed Model Context Protocol (MCP) bridge, according to research published by Noma Security.</p>



<p class="wp-block-paragraph">The flaw, tracked as <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-59726" target="_blank" rel="noreferrer noopener">CVE-2026-59726</a> and dubbed RufRoot, carries a maximum CVSS score of 10.0 and affects Ruflo versions prior to 3.16.3, Noma Security wrote in a blog <a href="https://noma.security/blog/rufroot-the-mcp-bridge-vulnerability-that-turns-agents-into-rogue-admins-cve-2026-59726/" target="_blank" rel="noreferrer noopener">post</a>.</p>



<p class="wp-block-paragraph">The vulnerability allows attackers to execute arbitrary code, steal large language model (LLM) API keys, access user conversations, hijack AI agents, and manipulate the platform’s persistent AI memory through a single HTTP request.</p>



<p class="wp-block-paragraph">The researchers said the issue stems from an unauthenticated MCP Bridge that is exposed by default and provides direct access to the tools AI agents use to interact with enterprise systems.</p>



<p class="wp-block-paragraph">“The MCP Bridge isn’t a random auxiliary debug interface; rather, it is Ruflo’s central nervous system. Every tool call, every agent action, every memory operation goes through the MCP bridge,” the researchers wrote. “Mistakenly giving unauthenticated access to the MCP Bridge means giving unauthenticated access to everything.”</p>



<h2 class="wp-block-heading">One request leads to full compromise</h2>



<p class="wp-block-paragraph">According to Noma Security, Ruflo’s built-in MCP Bridge is an Express.js server that handles every tool invocation made by AI agents. The bridge exposes 233 tools covering shell access, database operations, agent management, and memory storage.</p>



<p class="wp-block-paragraph">The researchers said the bridge’s /mcp endpoint accepts tool invocations without authentication. In a proof-of-concept demonstration, they used Ruflo’s terminal_execute tool to obtain command execution inside the container with a single HTTP request.</p>



<p class="wp-block-paragraph">“Because the MCP Bridge requires direct access to the underlying system resources to execute these commands, it creates a high-stakes security boundary,” the researchers wrote. “When an attacker can reach this endpoint without authentication, they gain a direct pipeline to the underlying host infrastructure.”</p>



<p class="wp-block-paragraph">The researchers said they were able to enumerate available tools, steal LLM provider API keys from environment variables, deploy attacker-controlled AI agent swarms, retrieve user conversations stored in MongoDB, and establish persistence.</p>



<p class="wp-block-paragraph">The researchers also demonstrated what they described as AI memory poisoning by inserting malicious entries into Ruflo’s AgentDB pattern store, allowing future AI responses to incorporate attacker-controlled instructions.</p>



<p class="wp-block-paragraph">Every stage of the attack chain was validated against a default Ruflo deployment running on AWS EC2, according to the researchers.</p>



<h2 class="wp-block-heading">Beyond Ruflo: A broader MCP security challenge</h2>



<p class="wp-block-paragraph">While the authentication flaw is specific to Ruflo, security practitioners say the research highlights broader risks surrounding AI orchestration platforms and MCP infrastructure.</p>



<p class="wp-block-paragraph">“MCP adoption has outpaced the security defaults built into a lot of orchestration tools,” said Amit Jena, AI Development Manager at Kanerika. “These platforms shipped fast, prioritized ease of setup over authentication, and assumed the network boundary would protect them. That assumption breaks down once the tool sits on a server reachable from a corporate network, which is increasingly where enterprises are running them.”</p>



<p class="wp-block-paragraph">Jena said the research also points to a security concern that extends beyond a single product.</p>



<p class="wp-block-paragraph">“The memory poisoning problem isn’t product-specific, and that’s the part worth paying attention to,” he said. “Any platform that gives agents a persistent, writable memory store needs to treat that store as a security boundary: who can write to it, and can you tell system-generated memory from memory an attacker planted. Very few platforms are doing that today.”</p>



<p class="wp-block-paragraph">He added that, unlike traditional persistence techniques, poisoned AI memory can remain inside a trusted data store and continue influencing future agent behavior after the original intrusion has ended.</p>



<h2 class="wp-block-heading">Patch addresses attack chain</h2>



<p class="wp-block-paragraph">Noma Security said it disclosed the vulnerability responsibly to Ruflo, which <a href="https://github.com/ruvnet/ruflo/security/advisories/GHSA-c4hm-4h84-2cf3" target="_blank" rel="noreferrer noopener">released</a> fixes within hours along with a public security advisory.</p>



<p class="wp-block-paragraph">According to the researchers, the updated release changes the MCP Bridge to bind to the loopback interface by default and fail closed if administrators attempt to expose it publicly without configuring authentication.</p>



<p class="wp-block-paragraph">Noma Security also urged organizations running Ruflo to immediately close firewall access to ports 3001 and 27017, rotate all LLM API keys, audit AgentDB for malicious entries because “a patched redeploy alone doesn’t undo poisoning,” and inspect MongoDB for signs of tampering.</p>



<p class="wp-block-paragraph">Jena said organizations should also review how AI orchestration platforms are deployed and managed.</p>



<p class="wp-block-paragraph">“If a component can execute a shell command or query a database, it gets the same authentication, network segmentation, and logging as any other privileged system in the environment,” he said. He also recommended that security teams inventory the tools exposed through AI agent deployments, audit persistent AI memory separately from software patching, and narrowly scope and rotate LLM provider credentials following any suspected exposure.</p>



<p class="wp-block-paragraph"><em>The article originally appeared on <a href="https://www.csoonline.com/article/4203408/critical-ruflo-flaw-lets-attackers-hijack-ai-agents-through-exposed-mcp-bridge.html">CSO</a>.</em></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How AI can improve site reliability engineering]]></title>
<description><![CDATA[One percent of AI-active developers now generate 46 times more AI-written lines of code per day than the median active user, according to the Cursor Developer Habits Report. The bottleneck is no longer writing software. It is understanding what happens after that software ships.



Every new serv...]]></description>
<link>https://tsecurity.de/de/3699904/ai-nachrichten/how-ai-can-improve-site-reliability-engineering/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699904/ai-nachrichten/how-ai-can-improve-site-reliability-engineering/</guid>
<pubDate>Mon, 03 Aug 2026 00:16:50 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">One percent of AI-active developers now generate 46 times more AI-written lines of code per day than the median active user, according to the <a href="https://cursor.com/insights" data-type="link" data-id="https://cursor.com/insights">Cursor Developer Habits Report</a>. The bottleneck is no longer writing software. It is understanding what happens after that software ships.</p>



<p class="wp-block-paragraph">Every new service, dependency, feature flag, generated abstraction, and deployment path increases the number of ways a production system can fail. AI has compressed the time it takes to create that complexity. It has not compressed the time it takes to understand it.</p>



<p class="wp-block-paragraph">The result is a production environment that changes faster than engineers can rebuild a mental model of it. AI can help in this situation because most debugging practices were designed for a slower world.</p>



<h2 class="wp-block-heading">Debugging yesterday and today</h2>



<p class="wp-block-paragraph">For decades, debugging was largely a spatial problem. A failure in Service A belonged to the team that owned Service A. They knew the deployment history, the operational quirks, the useful log queries, and the odd behaviors that never made it into the runbook. Incident response reflected that assumption. Teams owned services. Runbooks were scoped to those services. On-call rotations mirrored organizational boundaries.</p>



<p class="wp-block-paragraph">That model still works when failures stay local. If a deployment introduces a memory leak, or a bad configuration causes a service to crash, the symptom and the cause usually live in the same place. The owning team can investigate, identify the issue, and restore service. Those incidents are becoming a smaller share of production failures.</p>



<p class="wp-block-paragraph">AI-generated code is not inherently less reliable than human-written code. The change is <a href="https://www.infoworld.com/article/4183153/why-ai-coding-debt-is-different.html" data-type="link" data-id="https://www.infoworld.com/article/4183153/why-ai-coding-debt-is-different.html">volume and speed</a>. Teams can now introduce more code, touch more systems at once, and evolve architectures faster than before. As systems become more interconnected, failures increasingly surface somewhere other than where they start.</p>



<p class="wp-block-paragraph">A single-hop incident is local. The service experiencing the failure is also the service causing it. Investigation stays inside one team’s boundary.</p>



<p class="wp-block-paragraph">A multi-hop incident looks different. The checkout API begins timing out. Nothing appears wrong inside checkout. Latency is normal. Error rates are low. The actual problem is a queue consumer silently dropping messages because a schema change deployed two days earlier was only partially backward compatible. The queue team sees healthy throughput. The data platform team never receives a page because nothing in its service violates an alert threshold. Every team is right about its own system, yet nobody can explain why customers cannot complete purchases.</p>



<p class="wp-block-paragraph">The problem is not a lack of evidence. Modern production systems produce more telemetry than any human can use during an incident. The problem is knowing which evidence matters, which signals are coincidental, and how separate clues connect into a causal chain.</p>



<h2 class="wp-block-heading">The role of AI in production ops</h2>



<p class="wp-block-paragraph">That changes the role AI should play. AI should not be treated as a magic on-call engineer. A frontier model does not know your architecture. It does not remember prior incidents. It does not know which dashboards lie, which services fail together, what changed last week, or which dependencies matter most. On its own, it reasons inside a vacuum.</p>



<p class="wp-block-paragraph">The useful version of AI in production is more specific. It can assemble context, test hypotheses, trace dependencies, compare the current incident against past incidents, and rule out explanations that do not fit the timing or blast radius. It can do the work that currently eats the first 20 minutes of an incident: gathering evidence, checking recent changes, mapping dependencies, and narrowing the search space.</p>



<p class="wp-block-paragraph">Humans still make the decisions that require judgment. They decide whether the evidence is strong enough to act, whether a rollback is worth the risk, whether to wake another team, and whether the safest move is mitigation or deeper investigation. But they should not have to spend half the incident reconstructing a system the organization already operates.</p>



<p class="wp-block-paragraph">That is the larger productivity shift.</p>



<p class="wp-block-paragraph">If AI can absorb more of the troubleshooting tax, engineers can focus on the work that actually compounds. They can simplify fragile architectures. They can improve instrumentation in the places where incidents repeatedly go dark. They can design safer degradation paths, sharper alerts, better rollback patterns, and evals that catch semantic failures before customers do. They can feed production knowledge back into development, so code assistants and review processes understand which services are risky, which patterns have caused outages, and which dependencies deserve extra scrutiny.</p>



<p class="wp-block-paragraph">This is the work engineers rarely get enough time to do because they are stuck resolving the same classes of incidents again and again.</p>



<h2 class="wp-block-heading">Letting the engineers engineer</h2>



<p class="wp-block-paragraph">The goal is not to remove engineers from production. The goal is to stop wasting their judgment on work the system should already be doing. AI should make incidents shorter, but that is only the first-order benefit. The larger benefit is giving senior engineers more time to prevent future incidents instead of being pulled into every confusing one.</p>



<p class="wp-block-paragraph">As AI accelerates software creation, production operations need the same kind of acceleration on the other side. Not just faster debugging. Better allocation of human attention.</p>



<p class="wp-block-paragraph">The AI code avalanche will not be managed by asking engineers to troubleshoot forever at machine speed. It will be managed by making production systems more legible, more resilient, and less dependent on whichever expert happens to be awake.</p>



<p class="wp-block-paragraph"><em>—</em></p>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/blogs/new-tech-forum"><strong><em>New Tech Forum</em></strong></a><em><strong> provides a venue for technology leaders—including vendors and other outside contributors—to explore and discuss emerging enterprise technology in unprecedented depth and breadth. The selection is subjective, based on our pick of the technologies we believe to be important and of greatest interest to InfoWorld readers. InfoWorld does not accept marketing collateral for publication and reserves the right to edit all contributed content. Send all </strong></em><em><strong>inquiries to </strong></em><a href="mailto:doug_dineley@foundryco.com"><strong><em>doug_dineley@foundryco.com</em></strong></a><em><strong>.</strong></em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[JDK 27: The new features of Java 27]]></title>
<description><![CDATA[Java Development Kit 27, an Oracle-driven, planned update to standard Java, is set to reach its initial release candidate (RC) stage on August 6. This update has features ranging from making the Garbage-First (G1) garbage collector the default collector and adding structured concurrency to simpli...]]></description>
<link>https://tsecurity.de/de/3699910/ai-nachrichten/jdk-27-the-new-features-of-java-27/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699910/ai-nachrichten/jdk-27-the-new-features-of-java-27/</guid>
<pubDate>Mon, 03 Aug 2026 00:16:50 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph"><a href="https://openjdk.org/projects/jdk/27/">Java Development Kit 27</a>, an Oracle-driven, planned update to standard Java, is set to reach its initial release candidate (RC) stage on August 6. This update has features ranging from making the Garbage-First (G1) garbage collector the default collector and adding structured concurrency to simplify concurrent programming. JDK 27 is currently in rampdown phase 2, with the feature set now frozen. </p>



<p class="wp-block-paragraph">Overall, there are nine features listed on what is described as a reference implementation of JDK 27. The first five features include making G1 the default garbage collector, post-quantum hybrid key exchange for TLS 1.3, lazy constants, structured concurrency, and primitive types in patterns, <code>instanceof</code>, and <code>switch</code>. The next four include compact object headers, JFR (JDK Flight Recorder) in-process data redaction, a vector API, and PEM (Privacy-Enhanced Mail) encodings for cryptographic objects.</p>



<p class="wp-block-paragraph">The final release candidate stage for JDK 27 follows on August 20, with general availability scheduled for September 15. Early-access builds for JDK 27 can be found at <a href="https://jdk.java.net/27/">jdk.java.net</a>.</p>



<p class="wp-block-paragraph">With JDK 27, <a href="https://openjdk.org/jeps/523">G1 becomes the default garbage collector</a> in all environments, rather than just in server environments. Goals are to ensure that the HotSpot JVM will always select G1 and that performance including throughput, latency, memory footprint, and startup time does not degrade significantly.</p>



<p class="wp-block-paragraph">With <a href="https://openjdk.org/jeps/527" data-type="link" data-id="https://openjdk.org/jeps/527">post-quantum hybrid key exchange for TLS 1.3</a>, the goal is to enhance the security of Java applications that require secure network communication by implementing hybrid key exchange algorithms. Such algorithms defend against future quantum computing attacks by combining a quantum-resistant algorithm with a traditional algorithm.</p>



<p class="wp-block-paragraph"><a href="https://openjdk.org/jeps/531">Lazy constants</a> introduces an API for objects that hold unmodifiable data. Lazy constants are treated as true constants by the JVM, enabling the same performance optimizations that are enabled by declaring a field <code>final</code>. Compared to <code>final</code> fields, however, lazy constants offer greater flexibility in the timing of their initialization. This feature is in a third preview. </p>



<p class="wp-block-paragraph">The goal of <a href="https://openjdk.org/jeps/532" data-type="link" data-id="https://openjdk.org/jeps/532">primitive types in patterns, <code>instanceof</code>, and <code>switch</code></a> is to enhance pattern matching by allowing primitive types in all pattern contexts, and to extend <code>instanceof</code><strong> </strong>and <code>switch</code> to work with all primitive types. This feature is in a fifth preview. </p>



<p class="wp-block-paragraph"><a href="https://openjdk.org/jeps/533">Structured concurrency</a> simplifies concurrent programming by introducing an API that treats groups of related tasks running in different threads as single units of work. Goals include streamlining error handling and cancellation, improving reliability, and enhancing observability. Structured concurrency is in its seventh preview. </p>



<p class="wp-block-paragraph">JDK 27 makes <a href="https://openjdk.org/jeps/534">compact object headers</a> the default object header layout in the HotSpot JVM. Compact object headers reduce object headers from 96 bits down to 64 bits on 64-bit architectures, reducing heap size, improving deployment density, and increasing data locality. </p>



<p class="wp-block-paragraph"><a href="https://openjdk.org/jeps/536">JFR data in-process redaction</a> allows users to redact command-line arguments and the initial values of environment variables and system properties in JFR recordings. JFR recording files may contain events that include sensitive data, such as secrets in command-line arguments, access tokens in environment variables, and passwords in system properties. This data is (optionally) redacted before it leaves the process, so that sensitive information does not leak.</p>



<p class="wp-block-paragraph">The <a href="https://openjdk.org/jeps/537">vector API</a> introduces an API to express vector computations that reliably compile at run time to optimal vector instructions on supported CPUs, thus achieving better performance than equivalent scalar computations. This is an incubating API in its 12th incubation.</p>



<p class="wp-block-paragraph"><a href="https://openjdk.org/jeps/538" data-type="link" data-id="https://openjdk.org/jeps/538">PEM encodings of cryptographic objects</a> introduces an API for encoding objects that represent cryptographic keys, certificates, and certificate revocation lists in the PEM transport format, and for decoding from PEM back into objects. This is a preview API. </p>



<p class="wp-block-paragraph">JDK 27 is a short-term feature release (<a href="https://www.oracle.com/java/technologies/java-se-support-roadmap.html" data-type="link" data-id="https://www.oracle.com/java/technologies/java-se-support-roadmap.html">non-LTS</a>) that will receive six months of support from Oracle. Its predecessor, <a href="https://www.infoworld.com/article/4050993/jdk-26-the-new-features-in-java-26.html">JDK 26</a>, also a short-term release, became generally available on March 17. </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why open source matters in an AI world]]></title>
<description><![CDATA[I’m an old Borland guy. I started using Borland tools in the early 1990s, from Turbo Pascal through Delphi. I dabbled in Paradox. I even tried to stick with Borland Office. I wandered through the Inprise years, and the Kylix endeavor, and I was actually a Borland employee during the CodeGear/Emba...]]></description>
<link>https://tsecurity.de/de/3699912/ai-nachrichten/why-open-source-matters-in-an-ai-world/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699912/ai-nachrichten/why-open-source-matters-in-an-ai-world/</guid>
<pubDate>Mon, 03 Aug 2026 00:16:50 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">I’m an old Borland guy. I started using Borland tools in the early 1990s, from Turbo Pascal through Delphi. I dabbled in Paradox. I even tried to stick with Borland Office. I wandered through the <a href="https://en.wikipedia.org/wiki/Borland#Renaming_to_Inprise_Corporation">Inprise years</a>, and the <a href="https://en.wikipedia.org/wiki/Borland_Kylix">Kylix endeavor</a>, and I was actually a Borland employee during the <a href="https://en.wikipedia.org/wiki/CodeGear">CodeGear</a>/<a href="https://en.wikipedia.org/wiki/Embarcadero_Technologies">Embarcadero</a> migrations. </p>



<p class="wp-block-paragraph">You could write a book about the rise and fall of Borland. Suffice it to say that things got dodgy when Borland strayed from its focus on developer tools, and they never really recovered.  </p>



<p class="wp-block-paragraph">One of Borland’s missteps came with the open-sourcing of <a href="https://en.wikipedia.org/wiki/InterBase" data-type="link" data-id="https://en.wikipedia.org/wiki/InterBase">InterBase</a>, its RDBMS. In the early 2000s, <a href="https://www.infoworld.com/article/2262355/what-is-open-source-software-open-source-and-foss-explained.html" data-type="link" data-id="https://www.infoworld.com/article/2262355/what-is-open-source-software-open-source-and-foss-explained.html">open-source software</a> emerged from the academic shadows and began to commercialize. With the IPO of <a href="https://en.wikipedia.org/wiki/Red_Hat">Red Hat</a>, everyone was jumping on the Linux and open-source bandwagon. Borland made their move into this arena with InterBase. </p>



<p class="wp-block-paragraph">Two things soon happened. First, the <a href="https://www.firebirdsql.org/en/start/" data-type="link" data-id="https://www.firebirdsql.org/en/start/">Firebird</a> project was created as a fork of the InterBase source. Second, Borland retreated from the open-source project and reincorporated InterBase as a closed-source product. One might mark this as the beginning of developers losing faith in Borland.</p>



<h2 class="wp-block-heading">It was developers, then</h2>



<p class="wp-block-paragraph">And it always ends up being about the developers, right? I mean, who can forget a <a href="https://www.youtube.com/watch?v=8fcSviC7cRM" data-type="link" data-id="https://www.youtube.com/watch?v=8fcSviC7cRM">sweaty, maniacal Steve Ballmer jumping around</a> onstage screaming “Developers, developers, developers”? For many years, Microsoft was notoriously anti-open-source, but even they eventually recognized the power of open-sourcing major tools like <a href="https://www.infoworld.com/article/2264488/what-is-the-net-framework-microsofts-answer-to-java.html" data-type="link" data-id="https://www.infoworld.com/article/2264488/what-is-the-net-framework-microsofts-answer-to-java.html">.NET</a> and <a href="https://www.infoworld.com/article/2335960/what-is-visual-studio-code-microsofts-extensible-code-editor.html" data-type="link" data-id="https://www.infoworld.com/article/2335960/what-is-visual-studio-code-microsofts-extensible-code-editor.html">Visual Studio Code</a>. </p>



<p class="wp-block-paragraph">But Microsoft didn’t do that out of the goodness of their heart — they clearly saw those tools as a means to bringing developers to their Azure cloud platform. When Amazon launched AWS, they clearly were sidestepping the IT procurement process, making it easy for developers to spin up VMs with just a credit card. Apple shipped the iPhone without an SDK, expecting developers to figure things out.  That didn’t last long, and they soon course-corrected.</p>



<p class="wp-block-paragraph">Open source is great — but always remember that it offers benefits to companies beyond the software development process. Borland fumbled the ball with their open source efforts, but it soon became obvious how to leverage open source for corporate success. Or, as Stephen O’Grady argues in his book <a href="https://thenewkingmakers.com/" data-type="link" data-id="https://thenewkingmakers.com/">The New Kingmakers</a>, developers are the ones who decide what technologies succeed. Companies quickly recognized that courting developers with open-source software and other free resources was the way to bring them into the fold. Because developers write all the software that makes a tool, platform, or application successful, it’s always a smart move to make developers happy.</p>



<h2 class="wp-block-heading">It’s developers, now</h2>



<p class="wp-block-paragraph">AI hasn’t changed this equation. The latest incarnation can be seen from the company Nvidia. We think of Nvidia as a hardware company, cranking out GPUs as fast as they can. But GPUs don’t sell unless there is software that runs on them. Coding against a GPU in plain C++ was miserable, so Nvidia developed <a href="https://www.infoworld.com/article/2256401/what-is-cuda-parallel-programming-for-gpus.html" data-type="link" data-id="https://www.infoworld.com/article/2256401/what-is-cuda-parallel-programming-for-gpus.html">CUDA</a>, a proprietary layer that made building for their hardware relatively easy. And the more CUDA is used, the more people depend on Nvidia hardware. This is not an accident. As Nader Khalil, Nvidia’s Director of Developer Technologies, told me, “You have to make the best hardware that you can, and you have to make the best software to utilize it. Software is the part of the stack that touches the user.”</p>



<p class="wp-block-paragraph">Today, of course, developers are all about agentic coding, and Nvidia is eyeball deep in that world. As such, Nvidia provides a set of open-weight models called <a href="https://developer.nvidia.com/topics/ai/nemotron" data-type="link" data-id="https://developer.nvidia.com/topics/ai/nemotron">Nemotron</a> that developers can use, inspect, and fine-tune for their own purposes. And of course Nemotron runs really well on top of CUDA. </p>



<p class="wp-block-paragraph">Nvidia, like Microsoft and Amazon, is doing this because they want to sell their products to more people. Nvidia can’t make enough GPUs for Anthropic and OpenAI to keep up with demand, but they also want to sell GPUs to us developers by enabling us to run our own models on our own computers. </p>



<p class="wp-block-paragraph">The open source movement began with pure hearts and noble ideals. But the reality of open source is that its nobility is easily melded with business needs. Open source software is really the bait — and developers are the real catch.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic rejects open-weight AI bans, calls for China chip controls and safety tests]]></title>
<description><![CDATA[Anthropic CEO Dario Amodei has argued that policymakers should keep lower-risk open-weight AI accessible while placing stricter safeguards around frontier systems, including mandatory testing and limits on China’s access to advanced computing and model capabilities.



In a post outlining Anthrop...]]></description>
<link>https://tsecurity.de/de/3699913/ai-nachrichten/anthropic-rejects-open-weight-ai-bans-calls-for-china-chip-controls-and-safety-tests/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699913/ai-nachrichten/anthropic-rejects-open-weight-ai-bans-calls-for-china-chip-controls-and-safety-tests/</guid>
<pubDate>Mon, 03 Aug 2026 00:16:50 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Anthropic CEO Dario Amodei has argued that policymakers should keep lower-risk open-weight AI accessible while placing stricter safeguards around frontier systems, including mandatory testing and limits on China’s access to advanced computing and model capabilities.</p>



<p class="wp-block-paragraph">In a <a href="https://www.anthropic.com/news/position-open-weights-models" target="_blank" rel="noreferrer noopener">post</a> outlining Anthropic’s position, Amodei said broad restrictions, including bans on Chinese open-weight models used by US businesses, would not address his main national security concerns. Instead, he pointed to the possibility of authoritarian governments surpassing the US in advanced AI, as well as cyber, biological, and alignment risks posed by increasingly capable systems.</p>



<p class="wp-block-paragraph">Amodei also called for action against <a href="https://www.computerworld.com/article/4189347/anthropic-accuses-alibaba-of-using-25000-fake-accounts-to-scrape-claude-ai-2.html">industrial-scale model distillation</a>, which he said allows Chinese developers to improve their models with less computing power than would be needed to train comparable systems from scratch.</p>



<p class="wp-block-paragraph">The statement followed criticism of Anthropic for not signing an industry letter backed by Nvidia, Microsoft, Meta, IBM, Mistral, Hugging Face and other technology companies urging policymakers to avoid premature restrictions on <a href="https://www.computerworld.com/article/4172545/why-open-ai-models-are-gaining-ground-on-llms.html">open-weight models</a>.</p>



<p class="wp-block-paragraph">The letter said that open weights could broaden access to AI, intensify competition, and enable organizations to adapt and deploy models without relying on a single provider. Amodei agreed with parts of that case but disputed claims that openness inherently improves safety research or gives defenders an advantage over attackers.</p>



<p class="wp-block-paragraph">He said regulation should be based on a model’s capabilities and risks rather than whether its weights are openly available. Under that approach, sufficiently capable open and closed models would undergo <a href="https://www.cio.com/article/4168122/us-government-agency-to-safety-test-frontier-ai-models-before-release.html">testing before release</a>.</p>



<h2 class="wp-block-heading">Conditional support</h2>



<p class="wp-block-paragraph">Analysts said Anthropic had moved closer to industry consensus by rejecting blanket bans, but its support remained more limited than the approach backed by many major technology companies.</p>



<p class="wp-block-paragraph"><a href="https://my.idc.com/getdoc.jsp?containerId=PRF005848" target="_blank" rel="noreferrer noopener">Deepika Giri</a>, head of research for AI, analytics, and data at IDC, said the Nvidia-backed letter presented open weights as strategic infrastructure that should remain broadly accessible, in contrast with Anthropic’s more restrictive position.</p>



<p class="wp-block-paragraph">Amodei’s statement clarified that Anthropic supports open-weight models only under certain conditions, a stance that could also help the company preserve its competitive advantages as a proprietary model provider focused on compliance and tighter controls, according to <a href="https://omdia.tech.informa.com/authors/lian-jye-su">Lian Jye Su</a>, chief analyst at Omdia.</p>



<p class="wp-block-paragraph">The statement was “a real olive branch” to supporters of open-weight models, according to <a href="https://pareekh.com/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, CEO of Pareekh Consulting. But he said the disagreement had shifted from whether such models should be released to where policymakers should draw the line.</p>



<p class="wp-block-paragraph">“Anthropic still thinks that once a model gets powerful enough, releasing its weights publicly is riskier than keeping it locked behind an app, because you can never take it back or add safety fixes later,” Jain said.</p>



<h2 class="wp-block-heading">Will the controls work?</h2>



<p class="wp-block-paragraph">Analysts differed over whether Anthropic’s proposed controls would achieve their aims without creating new barriers for smaller AI developers.</p>



<p class="wp-block-paragraph">Jain said chip restrictions and measures against illicit model distillation would mainly affect model developers and infrastructure providers, rather than enterprises using models already on the market. Mandatory safety testing, however, could raise development costs and reduce the number of advanced open-weight models available.</p>



<p class="wp-block-paragraph">“Testing is expensive and time-consuming, and so, giant, well-funded companies like Anthropic, Google and OpenAI can afford it,” Jain said. Smaller developers seeking to release cutting-edge open-weight models could struggle to meet the same requirements, he added.</p>



<p class="wp-block-paragraph">The additional testing and screening could also restrict the number of open-weight models available to enterprises, according to Su. He said the requirements could weaken some of their principal benefits, including lower costs, reduced vendor dependence and community-led development.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/anandjoshi1/">Anand Joshi</a>, managing director of market research firm JP Data, questioned whether limiting China’s access to advanced chips would materially slow its AI development, arguing that Chinese companies had shown they could build highly capable models with less computing power. He supported action against illicit distillation, however, saying safeguards were needed to prevent developers from reproducing the capabilities of other models without authorization.</p>



<p class="wp-block-paragraph">The impact on most enterprise users could remain limited if less capable models were exempted, Jain said. Businesses deploying models that fall below the proposed testing threshold would probably face little additional cost.</p>



<h2 class="wp-block-heading">How CIOs should choose</h2>



<p class="wp-block-paragraph">Giri said CIOs should assess models according to their capabilities rather than whether they are open, and should demand independent testing, clear licensing, model documentation and accountability for monitoring and incident response.</p>



<p class="wp-block-paragraph">“Mandatory safety testing should be triggered by a model’s demonstrated capabilities, not its size or training cost,” Jain said, particularly when a system could significantly assist cyberattacks, biological misuse, or autonomous harmful actions.</p>



<p class="wp-block-paragraph">Before deployment, CIOs should seek independent evaluations, detailed model documentation, security test results and information about the model’s software supply chain, he added. <a href="https://www.forrester.com/analyst-bio/charlie-dai/BIO5344" target="_blank" rel="noreferrer noopener">Charlie Dai</a>, principal analyst at Forrester, said that assessment should include documented red-team results, model provenance, disclosures about training and fine-tuning, and evidence of independent testing against recognized safety benchmarks.</p>



<p class="wp-block-paragraph"><em>The article originally appeared on <a href="https://www.computerworld.com/article/4202178/anthropic-rejects-open-weight-ai-bans-calls-for-china-chip-controls-and-safety-tests.html">ComputerWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Lessons from Tesla’s AI strategy]]></title>
<description><![CDATA[For years, the public cloud was the default for new workloads because its convenience, elasticity, and breadth of services made sense. However, as AI’s strategic importance grows, its economics and infrastructure are changing. Tesla is one of the clearest examples of a company deciding that AI is...]]></description>
<link>https://tsecurity.de/de/3699914/ai-nachrichten/lessons-from-teslas-ai-strategy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699914/ai-nachrichten/lessons-from-teslas-ai-strategy/</guid>
<pubDate>Mon, 03 Aug 2026 00:16:50 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">For years, the public cloud was the default for new workloads because its convenience, elasticity, and breadth of services made sense. However, as AI’s strategic importance grows, its economics and infrastructure are changing. Tesla is one of the clearest examples of a company deciding that AI is too important, too expensive, and too central to its business to leave largely in the hands of a third-party cloud provider.</p>



<p class="wp-block-paragraph"> At the center of <a href="https://247wallst.com/investing/2026/07/11/forget-ai-hyperscalers-tesla-may-own-the-most-valuable-ai-application/">Tesla’s strategy is a simple idea.</a> If AI is key to how you build your products, run your business, and define your future, the infrastructure that powers AI becomes a strategic asset. It is no longer just plumbing but part of the product itself. Tesla’s models, databases, applications, and workflows increasingly rely on infrastructure that is built, hosted, and managed by Tesla. That means the company has direct control over the hardware, the software stack, data movement, performance tuning, and security posture. For a company that depends on AI to support autonomy, robotics, manufacturing intelligence, and future product direction, that control matters.</p>



<p class="wp-block-paragraph">This is the real heart of the matter. Tesla is not treating AI as a side project or a feature layer added on top of an existing business. AI is central to Tesla now and into the future. It is a force multiplier, but more than that, it is an essential aspect of product development, operational efficiency, automation, and competitive differentiation. Once a company reaches that level of dependence on AI, the conversation around infrastructure changes very quickly.</p>



<p class="wp-block-paragraph">Public cloud is attractive because it provides a complete AI ecosystem on demand. You can provision compute, storage, training environments, managed services, orchestration tools, and deployment pipelines without building much yourself. That is why I often call public cloud “the easy button” for AI. It is fast, convenient, and feature-rich. But convenience comes with a premium, and for many companies moving deeply into AI, that premium is becoming very hard to justify.</p>



<h2 class="wp-block-heading">Cost is driving AI out of the cloud</h2>



<p class="wp-block-paragraph">One of the biggest forces driving this shift is price. Many enterprises moving into AI are shocked by what public cloud providers charge for AI infrastructure. Training clusters, inference engines, storage, networking, observability, and support services all add up quickly. What begins as a convenient path to experimentation can become an extremely expensive operating model when AI moves into production at scale.</p>



<p class="wp-block-paragraph">In my experience during the past 15 years, public cloud is often at least twice as expensive as comparable private infrastructure for sustained workloads. That is not true in every case, and it depends heavily on utilization patterns, architecture, and operational maturity. However, for large, predictable, always-on AI workloads, public cloud economics often become difficult to defend. The markup associated with convenience, elasticity, and managed ecosystems is substantial.</p>



<p class="wp-block-paragraph">In response, companies are increasingly exploring alternatives. Some are moving toward <a href="https://www.infoworld.com/article/4140865/neoclouds-run-ai-cheaper-and-better.html">neoclouds </a>that specialize in AI infrastructure. Others are evaluating <a href="https://www.infoworld.com/article/4175895/the-sovereign-cloud-illusion.html">sovereign cloud</a> options for control, locality, or compliance reasons. Many are revisiting <a href="https://www.infoworld.com/article/2291750/what-the-private-cloud-really-means.html">private cloud </a>infrastructure for the most strategic and cost-intensive workloads. Tesla is becoming the poster child for how successful that approach can be when a company has the scale, the sophistication, and the long-term commitment to execute it well.</p>



<h2 class="wp-block-heading">Control, governance, and security</h2>



<p class="wp-block-paragraph">Cost is only one part of the equation. Control is the other major driver. When Tesla runs its AI infrastructure on equipment it owns and operates, it gains much tighter control over performance, data handling, workload placement, governance models, and operational priorities. That matters a great deal when the workloads involved are mission-critical and directly connected to the future of the company.</p>



<p class="wp-block-paragraph">A privately controlled AI environment can provide better <a href="https://www.csoonline.com/article/568841/what-is-information-security-definition-principles-and-jobs.html">security </a>because the organization has direct oversight of the infrastructure stack. It can provide better governance because data, models, and workflows remain inside systems the enterprise fully controls. It can also improve reliability and performance tuning because engineering teams can optimize specifically for their own AI pipelines rather than adapting to the generalized patterns of a shared cloud environment.</p>



<p class="wp-block-paragraph">Of course, many people are quick to point out that running your own private infrastructure comes with significant labor and cost. They are not wrong. Building and operating private AI infrastructure requires capital, engineering skill, facilities, procurement discipline, operational excellence, and long-term commitment. This is not a shortcut, nor is it easier than public cloud. In many ways, it is harder.</p>



<p class="wp-block-paragraph">However, the point is that for sophisticated companies with large-scale, steady-state AI needs, it can be worth it. Better control, better governance, better security, and ultimately lower cost can justify the additional operational burden.</p>



<h2 class="wp-block-heading">The future of AI infrastructure</h2>



<p class="wp-block-paragraph">What makes Tesla so important in this discussion is that the company chose this route because AI is inseparable from its business strategy. Many other enterprises are heading in this same direction. As AI becomes less experimental and more operational, the infrastructure conversation shifts from convenience to economics, control, and differentiation.</p>



<p class="wp-block-paragraph">Not every company should follow Tesla’s path. Many enterprises are not ready to build, host, and manage their own AI environments. Many lack the scale to justify it. Many still benefit tremendously from the agility of public cloud. But for organizations where AI is becoming central to products, services, and competitive advantage, Tesla’s strategy is increasingly relevant.</p>



<p class="wp-block-paragraph">There are three things every enterprise should think about when considering ownership of its own AI infrastructure:</p>



<ul class="wp-block-list">
<li>First, understand the operational burden in full. Private AI infrastructure requires teams, processes, facilities, and discipline that many organizations underestimate.</li>



<li>Second, know the economics of your workload patterns. If AI demand is large, steady, and strategic, the cost advantages of ownership may be compelling.</li>



<li>Third, think beyond cost alone and focus on control. If AI is core to your future, owning the infrastructure may offer strategic benefits in governance, security, optimization, and long-term independence that public cloud cannot easily match.</li>
</ul>



<p class="wp-block-paragraph">Tesla’s strategy is not for everyone, but it is a persuasive example of what happens when a company decides that AI is too important to rent forever. Public cloud remains the easy button, and for many organizations, that will be enough. But for companies that see AI as fundamental to how they will compete, private infrastructure may turn out to be the smarter choice.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Qualcomm shows Apple’s modem transition is almost complete]]></title>
<description><![CDATA[Apple may be moving faster than expected in its modem development work, and Qualcomm’s latest comments suggest that shift is already reshaping the iPhone supply chain. 



Qualcomm overnight said supply constraints are shrinking some of its Apple business faster than anticipated. “It’s availabili...]]></description>
<link>https://tsecurity.de/de/3699923/ai-nachrichten/qualcomm-shows-apples-modem-transition-is-almost-complete/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699923/ai-nachrichten/qualcomm-shows-apples-modem-transition-is-almost-complete/</guid>
<pubDate>Mon, 03 Aug 2026 00:16:50 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Apple may be moving faster than expected in its modem development work, and Qualcomm’s latest comments suggest that shift is already reshaping the iPhone supply chain. </p>



<p class="wp-block-paragraph">Qualcomm overnight said supply constraints are shrinking some of its Apple business <a href="https://www.reuters.com/business/retail-consumer/qualcomm-forecasts-weak-quarterly-profit-expects-apple-revenue-drop-accelerate-2026-07-29/" target="_blank" rel="noreferrer noopener">faster than anticipated</a>. “It’s availability of supply,” CEO <a href="https://www.reuters.com/business/retail-consumer/qualcomm-forecasts-weak-quarterly-profit-expects-apple-revenue-drop-accelerate-2026-07-29/" target="_blank" rel="noreferrer noopener">Cristiano Amon told Reuters</a>.</p>



<p class="wp-block-paragraph">While he wasn’t specific, that likely reflects the <a href="https://www.computerworld.com/article/4190611/apples-memory-problem-is-your-problem-too.html">broader industry shortage</a> in memory, storage, and everything else and means the company’s share of components used for the next iPhone launch will fall “well below” its anticipated estimates. Amon says this is part of a transition in which future Qualcomm income will be generated by AI datacenter demand.</p>



<p class="wp-block-paragraph">The company also intends to boost modem prices on Sept. 1 (And remember, the patent licensing agreement between Apple and Qualcomm expires in March 2027.)</p>



<p class="wp-block-paragraph">Given Apple is selling plenty of smartphones (even as the broader industry shrinks), supply constraints won’t necessarily be because of demand for the devices; this could reflect Apple’s plan to divide the iPhone release schedule across several months, as well as its future modem development efforts. </p>



<p class="wp-block-paragraph">Reports for months have indicated Apple plans to <a href="https://www.computerworld.com/article/4091060/apple-preps-for-iphone-diversification.html">introduce new iPhones twice a year</a>, with the Pro range updated each fall and entry-level devices scheduled for spring. It’s a move that’s likely to help build more consistent quarterly earnings by spreading demand across different parts of the year and could reduce short-term demand for components. </p>



<p class="wp-block-paragraph">Things look a little different this year, of course; the expected introduction of the <a href="https://www.applemust.com/what-we-think-we-know-about-iphone-ultra/" target="_blank" rel="noreferrer noopener">new iPhone Ultra</a> means Apple will be making three new iPhone models, not the customary four – though there is also speculation the Ultra may not ship in quantity until later on this year. </p>



<h2 class="wp-block-heading"><strong>How much does Apple need Qualcomm? Not much</strong></h2>



<p class="wp-block-paragraph">There’s also Apple’s own <a href="https://www.computerworld.com/article/1671276/what-you-need-to-know-about-apples-1b-intel-5g-modem-investment.html">modem development plans</a> to consider. We know Apple’s relationship with Qualcomm isn’t easy. The two firms were engaged in costly litigation before they found a way <a href="https://www.computerworld.com/article/1722166/thoughts-on-the-apple-qualcomm-settlement.html">to bury the hatchet</a> and work together on 5G iPhones while Apple <a href="https://www.computerworld.com/article/3829149/everything-we-know-about-apples-c1-5g-modem-in-iphone-16e.html">developed its C-series modems</a>.</p>



<p class="wp-block-paragraph">Those C-series modems are already used in Apple devices. The iPhone 16e, 17e and iPhone Air carry Apple’s C1/C1X modem, with the C2 variant expected in the 18 Pro series this year. </p>



<p class="wp-block-paragraph"><a href="https://9to5mac.com/2026/06/09/iphone-18-pros-new-c2-chip-will-bring-three-advantages-over-iphone-17/" data-type="link" data-id="https://9to5mac.com/2026/06/09/iphone-18-pros-new-c2-chip-will-bring-three-advantages-over-iphone-17/" target="_blank" rel="noreferrer noopener">Apple’s new modem</a> is expected to deliver better battery efficiency, improved cellular network privacy, and AI-supported network efficiency. So, your device should last longer, be less visible to your carrier, and better able to get a connection — even when connectivity is constrained. </p>



<p class="wp-block-paragraph">Next year’s 18-series devices will certainly stick with Apple’s modems, meaning Qualcomm’s remaining Apple business should be wrapped up in the release this fall. As Apple’s modem appears in more devices, you’ll probably only see Qualcomm modems used to provide mmWave support, which realistically has very little traction or carrier support outside America.</p>



<h2 class="wp-block-heading"><strong>Waiting to replace mmWave</strong></h2>



<p class="wp-block-paragraph">That view is supported by reports based on information <a href="https://daringfireball.net/2026/07/a_tale_of_two_modems" target="_blank" rel="noreferrer noopener">recently stolen from Apple’s India-based iPhone partner</a>, Tata. It claimed Apple will use the C2 in internationally sold iPhones Pro and Max, while keeping to Qualcomm in US devices.</p>



<p class="wp-block-paragraph">If Apple takes the same approach with next year’s iPhone releases, it would mean only US iPhones — and probably not all of them — have mmWave. As a result, Qualcomm’s modems will only be available in a very small subset of iPhones sold. That would almost certainly account for the modem maker’s reduced Apple optimism. (Apple is also part of the 6G standard development group, which implies it hopes to find some way to replace mmWave.)</p>



<p class="wp-block-paragraph">It also indicates Apple is less likely to renew its current patent licensing deal, though it could still require some licenses since Qualcomm’s SEPs include some 5G-essential technologies. The other takeaway here: Apple has a <a href="https://www.applemust.com/apples-5g-modem-grows-up-real-world-parity-with-qualcomm-is-finally-here/#google_vignette" target="_blank" rel="noreferrer noopener">high degree of confidence in its forthcoming C2 modem</a>, which makes sense given how well-received its C1 modem has been. </p>



<h2 class="wp-block-heading"><strong>A clean sweep</strong></h2>



<p class="wp-block-paragraph">One more thought. It is interesting the extent to which Tim Cook’s Apple seems to be finalizing much of its business before the transition to new CEO John Ternus on Sept. 1. (It is also notable that Qualcomm also intends to raise its prices on the same date.)</p>



<p class="wp-block-paragraph"><em>You can follow me on social media! Join me on <a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener">BlueSky</a>,  <a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener">LinkedIn</a>, <a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener">Mastodon</a> and subscribe to <a href="https://thecorenews.substack.com/p/welcome-to-the-core?r=5l3lg" target="_blank" rel="noreferrer noopener">The Core</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Q&A: Nvidia genAI chief explains why open models matter in AI]]></title>
<description><![CDATA[When Nvidia CEO Jensen Huang speaks, the tech industry listens. He used his first-ever post on X last week to argue that open AI models “strengthen safety and cybersecurity, accelerate innovation and diffusion, and enable sovereignty.”



Nvidia is a chip company (with a focus on GPUs). But it al...]]></description>
<link>https://tsecurity.de/de/3699927/ai-nachrichten/qa-nvidia-genai-chief-explains-why-open-models-matter-in-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699927/ai-nachrichten/qa-nvidia-genai-chief-explains-why-open-models-matter-in-ai/</guid>
<pubDate>Mon, 03 Aug 2026 00:16:50 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">When Nvidia CEO Jensen Huang speaks, the tech industry listens. He used his <a href="http://(https//x.com/search?q=jensen%20huang" target="_blank" rel="noreferrer noopener">first-ever post on X</a> last week to argue that <a href="https://www.computerworld.com/article/4172545/why-open-ai-models-are-gaining-ground-on-llms.html" data-type="link" data-id="https://www.computerworld.com/article/4172545/why-open-ai-models-are-gaining-ground-on-llms.html">open AI models</a> “strengthen safety and cybersecurity, accelerate innovation and diffusion, and enable sovereignty.”</p>



<p class="wp-block-paragraph">Nvidia is a chip company (with a focus on GPUs). But it also has its own AI models that include Nemotron, an open-weight model that’s free to download and modify. The company is also pushing for open AI technologies and security through the <a href="https://nvidianews.nvidia.com/news/nvidia-launches-nemotron-coalition-of-leading-global-ai-labs-to-advance-open-frontier-models" target="_blank" rel="noreferrer noopener">Nemotron Coalition</a>  and the newly launched <a href="https://blogs.nvidia.com/blog/open-secure-ai-alliance/" target="_blank" rel="noreferrer noopener">Open Secure AI Alliance</a>. </p>



<p class="wp-block-paragraph">With Huang’s recent comments in mind, <em>Computerworld</em> sat down with Kari Briski, Nvidia’s vice president of generative AI (genAI) software, to find out more about open models and why they matter for enterprise and sovereign applications.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/nvidia-headshot-kari-briski.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Kari Briski, vice president of generative AI software at Nvidia" class="wp-image-4202784" width="1024" height="768" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Kari Briski, vice president of generative AI software at Nvidia.</p>
</figcaption></figure><p class="imageCredit">Nvidia</p></div>



<p class="wp-block-paragraph"><strong>What do open models really give enterprises and countries? </strong>“Open models allow enterprises and countries to own, inspect, and adapt models with their own data. The learning rate of adoption differs by region and enterprise, so there are different pockets of acceleration, but all the models have made tremendous progress closing the gap. What’s interesting about Nemotron is that we also publish our data, and that opened up a new world of engagement. </p>



<p class="wp-block-paragraph">“Enterprises reached out, saying, ‘Thank you, but I want to understand why you put this set of data out.’ That got them in the mindset that they could curate, create, capture, and control their own data.”</p>



<p class="wp-block-paragraph"><strong>When you develop these open models, do you have CIOs in mind, or sovereign uses? Where does the rubber hit the road? “</strong>Both. At the highest level, it’s very much the same: use cases, data sets, outcomes you want to achieve. It used to be question and answer, now it’s agentic workloads, getting stuff done, calling tools. To get a task done, which tool do you call? That’s different for every enterprise and every local region, which is why we match local models to local ecosystems, with post-training on those local models. </p>



<p class="wp-block-paragraph">“One enterprise can have 2,000 tools; a local region, 2,000 regional tools. [They’re] fundamentally the same, but with different go-to-market motions: reinforcement learning environments, synthetic data generation, or anonymizing and differential privacy for healthcare and banking data.”</p>



<p class="wp-block-paragraph"><strong>Why does Nvidia put its models out in the open? What do you get out of it? </strong>“We’re building Nemotron first and foremost for ourselves, to understand our systems running at scale — not just for training but also for inference, which allows us to iterate on things like model architecture for token efficiency. We believe in a thriving ecosystem. When you put a model out into the open, you get more startups, more builders, lower entry barriers.”</p>



<p class="wp-block-paragraph"><strong>What’s the connection between open models and sovereign AI? “</strong>To be very honest, it’s about bootstrapping a region that otherwise didn’t have the compute to get to a base-level model. Centers of excellence historically lived in higher education or research, and in certain pockets of the world, getting onto a compute cluster was grant-based: get on, get off, then find another grant. That start-stop, not being able to constantly iterate, is difficult. It’s the scaling laws of AI: the more compute, the more intelligence; the more access, the faster you can drive  them. Open models and open data are that bootstrap. You don’t have to recreate capturing the knowledge of the internet as a pre-training model.”</p>



<p class="wp-block-paragraph"><strong>Regionally, things are different. Voice and word of mouth are big in South Asia, chatbots less so. What’s the approach going forward? Is it an SLM approach? </strong>“You’re going to hate my answer: it depends. Language is ever evolving. Go back to first principles: AI is infrastructure. Not just the model, but the harness, the skills, the runtime. All of this is a new computing platform, and when we deploy it, it’s how can it understand and adapt. We’re at the tip of the iceberg integrating AI into everyday applications. The more it can understand and update even dialects, the better. </p>



<p class="wp-block-paragraph">“Understanding those niche areas is what drives the data flywheel of deploying AI. It won’t be overnight. That’s why this is a new industrial revolution. We have to lay the infrastructure everywhere for these models to update. And to your point, it could be a large teacher model that at the edge is an SLM. It depends.”</p>



<p class="wp-block-paragraph"><strong>AI companies in Nepal told me, “We can’t innovate because we don’t have access to a GPU.” They want a model that runs on the hardware they have. Is that the way you look at it? </strong>“If you know Nvidia, it’s all about the ecosystem, and we want to enable developers. This is why we have many different sizes: Nano, Super, and Ultra of the Nemotron family, not just for where you deploy, but for developers to iterate on smaller GPUs, then scale to a more robust model like Ultra.</p>



<p class="wp-block-paragraph">“We run as a model-as-a-service across the cloud providers. Day zero, they all had it ready to go, along with our inference partners, optimized and efficient for their workload. We don’t pitch the checkpoint over the wall; we help them take it that last mile, and partners get early access, so on release day it’s available on whatever platforms they use.”</p>



<p class="wp-block-paragraph"><strong>The industry works together on open technology like Linux. Can you partner on models, and is the focus on performance or quality? “</strong>On performance versus quality, it’s both. You can’t have a high-quality model that is slow or heavy, and you can’t have a fast model that sucks. We’re going after three dimensions: efficient, state-of-the-art, and open. And models do work together today — a planning agent routes a question to the best model to complete the task.</p>



<p class="wp-block-paragraph">“On partnering, that’s our goal in true open source and in the Nemotron Coalition, bringing the best and brightest minds with the commitment to open source and collaboration. Members contribute in different ways: pre-training new architectures, post-training RL environments, contributing data. The goal is everybody working together on one model. That’s why the coalition matters for model architecture —  token efficiency, latent mixture of experts, changing how we route it. These are new architectures we’re thinking about. We need these ideas coming in from others.”</p>



<p class="wp-block-paragraph"><strong>Is the latest open-source model always the best? In developing countries, some go back to older models they’ve tested enough to predict the responses. “</strong>Models aside, that’s true for any software. You do an upgrade and it’s just not working the way it worked before. The results aren’t better. When you build a system around it with certain prompts, a model might not react the way it used to. This is why we built the coalition, why we work with a very close set of partners. We pull their evaluation benchmarks in-house to make sure we’re not regressing, only improving. </p>



<p class="wp-block-paragraph">“You have to switch your mind with AI and the way you test it. Is the latest model necessarily the best? I’m going to say yes. Companies and countries need the skills to quickly evaluate, update prompts, and adopt new models.”</p>



<p class="wp-block-paragraph"><strong>Can I fork an Nvidia model, put it on Hugging Face, and do what I want with it? Do you take lessons from the forks and benchmarks? “</strong>We have a very open license. We put out reduced precision NVFP4 checkpoints. Those are the most popular, especially with Ultra, because people want the smallest footprint to run that robust model. Even with mature models, there’s all kinds of quantization happening and getting posted back, and I love that community engagement. I love seeing different forks of our models. We track those, too, which gives us an idea of what matters to people. That’s the purpose of putting it out in the open: to see how they change it, how they need to adapt it, then put it back out for the rest of the world to enjoy.</p>



<p class="wp-block-paragraph">“Benchmarks are table stakes, not the ceiling of where we need to go, so we’re always looking for new benchmarks and new workloads. In the last 90 days, the style of workload changed dramatically, going from question-answer pairs to agentic workloads, and those workloads mattered to make sure we were tracing our model, which led to us being able to fully trace it. We want to show that you can be just as intelligent in a short amount of time, compute efficient, token efficient.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The future of AI hinges on openness and cooperation. China and Britain can gain much by working together | Zheng Zeguang]]></title>
<description><![CDATA[There is no point competing in isolation. There are so many benefits to be had, in manufacturing, healthcare, research and governanceZheng Zeguang is the Chinese ambassador to the UKArtificial intelligence is widely regarded as one of the defining technologies of our time. Like the steam engine, ...]]></description>
<link>https://tsecurity.de/de/3699887/ai-nachrichten/the-future-of-ai-hinges-on-openness-and-cooperation-china-and-britain-can-gain-much-by-working-together-zheng-zeguang/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699887/ai-nachrichten/the-future-of-ai-hinges-on-openness-and-cooperation-china-and-britain-can-gain-much-by-working-together-zheng-zeguang/</guid>
<pubDate>Mon, 03 Aug 2026 00:16:48 +0200</pubDate>
<content:encoded><![CDATA[<p>There is no point competing in isolation. There are so many benefits to be had, in manufacturing, healthcare, research and governance</p><ul><li><p>Zheng Zeguang is the Chinese ambassador to the UK</p></li></ul><p>Artificial intelligence is widely regarded as one of the defining technologies of our time. Like the steam engine, the harnessing of electricity and the internet before it, it has the potential to transform how we work, live and interact.</p><p>But every technological revolution brings challenges as well as opportunities. As AI systems become more capable, people are asking legitimate questions. How can AI remain safe, accountable and <a href="https://www.theguardian.com/technology/article/2024/aug/24/yuval-noah-harari-ai-book-extract-nexus">under human control</a>? How should its development be governed? How can its <a href="https://www.theguardian.com/technology/2026/jul/01/un-report-ai-inequality">benefits be shared</a> more widely?</p> <a href="https://www.theguardian.com/commentisfree/2026/jul/30/ai-future-china-britain-healthcare-research">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sam Altman and AI’s decel debate]]></title>
<description><![CDATA[On the latest episode of Equity, we discuss why Sam Altman has calling on the industry to "pace the rate of AI development."]]></description>
<link>https://tsecurity.de/de/3699786/ai-nachrichten/sam-altman-and-ais-decel-debate/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699786/ai-nachrichten/sam-altman-and-ais-decel-debate/</guid>
<pubDate>Mon, 03 Aug 2026 00:16:45 +0200</pubDate>
<content:encoded><![CDATA[On the latest episode of Equity, we discuss why Sam Altman has calling on the industry to "pace the rate of AI development."]]></content:encoded>
</item>
<item>
<title><![CDATA[How AI is shortening drug discovery timelines in China]]></title>
<description><![CDATA[Insilico Medicine has reduced the time needed to produce some drug development candidates to about one year by combining artificial intelligence with laboratory research in China, according to CEO Alex Zhavoronkov. The Hong Kong-listed company’s fastest programme reached candidate nomination in n...]]></description>
<link>https://tsecurity.de/de/3699758/ai-nachrichten/how-ai-is-shortening-drug-discovery-timelines-in-china/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699758/ai-nachrichten/how-ai-is-shortening-drug-discovery-timelines-in-china/</guid>
<pubDate>Mon, 03 Aug 2026 00:16:40 +0200</pubDate>
<content:encoded><![CDATA[<p>Insilico Medicine has reduced the time needed to produce some drug development candidates to about one year by combining artificial intelligence with laboratory research in China, according to CEO Alex Zhavoronkov. The Hong Kong-listed company’s fastest programme reached candidate nomination in nine months, while its typical timeline is about 13 months, Zhavoronkov said. He said […]</p>
<p>The post <a href="https://www.artificialintelligence-news.com/news/ai-drug-discovery-china/">How AI is shortening drug discovery timelines in China</a> appeared first on <a href="https://www.artificialintelligence-news.com/">AI News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI as an Enterprise Operating System]]></title>
<description><![CDATA[I hadn’t heard of Dan Guido until a few months ago, when I came across the video of a talk he gave at [un]prompted, an AI security practitioners’ conference. Dan is the CEO and cofounder of Trail of Bits, a software security research and development firm that works with companies in tech, defense...]]></description>
<link>https://tsecurity.de/de/3699743/ai-nachrichten/ai-as-an-enterprise-operating-system/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699743/ai-nachrichten/ai-as-an-enterprise-operating-system/</guid>
<pubDate>Mon, 03 Aug 2026 00:16:39 +0200</pubDate>
<content:encoded><![CDATA[I hadn’t heard of Dan Guido until a few months ago, when I came across the video of a talk he gave at [un]prompted, an AI security practitioners’ conference. Dan is the CEO and cofounder of Trail of Bits, a software security research and development firm that works with companies in tech, defense, and finance. […]]]></content:encoded>
</item>
<item>
<title><![CDATA[The Python Ecosystem That Changed AI Development]]></title>
<description><![CDATA[How one open-source ecosystem made state-of-the-art AI accessible
The post The Python Ecosystem That Changed AI Development appeared first on Towards Data Science.]]></description>
<link>https://tsecurity.de/de/3699711/ai-nachrichten/the-python-ecosystem-that-changed-ai-development/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699711/ai-nachrichten/the-python-ecosystem-that-changed-ai-development/</guid>
<pubDate>Mon, 03 Aug 2026 00:16:38 +0200</pubDate>
<content:encoded><![CDATA[<p>How one open-source ecosystem made state-of-the-art AI accessible</p>
<p>The post <a href="https://towardsdatascience.com/the-python-ecosystem-that-changed-ai-development/">The Python Ecosystem That Changed AI Development</a> appeared first on <a href="https://towardsdatascience.com/">Towards Data Science</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Teaching LLMs to Update Beliefs for Efficient Long-Horizon Interaction]]></title>
<description><![CDATA[Overview of ABBEL compared to traditional recursive summarization. Beliefs replace the full interaction history as the agent’s working context, and belief grading improves performance by
supervising the contents of each belief state..


As task horizons grow, LLM contexts can’t scale forever. Sel...]]></description>
<link>https://tsecurity.de/de/3699702/ai-nachrichten/teaching-llms-to-update-beliefs-for-efficient-long-horizon-interaction/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699702/ai-nachrichten/teaching-llms-to-update-beliefs-for-efficient-long-horizon-interaction/</guid>
<pubDate>Mon, 03 Aug 2026 00:16:37 +0200</pubDate>
<content:encoded><![CDATA[<!-- twitter -->














<p class="abbel-fig abbel-fig--wide abbel-fig--tight">
<img src="https://bair.berkeley.edu/static/blog/abbel/ABBEL%20main%20figure.png" alt="ABBEL overview">
<i class="abbel-fig-cap">Overview of ABBEL compared to traditional recursive summarization. Beliefs replace the full interaction history as the agent’s working context, and belief grading improves performance by
supervising the contents of each belief state..</i>
</p>

<p>As task horizons grow, LLM contexts can’t scale forever. Self-summarization enables concise, interpretable contexts, but at a significant performance cost, especially for human assistance domains where high quality data is scarce, e.g., collaborative code generation. We address this with <a href="https://arxiv.org/abs/2512.20111">ABBEL</a>: a framework that isolates and supervises the information content of summaries in the form of natural-language belief states.
<!--more--></p>

<h2>Motivation: the cost of recursive summarization</h2>

<p>For language models to effectively assist with increasingly complex tasks such as software development, they must be able to interact with us over hundreds or even thousands of steps. For such long tasks, it is impractical to keep the history of the entire interaction in context. The heuristic approach used so far has been summary generation, sometimes called context compaction. For example, Cursor’s latest model composer 2.5 uses compaction during training for improved performance (<a href="https://cursor.com/blog/self-summarization">Cassano et al., 2026</a>). Alongside composer, Grandcode (<a href="https://arxiv.org/abs/2604.02721">DeepReinforce et al., 2026</a>), the first system to consistently beat all human competitors in online coding competitions, despite using one of the newest efficient attention models (Qwen 3.5-397B),<sup><a href="http://bair.berkeley.edu/blog/2026/07/26/abbel/#fn:efficientattn" class="footnote">1</a></sup> still found it necessary to employ context summarization.</p>

<p>But compaction has a problem. Despite seemingly low performance gaps in benchmarks, model servers like Cursor continue to recommend that users avoid compaction with their coding assistants in the middle of a task (<a href="https://cursor.com/blog/continually-improving-agent-harness">Heule et al., 2026</a>).</p>

<p>To understand why, see below the performance over RL fine-tuning of a Context summary model compared to full context models in Combination Lock, a Wordle-like game that allows up to 16 guesses.<sup><a href="http://bair.berkeley.edu/blog/2026/07/26/abbel/#fn:wordlehard" class="footnote">2</a></sup> Though both model types improve over the course of training, the summary model never closes the gap.</p>

<p class="abbel-fig abbel-fig--chart-sm">
<img src="https://bair.berkeley.edu/static/blog/abbel/Average%20attempts%20to%20guess%20target%20word%20context%20summaries.png" alt="Average attempts to guess target word with context summary vs full context policies over training">
<i class="abbel-fig-cap">Fig. 1: Average attempts to guess the target word on Combination Lock over RL fine-tuning (lower is better). Context-summary policies improve with training but do not close the gap to full-context policies.</i>
</p>

<p>Making models self-summarize while completing a task increases the complexity of the learning problem. While this could typically be addressed by training with more data, the performance degradation observed in real world interactive settings likely arises from the difficulty we have in creating and using human simulators effectively to generate high quality training environments (<a href="https://jessylin.com/2025/07/10/user-simulators-1/">Lin et al., 2025</a>, <a href="https://nickatomlin.github.io/blog/user-simulators-2.html">Tomlin et al., 2025</a>). Thus, the better you can learn to summarize on the limited and messy multiturn interaction trajectories you can collect, the better off your model will be for downstream users.</p>

<h2>ABBEL: acting through belief bottlenecks</h2>

<p class="abbel-fig abbel-fig--wide-90">
<img src="https://bair.berkeley.edu/static/blog/abbel/ABBEL%20belief%20grading%20diagram.png" alt="ABBEL belief grading diagram">
<i class="abbel-fig-cap">Fig. 2: Autoencoder-inspired belief grading. The model encodes prior belief, action and observation (b<sub>t</sub>, a<sub>t</sub>, o<sub>t</sub>) into posterior belief b<sub>t+1</sub> and is rewarded for how well select information from the history can be reconstructed from that belief.</i>
</p>

<p>To address poor learning efficiency, we isolate the summary generation task. Drawing inspiration from recursive Bayesian estimation, we formulate summaries as belief states, which we periodically prompt the model to update based on new information.<sup><a href="http://bair.berkeley.edu/blog/2026/07/26/abbel/#fn:videoabbelslow" class="footnote">3</a></sup></p>

<div class="abbel-fig abbel-fig--video">
  <div class="abbel-frames is-playing" data-frame-count="16" data-frame-prefix="https://bair.berkeley.edu/static/blog/abbel/frames/frame_" data-interval="1300">
    <div class="abbel-frames__stage" role="button" tabindex="0" aria-label="Pause or advance ABBEL overview frame">
      <img src="https://bair.berkeley.edu/static/blog/abbel/frames/frame_00.png" alt="ABBEL overview animation frame">
      <!-- <span class="abbel-frames__hint">Click to pause</span> -->
    </div>
    <div class="abbel-frames__controls">
      <button type="button" class="abbel-frames__prev" aria-label="Previous frame">‹ Prev</button>
      <button type="button" aria-pressed="true" aria-label="Play or pause animation">Pause</button>
      <button type="button" class="abbel-frames__next" aria-label="Next frame">Next ›</button>
      <span class="abbel-frames__meta">1 / 16</span>
    </div>
    <div class="abbel-frames__dots" aria-hidden="true"></div>
  </div>
  <i class="abbel-fig-cap">Fig. 3: ABBEL rollout. Belief updates from the latest observation alternate with action selection conditioned only on the current posterior belief.</i>
</div>

<h3>Belief grading</h3>

<p>We then extract and supervise the contents of the belief states (Fig. 2, Belief Grading). Belief grading can be thought of as adding an auxiliary RL task, using heuristics designed to capture what makes a good belief as the reward. An example heuristic for coding could be shorter is better, but closer to being able to reconstruct the git diff is also better, so balancing these would yield a good belief. In domains where good heuristics are hard to define, we propose a general autoencoding-inspired grading function, which treats the current language model π<sub>θ</sub> as both encoder and decoder of information from
the history, and the belief states as the codes. We grade each belief b<sub>t+1</sub> by how well it can be used by the current model π<sub>θ</sub> to reconstruct the most recent observation o<sub>t</sub>:</p>

<p class="abbel-fig abbel-fig--equation">
<img src="https://bair.berkeley.edu/static/blog/abbel/Belief%20grading%20equation.png" alt="Eq. 1: Reconstruction grading objective">
<i class="abbel-fig-cap">Eq. 1: Reconstruction grading objective. Here b<sub>t+1</sub> is the updated belief, o<sub>t</sub> the latest observation, a<sub>t</sub> the action just taken, b<sub>t</sub> the prior belief, p<sub>I</sub> the task prompt, and π<sub>θ</sub> the current model. Higher grades reward beliefs that retain information needed to decode the latest observation.</i>
</p>

<h2>What do we gain by grading beliefs?</h2>

<h3>Collaborative coding on CollabBench</h3>

<p>We demonstrate the utility of belief grading in our motivating domain of human-driven assistive coding, with the CollabBench environment from Sweet-RL (<a href="https://arxiv.org/pdf/2503.15478">Zhou et al., 2025</a>).</p>

<p class="abbel-fig abbel-fig--portrait">
<img src="https://bair.berkeley.edu/static/blog/abbel/Collabbench.png" alt="CollabBench collaborative coding environment">
<i class="abbel-fig-cap">Fig. 4: CollabBench collaborative coding environment. The agent asks clarifying questions, then submits a function scored against hidden unit tests.</i>
</p>

<p>We see that with the general reconstruction-based belief grading function we reduce the performance gap from full context models by about 50%, and train in 50% fewer steps compared to training models to summarize without belief grading (no BG). After training, ABBEL still uses significantly less memory than the full context setting, as measured by the peak context token length (Peak Tokens).</p>

<div class="abbel-fig abbel-fig--table">
<div class="abbel-table-wrap">
<table class="abbel-table">
  <thead>
    <tr>
      <th>Model</th>
      <th>Test Pass Rate ↑</th>
      <th>Success Rate ↑</th>
      <th>Peak Tokens × 10² ↓</th>
      <th>Training Steps ↓</th>
    </tr>
  </thead>
  <tbody>
    <tr class="abbel-baseline">
      <td>Full Context</td>
      <td>0.52±0.02</td>
      <td>0.39±0.02</td>
      <td>14.08±0.55</td>
      <td>100</td>
    </tr>
    <tr>
      <td>ABBEL (no BG)</td>
      <td>0.46±0.02</td>
      <td>0.31±0.02</td>
      <td>4.20±0.37</td>
      <td>100</td>
    </tr>
    <tr>
      <td>ABBEL-rec-BG</td>
      <td>0.48±0.01</td>
      <td>0.36±0.01</td>
      <td>6.01±0.33</td>
      <td>50</td>
    </tr>
  </tbody>
</table>
</div>
<i class="abbel-fig-cap">Fig. 5: CollabBench results. With reconstruction belief grading, ABBEL-rec-BG recovers about half the gap to full context while using fewer peak tokens, and trains in 50 steps instead of 100.</i>
</div>

<h3>Combination Lock</h3>

<p>Additionally, in CombinationLock, we demonstrate that ABBEL with a belief grader which leverages domain knowledge (by computing useful statistics over the history and checking that they can be reconstructed from the belief state), enables even higher learning efficiency than full context (FULL CTX) models.</p>

<p class="abbel-fig abbel-fig--chart-sm">
<img src="https://bair.berkeley.edu/static/blog/abbel/Average%20Attempts%20to%20guess%20target%20word%20ABBEL.png" alt="Average Attempts to guess target word ABBEL">
<i class="abbel-fig-cap">Fig. 6: Average attempts to guess the target word on Combination Lock (lower is better). With domain-knowledge belief grading, ABBEL approaches or exceeds FULL CTX in this setting; without belief grading, learning is slower.</i>
</p>

<h3>Multi-objective question answering</h3>

<p>In a third environment, multi-objective question answering (from MEM1 <a href="https://arxiv.org/pdf/2512.24601">Zhang et al., 2025</a>, a recent work which performed end-to-end optimization in a modified version of typical recursive summarization), we demonstrate the utility of isolating belief states from reasoning, by showing that a Peak Belief length Penalty (more details in paper) significantly reduces memory usage with minimal performance degradation, unlike is commonly observed when penalizing reasoning lengths (<a href="https://proceedings.neurips.cc/paper_files/paper/2025/file/579b5b84311e122584dedab1d3b7613f-Paper-Conference.pdf">Arora et al., 2025</a>).</p>

<p class="abbel-fig abbel-fig--wide-lg">
<img src="https://bair.berkeley.edu/static/blog/abbel/Performance%20and%20memory%20usage%20in%20multi%20QA.png" alt="Performance and memory usage in multi QA">
<i class="abbel-fig-cap">Fig. 7: Exact-match score and peak memory versus number of objectives in multi-objective QA. ABBEL with a peak belief penalty (PBP) maintains comparable performance while using less memory than MEM1 and ABBEL without PBP in this evaluation.</i>
</p>

<h2>Related work</h2>
<p>Alternative solutions to managing long contexts involve different tradeoffs, and are worth considering depending on the requirements of a deployed system. Context compression methods generate dense representations which, while computationally efficient, sacrifice human-understandability (<a href="https://arxiv.org/abs/2604.09852">Kontonis et al., 2026</a>, <a href="https://arxiv.org/pdf/2506.06266">Eyuboglu et al., 2025</a>, <a href="https://arxiv.org/pdf/2510.19732">Gupta et al., 2025</a>, <a href="https://arxiv.org/pdf/2305.14788">Chevalier et al., 2023</a>, <a href="https://aclanthology.org/2025.acl-long.241.pdf">Deng et al., 2025</a>, <a href="https://proceedings.neurips.cc/paper_files/paper/2025/file/1c93b738747776f9d3fdd077a5a07114-Paper-Conference.pdf">Deng et al., 2025</a>, <a href="https://arxiv.org/abs/2207.06881">Bulatov et al., 2022</a>). Hand-designed summarization prompts (<a href="https://arxiv.org/pdf/2407.16741">Wang et al., 2025</a>, <a href="https://github.com/aorwall/moatless-tools">Örwall et al., 2025</a>, <a href="https://arxiv.org/pdf/2504.01848">Starace et al., 2025</a>) and pruning strategies (<a href="https://arxiv.org/pdf/2310.06839">Jiang et al., 2024</a>) specific to target environments require expert human knowledge and don’t allow an agent to learn what to remember as part of its decision-making strategy. Methods that process long contexts into an external memory store (<a href="https://arxiv.org/pdf/2310.08560">Packer et al., 2023</a>, <a href="https://arxiv.org/pdf/2502.12110">Xu et al., 2025</a>) for the agents or subagents to query (<a href="https://arxiv.org/pdf/2512.24601">Zhang et al., 2025</a>) are complementary, as they may benefit from better next context creation through summarization training. We would like to point out some exciting works in the space of general recursive summarization focused on math (<a href="https://arxiv.org/pdf/2602.03773">Wu et al., 2026</a>), reasoning with belief generation (<a href="https://arxiv.org/pdf/2506.15841">Zhou et al., 2025</a>), competitive coding with a distilled summarization module using similar autoencoding objectives to our general belief grader (<a href="https://arxiv.org/abs/2604.02721">DeepReinforce et al., 2026</a>), and adding continuous features to summaries (<a href="https://arxiv.org/abs/2604.09852">Kontonis et al., 2026</a>).</p>

<h2>What’s next for better memory?</h2>
<p>Many more possibilities are enabled through using explicit belief states as information bottlenecks for multi-step interaction. You could reward actions based on their effect on the belief state to guide exploration, transmit the explicit belief states for better communication between agents, or even improve user controllability by directly modifying the memories on which the agents’ decisions are based.</p>

<p>Some forms of information, e.g., what a person looks like, are not represented well by text alone. A continuously learning system will also have to capture such information. Additionally, if we want a system to learn to communicate in a brand new language or to play a brand new game better than any person in the world, the skills accumulated over the lifetime of conversations or games must be stored in a very compressed form, essentially taking on the role of the weights of the model itself.</p>

<p>More powerful systems will likely utilize a combination of multiple forms of memory, where the contents of the context may correspond to working memory while other approaches are used for short and long-term memory. How to instantiate these other forms of memory, for instance via test-time training, adapter memories, continuous context memories, or some combination thereof, presents an exciting challenge.</p>

<h2>Acknowledgements</h2>

<div class="abbel-ack">

Acknowledgements: We would like to thank <a href="https://www.alanesuhr.com/">Alane Suhr</a> and <a href="https://kartikgo.github.io/">Kartik Goyal</a> for advising this research as well as <a href="https://ethanm88.github.io/">Ethan Mendes</a>, <a href="https://davidhe137.github.io/">David He</a>, <a href="https://praeclarumjj3.github.io/">Jitesh Jain</a>, and <a href="https://nickatomlin.github.io/">Nicholas Tomlin</a> for comments on early drafts of this post. We would like to thank the MEM1 authors for their email correspondence and for sharing private reviewer feedback which we found particularly insightful.

</div>

<hr>

<h2>Citation</h2>

<p>If abbel was inspiring for your future work, please cite us with this! And here is some <a href="https://jakob-bjorner.github.io/abbel-advice.html">advice</a> for doing similar research!</p>
<div class="language-bibtex highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="nc">@misc</span><span class="p">{</span><span class="nl">lidayan2026abbellearningnaturallanguagebelief</span><span class="p">,</span>
      <span class="na">title</span><span class="p">=</span><span class="s">{ABBEL: Learning Natural-Language Belief States for Memory-Efficient Interaction}</span><span class="p">,</span> 
      <span class="na">author</span><span class="p">=</span><span class="s">{Aly Lidayan and Jakob Bjorner and Satvik Golechha and Kartik Goyal and Alane Suhr}</span><span class="p">,</span>
      <span class="na">year</span><span class="p">=</span><span class="s">{2026}</span><span class="p">,</span>
      <span class="na">eprint</span><span class="p">=</span><span class="s">{2512.20111}</span><span class="p">,</span>
      <span class="na">archivePrefix</span><span class="p">=</span><span class="s">{arXiv}</span><span class="p">,</span>
      <span class="na">primaryClass</span><span class="p">=</span><span class="s">{cs.CL}</span><span class="p">,</span>
      <span class="na">url</span><span class="p">=</span><span class="s">{https://arxiv.org/abs/2512.20111}</span><span class="p">,</span> 
<span class="p">}</span>
</code></pre></div></div>

<hr>

<div class="footnotes abbel-footnotes">
  <ol>
    <li>
      <p>
        With newer models the number of tokens till 50% compute spend is on attention gets much larger than 25K. Interleaving linear attention alternatives with full attention as is done with gpt-oss and DeepSeekv4, results in massive flops reductions for the attention computation. For example with DeepSeekv4-Pro (1.6T A49B) it requires nearly 450 thousand tokens to reach the 50% tradeoff point. Grandcode uses Qwen-3.5-397B-A17B a model which hits 50% FLOPs for attention at ~150 thousand tokens.
        <a href="http://bair.berkeley.edu/blog/2026/07/26/abbel/#fnref:efficientattn" class="reversefootnote">↩</a>
      </p>
    </li>
    <li>
      <p>
        This setting is technically solvable with much more computationally effective tools, but serves as a flexible test bed to study properties of recursive summarization. <a href="https://wordle-page.s3.amazonaws.com/assets/Wordle_Paper_Final.pdf">Bertsimas et al., 2022</a>, showed that an exact solution for the wordle game instantiated with the original vocabulary of the javascript game can be found with dynamic programming, but evidently the general formulation of wordle as a guessing game on K letters with L attempts and some dictionary of valid words and correct words D is NP hard to determine the minimal number of moves required.
        <a href="http://bair.berkeley.edu/blog/2026/07/26/abbel/#fnref:wordlehard" class="reversefootnote">↩</a>
      </p>
    </li>
    <li>
      <p>
        In practice there is an O(N/K) overhead cost for summary. N is the total number of actions. K is the number of actions till summarization is triggered. This is necessarily true for any summary approach. For ease of illustration this gif uses K = 1. In our experiments, to put more emphasis on summarization weaknesses we also use K=1. In practice overhead is small as K can be chosen to be near the efficient hardware limit.
        <a href="http://bair.berkeley.edu/blog/2026/07/26/abbel/#fnref:videoabbelslow" class="reversefootnote">↩</a>
      </p>
    </li>
  </ol>
</div>
<hr>

]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple still plans a camera-free AirPods Pro update for 2026]]></title>
<description><![CDATA[While the rumored camera-equipped AirPods Pro won't be coming out until 2027, an update is still expected by the end of 2026.AirPods Pro in a charging caseFall is the traditionally busy launch period for Apple's product catalog, and that can include AirPods. However, while there are rumors of a w...]]></description>
<link>https://tsecurity.de/de/3699116/ios-mac-os/apple-still-plans-a-camera-free-airpods-pro-update-for-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699116/ios-mac-os/apple-still-plans-a-camera-free-airpods-pro-update-for-2026/</guid>
<pubDate>Mon, 03 Aug 2026 00:15:25 +0200</pubDate>
<content:encoded><![CDATA[While the rumored camera-equipped <a href="https://appleinsider.com/inside/airpods-pro" title="AirPods Pro" data-kpt="1">AirPods Pro</a> won't be coming out until 2027, an update is still expected by the end of 2026.<br><br><div><img src="https://media.appleinsider.com/gallery/68434-144210-68156-143664-000-lead-AirPods-Pro-d2-xl-xl.jpg" alt="Close-up of white wireless earbuds resting in an open charging case, highlighting smooth plastic surfaces and small black speaker grilles"><br><span>AirPods Pro in a charging case</span></div><br>Fall is the traditionally busy launch period for Apple's product catalog, and that can include <a href="https://appleinsider.com/inside/airpods" title="AirPods" data-kpt="1">AirPods</a>. However, while there are rumors of a wild addition to the earbud range in development for 2027, Apple may still have something to launch in 2026.<br><br>Writing in Sunday's "Power On" <a href="https://www.bloomberg.com/news/newsletters/2026-08-02/apple-subscriptions-macbook-air-shortages-apple-to-make-glasses-health-device-msbvajjp?srnd=undefined">newsletter</a> for <em>Bloomberg</em>, Mark Gurman reiterates that AirPods Pro probably won't be coming out in 2026. <a href="https://appleinsider.com/articles/26/05/07/airpods-pro-with-cameras-probably-arent-arriving-in-2026-but-they-are-close">Back in May</a>, while the model was said to be very close to launch, being in the design validation testing (DVT) stage, it was thought that it was too late in the schedule for 2026, and 2027 was a safer bet.<br><br><br> <a href="https://appleinsider.com/articles/26/08/02/apple-still-plans-a-camera-free-airpods-pro-update-for-2026?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/245135?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Best Virtual Machine Software for Mac in 2026]]></title>
<description><![CDATA[The best virtual machine software for Mac lets you run Windows, Linux, older operating systems, and isolated development environments without replacing macOS.



Parallels Desktop offers the easiest Windows experience, while VMware Fusion provides powerful virtualization tools for free. UTM is a ...]]></description>
<link>https://tsecurity.de/de/3699008/ios-mac-os/best-virtual-machine-software-for-mac-in-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699008/ios-mac-os/best-virtual-machine-software-for-mac-in-2026/</guid>
<pubDate>Mon, 03 Aug 2026 00:15:20 +0200</pubDate>
<content:encoded><![CDATA[The best virtual machine software for Mac lets you run Windows, Linux, older operating systems, and isolated development environments without replacing macOS.



Parallels Desktop offers the easiest Windows experience, while VMware Fusion provides powerful virtualization tools for free. UTM is a strong open-source option, and VirtualBox remains useful for cross-platform testing.



Your Mac’s processor affects which operating systems it can run efficiently. Apple silicon Macs, including M1 through M5 models, deliver the best performance with ARM-based guest operating systems. Intel-based systems can run traditional x86 and x64 operating systems directly.



Best Virtual Machine Software for Mac Compared



Virtual machine softwareBest forApple silicon supportPriceMain limitationParallels DesktopRunning Windows easilyYesPaidSubscription costVMware Fusion ProFree professional virtualizationYesFreeLess polished Windows integrationUTMOpen-source virtualization and emulationYesFreeLimited graphics accelerationVirtualBoxCross-platform testingLimited but improvingFreeSeveral Apple silicon limitationsTartmacOS and Linux automationYesFreeCommand-line focused



⭐ 1. Parallels Desktop: Best Overall (We Recommend)







Parallels Desktop is the best choice for most people who need to run Windows on a Mac regularly. It provides a guided Windows 11 installation, shared folders, clipboard synchronization, drag-and-drop file transfers, and support for Mac peripherals.



Its Coherence mode hides the Windows desktop and displays Windows applications alongside regular Mac applications. You can open Windows software from the Dock, use macOS keyboard shortcuts, and access files stored on your Mac from inside Windows.



Parallels supports Windows 11 on Arm on Apple silicon Macs. Microsoft recognizes Windows 11 Pro and Enterprise running through Parallels as a compatible solution for Apple silicon systems.




    

    
        Parallels Desktop
        
            Run Windows on your Mac without rebooting. Our top recommendation for Apple silicon and Intel Macs.
        
    

    
        Free Trial
        
            Visit Website
        
    




Key Parallels Desktop features include:




One-click Windows 11 installation



Coherence mode for running Windows apps without displaying the complete Windows desktop



Shared Mac and Windows folders



DirectX 11 graphics support



USB device and printer sharing



Virtual machine snapshots



Retina display optimization



Development tools in the Pro edition




Parallels works well for Microsoft Office, business applications, web development, accounting software, testing, and many standard Windows programs. However, some applications that depend on unsupported hardware drivers, nested virtualization, specialised security components, or certain anti-cheat systems may not work correctly with Windows 11 on Arm.



Parallels requires a paid licence, and Windows activation usually requires a separate Windows licence. The Standard edition suits home users, while the Pro edition provides more processor, memory, networking, debugging, and automation controls.



2. VMware Fusion Pro: Best Free Virtual Machine Software for Mac







VMware Fusion Pro is the best free alternative to Parallels Desktop. Broadcom made Fusion Pro free for personal, educational, and commercial users, removing the previous paid licence requirement.



Fusion supports Windows 11 for Arm, Linux distributions, snapshots, virtual networks, cloning, encryption, and advanced hardware configuration. It also offers DirectX 11 graphics acceleration and fast file sharing on supported guest systems.



VMware Fusion Pro includes:




Windows 11 on Arm support



Multiple snapshots



Linked and full virtual machine clones



Custom virtual networking



Virtual disk encryption



3D graphics acceleration



Shared folders and clipboard integration



Import support for several virtual machine formats




Fusion gives developers and IT professionals more configuration options than most free tools. It works well for testing software, creating isolated networks, running Linux servers, examining suspicious files, and reproducing enterprise environments.



The setup process feels less straightforward than Parallels, particularly for people installing Windows for the first time. Downloads also require a Broadcom account. However, Fusion delivers excellent value because the Pro edition is free for all supported uses.



3. UTM: Best Open-Source Virtual Machine Software for Mac







UTM is a free and open-source virtual machine application built specifically for Apple platforms. It uses Apple’s Hypervisor framework to virtualize ARM64 operating systems at near-native speeds on Apple silicon Macs.



UTM can also emulate processors that do not match the Mac’s hardware architecture. For example, it can emulate an x86 system on an Apple silicon Mac, allowing you to experiment with older versions of Windows or specialised Linux distributions.



Supported architectures include:




ARM64



x86 and x86-64



ARM32



PowerPC



MIPS



RISC-V




Virtualization provides much better performance when the guest and host processor architectures match. Emulation translates instructions between different architectures, which requires considerably more processing power.



UTM provides downloadable configurations for Windows, Ubuntu, Debian, Kali Linux, Arch Linux, and other operating systems. Its Windows 11 configuration supports ARM64 and recommends 8GB of virtual memory.



UTM suits students, developers, security researchers, and enthusiasts who want more control without paying for a commercial product. Its graphics performance and desktop integration generally fall behind Parallels, so it is less suitable for demanding Windows applications or 3D software.



4. Oracle VirtualBox: Best for Cross-Platform Test Environments







VirtualBox has long been a popular free virtualization tool for Windows, Linux, and Intel-based Macs. It offers snapshots, shared folders, command-line management, virtual networking, and portable virtual disk formats.



Oracle now provides an Arm64 package for Apple silicon Macs, but the Apple silicon version still has several restrictions. Oracle documents limitations involving audio, storage, graphics, Guest Additions, unattended installation, and saved states on Arm hosts.



VirtualBox remains useful when a development team needs similar virtual machine configurations across multiple host operating systems. It also works well for lightweight Linux testing, training labs, network experiments, and older Intel Mac environments.



Mac users with Apple silicon should choose VirtualBox only after confirming that it supports the required guest operating system and features. VMware Fusion or UTM generally provides a more complete experience on current Macs.



5. Tart: Best for Developers and Continuous Integration







Tart is a specialised virtualization tool for building, running, and managing macOS and Linux virtual machines on Apple silicon. It focuses on command-line workflows, automation, reproducible images, and continuous integration rather than general desktop use.



Developers can clone prepared virtual machine images, run automated tests, create clean macOS environments, and integrate virtual machines into CI pipelines. Tart requires an Apple silicon Mac running macOS 13 Ventura or later.



Tart is a good option for:




Testing Mac applications across clean environments



Running automated macOS builds



Creating self-hosted CI runners



Managing reusable macOS and Linux images



Reproducing development environments




It does not aim to provide the simple Windows experience found in Parallels, and its command-line workflow makes it unsuitable for many casual users.



What to Check Before Installing a Virtual Machine



Before choosing virtual machine software, check your Mac’s processor, available memory, storage capacity, and required guest operating system.



An Apple silicon Mac should use ARM64 versions of Windows and Linux whenever possible. Parallels requires an Arm-based installation image when creating a Windows virtual machine on Apple silicon.



For comfortable performance, consider these starting allocations:



Guest operating systemRecommended RAMRecommended storageWindows 118GB or more64GB or moreDesktop Linux4GB or more30GB or moreLinux server2GB or more20GB or moremacOS testing VM8GB or more60GB or more



Avoid assigning all available processor cores or memory to the virtual machine because macOS still needs enough resources to remain responsive. A Mac with 16GB of unified memory can handle one moderate virtual machine, while 24GB or 32GB provides more room for development tools and multiple environments.



Which Mac Virtual Machine Software Should You Choose?



Choose Parallels Desktop when you want the easiest and most polished way to run Windows applications. VMware Fusion Pro is the strongest free option for developers, IT professionals, and users comfortable configuring virtual machines manually.



UTM works well for open-source virtualization, processor emulation, and older operating systems. VirtualBox remains useful for portable cross-platform labs, although its Apple silicon support has important limitations. Tart is the right choice for automated macOS and Linux testing on Apple silicon.



For most Mac users, Parallels Desktop provides the best overall experience. VMware Fusion Pro offers the best balance of advanced features and zero licence cost.]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 1,39ms -->